Legal & Privacy

Last updated: July 2026 (v1.0.39) · Governed by laws of India

1. Who We Are

Dosth App ("the App", "we", "us") is developed and operated by Dosth App Team, an independent developer. As Data Fiduciary under India's Digital Personal Data Protection Act 2023, we are responsible for how your personal data is collected, used and protected.

2. Data We Collect

  • Account data: Name, email address and authentication credentials via Firebase Authentication. Google Sign-In users share name, email and Google profile ID only — no password stored by us. We also record whether your account was created via the installed app or the website (used only to understand how people use Dosth — not shared or sold).
  • Profile data: Display name, DosthTag (auto-generated @username), preferred language and theme.
  • Group & expense data: Group names, members, expense amounts, splits and settlement records you create.
  • DosthSell data: Item listings, listing photos (Firebase Storage), buyer-seller chat messages and deal history.
  • Games data: Chess game results (win/loss/draw), games played count, Dosth Tag for leaderboard display, and your leaderboard visibility preferences. Ludo and Word Duel work similarly for multiplayer sync. Word Hunt, Dosth 4096, Sudoku, Spelling Scramble and Memory Match are entirely client-side — no game data, scores or progress from these is ever sent to or stored by Dosth servers. Solo vs AI Chess/Ludo games are not stored either.
  • Bill Split data: People you add as "members" are name labels for splitting purposes only — adding someone does not create or link to any Dosth account for them. Items, amounts and your saved member list sync to your account across your own devices. If you add your own payment details (e.g. a PayNow or PhonePe number) so it appears in shared messages, that is stored only on your device — not on Dosth servers.
  • Study data: Exam timetable plans, study preferences and custom schedule edits stored locally on your device only (AsyncStorage/localStorage). Not transmitted to servers.
  • Home Vault data: Home inventory items (appliances, electronics, warranties, serial numbers, service contacts, purchase prices) are stored only on your device using local device storage (AsyncStorage on mobile, localStorage on web). Dosth servers never receive or store this information. If you uninstall Dosth or clear app data, the inventory is permanently deleted.
  • QR Maker data: All QR codes (contact vCard, UPI payment, WiFi password, link, text) are generated entirely on your device. The encoded payload is rendered as an SVG image locally. Saved drafts (your name, UPI ID, WiFi credentials etc.) are stored only on your device. Nothing is sent to Dosth servers at any point.
  • Document data: Scanned documents and passport photos are processed locally in your browser. Passport photo background removal uses the remove.bg API — photos are sent to remove.bg for processing and are not retained by Dosth.
  • File Convert data: All file conversions (JPG/PNG/WebP/PDF conversion, Merge PDF, Split PDF, Shrink PDF, Unlock PDF, Protect PDF, Exact KB image compress, Unzip ZIP) are processed entirely in your browser using client-side JavaScript libraries (pdf.js, jsPDF, pdf-lib, JSZip). Your files are never transmitted to Dosth servers. Nothing is uploaded. Output files are created in your browser and downloaded directly to your device.
    • Unlock PDF: Your PDF and password are processed entirely on your device. Neither the file nor the password is sent anywhere.
    • Protect PDF: Encryption is applied client-side using pdf-lib. Your password is never stored or transmitted by Dosth.
  • ID Wallet data: Scanned document photos (Aadhaar, PAN, bank passbook) are sent to Groq only to read the text, exactly like Scanner's existing text extraction — not stored by Dosth. The extracted details (name, numbers, IFSC, etc.) are stored only on your device. Full card numbers and CVVs are never captured, even for cards.
  • Calculator data: Your calculation history, current in-progress calculation, memory value, and chosen color are all saved only on your device. Nothing is ever sent to Dosth servers. If you name and share a calculation via WhatsApp, that's sent only when you choose to, using WhatsApp's own share sheet — Dosth never sees or stores that message.
  • Compass data: Reads your device's own orientation sensor to show your current heading. This is processed and displayed entirely on your device — your direction or orientation is never sent anywhere, stored, or shared.
  • Spirit Level data: Reads your device's own motion sensor to show tilt/level, processed and displayed entirely on your device — never sent anywhere, stored, or shared.
  • Kids Learning data: Quiz progress (Primary 1–5 Maths, English, Science, and Maths Quest game scores) is stored only on your device. Quiz content itself is bundled with the app — no server fetches per question, and children's progress data never leaves the device.
  • Science Fair Projects: A static reference page — no data is collected, stored, or transmitted at all. Nothing to opt into or out of.
  • School Activities & Projects: Also a static reference page — no data is collected, stored, or transmitted at all.
  • Test Case Templates: A static template gallery — nothing is entered, collected, or sent to Dosth servers. Downloads happen entirely in your browser.
  • Scanner data: All scanned images, draft documents and export history are stored only on your device using local device storage (AsyncStorage). Dosth servers never receive, store or process your scanned documents or images.
    • Image → Text (OCR): The selected image is sent to Groq API solely to extract text. The image and extracted text are not stored by Dosth.
    • AI Remove Handwriting: The selected image is sent to Groq API for handwriting analysis only. Not stored by Dosth.
    • Images → ZIP: All processing happens entirely on your device. No data is sent to any server.
    • Share / Save (v1.0.25): Share via WhatsApp / Save as JPG / Compress to KB — all processing happens on your device. The Web Share API is used to invoke your phone's native share sheet; the file is passed directly to your chosen app and is not transmitted to Dosth servers.
    • Manual Erase: Canvas-based editing runs entirely in your browser. No data leaves your device.
    • Export PDF: PDF generation uses jsPDF library loaded from CDN (cdnjs.cloudflare.com). The PDF is generated on your device and downloaded directly. No document content is sent to Dosth or CDN servers.
  • D Carry data: D Carry listings you post — route, travel date, item description, WhatsApp number, carry mode and budget. Visible to all logged-in users. Auto-expires after 30 days.
  • Health data: Vitals you manually log — weight, blood pressure, blood sugar, heart rate, SpO2, temperature, sleep, water, steps, and member records are stored on Google Firebase (Firestore) under your user account (health_records and health_members collections). Only you can access your data — protected by Firestore Security Rules. No automatic sensor reading or Health Connect integration.
  • Location data: Approximate GPS used ONLY for home screen weather. Sent to Open-Meteo API — never stored.
  • AI feature inputs: Text/photos you send to AI features (Kisan AI, D Travel, Smart Listing, AI Greetings, D Invites) are processed by Anthropic Claude API or Google AI. Not retained for model training per provider API terms. Item descriptions typed into DosthSell Smart Listing are sent to Anthropic for listing generation only.
  • Contribution data: If you contribute via Support the Team, the following data is stored in Firebase Firestore: your Firebase user ID (server-side only, never displayed), your DosthTag and name (or "Anonymous" if you select the anonymous checkbox), contribution amount in ₹, UPI transaction ID, optional message, anonymous flag, and timestamp. Your DosthTag (or "Anonymous"), amount and message are publicly visible to all logged-in users in the contributions feed within the app. Selecting "anonymous" hides your DosthTag and name from the feed but does not delete the server-side record. You may request deletion of your contribution record at any time by emailing support@dostu.app from the email address associated with your Dosth account.
  • Push notification token: Expo Push Token stored against your user ID for notification delivery only (up to 3 devices). Used to deliver security alerts when a new device signs into your account.
  • Login history: Each sign-in records the device platform, model and timestamp in a private loginHistory subcollection. Visible only to you in Me → Security Scan → Recent sign-ins. Deleted when you delete your account.
  • Security Scan: When you use Security Scan, your email is sent to Have I Been Pwned (HIBP) — a public breach database. Results are cached on-device only for 24 hours and never stored on Dosth servers.
  • Crash logs: Anonymous error logs — device model, OS version and stack trace only. No personal data.
  • Advertising data: Dosth App does not show advertisements. There is no Google AdMob, AdSense, or other ad-network integration in the app or the website. No device advertising identifier is collected from your device. If advertising is introduced in the future, this section will be updated in advance and existing users will be notified in-app.

