2. Privacy Policy
Effective date: April 03, 2025 Company: RAB CORP Pvt Ltd Service: SYNC Privacy contact: privacy@rabcorp.co.in Grievance contact: Ashish Bhawkar, Ashish.bhawkar@rabcorp.co.in Physical address in India: B401 Ashwini Paradise, Gangadham chowk Kondhwa Bibvewadi road Pune 37
2.1 Purpose of this Privacy Policy
This Privacy Policy explains how RAB CORP Pvt Ltd collects, receives, stores, uses, shares, retains, protects, and deletes Personal Data when you use SYNC. It applies to the SYNC app, website, APIs, account systems, messaging features, support tools, grievance systems, reporting tools, security systems, and other related Services.
We are committed to building SYNC as a privacy-first, end-to-end encrypted messaging service. This means we design the Services to minimise access to the content of supported private messages while still operating the Services, protecting Users, complying with Applicable Law, and responding to valid grievances and lawful requests.
This policy uses the definitions in the Terms of Use / User Agreement unless a different definition is stated here.
2.2 Our role
For most Personal Data processed through SYNC, RAB CORP Pvt Ltd acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as applicable. We determine the purposes and means of processing Personal Data for account creation, communication, security, safety, support, legal compliance, and service operation.
Where we use vendors or service providers to process Personal Data on our behalf, they act as Data Processors or service providers and must process Personal Data according to our instructions, contracts, and Applicable Law.
2.3 Personal Data we collect or receive
We collect or receive different categories of Personal Data depending on how you use SYNC. Not every category applies to every User.
2.3.1 Account and registration information
We may collect your name, display name, phone number, email address, user handle, profile photograph, about/status text, password or password hash where applicable, OTP verification status, Firebase UID or similar authentication identifier, account creation date, account status, login channel, and account settings.
2.3.2 Authentication and verification information
We may collect OTP delivery information, login attempt information, authentication tokens, device binding information, session information, password reset information, account recovery details, voluntary verification details, and information required to prevent unauthorised access.
2.3.3 Device, network, and technical information
We may collect IP address, device model, operating system, app version, device identifiers used by the app, Firebase Cloud Messaging token, push notification token, language settings, time zone, network status, error logs, crash logs, diagnostic information, security event logs, and other technical information required to operate and protect the Services.
2.3.4 Messaging metadata and service metadata
For the operation of messaging services, we may process metadata such as sender and recipient identifiers, group or channel identifiers, message identifiers, timestamps, delivery state, read receipt state where enabled, encrypted message envelope information, message type, file type, file size, channel type, forwarding indicator, edit or deletion status, reply metadata, group membership information, admin status, connection request status, blocking status, privacy settings, and similar service information.
We design SYNC so that supported private one-to-one and supported group message content is end-to-end encrypted. We do not access the plaintext of those private message contents unless a User voluntarily reports the Content to us, shares it with us through support or grievance tools, or the Content is otherwise lawfully available to us.
2.3.5 Contact sync and discovery information
If you choose to use contact discovery or contact sync, we may process phone numbers, email addresses, contact identifiers, or other contact information from your device to help you find SYNC Users. We will use this information for contact discovery, fraud prevention, abuse prevention, and service operation. Where feasible, we may use hashing, minimisation, batching, or other privacy-preserving methods.
You can disable contact access through app settings or device settings, but some discovery features may not work without it.
2.3.6 User Content and encrypted Content
User Content may include messages, media, files, voice notes, documents, profile information, group names, group images, channel posts, broadcasts, reactions, and other information you create or share. For supported E2EE messages, the server may store or transmit encrypted payloads but not plaintext content. Some Content, such as public profile information, group names, channel names, support communications, reports, and voluntarily submitted attachments, may be visible to us or to other Users depending on the feature.
2.3.7 Reported Content and grievance information
When you submit a Report, grievance, abuse report, safety report, privacy request, legal notice, or support request, we may collect your name, Account identifier, contact information, complaint details, reported User details, message identifiers, group/channel identifiers, screenshots, attachments, the selected reported message or media, decrypted copies of reported Content voluntarily provided by you, timestamps, category selected, moderation decision, appeal details, and communications with you.
