Apna Angan · Privacy Policy
Jurisdiction: India (DPDP Act 2023) + global · Last updated: 2026-05-06
Apna Angan — Privacy Policy
Status — v1.0 working draft (2026-05-06). Drafted to align with the Digital Personal Data Protection Act 2023 (DPDP Act) and DPDP Rules 2025. Bracketed
[BROTHER REVIEW]markers indicate sections where Indian counsel should focus.
Effective date: [BROTHER REVIEW: confirm this is the date the app first goes live to any Indian user, even closed beta] Last updated: 6 May 2026 Operator: Storm Forge Pty Ltd (Australian Proprietary Company, ACN 697 468 081, ABN 71 697 468 081), trading as AppTree, publisher of Apna Angan. Contact for privacy queries: privacy@apptree.com.au Grievance Officer (DPDP § 8(10)): Venkat Ravilla — privacy@apptree.com.au
1. Who we are and who this policy applies to
Apna Angan is a household coordination application published by AppTree, the trading name of Storm Forge Pty Ltd, an Australian proprietary company. We act as a Data Fiduciary under the DPDP Act 2023 in respect of personal data of users in India. Throughout this policy, “we,” “us,” “AppTree,” and “Apna Angan” refer to the same operator.
This policy applies to your use of the Apna Angan mobile application and any related services (including this website). It covers personal data of:
- Data Principals in India (governed by the DPDP Act 2023 and DPDP Rules 2025)
- Users in jurisdictions outside India (governed by applicable local laws to the extent they apply)
Children’s data. A “child” under the DPDP Act means a person under eighteen (18) years of age. Apna Angan supports a “Junior” role for children. Junior accounts are created and operated by the household head (a parent or legal guardian) under verifiable parental consent — see section 8.
[BROTHER REVIEW: confirm we should reference DPDP Rules 2025 by name, and whether “Data Principal” is the preferred term in our customer-facing copy, or if we should use plainer language and define it once.]
2. What personal data we collect
Apna Angan is built around an on-device-first architecture. The Free tier never sends your household content to our servers. The Premium tier encrypts content on your device before any sync. We collect only the minimum personal data needed to operate the service.
| Category | What | When |
|---|---|---|
| Account identifier | Google account email | When you sign in with Google for backup or AI features |
| Display name + photo URL | From your Google profile | If you grant the userinfo.profile scope at sign-in |
| Subscription state | Google Play Billing entitlement (active / cancelled / paused) | When you subscribe to Premium or buy a top-up. We do not receive your card or payment details — Google holds those. |
| Bug reports you choose to send | The note you typed, optional screenshot, app version, device model, OS version, last 200 lines of debug log | Only when you tap “Send bug report” |
| Crash diagnostic logs | Stack trace, app version, device model | Automatically via Firebase Crashlytics when the app crashes — no household content |
| Calendar events from calendars you select | Title, start, end, location, all-day flag — only from the calendars you opt in to | Only after you grant READ_CALENDAR permission AND select which calendars (see Section 4a) |
We do not collect:
- Your contacts, SMS, call logs, or call history
- Your location (foreground or background)
- Microphone or camera content unless you explicitly invoke a feature that uses them, and even then the captured content stays on your device
- Browsing history outside the app
- Identifiers used for cross-app tracking or advertising
[BROTHER REVIEW: confirm this list is complete — particularly whether Firebase Crashlytics receipt of a stack trace counts as “personal data” under DPDP. Also: do we need to call out the Drive backup token explicitly here?]
3. How household content is stored
| Tier | Where the content lives |
|---|---|
| Free | Entirely on your device. Nothing about your tasks, bills, recipes, calendar, or family is sent to our servers. |
| Premium (sync on) | Content is encrypted on your device with a key derived from your household password. The encrypted blob is the only thing that ever reaches storage. We cannot decrypt it. |
| Drive backup (any tier — opt-in) | Encrypted blobs are written to your own Google Drive, in a folder we create on first run. We do not have access to your Drive contents. |
Zero-knowledge. Because encryption happens on your device with a key we never see, even if our infrastructure or your Drive folder were breached, the content would be unreadable to the attacker. The trade-off: if you forget your household password, the encrypted backup cannot be recovered. We do not run a key-recovery service.
