1. Introduction
Sanctuary ("Sanctuary", "we", "us", or "our") is a mobile application for library and study-space management in India. It helps library owners ("Managers") register students, assign seats, track study activity, send announcements, and collect membership payments. Students ("Students") use the app to access their membership, check in, view alerts, and pay renewals where enabled.
This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use the Sanctuary Android app (package name: com.sahgal.sanctuaryy) and related backend services.
The data controller for personal information processed through Sanctuary is:
Privacy / data requests: sanctuary.app.noreply@gmail.com
By creating an account, registering a student, or using Sanctuary, you agree to this Privacy Policy. If you do not agree, please do not use the app.
2. Who this policy applies to
This policy applies to:
- Library Managers — individuals who operate a library or study centre and use Sanctuary to manage their business.
- Students — individuals registered by a Manager to hold a seat or membership at that library.
Managers act as the primary point of contact for their Students' library relationship. Some data is visible only between a Student and their registering Manager.
3. Information we collect
We collect information you provide directly, information generated through use of the app, and limited device/technical data.
3.1 Account and identity
| Data | Who | Purpose |
|---|---|---|
| Full name | Managers, Students | Profile and library operations |
| Email address | Managers, Students | Login, account recovery, optional 2FA OTP |
| Password | Managers, Students | Authentication (stored securely via Firebase Auth; we do not store plain-text passwords) |
| Phone number | Managers | Account verification, trial registry, support |
| Student ID (e.g. SCH-XXX-1234) | Students | Login identifier (used with a password) |
3.2 Library and membership data
| Data | Who | Purpose |
|---|---|---|
| Library name, address, location coordinates | Managers | Library profile, student discovery, seat management |
| Desk/seat assignment, wing, time slots | Students | Seat booking and access rules |
| Membership plan, tier, expiry, status | Students | Access control and renewals |
| Registration type (monthly/temporary), booking dates | Students | Temporary or monthly memberships |
3.3 Aadhaar number (sensitive personal data)
When a Manager registers a Student, the registration flow may collect the Student's Aadhaar number (12 digits) to help generate a unique Student ID and credentials.
- Purpose: Identity verification for library registration only (internal ID generation).
- Storage: Stored in our secure database (Google Firebase Firestore) as part of the student record managed by the library.
- We do not sell Aadhaar data or use it for advertising.
- Retention: Kept while the student record is active; deletion requests are handled as described in Section 10.
3.4 Payment and financial information
| Data | Who | Purpose |
|---|---|---|
| Payment amount, plan, method (e.g. Razorpay online, Razorpay QR, cash) | Students / Managers | Membership payments and records |
| Transaction IDs, order IDs, payment status | Managers | Wallet, earnings, admin reconciliation |
| Platform fee and settlement metadata | Managers | Sanctuary fee (2%) and manager payout calculations |
| Bank account holder name, account number, IFSC, bank name | Managers | Withdrawal of earned balance to bank (payouts) |
| UPI ID (optional) | Managers | Display or payment configuration where enabled |
Card, UPI, and netbanking details entered during Razorpay checkout are processed by Razorpay Software Private Limited. We do not store full card numbers or UPI PINs. Cash payments are recorded by the Manager in the app; physical cash is not held by Sanctuary.
3.5 Study, attendance, and usage data
| Data | Who | Purpose |
|---|---|---|
| Check-in / check-out status and timestamps | Students | Library attendance |
| Focus hours, weekly goals, streaks, study calendar days | Students | Analytics and motivation features |
| Task completion, printing balance (if used) | Students | Library-specific features |
3.6 Device and technical data
| Data | Who | Purpose |
|---|---|---|
| Firebase Cloud Messaging (FCM) device token | Managers (and where enabled, Students) | Push notifications (alerts, renewals, broadcasts) |
| App version, device OS | All users | Support, security, compatibility |
We do not continuously track your location in the background.
3.7 Location data
| Data | Who | Purpose |
|---|---|---|
| GPS / coarse location (when you grant permission) | Managers | Setting or updating the library's address on a map |
Location is used only when you actively use the library location feature. We do not use location for unrelated advertising or profiling.
3.8 Communications and content
| Data | Who | Purpose |
|---|---|---|
| Broadcast messages, images, PDFs | Managers → Students | Library announcements |
| In-app notifications | System → Users | Plan expiry, payments, alerts |
| Support messages you send us | Managers | Customer support |
Photos and files uploaded are stored using Cloudinary and linked to your account or library.
3.9 Security features (optional)
| Data | Who | Purpose |
|---|---|---|
| Email OTP for two-factor authentication | Managers | Extra login security |
| OTP records (temporary) | Managers | Verification; deleted after use |
4. How we use your information
We use personal information to:
- Create and manage Manager and Student accounts.
