Privacy Policy and Data-Handling Notice

How RABC collects, uses, protects, shares, retains and deletes personal data in connection with SYNC.

2.1 Scope and responsible entity

This Policy applies to personal data processed by RABC in connection with SYNC Version 1.0.1. RABC PRIVATE LIMITED, CIN U62011PN2026PTC259973, incorporated under the Companies Act, 2013 on 5 September 2026, is the responsible service provider and, where applicable, the Data Fiduciary or data controller. It does not govern independent processing by another User, device platform, app store, telecom provider or external service that acts under its own policy.

2.2 Privacy-law position

RABC will comply with privacy and information-security law in force and applicable to the processing. The Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 have phased commencement; obligations that are not yet in force apply when legally commenced. Existing duties under the Information Technology Act, intermediary rules, CERT-In directions, contracts and other law continue as applicable.

2.3 Account and identity data

RABC may process a verified phone number for CHAT, verified email address for CONVERSE, display name, handle, profile image, Account channel, Account state, registration time, verification result, recovery data, selected privacy settings and records showing which legal version the Account accepted. RABC does not require CHAT and CONVERSE to use the same identifier.

Account and registration information may include the registered phone number or email address, display name, handle, profile photograph, about or status information, Account creation time, login channel, Account status, settings, recovery method and records of a legal acceptance. Authentication information may include verification status, authentication provider identifier, OTP delivery and attempt records, password reset events, session tokens or references, device binding and fraud-prevention signals. RABC does not need every item for every User or feature.

2.4 Age and eligibility data

RABC may process an eighteen-plus declaration, date of birth where the registration flow requests it, eligibility result, declaration time, Pack version, and proportionate age-assurance evidence where justified. Version 1.0.1 is not intended for children and does not provide a parental-consent registration route.

2.5 Device, network and security data

RABC may process device and app identifiers, operating system and app version, device registration, public keys and pre-keys, push token, IP address, network and connection information, login events, session state, authentication attempts, rate-limit events, security alerts, crash or diagnostic references, integrity signals and audit events. RABC limits diagnostic data and does not intentionally include private message plaintext in ordinary crash records.

Technical information may also include language, time zone, push-delivery result, message or call diagnostic references, security-event logs, error records and limited performance information required to troubleshoot the released Service. RABC will seek to avoid placing private-message plaintext, passwords, OTPs or private keys into ordinary telemetry and will restrict access to security-sensitive logs.

2.6 Contacts and permissions

If you choose contact discovery or another permission-based feature, the app may access the related device permission and process the minimum information needed for that feature. Contact access is optional and must be requested in context. Refusing it does not cancel your Account, though contact discovery may be limited. You must have lawful authority to provide another person’s contact information.

Where contact discovery is enabled, RABC may process phone numbers, email addresses or privacy-preserving representations needed to determine whether a contact uses SYNC, prevent abuse and return the chosen discovery result. Permission can be withdrawn through the device or application settings, but information already lawfully processed or needed for security and legal compliance may remain for its applicable period.

2.7 Communications and Content

Supported CHAT and CONVERSE message content and compatible media are end-to-end encrypted as described in the End-to-End Encryption and Communications Security Notice. RABC may transmit or temporarily store encrypted envelopes, encrypted media references and delivery material without possessing the plaintext. Public profiles, handles, group names, channel or broadcast material, official SYNC communications and other information visible by feature design are not necessarily private message content.

User Content may include messages, voice notes, photographs, video, files, reactions, replies, group and channel material, profile information and other material a User chooses to create or share. RABC does not intentionally collect or retain ordinary plaintext of supported E2EE private messages as part of routine delivery. Plaintext can become available when a participant reports selected Content, contacts support with it, publishes it through a feature visible to RABC or otherwise provides it lawfully.

2.8 Metadata

RABC may process sender and recipient identifiers, group membership and roles, conversation or message identifiers, timestamps, delivery and read status where enabled, routing data, encrypted-payload size or type, call participants, call timing and status, abuse-prevention signals and feature interactions. Metadata can reveal sensitive patterns and is protected through access controls, minimisation and retention limits appropriate to its purpose.

Service metadata may include forwarding indicators, edit or deletion status, reply relationships, file type and size, group or channel identifiers, invitation state, blocking or connection state, privacy-setting state and encrypted-envelope information. RABC processes only the metadata reasonably needed for delivery, safety, security, reliability, evidence, dispute resolution and legal compliance and applies access and retention controls according to those purposes.

2.9 Reports, grievances and requests

When you submit a report, grievance, privacy request, safety report or legal correspondence, RABC may process your identity and contact details, the accused Account or Content identifiers, complaint category, explanation, selected reported Content, screenshots or attachments, timestamps, evidence-preservation records, decision, appeal and communications with you. Only provide information relevant to the request.

A report may also contain the reporter’s Account identifier, the reported User’s identifier, selected decrypted messages or media, message or group identifiers, media hashes, complaint classification, authority documents, ownership evidence, moderation notes and communications about an appeal. Reported material is separated from ordinary message delivery and may be retained in a restricted evidence system subject to need-to-know access and audit records.

