Legal
Privacy Policy
Effective date: 7 August 2026
This Privacy Policy explains how Papai Sarkar (“I”, “me”, or “the Operator”) collects, uses, stores, and shares information when you use www.iampapaisarkar.dev and the iampapaisarkar mobile application (together, the “Services”).
The Services are a personal portfolio platform for showcasing software projects and professional information. This policy is written for Google Play / App Store disclosures and for visitors who contact me or sign in on mobile.
1. Who is responsible
Controller: Papai Sarkar
Location: Siliguri, India
Email: iampapaisarkar@gmail.com
Website: https://www.iampapaisarkar.dev
2. Information I collect
2.1 Information you provide
- Contact form (website): name, email address, and message content you submit.
- Account profile (mobile app): when you sign in with Google, I receive and store your name, email address, and profile photo URL associated with that Google account, plus identifiers needed to keep your account in sync (see below).
2.2 Information from Google / Firebase Authentication
Mobile sign-in uses Google Sign-In and Firebase Authentication. Depending on what Google returns and what is required to operate the account, the backend may store:
- Display name and email
- Avatar / profile photo URL
- Google account subject identifier
- Firebase user ID (UID)
- Last login timestamp and account role (for example, standard user)
I do not receive your Google password. Authentication tokens are verified server-side with Firebase Admin; short-lived Firebase ID tokens authorize API requests from the app.
2.3 Usage and technical data
- Favorites: which portfolio projects you mark as favorites while signed in
- Downloads: when authenticated download links are used, download events may be recorded (for example, which build was requested and when) to prevent abuse and understand demand
- Device / app preferences (on device): local storage (MMKV) may keep auth session data, cached user profile fields, and theme preference (light/dark)
- Server logs: standard request metadata such as timestamps, approximate IP, user-agent, and error diagnostics may be retained temporarily for security and reliability
2.4 Information I do not intentionally collect
- Precise GPS location
- Contacts, SMS, call logs, or microphone / camera content
- Payment card details (the portfolio app does not process payments)
- Advertising IDs for cross-app tracking or interest-based ads within the Services
3. How I use information
I use personal information to:
- Operate authentication and keep your mobile profile in sync
- Show portfolio content, favorites, and authorized downloads
- Respond to contact messages and professional inquiries
- Maintain security, prevent abuse, and diagnose outages
- Improve the Services and fulfill legal obligations when required
I do not sell your personal information. I do not use your data to build advertising audiences for third-party marketers.
4. Legal bases (where applicable)
Depending on your location, processing may rely on:
- Contract / service delivery — providing the features you request (account, favorites, downloads)
- Legitimate interests — securing the Services, understanding portfolio engagement, improving reliability
- Consent — where required for optional communications or certain cookies/technologies
- Legal obligation — when the law requires retention or disclosure
5. How I share information
I share information only as needed to run the Services:
- Google / Firebase: authentication and identity verification
- Hosting, database, and cloud storage providers: to store application data, media (banners, screenshots, builds), and serve the API/website
- Email delivery providers: to transmit contact-form messages to me
- Professional advisors or authorities: if required to comply with law, enforce Terms, or protect rights, safety, and security
Processors act on my instructions and should only process data as needed to provide their service. I do not share account data with other users of the portfolio app.
6. International transfers
Infrastructure and subprocessors may process data in India and other countries (for example, where Google Cloud / Firebase or hosting providers operate). Where required, appropriate safeguards are expected from those providers under their terms.
7. Retention
- Account data: kept while your account remains active
- Contact messages: kept as long as needed to respond and maintain a professional record, then deleted or archived
- Security / download logs: kept for a limited period unless needed longer for abuse investigation
- On-device storage: cleared when you sign out or uninstall the app (subject to OS behavior)
To request deletion of your account and associated server-side profile data, use the dedicated Delete account page (in-app deletion is also available under About → Your account), or email iampapaisarkar@gmail.com from the same address used to sign in. I will verify web/email requests and delete or anonymize personal data except where retention is required by law or for legitimate security records.
8. Security
I use industry-standard measures appropriate to a small personal product, including HTTPS, token-based API authorization, server-side Firebase token verification, rate limiting, and restricted access to production systems. No method of transmission or storage is 100% secure; please use a strong Google account and keep your devices updated.
9. Children’s privacy
The Services are not directed to children under 13 (or the equivalent minimum age in your region). I do not knowingly collect personal information from children. If you believe a child has provided data, contact me and I will take appropriate steps to remove it.
10. Your rights
Depending on applicable law (including GDPR/UK GDPR where relevant, and India’s Digital Personal Data Protection Act where applicable), you may have rights to access, correct, delete, restrict, or object to certain processing, and to withdraw consent where processing is consent-based. To exercise rights, email iampapaisarkar@gmail.com.
You can also manage Google account permissions in your Google Account settings and revoke app access there.
11. Cookies and similar technologies (website)
The website may use a preference cookie (for example, light/dark theme) and a session token used to protect the contact form against cross-site request forgery. Analytics or marketing tags, if enabled, are described in site configuration and can be limited through browser controls where available.
12. Mobile permissions
The Android/iOS app primarily requires network access to load portfolio content and authenticate. Additional OS permissions are requested only if a feature needs them and will be accompanied by an in-OS prompt. The app does not require SMS, contacts, or precise location access for core portfolio browsing.
13. Data Safety summary (app stores)
For store questionnaires, the following summary is accurate as of the effective date:
- Collected: name, email, user IDs, profile photo URL, app activity related to favorites/downloads, crash/diagnostic logs as generated by platforms
- Purpose: app functionality, account management, security, and developer communications related to your inquiries
- Sharing: with service providers that power auth, hosting, and email — not sold
- Encryption: data in transit is protected with HTTPS/TLS
- Deletion: available by contacting the email above
14. Changes to this policy
I may update this Privacy Policy to reflect product, legal, or operational changes. The effective date at the top will be revised when material changes are published. Continued use of the Services after an update means you acknowledge the revised policy.
15. Contact
Privacy questions or deletion requests:
iampapaisarkar@gmail.com
Also see the Terms of Service.