- Operate seat assignment, membership, check-in, and study statistics.
- Process payments through Razorpay and record cash payments initiated by Managers.
- Calculate platform fees, manager wallet balances, and payout requests.
- Send push notifications and in-app alerts (e.g. plan expiry, broadcasts, payment confirmations).
- Provide customer support and respond to your requests.
- Improve security, prevent fraud, and enforce our terms.
- Comply with applicable law and respond to lawful requests.
5. Legal bases (India)
Where applicable under Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP Act), we process personal data based on one or more of the following:
- Consent — e.g. when you register, enable notifications, or provide optional data.
- Performance of a contract — providing the Sanctuary service you signed up for.
- Legitimate interests — securing the platform, preventing abuse, and improving reliability (balanced against your rights).
- Legal obligation — where we must retain or disclose data under law.
For certain sensitive personal data (such as Aadhaar), we rely on clear purpose limitation tied to library registration and your Manager's role in providing the service.
6. Sharing with third parties
We share personal data only as necessary to provide the service:
- Google Firebase — Authentication, Firestore database, Cloud Functions, and FCM push notifications. Data may be stored on Google servers.
- Razorpay Software Private Limited — Payment processing, order management, and payout disbursements. Subject to Razorpay's Privacy Policy.
- Cloudinary — Cloud storage for images and file uploads (profile photos, broadcast attachments).
- Email/OTP service provider — Sending 2FA OTP emails to Managers where enabled.
These are data processors acting on our instructions, not independent data controllers who can use your data for their own purposes.
We may disclose data if required by law, court order, or government authority, or to protect the rights or safety of users and the public.
We do not sell, rent, or share your personal data with advertisers or unrelated third parties.
7. Data retention
We retain personal data as long as your account is active or as needed to provide the service. For Managers, data is retained until account deletion is requested and processed. For Students, data is retained as part of the library record maintained by the Manager.
Payment records and transaction logs may be retained longer where required by law or for audit purposes.
Managers can remove or update student records through the app. Deletion of a Firebase Auth account may not automatically delete all Firestore records; contact us if you need help.
Backup and log data held by Google Firebase may persist for a limited time according to Google's systems.
8. Security
We use industry-standard measures including:
- HTTPS encryption for data in transit.
- Firebase Authentication for secure sign-in.
- Firestore security rules so users can access only data they are authorised to see.
- Server-side validation for payments and sensitive operations (Cloud Functions).
No method of transmission or storage is 100% secure. You are responsible for keeping your password confidential and logging out on shared devices.
9. Your choices and rights
Depending on applicable law (including the DPDP Act), you may have the right to:
- Access personal data we hold about you.
- Correct inaccurate data (many fields can be updated in-app or via your Manager).
- Delete your data or request account closure.
- Withdraw consent where processing is consent-based (e.g. notifications — disable in device settings).
- Nominate another person to exercise rights on your behalf in certain cases (as per DPDP Act).
How to exercise your rights
Email sanctuary.app.noreply@gmail.com with: your name and role (Manager or Student), registered email or Student ID, and a clear description of your request. We aim to respond within 30 days. Students should also contact their library Manager for data held in the context of that library.
Push notifications: You can disable notifications in your device Settings → Apps → Sanctuary → Notifications.
Location: You can deny location permission; you can still set library address manually.
10. Account deletion
- Managers: To delete your Sanctuary manager account and associated library data, email sanctuary.app.noreply@gmail.com. We will verify ownership and process deletion subject to legal retention needs (e.g. payment logs).
- Students: Contact your library Manager to remove your membership. For complete erasure of data from our systems, email us with your Student ID and library name.
Deletion may be irreversible. Some anonymised or aggregated statistics may remain.
11. Children
Sanctuary is designed for library-managed study spaces, not for direct sign-up by young children under 13. Students are typically registered by a Manager (library owner). If you believe we have collected personal data from a child without appropriate consent, contact sanctuary.app.noreply@gmail.com or the registering library so we can take appropriate action.
12. International data transfers
Our service providers (including Google Firebase and Cloudinary) may process data on servers located outside India (e.g. United States or other regions). Where data is transferred internationally, we rely on the service providers' contractual and security safeguards and applicable legal requirements.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date. For material changes, we may notify you through the app or by email where appropriate.
Continued use of Sanctuary after changes means you accept the updated policy.
14. Grievance and contact
For privacy questions, complaints, or data requests:
Email: sanctuary.app.noreply@gmail.com
For general app support (non-privacy): use in-app Sanctuary Support or the contact details shown in the app.
If you are not satisfied with our response, you may have the right to lodge a complaint with the Data Protection Board of India under the DPDP Act, once fully operational, or seek remedies under applicable law.