This policy explains how Varun Rao, doing business as Parampara ("we", "us"), handles your information when you use the Parampara app and the website at myparampara.in.

The most important thing to know: your vault is locked on your own device with a key made from your secret phrase, which never leaves your phone. That means we cannot read the contents of your vault. Not our team, and not anyone who might break into a server. The only things we can read are your account email, records of when you signed in, and anonymous notes about which screens were used. Never what is inside.

1. What we collect

Information we can read: your account email address, so you can sign in and we can send you essential messages. On the website, standard technical data such as IP address and browser type, to keep the site secure.

Sign-in records, to protect your account: each time you sign in we record the time, the sign-in method, the device description your phone reports, and the city we estimate from your internet address. We use this only to spot suspicious access to your account. We never take location from your phone's GPS.

App usage, to improve the app: we record which screens are opened and which kinds of action happen (for example "an entry was added" and its category, or "an invitation was sent"). These records carry no vault content: no titles, no numbers, no names, no email addresses. If the app crashes, we receive a technical crash report to fix the fault. If you installed the app from a link we shared, we record which campaign it came from.

Information we store but cannot read: everything you put inside your vault, including insurance, bank and investment details, property records, wills, nominee details, gold, government IDs such as PAN or Aadhaar if you choose to add them, and any photos or PDFs of papers you attach. This is all locked on your device before it is saved. We store only scrambled data we cannot open. The names of the people you invite as trusted family are also stored scrambled; our servers hold only a one-way fingerprint of an invitee's email, never the address itself.

2. How your vault stays private

Your device creates an encryption key from your secret phrase. That phrase and key never leave your phone. Each item is locked before it is uploaded, so we only ever store data we cannot read. Your recovery code, your safety net if you forget your phrase, also only exists on your device and in the copy you save. If you lose both your phrase and your recovery code, not even we can open your vault. That is the honest trade-off of real privacy.

3. How we use your information

We use the little we can read only to run the service: to create your account and sign you in, to send you essential messages, to keep the service secure, to answer your questions, and to meet legal duties. We do not use your vault contents for anything, because we cannot read them. We do not profile you, show ads, or sell your data.

4. When and with whom we share

We do not sell your personal information, and we never share your vault contents, because we cannot read them. We rely on a small number of service providers who process data only on our instructions:

  • Supabase: hosting, database, sign-in and file storage. Your account and your encrypted vault live here, on servers in India.
  • Resend: sending the emails you receive from us, such as sign-in codes and family invitations.
  • PostHog (European Union): the app-usage records described above.
  • Sentry (European Union): crash reports.
  • Cloudflare: serving this website.

Only the encrypted, unreadable form of your vault ever reaches any of them. When you give a family member access, their copy of the key is created on your phone and sealed so that only they can open it; we never hold a key that opens your vault. We may disclose information if required by law, but vault contents remain unreadable to us and to anyone without your key.

5. Cookies

Our website uses essential cookies and a small amount of privacy-respecting analytics to improve the site. None of these can see inside your vault. Neither the website nor the app carries advertising trackers, and we do not use advertising identifiers.

6. How long we keep your information

We keep your account information and your encrypted vault for as long as your account is active. When you delete your account, we delete your account data and your encrypted vault from our active systems. Any residual copy in backups is purged on our regular cycle, and remains unreadable to us.

7. Children

Parampara is for adults (18+). We do not knowingly collect information from children.

8. Your rights under the DPDP Act

We aim to align with India's Digital Personal Data Protection Act, 2023. As a Data Principal you may access a summary of the personal data we process, correct or complete it, ask us to erase it, withdraw consent, and nominate another person to exercise your rights. To do any of these, email [email protected]. We may need to verify your identity first. Your personal data is stored in India.

9. Grievance Officer

You can raise any concern about how your data is handled with our Grievance Officer:

Varun Rao, Parampara
Email: [email protected]
Bengaluru, Karnataka 560103, India

We aim to acknowledge grievances within 72 hours.

10. Updates and contact

We may update this policy from time to time; the date above will change, and we will tell you in the app or by email if the change is significant. Questions? Write to [email protected].