1. Scope & Role
This Privacy Policy applies to the BharatGeoTag mobile, desktop and web application (the "Service") published by Trivartha ("we", "us", "our"). Trivartha is the Data Fiduciary of any personal data you choose to share with us through the in-app support, premium upgrade, or feedback flows, in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act").
Most data processed by BharatGeoTag — your photos, location fixes, project metadata and field reports — stays on your device. We do not operate a backend that ingests your captures. Where we do receive personal data (for example, your Google Play purchase receipt when you upgrade to BharatGeoTag Pro), we act as the Data Fiduciary and process it only for the purposes stated in this policy.
2. Key Definitions
- Personal Data / Personal Information — any data that identifies or can reasonably identify a natural person.
- Data Principal — the individual to whom Personal Data relates (you).
- Data Fiduciary — the entity that determines the purpose and means of processing (Trivartha).
- Data Processor — a third party that processes data on our behalf (e.g. Google Play Billing).
- Processing — any operation performed on Personal Data, including collection, storage, use, disclosure or erasure.
3. What We Collect
BharatGeoTag is designed around the principle of data minimisation. Below is the exhaustive list of data the Service may collect.
3.1 Data you capture directly (stored on-device)
| Category | What | Where it lives |
|---|---|---|
| Photos & stamps | Original and stamped JPEGs you capture or import through the in-app editor. | App-private documents directory (photos/, photos/stamped/, photos/originals/). |
| Location | Latitude, longitude, accuracy (m), altitude, speed, heading, mock-location flag and fix timestamp. | Embedded in EXIF and stamp overlay on the JPEG; live fixes are never uploaded. |
| Address | Reverse-geocoded Indian address (locality, city, district, state, PIN, country), Plus Code. | Derived on-device; persisted only in the stamp overlay. |
| Sensor data | Compass heading, magnetometer presence flag (sampled at 1 Hz). | Stamp overlay only. |
| Weather | Current temperature, condition and wind (only if enabled in Settings). | Stamp overlay only; cached locally for 30 min. |
| Map snapshot | OSM raster tile snapshot (only if enabled and a free-tier map type is selected). | Stamp overlay only. |
| QR payloads | Decoded text/URL from QR codes you scan in-app. | Local only; never transmitted. |
| Project, visit, inspection & property metadata | Names, accent colours, custom fields, linked photo paths. | JSON files under getApplicationDocumentsDirectory(). |
| Custom fields & stamp templates | User-defined text fields and stamp layouts. | JSON files under app docs directory. |
| Company branding | Optional company name, contact, website, footer and logo you upload. | JSON + image under app docs directory. |
3.2 Data we may receive when you contact us or upgrade
- Support communications — your name, email and the contents of any message you send to support@trivartha.com.
- Google Play purchase receipt — anonymised product identifier, purchase state, obfuscated account ID and signed purchase token, validated server-side via the Play Developer API solely to confirm Pro entitlement.
- Crash & error reports — none. The Service does not embed a crash-reporting SDK. Diagnostics stay inside the device's
flutterconsole in debug builds only (kDebugMode-gated) and are never transmitted. - Analytics — none. The Service contains no third-party analytics, advertising or marketing SDK.
3.3 Data we explicitly do not collect
enableAudio: false. Captured JPEGs are saved exclusively to the app-private documents directory — they are not written to your device's shared photo gallery unless you explicitly tap Share or Export.
4. Permissions & Their Purpose
| Permission | Purpose | Triggered when |
|---|---|---|
CAMERA | Capture the live photo to be stamped. | You tap the Camera card on the home screen. |
ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION | Obtain GPS fix for the stamp. | You tap the Camera card on the home screen. |
INTERNET | Fetch OSM tiles, Open-Meteo weather, India Post PIN lookup. | Only when those features are enabled in Settings; the app otherwise works fully offline. |
ACCESS_NETWORK_STATE | Show the "Offline" pill in the top app bar. | Always-on background listener. |
FOREGROUND_SERVICE / FOREGROUND_SERVICE_LOCATION | Companion permissions used by geolocator on Android 14+ to keep the location stream alive during an active capture session. | Only while the camera or an active visit/inspection/property screen is in the foreground. |
You may revoke any of the above permissions at any time through your device settings; doing so will disable the corresponding feature in the app and surface a friendly in-app message instead of crashing.
5. How We Use Your Data
- To provide the core Service — stamping the JPEG with location, address, sensor and weather data; persisting photos, projects, visits and inspections; generating PDF Field Reports.
- To honour your privacy preferences — the in-app PrivacyShareDialog lets you strip GPS or EXIF metadata from a copy of the JPEG before sharing. Your "remember my choice" preference is stored on-device.
- To manage your Pro entitlement — validating Google Play purchase receipts; storing the resulting entitlement in platform secure storage (Android Keystore / iOS Keychain / Linux libsecret / Windows DPAPI).