[BROTHER REVIEW: please confirm the language “zero-knowledge” is acceptable here, or if Indian counsel prefers a plainer term (“end-to-end encrypted” / “your-key-only encryption”).]
4. Why we process the data we collect (purpose limitation)
Under DPDP § 5, we process your personal data only for the purposes you have consented to:
- To provide the Service — render your tasks, bills, recipes, calendar; sync across your devices when you turn sync on
- To deliver Premium AI features — Daily Story, Predictive Engine, voice transcription, Tell Angan brain-dump parsing
- To send subscription receipts and renewal reminders via Google Play Billing
- To respond to your bug reports and grievances
- To diagnose crashes and improve reliability
- To comply with legal obligations (tax filings, regulatory requests)
We do not:
- Sell your personal data
- Trade your personal data with advertisers
- Use your personal data to train any AI model
- Display advertising in any form, in any AppTree product
4a. Calendar data (when you enable it)
If you grant Apna Angan permission to read your phone’s calendars, the following terms apply:
You choose which calendars to read. When you first grant permission, Apna Angan shows the list of calendars on your device and asks you to pick which ones to import. Personal calendars are suggested by default. Work, Birthdays, and Holidays calendars are off unless you explicitly turn them on.
What we read. Only the events from the calendars you select. For each event we read: title, start time, end time, location, all-day flag. We do not read attendees, organizers, full descriptions, or event content beyond what’s listed here.
What we filter out. Even from selected calendars, the following are skipped automatically (you can disable each filter in Settings):
- Events you declined
- Events with titles containing “private” or “confidential”
- Events with titles matching common work patterns (“standup”, “1:1”, “sprint”, “OKR”, “all-hands”, etc.)
- Recurring events with more than four occurrences (likely work cadences)
Where calendar data lives. Calendar events are imported into your local Apna Angan database on your phone. They are NOT sent to our servers. If you have Premium sync enabled, encrypted blobs of the imported events go into your own Google Drive folder, never our infrastructure.
Two-way sync. When Apna Angan refreshes from your selected calendars (every 12 hours by default), we reconcile: new events are imported, changed events update, and events that were deleted from the source calendar are removed from Apna Angan.
Pause and revoke. You can pause calendar sync at any time in Settings → Calendar Sync. To revoke OS-level access entirely, use Android Settings → Apps → Apna Angan → Permissions → Calendar.
Source attribution. Every imported event is tagged in our local database with the source calendar’s ID and the device’s external event ID, so you can always tell which events came from your calendar vs. which were created inside Apna Angan.
[BROTHER REVIEW: please confirm this calendar-source disclosure satisfies DPDP § 5 (notice) granularity for the calendar processing path. We want it explicit because reading a user’s calendar is sensitive.]
5. Bug reports
When you send a bug report from the app, we receive:
- The note you typed
- The screenshot you chose to attach (you can untick “Include screenshot”)
- The route you were on, app version, device model, OS version
- Recent crash summaries (no household content)
- The last 200 lines of the app’s debug log
The screenshot shows exactly what was on your screen at the moment of capture. You are asked to review it before sending. We retain bug reports only for the duration needed to investigate and respond — typically up to 90 days, then deleted.
6. AI features
Apna Angan’s Premium AI features (Daily Story, Predictive Engine, voice intent classification, Tell Angan extraction) call Google Gemini APIs.
Managed AI mode (default for Premium): AppTree holds an API key with Google. Your AI requests pass from your phone, through Google’s Gemini API under that key, and return to your phone. The request body goes to Google, not to AppTree servers. We never read your AI prompts or responses. Google operates Gemini under its own privacy terms — see Google’s Generative AI Privacy Notice.
