🔒 Privacy Policy

Bharosa365 protects you from scams — and protects your privacy while doing it. This policy explains, in plain terms, what we do and do not collect.

Last updated: 21 July 2026

📖 Introduction

Bharosa365 ("the Application", "the Service") is a consumer anti-scam application that helps you avoid one-time-password (OTP) fraud, scam and phishing links, and malicious apps. It is published by FINDVEND SOLUTIONS (OPC) PRIVATE LIMITED ("the Company", "We", "Us", "Our").

Because Bharosa365 needs access to some of the most sensitive information on your phone in order to protect you, we have built it to keep that information on your device wherever possible. This Privacy Policy explains what we collect, why, who we share it with, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDPA). By using the Service, you agree to the practices described here.

📚 Definitions

  • Account — a unique account created for you (via Google Sign-In) to access the Service.
  • Application / Service — Bharosa365, the mobile app provided by the Company.
  • Company / Data Fiduciary (referred to as "We", "Us" or "Our") — FINDVEND SOLUTIONS (OPC) PRIVATE LIMITED, Ground Floor, 16-11-16/c/b, Plot No. 210, Sripuram Colony, Malakpet, Behind RTO Office Malakpet, Teegalguda, Hyderabad – 500036, India.
  • Device — the mobile device on which you use the Service.
  • Personal Data — any information that relates to an identified or identifiable individual.
  • On-Device Processing — analysis that happens entirely on your Device, where the information analysed never leaves your phone.
  • You / Data Principal — the individual using the Service to whom the Personal Data relates.

🛡️ How Bharosa365 Works (On-Device Processing)

To warn you the moment a scam is happening, Bharosa365 — with your permission — reads incoming notifications, monitors whether a call is in progress, and scans links and app signals for known threats.

🔒 This happens on your phone — not on our servers

All scam detection runs entirely on your Device. The contents of your notifications and messages, your OTP codes, and the links inside them are analysed locally and are never transmitted to us or to any third party. We do not store your messages or OTP codes; OTP values are never saved at all. A short history of the alerts Bharosa365 has shown you is kept locally on your Device and is automatically deleted after 90 days.

To do this, Bharosa365 uses your Device's notification-access, display-over-other-apps, and phone-state capabilities. It monitors only whether a call is ringing, active, or ended — it does not read, store, or transmit the caller's number or your phone number.

📊 What We Collect — and What We Don't

Information we collect

DataSourceWhy
Email address (required)Google Sign-InTo create and manage your Account and your subscription
Display name & profile photo (optional)Your Google profileTo personalise the app (e.g. "Welcome, <name>")
Account identifier (Google/Firebase user ID)Google Sign-InTo identify your Account securely
Device & diagnostic data (device model, brand, Android version, app version, crash logs, a randomly generated install identifier)Your DeviceSupport, stability, and to measure installs/attribution
Subscription & purchase records (purchase token, order ID, plan, amount)Google Play BillingTo activate and manage your paid subscription

Information processed only on your Device (we do not collect or receive it)

  • The contents of your notifications and messages
  • OTP codes (never stored, never transmitted)
  • The sender/name shown on a notification
  • Links (URLs) scanned for threats
  • Whether a phone call is in progress
  • App-usage signals used for local scam detection

🚫 What Bharosa365 does NOT collect

We do not collect your phone number, Aadhaar, PAN or any government ID, bank/card/UPI details, your contacts, your location, your photos, or camera/microphone data. Bharosa365 also does not show ads and does not sell your personal data.

Payments: subscriptions are processed entirely by Google Play. We never see or store your card, bank, or UPI details — we only receive a confirmation token and order ID from Google.

🔑 Permissions We Request

Bharosa365 asks only for the permissions it needs to protect you. You can review or revoke these at any time in your Device settings (though protection may be reduced if you do).

PermissionWhy we need it
Notification accessTo detect suspicious OTP messages and scam links as they arrive — processed on your Device.
Display over other appsTo show a full-screen warning over a scam app or call so you see it in time.
Phone stateTo know whether a call is in progress (a key scam signal). No number is read.
Post notifications, run in background, restart after reboot, ignore battery optimisationTo keep protection running reliably.
BillingTo offer the paid subscription via Google Play.

