Privacy Policy

Effective date: 28 July 2026  |  Last updated: 22 September 2026

This Privacy Policy explains how Tax Collars Private Limited (CIN U74999TN2020PTC137643), a company registered in India ("we", "us", "our"), handles your information when you use Privy Manager — our mobile applications for Android and iOS, and our browser-based web app (together, the "App"). Privy Manager is a private messaging app built so that we hold as little of your data as possible — and cannot read what we do hold.

Everything in this Policy applies to all three unless a section says otherwise. Where the web app genuinely differs — because a browser cannot offer what a phone's operating system does — we say so plainly: see §2.6 (reCAPTCHA) and §8 (local security).

By creating an account or using the App, you agree to this Policy. If you do not agree, please do not use the App.

1. The short version

The rest of this Policy is the detail behind those statements.

2. Information we collect

2.1 Account information

2.2 Your content — encrypted

Messages, attachments, photos, files, and voice notes are encrypted on your device before upload (see §3). Our servers store and relay only ciphertext. This includes Personal Notes (conversations with yourself).

2.3 Conversation metadata — not encrypted

To route and deliver messages, our servers necessarily process in readable form:

We use this metadata only to operate the service. We never sell it, share it for advertising, or use it to profile you.

2.4 Device and session information

For each signed-in session we store: the platform (iOS, Android or web), a device name (e.g. "iPhone 15"), whether the device is mobile, session state (active, primary, revoked), sign-in and sign-out times, and a push-notification token. You can view this session history in the App and revoke sessions remotely.

Sign-in records. Each sign-in attempt is logged by our authentication provider, including your IP address and the app or browser identifier your device sent. We also count failed sign-in attempts for each account, to temporarily block password guessing, and notify you the first time your account is blocked this way. We use these records only to protect accounts.

2.5 Reports and support messages

If you report a conversation (§9), the report stores: your account identifier (as reporter), the conversation and reported account identifiers, the subject and description you wrote, whether you marked it illegal or urgent, and references to the messages you cited as evidence. Reported message content itself remains encrypted.

If you write to us from Help & Support in the App, we store your message, the subject you chose and your account identifier, and email them to our support address so we can answer you. A support message is ordinary text, not encrypted content — write it as you would any email.

2.6 Operational data

Standard infrastructure logs (error traces, function invocations, and the sign-in records in §2.4) and abuse-prevention signals (e.g. Firebase App Check attestation, rate-limiting records — the username-recovery rate limiter stores only a one-way hash of the email address). These logs never contain message content.

reCAPTCHA — web app only. The Privy Manager web app uses Google reCAPTCHA Enterprise, through Firebase App Check, to check that requests come from a real browser running our app rather than an automated script. To make that judgement, Google receives technical information about your browser and how you interact with the page, and sets its own cookies; this is governed by Google's Privacy Policy and Terms of Service. We receive only a pass/fail verdict — never the underlying signals, and never anything tied to your messages. There is no puzzle or checkbox to solve; the check is invisible. This applies only to the web app: the Android and iOS apps prove their integrity through Google Play Integrity and Apple App Attest, which do not involve reCAPTCHA.

2.7 What we do NOT collect

3. How encryption works — and its honest limits

Honest limits — please read:

4. How we use information

We use the information in §2 only to:

  1. create and authenticate your account and sessions;
  2. deliver messages, media, and push notifications;
  3. operate the features you invoke (disappearing messages, delete-for-everyone, group moderation, session management, account recovery);
  4. keep the service secure — prevent abuse, spam, and unauthorised access;
  5. review reports filed by users (§9); and
  6. comply with valid legal obligations (§10).

We do not use your information for advertising, profiling, model training, or any purpose unrelated to running the App. We never sell personal data.

5. Push notifications

We use Firebase Cloud Messaging (and, on iOS, Apple Push Notification service) to tell your device that something arrived. Because content is end-to-end encrypted, a notification never carries readable message text from our servers; where the App shows a message preview, your own device fetches and decrypts the message.

To make an alert useful, a notification does carry the sender's name, the conversation's name and the kind of message (for example "Photo" or "Voice note"), readable to the notification service that delivers it to your device (§7). You control this in Settings: Generic removes all three, Secure conversations can be set to In-app only or Off, and you can turn notifications off entirely in your device settings.