AI is optional. A toggle in Settings → AI turns AI features off entirely. With AI off, your token bucket is zero; no AI calls leave your phone; voice and Daily Story are hidden. Tasks, bills, reminders, recipes, and the Tell Angan typed splitter all continue to work locally. By design:
- Junior (kids) accounts have AI hardcoded off. Even a household head cannot enable AI for a Junior. Child-safety baseline.
- Crew (household help) accounts have AI hardcoded off. Crew has a reduced application surface; AI is not part of it.
[BROTHER REVIEW: please confirm this section is sufficient to satisfy DPDP § 5 (notice) and § 6 (consent) for the AI processing — we may need to be more explicit about the Google sub-processor relationship and the cross-border transfer it implies under DPDP § 16.]
7. Your rights as a Data Principal
Under the DPDP Act 2023 you have the following rights regarding your personal data:
Right to access (§ 11(1)). You can request a summary of the personal data we hold about you, and details of any processing activity.
Right to correction or erasure (§ 12). You can ask us to correct inaccurate data, or to erase data we hold. The app provides:
- Settings → Account → Export my data — generates a JSON file of everything we hold
- Settings → Account → Delete my account — wipes your account from our records and revokes any cloud sync. Local data on your device can be wiped via Android factory-reset of the app
Right to grievance redressal (§ 13). You can file a complaint with our Grievance Officer (contact below). We will respond within 30 days.
Right to nominate (§ 14). You can nominate another person to exercise your rights in the event of your death or incapacity. Contact our Grievance Officer to register a nominee.
Right to withdraw consent (§ 6). You can withdraw consent at any time via Settings → Account → Delete my account. Free-tier features remain available. Premium features that depend on processing will stop.
To exercise any of these rights, contact our Grievance Officer at the address below.
[BROTHER REVIEW: confirm § 11, § 12, § 13, § 14, § 6 references are correct in the DPDP 2023 text and whether the 30-day response window matches DPDP Rules 2025 prescription.]
8. Children (under 18)
Apna Angan supports a Junior role for children in the household.
- Junior accounts can only be created by the household head (a parent or legal guardian)
- Creating a Junior account constitutes the household head’s verifiable parental consent for that child’s data to be processed under the household subscription
- Junior data is stored on the household head’s device, encrypted, and follows the same protections as all other household data
- AI features are hardcoded OFF for Junior accounts. No exceptions, no toggles
- We do not target advertising at children (we do not advertise at all)
- We do not track Junior behaviour for any purpose other than the household-coordination features (chore tracking, school information, medication reminders)
If you believe we hold data of a child without verifiable parental consent, contact our Grievance Officer immediately and we will erase that data.
[BROTHER REVIEW: DPDP § 9 governs children. Please confirm the verifiable-parental-consent mechanism (i.e. household-head action constitutes consent) holds up under § 9, and whether we need any additional age-verification gating.]
9. Crew (household help) — special protections
Apna Angan supports a Crew role for domestic workers, drivers, cooks, and similar household helpers who are members of your household. Crew dignity is a brand commitment and a compliance commitment:
- Crew can decline tasks with an optional reason
- Crew can leave a household at any time without losing their account; their personal record carries via personGlobalId
- Crew receive only a reduced subset of household data — they do not see medical records, financial accounts, or family-graph relationships
- AI features are hardcoded OFF for Crew accounts. By design
- Crew salary, leave, and escalation chains are tracked respectfully — not as rounding errors
Household heads agree, by accepting these features, to respect Crew rights. Misuse may result in suspension under our Acceptable Use Policy (see Terms of Service).
10. Data retention
Our default retention philosophy is forever-on-your-device for household content (you control deletion). For data we hold on our side:
| Data | Retention |
|---|---|
| Account identifier (email) | Retained while account is active. Erased on Delete-my-account. |
| Subscription state | Retained while subscription is active + 7 years (Indian tax record requirement) |
| Bug reports | Up to 90 days, then deleted |
| Crash diagnostics | 90 days rolling, anonymised summary thereafter |
| Encrypted backup blobs (Drive) | Stored on YOUR Drive — you control retention |
[BROTHER REVIEW: 7-year retention for subscription state — please confirm under Indian tax/audit requirements (Income Tax Act § 44AA and applicable rules).]
