Legal & Data Protection Transparency

Privacy Policy

Your personal vault privacy, on-device OCR security, and data protection practices for the INO (Intelligent Network Organizer) application.

Effective Date September 10, 2026
Last Updated September 10, 2026
Application INO (Android & iOS)
Data Fiduciary INO
SECTION 01

About INO & Data Fiduciary Details

Welcome to INO (Intelligent Network Organizer) ("Application", "Service", "we", "us", or "our"). INO is designed as a personal digital life vault and organization tool, helping individuals securely manage their documents, identity credentials, assets, expenses, reminders, and family vaults.

This Privacy Policy outlines how your personal data is collected, stored, processed, and safeguarded when using the INO mobile application and related services.

Data Fiduciary / Controller Information:

  • Legal Entity / Developer Name: INO
  • Registered Address: HNO - 2-2, Ramachandrapuram Velmula Medak Telangana
  • Privacy & Support Email: inosupport.app@gmail.com
SECTION 02

Age Limitation (18+ Requirement)

INO is intended solely for adult users who are 18 years of age or older. We do not intentionally collect, store, or solicit personal data from children or individuals under the age of 18.

If we become aware that personal information of a person under 18 years of age has been collected without verified parental consent, we will promptly delete that account and all associated cloud and local data.

SECTION 03

Information We Collect & Processing Purposes

We only collect data necessary to provide and enhance your vault functionality. We do not sell your personal information.

Category Specific Data Points Storage Location Purpose
Account & Identity Full name, email address, phone number (if OTP login used), profile photo (optional), user ID. Supabase Auth & Database (Encrypted in transit & at rest) User registration, authentication, session maintenance, security alerts.
Vault Documents Scanned documents (PDFs, Images), document metadata, custom tags, expiry dates, notes. User-isolated Supabase Storage bucket & Postgres database Organizing, viewing, and safeguarding user documents.
Structured Wallets Identity numbers (Aadhaar, PAN, Passport, DL), health details, insurance policies, property details, investments, vehicle records. Per-wallet Supabase Postgres tables with Row-Level Security Personal management, portfolio net-worth calculation, and expiry tracking.
Password Vault Account logins, passwords, security notes. Encrypted Ciphertext only in database; key derived via Master Passphrase (client-side). End-to-end encrypted password storage. INO servers cannot read plaintext passwords.
Reminders & Notes Document expiry dates, custom reminders, personal notes. Supabase Database & local on-device cache Triggering local and push notification alerts for renewals and tasks.
Device & Push Tokens Device OS, platform, Firebase Cloud Messaging (FCM) registration token. Supabase device_tokens table (Purged on sign-out) Delivering automated reminder push notifications and security alerts.
SECTION 04

Camera, Photos & On-Device OCR Processing

INO provides powerful camera scanning and optical character recognition (OCR) features:

📸

Camera Permission

Used exclusively when you actively capture a physical document, scan a QR code, or take a receipt photo. The camera is never accessed in the background.

🖼️

Photo Library (Photo Picker)

INO utilizes modern system photo pickers that grant temporary access only to the single image you select to import.

⚡

100% On-Device ML Kit OCR

Text recognition (Google ML Kit) runs entirely on your local device. Scanned images are NOT uploaded to third-party AI or external OCR cloud APIs.

SECTION 05

QR Code & Secure Document Sharing

When you create a document share link or QR code:

  • Granular Disclosures: You select exactly which fields (e.g. name, masked ID number) are visible to the recipient.
  • View-Once & Expiry: Links can be configured with strict view-once limits or auto-expiring time windows.
  • Revocation: You can revoke active links immediately at any time from the "Manage Shares" screen.
  • UPI Payment QRs: Scanning a UPI payment QR extracts payment details locally and launches installed payment apps (e.g. Google Pay, PhonePe, BHIM) via the operating system. INO does not process payments or store financial credentials.
SECTION 06

Voice Navigation & Microphone Usage

INO offers optional voice navigation commands (e.g. "Open Aadhaar Card", "Go to Reminders"):

  • User-Initiated Only: The microphone is activated only while you tap and hold or activate the voice assistant modal.
  • Local Speech Processing: Uses native OS Speech-to-Text services (Android SpeechRecognizer / iOS Speech Framework).
  • No Audio Retention: Audio streams are processed in real-time to match navigation routes and are immediately discarded. No voice recordings are stored on our servers.
SECTION 07

Biometric Authentication & App Lock

You can enable biometric lock (Fingerprint / Face ID) to safeguard app access:

  • Authentication is handled strictly by the device operating system (Android BiometricPrompt / iOS LocalAuthentication).
  • Biometric Data Privacy: INO never accesses, collects, transmits, or stores raw fingerprint or facial recognition data. The app receives only a cryptographic boolean confirmation from the OS.
SECTION 08

Password Vault Security & Client Encryption

Passwords stored in the INO Password Vault are protected using zero-knowledge client-side encryption:

Client-Side Zero-Knowledge
  • Derivation: Key derived using PBKDF2-HMAC-SHA256 (210,000 rounds) with a user-chosen Master Passphrase and unique salt.
  • Encryption: Entries encrypted via AES-256-GCM on your device before transmission.
  • Server Storage: Only encrypted ciphertext is stored on the database. Even database administrators cannot view your stored passwords.
  • Master Passphrase: Your master passphrase is never stored on the server and cannot be recovered by INO staff.
SECTION 09

Third-Party Services & Integrations

We partner with reputable infrastructure providers strictly to deliver core vault features:

Supabase Inc. Database, Auth & Cloud Storage

Stores user account records, encrypted database tables, and uploaded document attachments. Enforces strict Row Level Security (RLS) policies.