🎯 How We Use Your Data

  • To provide the Service — detect scams and warn you, on your Device.
  • To manage your Account and subscription — sign-in, entitlement, and renewals.
  • For stability and support — diagnose crashes and respond to your requests.
  • To comply with law — where we are legally required to retain or disclose information.

We do not use your personal data for advertising or profiling, and we do not sell it.

🤝 Who We Share Data With

We do not sell your data and we do not share it with advertisers. We share limited account, device, and subscription data with the following service providers (Data Processors), each engaged under a data-processing agreement and used only to run the Service:

ProviderLocationWhat they process, and why
Google / Firebase (Google LLC / Google Cloud)United States & global Google infrastructureSign-in (Google Sign-In / Firebase Authentication), account & subscription storage (Cloud Firestore), app-integrity (App Check), and crash diagnostics (Crashlytics).
Google Play (Billing)United States & global Google infrastructureProcessing your subscription payment. Google, not Bharosa365, handles your payment details.

We may also disclose personal data where required by law, to enforce our terms, or in connection with a merger, acquisition, or asset sale (in which case we will notify you and this policy will continue to apply).

🌐 Cross-Border Data Transfer

Your account, subscription, and diagnostic data are stored and processed on Google Cloud / Firebase infrastructure, which may be located outside India (including in the United States). We rely on Google's contractual and technical safeguards for these transfers and process such transfers in accordance with the DPDPA. All scam-detection processing of your messages and OTPs remains on your Device and is never transferred.

⏰ Data Retention

  • On-device alert history — automatically deleted after 90 days.
  • OTP codes / message contents — never stored.
  • Account & subscription data — retained while your Account is active, and deleted when you delete your Account or ask us to (see "Your Rights").
  • Crash diagnostics — retained for a limited period per Google's default retention for Crashlytics.

When you request deletion, we remove your account and subscription records promptly, and in any case within 30 days, except where we must retain limited data to meet a legal obligation.

⚖️ Your Rights & Choices

🔑 Under the DPDPA, you have the right to:

  • Access — a summary of the personal data we hold about you and how it is processed.
  • Correction & updating — correct or update your information.
  • Erasure — delete your account and personal data.
  • Withdraw consent — at any time (this may reduce protection or require you to sign out).
  • Grievance redressal — raise a complaint with our Grievance Officer.
  • Nominate — nominate another individual to exercise your rights in the event of death or incapacity.

Deleting your account: you can delete your account and its data directly in the app (open the side menu → Delete Account). You may also request access, correction, or deletion by emailing support@bharosa365.com.

🧑‍⚖️ Grievance Officer

In accordance with the DPDPA, you may contact our Grievance Officer with any complaint about how your personal data is handled:

  • Grievance Officer, FINDVEND SOLUTIONS (OPC) PRIVATE LIMITED
  • Email: support@bharosa365.com
  • Address: Ground Floor, 16-11-16/c/b, Plot No. 210, Sripuram Colony, Malakpet, Behind RTO Office Malakpet, Teegalguda, Hyderabad – 500036, India

We will acknowledge and address your grievance within the timelines required by applicable law.

🔐 Security of Your Personal Data

We use reasonable security safeguards to protect your data, including: encryption of all data in transit (HTTPS/TLS); encryption of your account record at rest on your Device; app-integrity verification (Google Play Integrity / Firebase App Check) to protect our systems; and Google-managed encryption for data stored on our backend. No method of transmission or storage is completely secure, but we work to protect your information and to notify the appropriate authorities and affected users of a personal-data breach as required by law.

👶 Children's Privacy

Bharosa365 is intended for adults and is not directed to children under 18. We do not knowingly collect personal data from a child without verifiable parental or guardian consent as required by the DPDPA. If you believe a child has provided us personal data, please contact us and we will take steps to delete it.

🔄 Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and change the "Last updated" date, and where the change is significant we will provide a prominent notice in the app or by email before it takes effect. Please review this policy periodically.

📞 Questions About This Policy?

If you have any questions about this Privacy Policy or your personal data, contact us — we're here to help.

📧 support@bharosa365.com