Reported Content may be stored in a secure evidence or moderation system and may be preserved or disclosed where required by Applicable Law.
2.3.8 Child safety and age-related information
Where required, we may process age, date of birth, parental or guardian contact details, verifiable parental consent records, child safety reports, minor-related complaints, account restrictions, and information required to protect children or comply with child protection laws.
2.3.9 Lawful request, security, and compliance information
We may collect and maintain records of court orders, government directions, law enforcement requests, Section 69 requests, preservation requests, CERT-In communications, Grievance Appellate Committee communications, takedown requests, legal basis, response records, evidence preservation records, audit trails, and transparency reporting data.
2.3.10 Communications with us
We may process information you provide when you contact support, respond to surveys, submit feedback, make a complaint, participate in beta testing, communicate with our legal or privacy teams, or otherwise interact with us.
2.4 Information we do not intentionally collect
We do not intentionally collect the plaintext content of supported end-to-end encrypted private messages in the ordinary course of providing the messaging service. We do not require you to provide unnecessary sensitive information to use the basic messaging features. We do not sell your Personal Data.
We do not ask for your password, OTP, or private encryption keys through support messages. You should never share such credentials with anyone.
2.5 Purposes of processing
We process Personal Data for the following purposes:
creating, verifying, authenticating, and maintaining Accounts;
enabling one-to-one chats, group chats, file and media sharing, reactions, channels, broadcasts, forwarding, connection requests, user search, and related functions;
operating E2EE key distribution, device registration, pre-key management, group key management, and encryption-related safety functions;
delivering notifications through push, email, SMS, or in-app messages;
syncing contacts and helping Users discover contacts where they choose to use such features;
providing privacy controls, blocking, last-seen controls, read receipt controls, group settings, channel controls, and account settings;
preventing spam, malware, unauthorised access, impersonation, fraud, abuse, child harm, public order risks, and other misuse;
receiving, reviewing, resolving, and preserving Reports, grievances, and appeals;
complying with the IT Rules, the Information Technology Act, DPDP framework, CERT-In directions, court orders, government directions, and other Applicable Law;
responding to lawful requests and preserving or providing information where lawfully required;
securing, testing, debugging, maintaining, and improving the Services;
notifying Users about policies, changes, safety notices, breach notices, and periodic legal reminders;
conducting internal analytics, performance monitoring, and service improvement in a privacy-respecting manner;
enforcing our Terms and Community Guidelines; and
protecting the rights, safety, property, and legal interests of Users, the Company, authorities, and third parties.
2.6 Legal basis and consent
Under the DPDP framework, we process Personal Data based on consent where consent is required, and for certain legitimate uses or legal obligations where Applicable Law permits. Depending on the context, processing may be based on:
your consent, such as when you create an Account, provide contact details, enable contact sync, upload profile information, submit a Report, or use optional features;
processing necessary to provide the Services requested by you;
compliance with legal obligations, court orders, government directions, CERT-In directions, or lawful requests;
prevention, detection, investigation, or response to cyber security incidents, fraud, spam, abuse, or unlawful activity;
responding to grievances, privacy requests, and legal claims;
protecting children and vulnerable Users; and
other grounds permitted under Applicable Law.
Where we request consent, we aim to present notices in clear and plain language, with an itemised description of Personal Data and the purpose of processing. You may withdraw consent through the available in-app settings or by contacting privacy@rabcorp.co.in, subject to legal retention, security, safety, and service limitations. Withdrawing consent may limit or disable some features.
2.7 End-to-end encryption and what we can access
For supported private chats and supported group chats, message content is end-to-end encrypted. In ordinary operation, we cannot read the plaintext of those messages. We may process encrypted message envelopes and metadata needed to deliver the message.
