This Privacy Policy explains how Shanty (“Ember”, “we”, “us”) collects, uses, discloses, retains, and protects your personal data when you use the Ember Connect mobile application and related services (the “Platform”). We act as the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”). By creating an account and providing consent, you agree to the practices described here. This notice is provided in English; you may request a summary in any language listed in the Eighth Schedule to the Constitution of India by contacting our Grievance Officer.
1. Data We Collect
- Account & identity: mobile phone number (via OTP), and the role you select (connect / earn).
- Profile: display name, age (18+), gender, bio, city, profession, height, relationship status, languages, interests, and profile photos.
- Verification (earners): a short verification video and passphrase used to confirm identity. Verification videos are reviewed manually by our staff; we do not perform automated biometric or facial-recognition matching on them.
- Usage & calls: connection requests, call metadata (participants, timestamps, duration), subscriptions, and earnings. The audio and video of your calls are transmitted in real time and are not recorded or stored by us.
- Payments: transaction identifiers and, for payouts, masked bank/UPI details. Full card/bank credentials are handled by our payment processor and are never stored by us.
- Device & technical: push-notification (FCM) token, IP address, and app/diagnostic logs.
- Advertising: your device's resettable advertising identifier (Google Advertising ID) and coarse, non-precise ad-related signals, collected by Google AdMob to serve and measure in-app ads (see Section 5).
2. Purposes & Legal Basis
We process your personal data on the basis of the consent you provide at sign-up (and, where applicable, for the performance of our services and to meet legal obligations). We use your data to:
- authenticate you and secure your account;
- build your public profile and power discovery and matching;
- facilitate video/voice calls and enforce call time limits;
- process subscriptions, commissions, and earner payouts;
- send service and safety notifications;
- show and measure in-app advertising;
- prevent fraud, abuse, and violations of our Terms; and
- comply with applicable law.
3. App Permissions
The app requests the following device permissions, each only for the stated purpose:
- Camera & Microphone: required for video/voice calls and for recording the earner verification video. Never accessed outside a call or verification you initiate.
- Photos / media: to let you choose profile photos for upload.
- Notifications: to alert you to incoming calls, connection requests, and service messages, including full-screen incoming-call alerts.
- Phone / call integration: to display incoming Ember calls using your device's native call screen.
You can revoke any permission in your device settings; related features will stop working but the rest of the app remains usable.
4. Consent & Withdrawal
We record the consent you give at registration, including the policy version and the time of consent, as evidence required under the DPDP Act. You may withdraw consent at any time from within the app (Profile → Privacy & Data) or by contacting our Grievance Officer. Withdrawing consent will require us to stop most processing and may mean you can no longer use the Platform. Withdrawal does not affect processing already carried out lawfully.
5. Advertising
We show in-app advertisements served by Google AdMob. AdMob may collect and process your device's advertising identifier, IP address, and app-interaction signals to serve, personalise (where permitted), and measure ads, as described in Google's Privacy Policy and how Google uses data from partner apps. You can opt out of ad personalisation and reset or delete your advertising identifier at any time in your device settings (Android: Settings → Google → Ads; iOS: Settings → Privacy & Security → Tracking / Apple Advertising). We do not share your profile, call, or payment data with advertisers.
6. Sharing & Third-Party Processors
We do not sell your personal data. We share it only with service providers (Data Processors) who process it on our behalf under contract, and where required by law or to protect rights and safety (including responding to lawful requests from law-enforcement and government agencies). Our key processors are:
| Processor | Purpose | Location |
|---|---|---|
| Google Firebase (Authentication, Cloud Messaging) | Phone OTP authentication and push notifications | Global / USA |
| Google Cloud Storage | Storage of profile photos and verification media | Asia (Mumbai) / Global |
| Google Cloud SQL (PostgreSQL) | Primary application database hosting | India (Mumbai) |
| Google Cloud Memorystore (Redis) | Session and rate-limit state cache | India (Mumbai) |
| 100ms | Real-time video/voice call infrastructure (media relayed in real time, not stored) | Global |
| Razorpay | Payment processing and payouts | India |
| Google AdMob | In-app advertising (see Section 5) | Global |
Other users of the Platform can see the profile information you choose to publish (name, photos, bio, and similar profile fields). Your phone number is never shown to other users.