3. What We Never Do

  • Never sell your data to advertisers or data brokers
  • Never read your contacts, messages or camera without your action
  • Never background-track your location
  • Never store your UPI ID or bank details
  • Never use your data for behavioural profiling or non-essential third-party sharing
  • Never see your Dosth Drop file content — files transfer directly between devices, we have no access to them

4. Data Storage & Security

All data stored in Google Firebase (Firestore + Storage), encrypted in transit (TLS) and at rest (AES-256). Firestore Security Rules ensure you only access your own data.

5. Third-Party Services

  • Google Firebase — database, authentication, storage, crash reporting
  • Have I Been Pwned (HIBP) — security breach database check (Security Scan feature)
  • Google AdMob — not used. May be added in the future if advertising is reintroduced.
  • Anthropic Claude API — Kisan AI, Trip Planner, Smart Listing AI
  • Google AI APIs — AI Greetings and other generative features
  • Open-Meteo — weather data (anonymous GPS, no account)
  • EmailJS — transactional emails (OTP, settlement notifications)
  • Expo — push notifications
  • PeerJS Cloud (0.peerjs.com — free public infrastructure provided by the PeerJS project): used only when you use Dosth Drop, for the initial ~5KB connection handshake. Sees only the 6-digit connection code and the public IP addresses of both devices during the brief handshake. Never sees file content. After handshake, PeerJS is not involved in the transfer.
  • Google STUN servers (stun.l.google.com) — standard WebRTC infrastructure used to discover IP addresses for direct device-to-device connection during Dosth Drop. No file content, no account information.