Submitting one reported item authorises processing of that item and the context reasonably necessary to assess it; it does not provide automatic access to unrelated conversations. A complainant should not send unnecessary intimate material or child sexual abuse material by ordinary email.

2.10 Calls

For a direct call, RABC may process participants, signalling messages, call identifier, invitation and response, start and end times, status, network-quality and security events, and relay information needed for connectivity. Direct media uses encrypted WebRTC transport. RABC does not record call audio or video in ordinary operation for Version 1.0.1.

2.11 Purposes

RABC processes personal data to create and verify Accounts; provide CHAT and CONVERSE; deliver messages, media, calls and notifications; manage contacts, groups, channels and official communications; operate encryption and device security; prevent fraud, spam, malware and abuse; respond to reports and grievances; protect Users; troubleshoot; maintain availability; enforce the Pack; comply with law; preserve and establish legal claims; and improve reliability using appropriately limited information.

More specifically, RABC may use the relevant categories to authenticate and recover Accounts; distribute public keys and encrypted envelopes; deliver messages, files, calls and notifications; manage groups, channels and blocking; enable optional contact discovery; investigate reports; prevent spam, malware, impersonation, fraud and child harm; secure and debug systems; comply with court, government and CERT-In directions; respond to privacy rights; preserve legal claims; provide important policy notices; and measure reliability using appropriately limited information.

RABC will not process personal data for an incompatible unrelated purpose merely because the information is technically available. A materially new purpose that requires notice or consent will be explained before that processing begins.

2.12 Legal grounds and consent

Depending on the law and purpose, processing may be necessary to perform the User agreement, comply with law, protect a person from a threat to life or immediate danger, respond to a voluntarily submitted request, support a legally recognised use, or rely on consent. When consent is required, RABC will state the data and purpose and allow withdrawal through the stated channel. Withdrawal does not invalidate earlier lawful processing and may make a requested feature unavailable.

Consent requested by RABC will be specific, informed and expressed through a clear affirmative action. Optional contact access, optional marketing, optional analytics beyond what is necessary, and any future optional personalisation will not be treated as accepted merely because the User accepted the Terms. Withdrawal will be offered through the stated application or contact method and will be handled as easily as reasonably required by Applicable Law.

2.13 No sale of personal data

RABC does not sell personal data. RABC does not permit an advertiser to read supported private E2EE message content. If an advertising or commercial personalisation model is introduced later, RABC will publish a new notice and obtain any consent required before using data for that purpose.

2.14 Service providers

RABC may use carefully selected processors for hosting, cloud infrastructure, encrypted backup or recovery, authentication, push notifications, email or SMS delivery, app distribution, security, monitoring and customer communications. At the Version 1.0.1 technical baseline, relevant infrastructure may include Hostinger, Oracle Cloud Infrastructure and Google Firebase. A provider receives only the categories reasonably needed for its function and remains subject to contractual and legal controls as applicable.

A processor may receive only the information reasonably needed for its assigned function. Contracts and access controls will require appropriate confidentiality, security, permitted-purpose, incident-cooperation, deletion or return, and sub-processor protections according to the service and law in force. RABC remains responsible for the decisions and obligations that Applicable Law assigns to it as the responsible entity.

2.15 Other disclosures

RABC may disclose information to a User at the User’s direction; to group, channel or call participants as required by the feature; to an authorised representative after verification; to professional advisers under confidentiality; in a corporate restructuring subject to lawful safeguards; to protect rights, safety and systems; or in response to lawful process. RABC reviews requests for validity, scope and authority and discloses only information under its control or possession that it is legally permitted or required to disclose.

Information visible to other Users can include the profile information and status chosen by the User, group membership and roles, messages or reactions sent to recipients, read or delivery indicators where enabled, call participation, and material deliberately published to a channel or broadcast audience. The recipient may keep, copy, screenshot, export, report or lawfully disclose information after receiving it.

For authority, child-safety or corporate-transaction disclosures, RABC will consider identity, legal basis, necessity, proportionality, confidentiality and the rights of affected persons. Corporate successors will receive personal data only subject to lawful safeguards and the purposes reasonably connected with the transaction and continuing Services.

2.16 International processing

Infrastructure and vendors may operate in India or other lawful locations. Where personal data is transferred outside India, RABC will apply restrictions, contracts and safeguards required by law in force at the time. Version 1.0.1 is an India launch; availability elsewhere does not arise merely because a person can technically reach an application page.

2.17 Retention principles

RABC retains personal data only for a stated service, safety, security, evidentiary, dispute or legal purpose. Retention depends on the data category and event. When a period ends, RABC deletes, de-identifies or securely disposes of the information unless a lawful hold, unresolved dispute, fraud investigation, safety need or other legal duty requires continued preservation.