- To respond to you — when you write to support, we use the contact details you provided solely to reply.
- To comply with law — preserving records we are legally required to keep (for example, GST invoices for Pro purchases, retained by our payment processor).
6. Storage, Security & Retention
All user-generated content (photos, project data, custom fields, company branding, stamp templates, premium entitlement) is stored on your device in the application-private documents directory obtained from path_provider's getApplicationDocumentsDirectory(). Other apps and the operating system cannot read this directory without root access.
We apply the following technical safeguards:
- Atomic writes. Every JSON repository writes through a
tmp → renamehelper (core/security/path_safety.dart) so partial writes can never corrupt state. - Path-traversal protection. User-supplied filenames are funnelled through
safeBasename()before they reach the filesystem. - Encrypted premium entitlement. The Pro entitlement is mirrored to platform secure storage, never to plain JSON on disk.
- Debug-only logging.
AppLoggeris gated bykDebugMode; release builds emit no log lines. - Zero-server capture. We have no remote service that receives your photos or location fixes.
7. Third-Party Services
The Service relies on a small, named set of third-party endpoints. Each is invoked only when you have explicitly enabled the feature in Settings, and only the minimum data needed to fulfil the request leaves the device.
| Provider | Purpose | Data shared | Link |
|---|---|---|---|
| OpenStreetMap tile servers | Render the map snapshot overlay in stamps. | Latitude/longitude, zoom, OSM-compliant User-Agent string. | openstreetmap.org/copyright |
| Open-Meteo | Fetch current weather for the stamp overlay. | Latitude/longitude, units. | open-meteo.com/en/privacy |
| India Post | Reverse-lookup PIN code → post office name (used to enrich the address line). | PIN code only. | indiapost.gov.in |
| Google Play Billing & Google Play Developer API | Validate Pro subscriptions and one-time purchases. | Anonymised product ID, purchase token, signed JWT receipt. | policies.google.com/privacy |
| Apple App Store / StoreKit | Same as above on iOS. | Anonymised product ID, signed JWS receipt. | apple.com/legal/privacy |
8. Sharing & Disclosure
We do not sell, rent or trade your Personal Data. We share data only in the following narrow circumstances:
- With your action. When you tap Share, the app passes the selected JPEG/PDF to the OS share sheet. The recipient is chosen by you; from that point their privacy practices apply.
- With processors. Google (Play Billing), Apple (StoreKit) and our payment processor solely to validate Pro entitlement and pay us.
- For legal reasons. If we receive a valid order from a competent Indian authority, or to prevent imminent harm, in accordance with the DPDP Act and the Information Technology Act, 2000.
- In a business transfer. If Trivartha is acquired or merges, Personal Data held by us may be transferred to the acquirer under confidentiality obligations no less protective than this policy.
9. Children's Privacy
The Service is intended for professional users (engineers, surveyors, inspectors, journalists, project managers) and is not directed to children under 18. We do not knowingly collect Personal Data from children. If you believe a child has provided us data, contact the Grievance Officer and we will erase it.
10. Your Rights & Choices (DPDP Act 2023)
As a Data Principal you have the right to:
- Confirm whether we process your Personal Data.
- Request access to a summary of the Personal Data and the processing activities related to you.
- Correct inaccurate or misleading Personal Data.
- Erase Personal Data (subject to lawful retention grounds).
- Withdraw consent at any time, with the same ease as it was given.
- Nominee appointment — under §11 of the DPDP Act, you may nominate another individual to exercise your rights in the event of your death or incapacity.
- Grievance redressal — file a complaint with our Grievance Officer (see §13).
Most of these rights can be exercised immediately and automatically from within the app — see our Data Deletion and Account Deletion guides. For anything that requires our involvement, we will respond within 15 days, as required by the DPDP Act.
11. International Transfers
We are headquartered in India and the on-device data we describe above never leaves India. The limited data we receive through Google Play Billing may be processed on Google's global infrastructure; by using the Service you understand that Google may process such data outside India under its own privacy framework. We do not transfer your on-device content to any overseas recipient.
12. Changes to This Policy
We may update this policy from time to time. The Effective date at the top of this page reflects the latest revision. Material changes (for example, a new third-party processor) will be announced through an in-app banner at next launch. Continued use of the Service after the effective date constitutes acceptance.
13. Contact & Grievance Officer
For any question, complaint, or to exercise your rights under the DPDP Act / IT Act, please contact:
Grievance Officer
Jai Prakash Verma — Partner
Trivartha
Email: support@trivartha.com
Phone: +91-8433668083
Website: https://bharatgeotag.trivartha.com
If we are unable to resolve your complaint within 15 days, you may escalate it to the Data Protection Board of India under §27 of the DPDP Act, 2023.