We may be able to access or process the following information even when E2EE is used:
account details, phone number, email address, display name, user handle, profile photo, and settings;
device information, authentication information, push notification tokens, and security logs;
metadata needed to deliver and secure messages, such as message identifiers, routing information, delivery status, group membership, file type, timestamps, and encrypted payload information;
Content you make public or semi-public, such as public profile information, group names, channel posts, broadcasts, or profile photos, depending on feature settings;
Content you voluntarily provide to us through Reports, grievances, support requests, screenshots, attachments, or lawful complaint mechanisms;
decrypted copies of specific messages or media that a reporting User chooses to submit through the reporting process;
information required to comply with valid legal orders, to the extent it is under our control or possession; and
logs, audit trails, and preserved records required for investigation, cyber security, or legal compliance.
We do not create a backdoor into E2EE private messages. We do not provide plaintext message content that we do not have. We do not share private encryption keys with law enforcement or third parties.
2.8 How voluntary abuse reporting works with encryption
If you report a message, media file, profile, group, channel, broadcast, or other Content, the app may send us the selected reported Content, relevant metadata, sender or group identifiers, message identifiers, timestamps, media hash, and supporting information. This is voluntary from the reporting User and is necessary so that we can review the Report.
Reported Content may be reviewed by trained personnel or suitable technical systems, preserved as evidence, shared with appropriate authorities where required by Applicable Law, used to enforce our policies, and included in aggregate transparency or compliance reports without identifying you unless required or permitted by law.
2.9 Data sharing
We may share Personal Data in the following situations:
With other Users: information such as your display name, profile photo, user handle, status, group membership, messages sent by you, reactions, read receipts where enabled, last-seen information according to your settings, and Content you choose to share.
With group, channel, or broadcast participants: Content and metadata necessary for the feature, subject to feature settings and encryption design.
With service providers and Data Processors: hosting providers, security providers, email or SMS providers, Firebase or push notification providers, support systems, analytics or diagnostics providers, and other vendors that help us operate the Services.
With authorities: courts, competent authorities, law enforcement agencies, government bodies, CERT-In, the Grievance Appellate Committee, or other lawful bodies where required or permitted by Applicable Law.
For child safety: appropriate authorities or agencies where required for child protection, CSAM, child harm, or mandatory reporting.
For corporate transactions: where we undergo merger, acquisition, restructuring, financing, sale of assets, insolvency, or change of control, subject to appropriate safeguards and Applicable Law.
With your consent or direction: where you ask us to share information or use integrations that require sharing.
We require service providers to use Personal Data only for authorised purposes and to apply appropriate security safeguards.
2.10 Retention
We retain Personal Data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by Applicable Law, court order, government direction, CERT-In direction, legal claim, security need, grievance process, or evidence preservation requirement.
Our retention approach includes the following:
plaintext content of supported E2EE private messages is not stored by us in the ordinary course of service operation;
encrypted undelivered messages, encrypted payloads, and media may be stored for service delivery, retry, synchronisation, backup or account continuity features if enabled, and deletion may depend on feature settings and technical requirements;
Account registration information may be retained for at least one hundred and eighty days after cancellation or withdrawal of registration, as required under the IT Rules;
removed or disabled Content and associated records may be preserved for at least one hundred and eighty days for investigation purposes, or longer if required by a court or lawfully authorised government agency;
ICT system logs subject to CERT-In directions may be maintained securely for a rolling period of one hundred and eighty days within Indian jurisdiction;
Personal Data, associated traffic data, and processing logs may be retained for at least one year where required under the DPDP Rules or other Applicable Law;
grievance, support, legal request, and moderation records may be retained as long as needed for legal compliance, dispute resolution, transparency reporting, audit, or safety;
child safety records may be retained as long as necessary to protect children, comply with law, and cooperate with authorities; and
where a special statutory retention period applies, including for large social media intermediaries or other notified classes, we may retain data for the period required by Applicable Law.
When retention is no longer necessary or lawful, we will delete, de-identify, aggregate, or securely dispose of Personal Data according to our internal retention procedures.