2.18 Statutory and operational retention

Registration information is retained for at least one hundred and eighty days after cancellation or withdrawal where the intermediary rules require it. Information removed or disabled following actual knowledge, voluntary action or a grievance, together with associated records, may be preserved for one hundred and eighty days or longer when required by a court or lawfully authorised government agency. ICT system logs required by CERT-In are maintained securely for a rolling one hundred and eighty days within Indian jurisdiction.

Legal acceptance evidence, invoices, disputes and corporate records may be retained for the applicable limitation, tax, audit or defence period. Encrypted undelivered messages and media are retained only as needed for delivery, synchronisation, retry or an enabled continuity feature. Controlled backups expire on their configured schedules; where deletion cannot alter an immutable backup immediately, restoration controls must prevent deleted active data from being silently reintroduced.

Grievance, moderation, child-safety, privacy-request and law-enforcement records may be retained for the period reasonably required to resolve the matter, comply with a binding direction, demonstrate due diligence, defend or establish legal claims and complete an audit. Security evidence may be retained while a threat, fraud pattern or Account-ownership dispute remains active. RABC will record a retention basis or schedule for material categories rather than retaining them indefinitely by default.

2.19 Account deletion

An authenticated User may request deletion of the relevant CHAT or CONVERSE Account using the available Account process or privacy@rabcorp.co.in. RABC may verify identity and apply a short security or cancellation process. Deletion removes or de-identifies active Account data within the applicable system, subject to recipient copies, statutory retention, lawful holds, security evidence, backups and information that must remain to prevent fraud or establish legal rights.

2.20 Your privacy rights

Subject to Applicable Law, verification and lawful exceptions, you may ask for a summary of personal data and processing, correction of inaccurate or misleading data, completion of incomplete data, erasure of data no longer required, withdrawal of consent, grievance redressal and nomination rights when those rights apply. Send the request from the registered identifier where possible to privacy@rabcorp.co.in and state the affected Account channel and request. RABC will communicate through a verified channel and may narrow or refuse a request where law permits or requires.

A verified request may seek correction of inaccurate or misleading information, completion of incomplete information, updating, erasure where the purpose has ended, withdrawal of consent, information about processing, grievance redressal or nomination where the relevant legal right is in force. RABC may ask for information sufficient to match the requester to the correct CHAT or CONVERSE Account and to protect another person’s data.

A request may be narrowed, delayed or refused where permitted or required because RABC cannot verify the requester, the information belongs to another person, a legal hold applies, retention is required for security or evidence, disclosure would prejudice an investigation, or another lawful exception applies. RABC will explain the decision to the extent legally and reasonably possible.

2.21 Security safeguards

RABC uses safeguards proportionate to risk, which may include end-to-end encryption for supported messages, encrypted transport, restricted administration, least privilege, device and session controls, hashing or encryption of selected records, monitoring, logs, isolated backups, vulnerability management, secure development, audit evidence and incident response. No system is invulnerable, and Users must secure their devices and identifiers.

2.22 Personal data breaches and cyber incidents

RABC will investigate suspected incidents, contain harm, preserve evidence and make notifications required by law. Reportable cyber incidents must be reported to CERT-In within the applicable six-hour period after notice or discovery. When the substantive DPDP breach duties apply, RABC will notify affected Data Principals and the Data Protection Board in the manner and time then prescribed. RABC may notify Users sooner where protective action is appropriate.

Where notification is required, RABC will communicate in clear language the nature of the incident, likely consequences, protective steps already taken, steps the affected person can take, and a contact for questions. Notification duties will be applied according to the provisions and timelines legally in force on the date of the incident; this Pack does not prematurely represent a phased provision as already operative.

2.23 Adult-only service and child data

RABC does not knowingly offer Version 1.0.1 to a child. If RABC reasonably identifies an under-eighteen Account, it may restrict or terminate the Account, limit further processing, preserve safety evidence and make a mandatory report. RABC will not use a guardian’s consent to continue the child’s ordinary access under this launch policy.

2.24 Automated safeguards

RABC may use rate limits, malware detection, integrity signals, duplicate or hash indicators, security rules and other automated safeguards to protect the Services. Such tools do not give RABC routine access to private E2EE plaintext. Where a decision has a serious effect and law requires review, RABC will provide appropriate human oversight or a challenge channel.

2.25 Changes and contact

RABC will assign a new controlled version and content hash to published changes. A material change may require fresh acceptance. Privacy questions and rights requests must be sent to privacy@rabcorp.co.in. Complaints about the handling of a privacy request may be sent to grievance@rabcorp.co.in. General legal correspondence may be sent to compliance@rabcorp.co.in.

2.26 Information RABC does not intentionally collect

RABC does not intentionally collect the plaintext of supported E2EE private messages in the ordinary course of delivery, does not require unnecessary sensitive information for basic messaging, and does not sell personal data. RABC does not ask for a password, OTP or private encryption key through support, grievance or official SYNC messages. Users must not provide those credentials to any person claiming to act for RABC.