Privacy Policy
Application: Kaagaz (Package Name:
com.easydoc.app) | Domain: kaagaz.net
Kaagaz is designed from the ground up for older adults and families to keep their sensitive papers safe. We treat your personal documents with bank-grade security: your documents are encrypted on your phone using AES-256 hardware keys before anything touches the cloud. We do not sell your data, we do not display advertisements, and we never send your document photos to third-party AI vision models.
1. Introduction & Scope
This Privacy Policy explains how Kaagaz ("we", "our", or "us"), operated under the domain https://kaagaz.net/ and through the Android application Kaagaz (Application ID: com.easydoc.app), collects, uses, encrypts, and handles user and device data.
This policy applies to all users of the Kaagaz Android application and visitors to our website worldwide. It is accessible at all times without login, geofencing, or geographical restrictions at https://kaagaz.net/privacy.html and directly from within the application under Settings → Privacy Policy and Help → Privacy.
2. What Sensitive User & Device Data We Collect and How We Treat It
We practice strict data minimization. We only access and process information that is strictly necessary to provide the core document management and family-sharing functionalities.
| Data Type | Collection Method | Purpose & Security Treatment | Third Parties Shared With |
|---|---|---|---|
|
Phone Number (Personal Identification) |
Entered by user during phone verification; verified via SMS OTP | Used to authenticate your account, allow restoration of encrypted backups on a new phone, and match member identities for live shared family folders. Stored securely via Firebase Authentication. (Optional: users can tap "Skip for now" to use the app in phone-only mode). | Google LLC (Firebase Auth) for SMS OTP delivery. Not shared with any other party. |
|
Photos & PDF Documents (User Files & Media) |
Captured via in-app camera or selected by user via system document picker |
Personal Library: Encrypted on-device using AES-256-GCM hardware keys in Android Keystore before writing to disk. When cloud backup is enabled, files are encrypted under an account key wrapped with the user's secret 5-word recovery phrase. Cloud storage receives only ciphertext. Shared Folders: Decrypted locally and stored in private cloud storage with strict Firestore security rules matching verified member phone numbers. |
Google LLC (Firebase Cloud Storage) for encrypted storage. Never shared with advertisers or AI vision models. |
|
Voice / Audio Clips (Microphone Data) |
Recorded only when user taps the microphone button | Processed ephemerally: sent through our secure Cloud Function proxy to transcribe spoken voice queries into text in Hindi, English, or Hinglish (e.g. "Show electricity bill"). Voice recordings are NOT stored for advertising, user profiling, or model training. | Sarvam Technologies Private Limited (Sarvam AI) as a contracted data processor for speech-to-text conversion. |
|
Contacts (Family Helper & Sharing) |
Single contact picked via Android System Contact Picker |
No Address Book Access: The app holds NO READ_CONTACTS permission. It cannot read or scan your address book. When adding a Family Helper or sharing a folder, the Android system picker returns only the single chosen contact's name and number.
|
Not shared. Helper information remains on the device; shared folder recipient phone number is stored in Firestore security rules to verify membership. |
|
Crash & Diagnostic Logs (Technical Data) |
Automatically generated upon application crash | Anonymized stack traces and device characteristics (Android OS version, device model) to detect and resolve software defects. Does NOT contain document images or personal contents. | Google LLC (Firebase Crashlytics). |
3. Disclosures Regarding Third-Party Service Providers
We do not sell, rent, trade, or transfer your personal data or document contents to third-party commercial entities, data brokers, or advertising networks. We work exclusively with the following contracted service providers who act as data processors bound by confidentiality and data protection agreements:
- Google LLC (Firebase & Google Cloud): Provides cloud database (Cloud Firestore), encrypted object storage (Firebase Storage), authentication infrastructure (Firebase Auth), and crash diagnostics (Firebase Crashlytics). Data is hosted in secure data centers adhering to ISO 27001, SOC 1/2/3, and GDPR standards. Google Privacy Policy.
- Sarvam Technologies Private Limited (Sarvam AI): Provides speech-to-text voice transcription for Indian regional languages and accents. Transcriptions are transmitted via TLS 1.3 through an authenticated server proxy and processed ephemerally. Sarvam AI Privacy Policy.
4. Encryption and Technical Security Architecture
We use defense-in-depth security to protect your family documents:
- On-Device Encryption: Local documents are encrypted using AES-256-GCM via the Android Jetpack Security / Android Keystore system. The decryption keys never leave your physical device.
- Zero-Knowledge Cloud Backup Envelope: Cloud backup encrypts documents under a 32-byte cryptographic account key, which is stretched using PBKDF2-HMAC-SHA256 (210,000 iterations) and wrapped with your 5-word recovery phrase. We do not possess your recovery phrase; if lost, even our administrators cannot decrypt your backup.
- Encryption in Transit: All communication between the app, backend proxies, and cloud storage is encrypted using TLS 1.3.
- App Check & Play Integrity: Backend API endpoints require cryptographic proof from Google Play Integrity to verify that requests originate from an authentic, untampered build of the Kaagaz application.
5. User Data Retention & Deletion Rights
In accordance with Google Play Developer Policy and India's Digital Personal Data Protection Act (DPDPA 2023), you have complete control over your data retention:
- Retention Period: Data is retained only as long as your account remains active. Deleted documents reside in the "Bin" for 30 days before permanent deletion, during which you can restore them with one tap.
- In-App Account & Data Deletion: You can delete all your data directly inside the application by navigating to Settings → Delete my account and documents. This immediately deletes local database entries, clears local encryption keys, purges all cloud backups, and removes shared directory memberships.
- Public Web Deletion Request (Mandatory Google Play URL): If you have uninstalled the app or lost access to your device, you can submit an account deletion request without reinstalling the app at: https://kaagaz.net/delete-account.html.
- Processing Timeline: Verified web deletion requests are completely expunged from all active cloud databases and storage within 48 hours.
6. Children’s Privacy
Kaagaz is designed for adults, older individuals, and family caregivers. The service is not targeted at, nor intended for use by, children under the age of 13 (or under 18 years of age in applicable jurisdictions without parental consent). We do not knowingly collect personal identifiable information from children. If we discover that a child has provided us with personal data, we will immediately delete such data from our servers.
7. Statutory Compliance & User Rights
Under applicable laws, including the Digital Personal Data Protection Act, 2023 (India) and international privacy frameworks, you have the right to:
- Access: Review all personal documents and data stored in your account.
- Correction: Update, edit, or reclassify documents, folder labels, and notes at any time.
- Erasure: Withdraw consent and have your personal information permanently destroyed.
- Grievance Redressal: File an inquiry or complaint with our Data Protection Grievance Officer.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect operational, legal, or regulatory updates. Any material changes will be notified prominently within the Kaagaz application and by updating the "Last Updated" date at the top of this webpage. We encourage users to review this page periodically.
9. Grievance Officer & Contact Details
For any privacy inquiries, grievance escalations, or requests to exercise statutory data rights, please contact our designated Grievance Officer:
Designated Grievance Officer: Data Protection & Privacy Office
Application: Kaagaz (com.easydoc.app)
Email: privacy@kaagaz.net | support@kaagaz.net
Website: https://kaagaz.net/
Response Window: All statutory privacy inquiries and deletion requests are addressed within 30 days.