Copy config/legal.sample.php to config/legal.php and fill it in.
Missing: company_name, address, support_email, grievance_officer, grievance_email, effective_date.
This banner is shown to everyone who opens the page, including Google and Play Store reviewers.
Privacy Policy
The short version
We collect what we need to run a referral and earnings platform, and to pay you. That includes identity and bank details, because money moves. We do not sell your personal data, and we do not share it for advertising.
Your chats are a separate matter, and they are covered in their own section below — including what we can and cannot read.
1. What we collect
When you create an account
- Name, mobile number, email address, username
- Profile photo and "about" text, if you add them
- Who referred you, and your own referral code
- Sign-in times and last-seen time
When you complete KYC
Required before we can pay you, and required of us by Indian regulation. This is sensitive information and we treat it that way.
- Full name as on your documents, and date of birth
- PAN number and Aadhaar number
- Address, city, state and postal code
- Bank name, account holder name, account number, IFSC code, UPI ID
- Images of your documents — PAN card, Aadhaar (front and back), a selfie, and proof of your bank account
When you earn, spend or withdraw
- Transactions, commissions, wallet balance and adjustments
- Withdrawal and deposit requests, and their status
- Coupons generated or used
When you use Connect (chat)
- Messages, and the photos, videos, voice notes and documents you send
- Who you talk to, when, and whether you are online
- Call records — who called whom and for how long. Calls are not recorded.
- Read receipts and last-seen, unless you turn them off in Privacy settings
Automatically, from your device
- Device type, app version and a device identifier, so a session can be signed out
- A notification token, so we can wake your phone for a message or a call
- IP address and basic request logs, for security and fraud investigation
2. Why we collect it
- To run your account — sign you in, show your team, track referrals
- To pay you — KYC and bank details exist for this and are used for this
- To meet legal obligations — tax, anti-fraud and KYC rules that apply to us
- To deliver messages and calls in Connect
- To keep the platform honest — detecting fraudulent referrals and abuse
- To support you when you raise a ticket
We do not use your data to build advertising profiles, and we do not sell it.
3. Your chats, specifically
Media is deleted on a schedule
Photos, videos, voice notes and documents sent in Connect are removed from our servers after 3 days. The message stays; the file goes. This is how we keep the service affordable, and it means we are not holding your media indefinitely.
The app keeps a copy of media you have already viewed on your own phone, so it keeps working after we have deleted ours. You can clear that at any time in Settings → Chats → Storage.
End-to-end encryption, when it is on
Connect supports end-to-end encryption. When it is enabled for a conversation, messages are encrypted on the sending device and can only be opened on the receiving devices. We cannot read them. The keys are generated on your device and the private half never reaches our servers — there is no master key, and no way for us or anyone else here to decrypt your messages.
When it is not enabled, messages are stored on our servers in a form we can read, and may be accessed by authorised staff where there is a lawful reason to — a fraud investigation, a legal order, or a report you have made. We do not read chats casually.
You can see whether encryption is active for a conversation in the app.
Backup to your own Google Drive
You can choose to back up your Connect media to your own Google Drive. If you do:
-
We request only the
drive.filepermission. That gives this app access to only the files it creates itself — we cannot see, read or touch anything else in your Drive. - The backup lives in your Google account. It is yours, not ours.
- No administrator here can read your backup. There is no page, no route and no tool that opens one.
- We store the access token Google gives us in encrypted form, so we can upload on your schedule. You can disconnect at any time, which stops future backups and leaves the existing files in your Drive untouched.
- Deleting your backup is a separate, explicit action. We never delete it for you.
Backup is entirely optional. Nothing about your account depends on it.
4. Who we share it with
We share personal data only where it is necessary, and only with:
- Payment and banking partners, to send you money
- Google (Firebase), to deliver push notifications. Where end-to-end encryption is on, the notification carries no message text.
- Google Drive, only if you connect it, and only files this app creates
- Partner merchants, where you have used an offer — the minimum needed to confirm a transaction and pay your commission
- Authorities, where the law requires it or where we must act on a lawful order
Other members see what you would expect them to: your name, username, profile photo and about text, your online status and read receipts unless you have turned those off, and the messages you send them. Your mobile number and email can be hidden in Privacy settings.
We do not sell your personal data to anyone.
5. How long we keep it
- Chat media — 3 days, as above
- Messages — until you or the sender delete them, or you delete your account
- KYC and financial records — kept for as long as Indian tax and KYC regulation requires, which is usually several years, even after you close your account. We cannot delete these on request while that obligation stands.
- Account data — [retention period to be confirmed]
6. Your rights
Under the Digital Personal Data Protection Act, 2023, you can ask us to:
- Tell you what personal data we hold about you
- Correct anything that is wrong
- Delete your data, subject to the legal retention above
- Withdraw consent you have given, including disconnecting Google Drive backup
- Nominate someone to act for you if you cannot
Write to [support email] and we will respond within the time the law allows.
7. How we protect it
- Passwords are hashed, never stored in a readable form
- Chat media can be encrypted on disk; end-to-end encryption is available for messages
- Google Drive tokens are encrypted before storage
- Access to member data by staff is limited to what a role requires
- Traffic to and from our servers is encrypted in transit
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data we will tell you and the Data Protection Board as the law requires.
8. Children
Bharat Refer is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, tell us and we will remove it.
9. Changes
If we change this policy in a way that matters, we will tell you in the app and update the effective date above. Continuing to use Bharat Refer after that means you accept the change.
10. Contact us
Grievance Officer
As required by Indian law, you can raise a complaint about how we handle your data with our Grievance Officer:
- Name
- [grievance officer name]
- [grievance email]