7. International Transfers
Some processors listed above store or process data on servers outside India. Where this happens, we take reasonable steps to ensure your data continues to be protected and that transfers comply with the DPDP Act and any restrictions notified by the Government of India.
8. Data Retention
We retain personal data only for as long as necessary for the purposes above. In particular:
- Profile and account data: for the life of your account.
- Call, subscription, and transaction records: retained while your account is active and thereafter as required for financial, tax, and legal compliance.
- Verification media: retained while your account is active and deleted after account closure.
- Server and diagnostic logs: retained for up to 12 months, or longer where needed for an ongoing security or legal matter.
When you delete your account, we erase your profile, photos, and verification media, and delete or irreversibly anonymise associated records, except where retention is legally required (e.g. financial records).
9. Your Rights
Under the DPDP Act you have the right to:
- Access a summary of the personal data we process about you — available in-app from Profile → Privacy & Data → View my data;
- Correct or update inaccurate or incomplete data (editable in-app);
- Erase your data by deleting your account in-app;
- Withdraw consent as described in Section 4;
- Nominate another individual to exercise your rights in the event of death or incapacity; and
- Grievance redressal — raise a complaint with our Grievance Officer (Section 12) and, if unsatisfied, with the Data Protection Board of India.
10. Security
We use reasonable technical and organisational safeguards, including encrypted transport (HTTPS), secrets held in a managed secret store, access controls and role-based admin permissions, signed time-limited URLs for sensitive media, and audit logging of administrative actions. No system is perfectly secure; in the event of a personal-data breach we will notify the Data Protection Board and affected users as required by law.
11. Child Safety Standards & Anti-CSAE Policy
Ember Connect maintains a strict zero-tolerance policy against Child Sexual Abuse Material (CSAM) and Child Sexual Abuse and Exploitation (CSAE). The Platform is strictly for adult users aged 18 and older. Minors under 18 years of age are strictly prohibited from creating accounts, accessing, or using Ember Connect.
11.1 Prohibition of Child Sexual Abuse & Exploitation (CSAE)
Ember Connect explicitly prohibits any user from creating, uploading, sharing, streaming, soliciting, or distributing content or engaging in conduct that constitutes or promotes Child Sexual Abuse Material (CSAM), Child Sexual Abuse and Exploitation (CSAE), child grooming, or any form of child endangerment or harm.
11.2 Safety Mechanisms & In-App Reporting
We employ active moderation, technical safeguards, and reporting mechanisms to protect users and prevent misuse:
- In-App Profile & Call Reporting: Users can instantly report any suspicious activity, user, or profile via the in-app "Report User" button directly within profiles and active call screens.
- Proactive Review: Reported accounts and media are flagged for immediate administrative review and moderation.
- Account Suspension & Permanent Termination: Accounts involved in any CSAE/CSAM violation or underage usage are immediately suspended and permanently banned.
11.3 Law Enforcement Reporting
In accordance with applicable global child protection laws and regulations, Ember Connect promptly reports any identified instance of CSAM/CSAE to relevant legal and law enforcement authorities, including the National Center for Missing & Exploited Children (NCMEC) and Indian Cyber Crime reporting portals.
11.4 Dedicated Child Safety Contact Point
For inquiries, concerns, or urgent reporting regarding child safety or CSAE violations on Ember Connect, please contact our dedicated Child Safety Officer:
Child Safety Officer: Prince Yadav
App / Developer Name: Ember Connect (Shanty)
Child Safety Contact Email: naitiksolution304@gmail.com
Grievance Office Address: First Floor, House No. 375, Yadav Mohalla, Rajokri, New Delhi - 110038
12. Grievance Officer
In accordance with the DPDP Act and the Information Technology Act, the contact details of our Grievance Officer are:
Prince Yadav
Email: naitiksolution304@gmail.com
Shanty
We will acknowledge complaints within 24 hours and resolve them within 15 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified in-app and the version number above will change. Continued use after an update, or re-affirming consent when prompted, constitutes acceptance of the revised Policy.
Ember