Last updated: July 2026
1. Definitions
- “Data Fiduciary” means the Developer (Gowtham Ram M), the sole proprietor operating this Platform.
- “Data Principal” means the User whose personal data is processed.
- “Personal Data” means any data about an individual who is identifiable by or in relation to such data.
- “Processing” means any operation performed on Personal Data.
- “Third-Party Processor” means Google Firebase and other service providers engaged by the Developer.
2. Data Fiduciary & Legal Basis
The Developer acts as the Data Fiduciary under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. All Personal Data is processed based on explicit consent obtained during registration, which the User affirms is given freely, with full knowledge, and for specific lawful purposes as required under Section 6 of the DPDP Act.
The User acknowledges that the Developer is a sole individual developer and not a large corporate entity. Data protection measures are proportionate to the scale of operations and reliance on industry-standard third-party infrastructure.
3. Personal Data Collected
We collect and process the following categories of Personal Data:
- Identity Data: display name, email address.
- Authentication Data: password (hashed by Firebase), Firebase UID, authentication provider metadata.
- Age & Consent Data: self-declared age band; for users under 18 — parent/guardian name, parent/guardian email, recorded parental affirmation, consent timestamp, and consent version identifier.
- Activity Data: reading progress, bookmarks, story completion status, session timestamps.
- Q&A Data: questions submitted through the in-story reader Q&A feature and associated responses.
- Technical Data: anonymized IP address, browser type, operating system, device category (via Firebase Analytics, where enabled).
We do NOT collect: government IDs, payment information, precise geolocation, biometric data, or sensitive personal data as defined under the DPDP Act.
4. Purpose & Legality of Processing
Personal Data is processed strictly for the following lawful purposes:
- To create and maintain user accounts and authenticate access.
- To sync reading progress and bookmarks across devices.
- To fulfil parental-consent obligations for users under 18 under the DPDP Rules, 2025.
- To provide the in-story Q&A feature and enforce daily usage limits.
- To send service-related communications (no marketing without separate opt-in).
- To generate anonymized aggregate analytics for Platform improvement.
- To comply with legal obligations and respond to lawful government requests.
Data is not sold, rented, or traded to any third party for commercial purposes.
5. Parental Consent (Option 2 — DPDP Rules, 2025)
The Platform is designed for young readers. Accounts for users under 18 require a parent or guardian. During registration, users under 18 must:
- Declare their age band.
- Provide a parent or guardian's name and email address.
- Affirm that the parent or guardian has approved use of the Platform.
This affirmation, along with a timestamp and consent version identifier, is recorded and stored as consent metadata. This constitutes pragmatic parental consent (Option 2) under the DPDP Rules, 2025.
DigiLocker or Rule 10 identity-token verification is not yet implemented. Verifiable digital parental consent via DigiLocker or equivalent government-issued identity tokens is planned as a future enhancement. Until then, the Platform relies on the declarative consent process described above.
6. Data Principal Rights under DPDP Act, 2023
Subject to verification of identity and applicable exceptions under Section 12, 13, and 14 of the DPDP Act, every Data Principal has the right to:
- Access: Obtain confirmation of processing and a summary of Personal Data held.
- Correction & Erasure: Request rectification of inaccurate data or deletion of account data.
- Grievance Redressal: Register a complaint with the Grievance Officer (detailed below).
- Nomination: Nominate another individual to exercise rights in case of death or incapacity.
Limitation:The Developer may refuse requests where identity cannot be verified, where the request is manifestly unfounded or excessive, or where compliance would require disproportionate effort given the Developer's status as an individual operator. The User agrees that the Developer's liability for any failure to fulfil a rights request is limited to the extent permitted under the Terms & Conditions.
7. Data Retention & Deletion
- Personal Data is retained only as long as the User's account is active.
- Upon account deletion request, Personal Data is purged within 30 days, except where retention is required by law or for the exercise/defence of legal claims.
- Anonymized analytics data may be retained indefinitely as it is no longer Personal Data.
- Backup systems may retain residual copies for up to 90 days after deletion.
8. Data Storage, Security & Third-Party Processors
Personal Data is stored in Firebase Firestore and Google Cloud Storage (Google Cloud infrastructure). Firebase Authentication manages session cookies and identity tokens.
The Developer relies on Google's security certifications and does not operate independent data centres. Industry-standard measures are applied: TLS encryption in transit, encryption at rest, Firebase Security Rules, and admin-only write access to production data.
No warranty of absolute security is provided. The Developer shall not be liable for data breaches, leaks, or unauthorized access originating from third-party infrastructure failures, zero-day exploits, or force majeure events, to the maximum extent permitted by law.
9. Cross-Border Data Transfers
While primary storage is in India, Google's global infrastructure may process or replicate data in other jurisdictions with adequacy decisions or standard contractual clauses. By using the Platform, the User expressly consents to such transfers as necessary for service delivery.
10. Cookies & Tracking Technologies
We use essential cookies for Firebase Authentication session management. Firebase Analytics may deploy anonymized usage tracking cookies. Users may disable analytics tracking through browser or device settings. No third-party advertising cookies are used.
11. AI Data Processing Disclosure
Story content is generated by third-party artificial intelligence models. The Developer does not train AI models on User Personal Data. Reading history, bookmarks, and Q&A interactions are used solely for internal sync, feature delivery, and usage limits — they are not fed into AI training datasets. AI models may produce inaccurate outputs (“hallucinations”); see our Disclaimer.
12. Limitation of Liability
To THE MAXIMUM EXTENT PERMITTED BY LAW, the Developer's aggregate liability for any claim arising from data protection or privacy matters shall not exceed INR 5,000 (Five Thousand Rupees), fixed and non-negotiable, regardless of whether the Platform is used free of charge or otherwise. No User has paid or will be required to pay any fee for access; therefore, the liability cap is expressly fixed at INR 5,000 and shall not be reduced to zero by operation of any “amount paid” clause. The Developer shall not be liable for indirect, consequential, or punitive damages.
13. Grievance Officer
Name: Gowtham Ram M
Email: gowthamm161@gmail.com
Address: Chennai, Tamil Nadu, India
Response Time: Acknowledgment within 48 hours; substantive resolution within 30 days.
For complaints under the IT Rules, 2021 (Intermediary Guidelines and Digital Media Ethics Code), contact the Grievance Officer at the email above. For content-related complaints, use the subject line: [Content Complaint] <story title or empire>. Unresolved grievances may be escalated to the Data Protection Board of India under the DPDP Act, 2023.
14. Changes to this Policy
The Developer may modify this Privacy Policy at any time. Material changes shall be notified by email or in-app notice. Continued use after changes constitutes binding acceptance. If the User does not agree, they must immediately cease using the Platform and request account deletion.
15. Contact
For questions, data access requests, or complaints, email gowthamm161@gmail.com.