6. Device permissions

The App requests permissions only when a feature needs them, and the captured data goes only where you send it:

PermissionUsed forWhere the data goes
CameraTaking photos to send or set as profile photoEncrypted and sent only to the conversation you choose
MicrophoneRecording voice notesEncrypted and sent only to the conversation you choose
Photos / filesAttaching media and documents; exporting your recovery codeEncrypted and sent only to the conversation you choose
NotificationsMessage alertsSee §5
Biometrics (Face ID / fingerprint)Unlocking the App locallyNever leaves your device (§2.7)

Denying a permission only disables the corresponding feature.

7. Where your data lives, and who processes it

We do not run our own data centres. We use a small number of infrastructure processors, bound by their own contractual and legal safeguards:

These providers act on our instructions to run the service. We share nothing with anyone else, except as described in §9 (moderation) and §10 (legal process). If data is processed outside your country, we take reasonable steps to ensure it receives equivalent protection.

8. Data on your device, PINs, and local security

9. Moderation, reporting, and suspension

10. Legal requests

11. How long we keep data

DataRetention
Messages & media (ciphertext)While your account is active — you decide when to delete
Disappearing messagesDeleted on the timer you and your conversation set
Messages deleted "for everyone" / by a group adminRemoved on deletion (a tombstone note may remain)
Account data & conversation metadataPurged from our live systems as soon as the account is deleted — there is no grace period
Inactive accountsDeleted automatically after 365 days without use. We warn you by notification 30 days and 7 days beforehand
Sessions & push tokensDeleted on sign-out/revocation; purged with the account
Reports and support messagesUntil resolved, then 180 days
Operational logs, including sign-in records and IP addresses (§2.4)Up to 90 days, per infrastructure defaults
Failed sign-in countsCleared automatically after 24 hours without a failed attempt
Database backupsUp to 7 days, then deleted automatically
Recovery-email rate-limit hashesRolling short-term window

Deleting an account is immediate and cannot be undone. Whether you delete it yourself or it is removed for inactivity, the same process runs: your profile, conversation metadata, encryption keys, recovery data and the login itself are purged from our live systems in a single pass. We keep nothing back for a recovery window, so export anything you want to keep before you delete. Copies inside our encrypted database backups expire within 7 days; backups exist only to recover from a disaster, never to bring back a deleted account. Operational logs age out on the schedule in the table above.

“Inactive” means nobody has opened the app on any of your devices. Opening it resets the clock and cancels any warning already sent. Because the warnings are notifications, they will not reach you if you have uninstalled the app or turned notifications off — the account is still deleted at 365 days.

Local copies on your own devices (§8) are yours and persist until you remove them.

12. Your rights and choices

Subject to applicable law (for users in India, the Digital Personal Data Protection Act, 2023), you may:

We will respond to verified requests within the time required by law. Note that we cannot identify you from encrypted content — requests must come from your authenticated account or verified recovery email.

13. Children

Privy Manager is not intended for anyone under 18. We do not knowingly collect data from children. Since we collect no age or identity information, we rely on you to meet this requirement; if we learn an account belongs to a minor, we will delete it.

14. Security

We protect your data with, among other measures: end-to-end encryption of content (§3), TLS for all transport, hardware-backed key storage on device, per-account key isolation, server-side access rules that restrict every record to its owner or conversation participants, app-integrity attestation, and rate-limited, non-revealing recovery flows. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and the relevant authorities as the law requires.

15. Changes to this Policy

We may update this Policy as the App evolves. Material changes will be announced in the App before they take effect, with the new effective date shown at the top. Continued use after the effective date means you accept the updated Policy.

16. Contact & Grievance Officer

Tax Collars Private Limited
CIN: U74999TN2020PTC137643
3rd Floor, No. 45, Ceebros Centre, Montieth Road,
Egmore, Chennai, Tamil Nadu 600008, India

Privacy queries: privacy@privymanager.com
Support: support@privymanager.com

Grievance Officer (Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 / DPDP Act, 2023):
Shubham Sarawagi
Tax Collars Private Limited, 3rd Floor, No. 45, Ceebros Centre,
Montieth Road, Egmore, Chennai, Tamil Nadu 600008, India
grievance@privymanager.com

We acknowledge complaints within 24 hours and resolve them within 15 days (or as the applicable rules require).