We are not responsible for the privacy practices or availability of third-party services.

Service availability & third-party infrastructure: Dosth App is built on Google Firebase and depends on the continued availability of Firebase and the other third-party services listed above. We do not control, and are not responsible for, any outage, downtime, data loss, security incident, or discontinuation of service at the infrastructure level of Google Firebase, Google Cloud, or any other third-party provider listed above. In the event of such an incident, our ability to restore service or recover data is limited by that provider's own systems and service commitments, not ours. We do not guarantee uninterrupted or error-free operation of Dosth App.

6. Data Retention

  • Active account data: retained while your account exists
  • D Carry listings: auto-expire after 30 days
  • Crash logs: 90 days rolling
  • After account deletion: expense records anonymised, DosthSell chat retained for buyer protection (90 days)

7. Your Rights — DPDP Act 2023

  • Right to access your personal data
  • Right to correct inaccurate data
  • Right to erase your data (via Delete Account)
  • Right to withdraw consent
  • Right to nominate a representative

Email: support@dostu.app — we respond within 30 days.

8. Grievance Officer — DPDP Act 2023

Dosth App Team
Email: support@dostu.app
Response within 30 days of written request.

📦 D Carry — Intermediary Notice

Dosth App facilitates connections between community members for carrying items between India and Singapore. We do not verify items, carriers, requesters or WhatsApp numbers. All arrangements, payments and customs compliance are solely the responsibility of the parties involved. Dosth App is not liable for any loss, damage, seizure or dispute arising from D Carry arrangements.

💛 Gold Calculator — Comparison Only

This tool shows price differences between Singapore and India for personal reference. It does not recommend where to buy gold. Gold prices fluctuate continuously. Estimates are based on inputs you provide and international spot rates. Not investment advice. Always confirm final price with your jeweller. Check customs allowances before travel. Dosth App is not liable for any loss arising from gold price estimates.

🏦 Loan Calculator — Reference Only

EMI calculations are estimates using standard reducing-balance formula. Actual EMI may differ based on your bank's specific terms, processing fees and insurance. Not financial or mortgage advice. Consult your bank or a licensed financial advisor before taking any loan.

🏦 Bank Loan Inquiry — Preliminary Estimate Only

Bank Loan Inquiry is a reference tool for bank staff to give customers a preliminary housing-loan eligibility estimate. It does not constitute a loan offer, sanction letter, or commitment by any bank. Final approval is always subject to the bank's complete underwriting process, credit checks and documentation requirements. Dosth App is not affiliated with any specific bank and is not liable for any lending decision, delay or dispute arising from use of this tool. Customer details entered are never transmitted to or stored on Dosth servers. Whenever a message is shared (WhatsApp or copy), Dosth saves a record of that inquiry — name, mobile, DOB, income figures, and the eligibility result — only on the staff member's own device, so it can be found again for follow-up and exported as a CSV for a chosen date range. This record stays on-device only; it is not synced or backed up anywhere by Dosth, and is lost if the app's local storage is cleared.

🧾 Receipt Validator — Reference Tool Only

Receipt Validator uses AI to read a photographed receipt and checks whether the items, tax and discounts add up to the printed total. This is a reference tool only — AI reading can occasionally misread blurry, handwritten or low-light photos, and the app displays exactly what it read so you can verify against the physical receipt. It is not proof of a billing error and should not be the sole basis for a dispute with a merchant. Your receipt photo is sent to Dosth's AI service to be read; the app itself does not save the photo or extracted items anywhere.

🌾 Kisan AI — General Information Only

AI-generated crop, weather and farming advice is general information only. Not professional agricultural advice. Always consult qualified agricultural experts for farming decisions.

❤️ Health — Not a Medical Device

Health is a manual vitals tracker for personal awareness only. Not a medical device. Do not make medical decisions based on data in Health. Always consult a qualified healthcare professional.

🏛️ Political Banner Generator — Your Responsibility

You are solely responsible for political content you generate and share. Dosth App does not endorse any political party, candidate or ideology. Content must comply with Election Commission of India guidelines and applicable laws.

🤖 AI-Generated Content

All AI features generate content AS-IS with no guarantee of accuracy. Always review AI output before using for any important decision.