Google Firebase Cloud Messaging (FCM) Push Notifications

Delivers reminder notifications and security alerts to your device using registration tokens. Device tokens are deleted when you log out.

Google Sign-In (OAuth) Authentication

Enables one-tap sign-in using your Google account. Transmits only your basic public profile (name, email, avatar).

Vercel Inc. Web Proxy & Privacy Hosting

Hosts the web viewer for recipient document sharing and this public Privacy Policy page. No user passwords or tokens are stored on Vercel.

Swissquote & Frankfurter API Live Market Rates (Keyless)

Provides public spot gold/silver prices and USD/INR exchange rates for net worth estimations. No user data or identifiers are transmitted.

SECTION 10

Data Security & Storage Architecture

INO employs multiple layers of security to safeguard your digital life:

🔒 Transit Encryption

All network communications between the mobile app, web viewer, and server endpoints are encrypted using TLS 1.3 / HTTPS.

🛡️ Row Level Security (RLS)

Database queries and storage bucket requests enforce Postgres Row Level Security policies restricted strictly to auth.uid() = owner.

📱 Screen & Clipboard Security

Sensitive screens block screenshots/screen recording when enabled, and copied sensitive data is cleared from the clipboard automatically.

🔑 Secure Key Storage

Local session tokens are stored in hardware-backed storage (Android Keystore / iOS Keychain) via FlutterSecureStorage.

SECTION 11

Data Retention Policy

  • Active Usage: Your documents and records are retained for as long as your account remains active.
  • Pruning of Temporary Logs: Push notification outbox logs and security alerts are automatically pruned after 90 days.
  • Exporting Data: You may export a complete offline archive of your stored data and documents anytime via Profile → Export My Data.
SECTION 12

Account & Data Deletion

You have full authority to permanently delete your account and all associated personal data at any time.

Option A: Instant Deletion Inside the INO App

  1. Open the INO application on your mobile device.
  2. Navigate to the Profile tab (bottom navigation).
  3. Scroll down and tap Delete Account.
  4. Complete the account verification process provided by INO to confirm your identity.
  5. Confirm deletion. The app immediately executes the server-side transactional purge and logs you out.

Option B: Public Web Deletion Request (No App Needed)

If you have uninstalled the app or lost your device, you can request permanent deletion at our public portal:

👉 Email our Data Protection team directly at inosupport.app@gmail.com with the subject line "Account Deletion Request" from your registered email address. We will process account deletion requests and delete associated personal data in accordance with our data retention policy and applicable laws.

What Data is Permanently Purged?

  • ✓ Authentication record in auth.users, hashed credentials, and profile.
  • ✓ All uploaded document files, images, PDFs, and backups in Cloud Storage.
  • ✓ All database records across Identity, Document, Health, Insurance, Financial, Property, Vehicle, and Card wallets.
  • ✓ Password vault encrypted records and keys.
  • ✓ Active document share links, view-once tokens, and family vault memberships.
  • ✓ Push notification tokens and device records.
  • ✓ Local cached session tokens and preferences on your device.
SECTION 13

User Privacy Rights (DPDP & GDPR Compliance)

Depending on your jurisdiction, you enjoy specific statutory privacy rights:

🇮🇳 India DPDP Act 2023 Rights

  • Right to Access: Request a summary of personal data being processed.
  • Right to Correction & Erasure: Correct inaccurate information or delete personal data.
  • Right of Grievance Redressal: Contact our team for swift resolution of privacy concerns.
  • Right to Nominate: Nominate another individual to exercise data rights in the event of death or incapacity.

🇪🇺 EU GDPR Rights

  • Right of Access & Portability: Export personal data in a structured, machine-readable format.
  • Right to Rectification & Erasure: Request immediate correction or erasure of personal data.
  • Right to Restrict Processing: Request restrictions on specific processing activities.
  • Right to Lodge Complaint: File a complaint with an EU Data Protection Authority.
SECTION 14

No Advertising & No Third-Party Tracking

✓ 100% Ad-Free ✓ No Tracking SDKs ✓ No Data Broker Sharing

INO is completely free of third-party advertising networks (e.g. Google AdMob, Meta Audience Network). We do not include third-party tracking or behavioral profiling SDKs. Firebase Analytics collection is explicitly deactivated in app builds.

SECTION 15

Contact Information & Privacy Grievances

If you have questions, feedback, or wish to exercise your data rights, please reach out to our team:

📧
Privacy & Support Email:
inosupport.app@gmail.com
🏢
Registered Address:
INO, HNO - 2-2, Ramachandrapuram Velmula Medak Telangana