Privacy Policy
Effective Date: September 26, 2026 • Version 3.0 • Compliance: GDPR, CCPA/CPRA & Indian DPDP Act 2023
1. Identity of the Data Controller
This Privacy Policy governs the collection, use, and protection of personal data by Promise Technologies Pvt. Ltd. ("Promise," "we," "us," or "our"). We are committed to safeguarding personal integrity and digital sovereignty.
For questions or requests regarding your personal data, you may reach our Data Protection and Grievance team at privacy@sovereign-promise.app.
2. Our Core Principle: Privacy as Honor
Zero Data Brokering Pledge: We do not sell your personal data. We do not rent, broker, or trade personal identifiers. We do not serve third-party advertisements or profile your habits for advertising networks. Your private vows and diary entries are yours alone.
Our revenue model relies entirely on voluntary in-app digital purchases (Artisan and Masterwork seals) and optional Pro subscriptions.
3. Information We Collect and How We Collect It
We practice strict data minimization. We only process information necessary to provide the service:
A. Information Stored Locally on Your Device
- Personal Promises, Vows, and Habits: Stored on your device in an encrypted local database.
- Private Sanctuary Diary & Voice Reflections: Secured using AES-256-GCM encryption with keys held in your device hardware keystore (Android Keystore / iOS Keychain). We cannot read your private diary entries.
- Morning Awakening Alarm Preferences: Stored locally on your device.
B. Information Stored in Cloud Services (When Online Sync is Active)
- Public Username Handles (@handle): Claimed handles are registered in our central Firestore directory to enable mutual pact invitations and social witness signing without exposing personal phone numbers or email addresses.
- Authentication Identifiers: If you sign in via Google Sign-In, we record your standard unique user identifier (UID) and email address solely to maintain account ownership, verify handles, and restore purchases. Anonymous guest sessions generate a cryptographic local keypair.
- Encrypted Backup Archives: If you enable Encrypted Cloud Backup, your data is encrypted on your device with your private master passphrase before transmission. We hold the ciphertext; we do not hold your passphrase.
- Sensory Origin Seal Coordinates: If you explicitly choose to attach a physical location stamp to a sacred seal ceremony, the application records coordinates at that single instant. We never run continuous background location tracking.
4. Lawful Bases for Processing (GDPR Article 6)
Under the European General Data Protection Regulation (GDPR) and the UK GDPR, we process personal data under the following legal bases:
- Performance of a Contract (Art. 6(1)(b)): To register your handle, record mutual pacts, process subscriptions, and fulfill requested services.
- Legitimate Interests (Art. 6(1)(f)): To prevent fraudulent handle squatting, secure our infrastructure, and ensure network integrity.
- Consent (Art. 6(1)(a)): For optional precise location tagging on sacred seal ceremonies and local notification reminders. You can revoke consent at any time in device settings.
- Legal Obligation (Art. 6(1)(c)): To maintain tax, financial, and statutory dispute records required by law.
5. Authorized Third-Party Sub-processors
We work exclusively with trusted infrastructure providers who meet rigorous security certifications (SOC 2, ISO 27001):
- Google Cloud Platform & Firebase (Google LLC): Cloud Firestore, Firebase Authentication, Cloud Functions, and Firebase Hosting. Data stored in secure regional data centers under Standard Contractual Clauses (SCCs).
- Google Play In-App Billing (Google LLC): Tokenized payment processing for subscriptions and digital seal licenses on Android.
- Apple StoreKit (Apple Inc.): Tokenized payment processing for subscriptions and digital licenses on iOS.
- Google Gemini API (Google LLC): Powers private philosophical counseling in the Socratic Confidant. Customer prompts submitted to the API are not used to train Google foundation models.
6. Your Global Rights (GDPR & California CCPA/CPRA)
Regardless of your geographic location, we provide comprehensive rights over your personal information:
- Right of Access & Portability: You may export your commitments, diary entries, and verification certificates at any time as JSON or PDF in Settings.
- Right to Rectification: You can edit active commitments, update display settings, or modify profile details directly in the app.
- Right to Erasure ("Right to Be Forgotten"): You have the absolute right to delete your data. You can delete your account in the app or via our Web Account Deletion Portal.
- Right to Restrict or Object to Processing: You may disable cloud sync at any time to run Promise strictly as an offline vault.
- California "Do Not Sell or Share My Personal Information": We do not sell or share personal information for cross-context behavioral advertising. We do not discriminate against users who exercise privacy rights.
7. Data Retention & Permanent Deletion
We retain data only as long as your account remains active. Upon initiating account deletion:
- Your unique handle reservation is released or retired.
- All cloud sync documents, witness signatures, and backup archives are permanently and irreversibly purged from our servers within 48 hours.
- Local data stored on your device is deleted immediately when you trigger in-app deletion or uninstall the app.
8. Statutory Grievance Redressal Officer (Indian IT Act & DPDP Act 2023)
In accordance with the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act 2023, the contact details of our designated Grievance Redressal Officer are:
Designation: Grievance Redressal Officer
Entity: Promise Technologies Pvt. Ltd.
Registered Address: Bengaluru, Karnataka, India
Official Email: grievance@sovereign-promise.app
Statutory SLA: Acknowledgment within 24 hours • Redressal within 15 calendar days.
9. Children's Privacy
Promise is intended for general audiences aged 13 and above (or 16 in the European Union). We do not knowingly solicit or collect data from children under 13. If you become aware that a child has created an account, please email us at privacy@sovereign-promise.app for immediate deletion.
10. Updates to this Policy
We may update this Privacy Policy from time to time. When material changes are made, we will notify you by updating the "Effective Date" at the top of this document and displaying an in-app notice.