Android App

Privacy Policy

Sanctuary  ·  com.sahgal.sanctuaryy  ·  Effective: 23 May 2026

1. Introduction

Sanctuary ("Sanctuary", "we", "us", or "our") is a mobile application for library and study-space management in India. It helps library owners ("Managers") register students, assign seats, track study activity, send announcements, and collect membership payments. Students ("Students") use the app to access their membership, check in, view alerts, and pay renewals where enabled.

This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use the Sanctuary Android app (package name: com.sahgal.sanctuaryy) and related backend services.

The data controller for personal information processed through Sanctuary is:

Abhay Sahgal (individual developer)
Privacy / data requests: sanctuary.app.noreply@gmail.com

By creating an account, registering a student, or using Sanctuary, you agree to this Privacy Policy. If you do not agree, please do not use the app.

2. Who this policy applies to

This policy applies to:

Managers act as the primary point of contact for their Students' library relationship. Some data is visible only between a Student and their registering Manager.

3. Information we collect

We collect information you provide directly, information generated through use of the app, and limited device/technical data.

3.1 Account and identity

DataWhoPurpose
Full nameManagers, StudentsProfile and library operations
Email addressManagers, StudentsLogin, account recovery, optional 2FA OTP
PasswordManagers, StudentsAuthentication (stored securely via Firebase Auth; we do not store plain-text passwords)
Phone numberManagersAccount verification, trial registry, support
Student ID (e.g. SCH-XXX-1234)StudentsLogin identifier (used with a password)

3.2 Library and membership data

DataWhoPurpose
Library name, address, location coordinatesManagersLibrary profile, student discovery, seat management
Desk/seat assignment, wing, time slotsStudentsSeat booking and access rules
Membership plan, tier, expiry, statusStudentsAccess control and renewals
Registration type (monthly/temporary), booking datesStudentsTemporary or monthly memberships

3.3 Aadhaar number (sensitive personal data)

When a Manager registers a Student, the registration flow may collect the Student's Aadhaar number (12 digits) to help generate a unique Student ID and credentials.

If you are a Student or parent/guardian with questions about Aadhaar collection, contact your library Manager first, or email sanctuary.app.noreply@gmail.com.

3.4 Payment and financial information

DataWhoPurpose
Payment amount, plan, method (e.g. Razorpay online, Razorpay QR, cash)Students / ManagersMembership payments and records
Transaction IDs, order IDs, payment statusManagersWallet, earnings, admin reconciliation
Platform fee and settlement metadataManagersSanctuary fee (2%) and manager payout calculations
Bank account holder name, account number, IFSC, bank nameManagersWithdrawal of earned balance to bank (payouts)
UPI ID (optional)ManagersDisplay or payment configuration where enabled

Card, UPI, and netbanking details entered during Razorpay checkout are processed by Razorpay Software Private Limited. We do not store full card numbers or UPI PINs. Cash payments are recorded by the Manager in the app; physical cash is not held by Sanctuary.

3.5 Study, attendance, and usage data

DataWhoPurpose
Check-in / check-out status and timestampsStudentsLibrary attendance
Focus hours, weekly goals, streaks, study calendar daysStudentsAnalytics and motivation features
Task completion, printing balance (if used)StudentsLibrary-specific features

3.6 Device and technical data

DataWhoPurpose
Firebase Cloud Messaging (FCM) device tokenManagers (and where enabled, Students)Push notifications (alerts, renewals, broadcasts)
App version, device OSAll usersSupport, security, compatibility

We do not continuously track your location in the background.

3.7 Location data

DataWhoPurpose
GPS / coarse location (when you grant permission)ManagersSetting or updating the library's address on a map

Location is used only when you actively use the library location feature. We do not use location for unrelated advertising or profiling.

3.8 Communications and content

DataWhoPurpose
Broadcast messages, images, PDFsManagers → StudentsLibrary announcements
In-app notificationsSystem → UsersPlan expiry, payments, alerts
Support messages you send usManagersCustomer support

Photos and files uploaded are stored using Cloudinary and linked to your account or library.

3.9 Security features (optional)

DataWhoPurpose
Email OTP for two-factor authenticationManagersExtra login security
OTP records (temporary)ManagersVerification; deleted after use

4. How we use your information

We use personal information to:

We do not sell your personal information to third parties for their marketing.

5. Legal bases (India)

Where applicable under Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP Act), we process personal data based on one or more of the following:

For certain sensitive personal data (such as Aadhaar), we rely on clear purpose limitation tied to library registration and your Manager's role in providing the service.

6. Sharing with third parties

We share personal data only as necessary to provide the service:

These are data processors acting on our instructions, not independent data controllers who can use your data for their own purposes.

We may disclose data if required by law, court order, or government authority, or to protect the rights or safety of users and the public.

We do not sell, rent, or share your personal data with advertisers or unrelated third parties.

7. Data retention

We retain personal data as long as your account is active or as needed to provide the service. For Managers, data is retained until account deletion is requested and processed. For Students, data is retained as part of the library record maintained by the Manager.

Payment records and transaction logs may be retained longer where required by law or for audit purposes.

Managers can remove or update student records through the app. Deletion of a Firebase Auth account may not automatically delete all Firestore records; contact us if you need help.

Backup and log data held by Google Firebase may persist for a limited time according to Google's systems.

8. Security

We use industry-standard measures including:

No method of transmission or storage is 100% secure. You are responsible for keeping your password confidential and logging out on shared devices.

9. Your choices and rights

Depending on applicable law (including the DPDP Act), you may have the right to:

How to exercise your rights

Email sanctuary.app.noreply@gmail.com with: your name and role (Manager or Student), registered email or Student ID, and a clear description of your request. We aim to respond within 30 days. Students should also contact their library Manager for data held in the context of that library.

Push notifications: You can disable notifications in your device Settings → Apps → Sanctuary → Notifications.

Location: You can deny location permission; you can still set library address manually.

10. Account deletion

Deletion may be irreversible. Some anonymised or aggregated statistics may remain.

11. Children

Sanctuary is designed for library-managed study spaces, not for direct sign-up by young children under 13. Students are typically registered by a Manager (library owner). If you believe we have collected personal data from a child without appropriate consent, contact sanctuary.app.noreply@gmail.com or the registering library so we can take appropriate action.

12. International data transfers

Our service providers (including Google Firebase and Cloudinary) may process data on servers located outside India (e.g. United States or other regions). Where data is transferred internationally, we rely on the service providers' contractual and security safeguards and applicable legal requirements.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date. For material changes, we may notify you through the app or by email where appropriate.

Continued use of Sanctuary after changes means you accept the updated policy.

14. Grievance and contact

For privacy questions, complaints, or data requests:

Abhay Sahgal
Email: sanctuary.app.noreply@gmail.com

For general app support (non-privacy): use in-app Sanctuary Support or the contact details shown in the app.

If you are not satisfied with our response, you may have the right to lodge a complaint with the Data Protection Board of India under the DPDP Act, once fully operational, or seek remedies under applicable law.