11. Cross-border data transfers
DPDP § 16 governs transfers of personal data outside India. Your data may be processed outside India in the following ways:
- Storm Forge servers are physically in Mumbai (asia-south1) — no cross-border transfer for sync data
- Google Gemini API (when AI is on) is a Google service that may route requests to Google data centres globally. Google operates under its own Privacy Notice and applicable agreements
- Google Drive backup is hosted by Google under your account; routing is governed by Google’s data residency policies
- Google Play Billing routes payment data through Google; we do not see card data
- Crashlytics (Firebase) sends anonymised crash diagnostics to Google infrastructure
The Indian government has not, as of the date of this policy, restricted transfer of personal data to any of these jurisdictions or providers. If the Government issues such a restriction, we will update our practices to comply.
[BROTHER REVIEW: cross-border transfer rules under DPDP § 16 await Central Government notification of “negative list” countries. Please confirm we are aligned with the most recent guidance.]
12. Security
We use commercially reasonable technical and organisational measures to protect your data, including:
- Zero-knowledge encryption for all household sync content (AES-256, key derived on device)
- Biometric lock on the app
- Encrypted Drive backup (you hold the key)
- API keys restricted to the Apna Angan Android package and SHA-1 fingerprint
- Cloud Console budget alerts to prevent runaway compute costs
- Cloud Crashlytics to detect and triage incidents
No system is perfectly secure. If a breach occurs, we will:
- Notify our Grievance Officer immediately
- Notify affected Data Principals within the time prescribed by DPDP Rules 2025
- Notify the Data Protection Board of India in the prescribed manner
- Investigate the cause and patch
[BROTHER REVIEW: DPDP Rules 2025 specify breach notification timelines — please verify and slot the exact “within X hours” language here.]
13. Grievance redressal
Under DPDP § 8(10) and § 13, AppTree appoints a Grievance Officer to handle Data Principal complaints.
Grievance Officer: Venkat Ravilla Email: privacy@apptree.com.au Address: [BROTHER REVIEW: insert Storm Forge registered address — Sydney, NSW, Australia] Response time: within 30 days of receipt of a complete complaint
If you are not satisfied with our response, you may approach the Data Protection Board of India under DPDP § 27.
[BROTHER REVIEW: as a foreign Data Fiduciary, do we need a separate India-resident Grievance Officer? Please confirm. If yes, this is a hire we’d need to make before paid GA.]
14. Data Protection Officer
Under DPDP § 10, only Significant Data Fiduciaries must appoint a Data Protection Officer. AppTree has not been classified as a Significant Data Fiduciary as of the effective date of this policy. We will appoint a DPO if and when classified, and update this policy.
For all privacy queries, contact our Grievance Officer (above).
15. Changes to this policy
We will publish material changes at least 30 days before they take effect, and notify Data Principals via in-app banner. The “Last updated” date at the top of this policy reflects the latest revision.
16. Contact
Storm Forge Pty Ltd t/a AppTree [BROTHER REVIEW: insert registered address] ABN 71 697 468 081 · ACN 697 468 081
privacy@apptree.com.au · support@apptree.com.au
Reviewer notes for [BROTHER REVIEW]:
- Whole-doc tone check: is this DPDP-compliant in language and structure? Is anything misleading or under-stated?
- Section-by-section bracketed prompts marked
[BROTHER REVIEW]highlight specific items.- Indian-resident Grievance Officer requirement (§ 13) — likely yes for a foreign Data Fiduciary; please confirm.
- SDF classification triggers (§ 14) — confirm we don’t qualify yet.
- Children’s verifiable parental consent (§ 9) — confirm household-head action satisfies this.
- 30-day grievance response window — confirm matches DPDP Rules 2025.
- 7-year subscription retention — confirm under Income Tax Act.
- Cross-border transfer rules (§ 16) — confirm aligned with most recent Central Government guidance.
- Breach notification timeline — slot exact prescribed timing from DPDP Rules 2025.