2.11 Security safeguards
We use technical and organisational safeguards designed to protect Personal Data and the Services. These may include end-to-end encryption for supported private messaging, transport encryption, encryption or hashing of selected data, access controls, authentication, least-privilege administration, monitoring, logging, audit trails, backups, secure development practices, vulnerability management, incident response, and vendor security controls.
No system is perfectly secure. You should protect your device, update the app, keep credentials confidential, avoid sharing OTPs, and report suspected compromise promptly.
2.12 Cyber security and personal data breach notifications
If we become aware of a personal data breach, we will take steps required by Applicable Law. Where required, we will notify affected Data Principals in clear language and provide information about the breach, likely consequences, safety measures, and contact details for questions. We will also intimate the Data Protection Board of India as required, including further details within the timelines prescribed under Applicable Law.
If a cyber security incident is reportable to CERT-In, we will report it and share related information within the applicable CERT-In timelines, including the requirement to report certain cyber incidents within six hours of noticing the incident or being brought to notice, to the extent applicable.
2.13 Your rights under the DPDP framework
Subject to Applicable Law, you may have the right to:
access information about the processing of your Personal Data;
seek correction of inaccurate or misleading Personal Data;
seek completion of incomplete Personal Data;
seek updating of Personal Data;
seek erasure of Personal Data that is no longer necessary for the specified purpose, subject to legal retention;
withdraw consent where processing is based on consent;
use grievance redressal mechanisms;
nominate another individual to exercise your rights in the event of death or incapacity, where applicable; and
make a complaint to the Data Protection Board of India where permitted under Applicable Law.
To exercise rights, contact privacy@rabcorp.co.in or use the in-app privacy request mechanism. We may need to verify your identity before acting on a request. We may reject, limit, or delay a request where permitted or required by law, including where retention is required for security, legal compliance, evidence preservation, investigation, dispute resolution, or rights of others.
2.14 Children and minors
A “child” means a person below eighteen years of age. Children may use SYNC only where permitted by Applicable Law, with verifiable parental consent where required, and subject to the Child Safety Policy.
We do not knowingly permit use of the Services in a way that is detrimental to children. We do not knowingly process children’s Personal Data in a manner prohibited by Applicable Law. We may restrict features, require age or parental verification, disable accounts, remove Content, report child safety matters to authorities, or take other protective measures.
Parents or guardians may contact support@rabcorp.co.in or Ashish Bhawkar, Ashish.bhawkar@rabcorp.co.in for child safety concerns.
2.15 Cross-border transfers
We may process or store Personal Data in India and other jurisdictions through our systems or service providers, subject to Applicable Law. Where Personal Data is transferred outside India, we will comply with restrictions or requirements specified by the Central Government, including any requirements relating to making Personal Data available to a foreign State or entities under its control.
Certain logs or records may be maintained within Indian jurisdiction where required, including CERT-In log retention requirements.
2.16 International users
SYNC is designed with Indian legal compliance as a primary baseline. If you access the Services from outside India, you are responsible for complying with local laws. We may process your information in India or other jurisdictions where our service providers operate.
2.17 Automated tools and safety systems
We may use automated tools, technical measures, hash matching, metadata-based signals, rate limits, account integrity signals, spam detection, malware detection, or other systems to protect Users and enforce policies. Where required, automated systems are subject to appropriate human oversight and review. We aim to design such systems with due regard to accuracy, fairness, privacy, security, and risk of bias.
2.18 Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will publish the updated policy in the app, on the website, or through another appropriate method. Where required, we will notify you of material changes or seek fresh consent. Continued use of the Services after the effective date means that you acknowledge the updated policy.
2.19 Contact details
Privacy contact: privacy@rabcorp.co.in Grievance Officer: Ashish Bhawkar, Ashish.bhawkar@rabcorp.co.in Support: support@rabcorp.co.in Child safety: support@rabcorp.co.in Law enforcement: law.enforcement@rabcorp.co.in Postal address: B401 Ashwini Paradise, Gangadham chowk Kondhwa Bibvewadi road Pune 37
03 April 2026