Data Protection · Indian DPDP Act & GDPR

Privacy PolicyInformation Collection, Processing, Disclosures & Security Safeguards

Effective Date: January 1, 2024•Last Updated: September 8, 2026•Compliance: DPDP Act (India) · IT Rules 2011 · GDPR

1. Overview & Scope

This Privacy Policy describes how Trinadh Thatakula (Spectra Apps) ("we", "our", or "us") collects, uses, processes, stores, and safeguards information when you visit our website (https://www.trinadhthatakula.com), download and use our Android applications published under Spectra Apps on Google Play, interact with our open-source tools (Thor, Odin, Asgard UI), or contribute voluntary sponsorships/donations through platforms including GitHub Sponsors, Patreon, Buy Me a Coffee, Ko-fi, and PayPal.

We are committed to user privacy, adhering to the Digital Personal Data Protection Act, 2023 (DPDP Act, India), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and global best practices including GDPR.

2. Information We Collect (FOSS vs. Other Projects)

We maintain distinct, transparent data policies depending on whether you are using our open-source FOSS tools or our other published mobile applications:

A. FOSS Projects (Zero Data Collection)
100% Private

For all our Free and Open Source Software (FOSS) projects (including Thor App Manager, Odin, Asgard UI, and our public MCP tools), we do NOT collect, transmit, store, track, or process any personal information, telemetry, or user analytics whatsoever.

These applications run entirely locally on-device, and the complete source code is auditable in public GitHub repositories.

B. Other Apps (Basic Data as Demanded)
Play Store

For other mobile applications and games published under Spectra Apps on Google Play, we only collect minimal, basic data strictly as demanded by the specific application's core functionality (such as anonymized crash telemetry via Google Play / Firebase Crashlytics to fix bugs, or anonymous state selections in Fuel Pulse).

Refer to Individual App Terms:Please refer to each specific application's individual In-App Terms of Service and Privacy Policy (accessible in the app's Settings menu and on its Google Play Store listing) for detailed, per-app permission disclosures.
C. Privacy-Preserving Website Visit Counter:When this portfolio loads, it creates a random token in your browser's per-tab session storage and sends it to our Firebase HTTPS function. The function stores only a one-way SHA-256 hash of that random token, together with creation and expiry times, to avoid counting retries or reloads twice. It expires after 24 hours and is removed by Firestore's managed TTL cleanup, normally within 48 hours. We retain the aggregate visit total. The counter database does not persist your IP address, browser user-agent, page path, referrer, precise location, or the original token. Google Firebase may process standard connection metadata in operational security logs under its own retention policy. The counter is approximate, is not used for advertising or profiling, and does not track you across websites.
D. Voluntarily Provided Support & Sponsorship Data:When you email our helpdesk or contribute a voluntary sponsorship via GitHub Sponsors, Patreon, Buy Me a Coffee, Ko-fi, or PayPal, we receive only the contact email/username necessary to respond to your request (guaranteed response within 24 hours) or acknowledge your backer tier.
Financial Data Exclusion:We NEVER collect, store, or process full credit card numbers, debit card details, CVVs, netbanking passwords, or UPI PINs. All financial payments and recurring memberships are processed securely by PCI-DSS compliant third-party payment aggregators.

3. Purpose & Use of Information

The information collected is strictly utilized for the following legitimate purposes:

  • To provide, maintain, optimize, and diagnose our open-source tools and mobile applications.
  • To display an approximate aggregate count of portfolio browser sessions without building visitor profiles.
  • To respond to user support inquiries, bug reports, feature requests, and grievance escalations.
  • To verify sponsorship status, acknowledge community backers (with consent), and issue donation confirmations.
  • To fulfill statutory accounting, legal, tax, and regulatory compliance obligations in India.
  • To prevent fraudulent activity, security breaches, or unauthorized misuse of our services.

4. Parties to Whom Information is Disclosed & Method of Disclosure

We do NOT sell, rent, barter, or trade personal data to third parties, advertising networks, or data brokers. Data is disclosed only to the following specific service providers solely as required for operation:

1. Payment Platforms & AggregatorsEntities: GitHub Sponsors, Patreon, Buy Me a Coffee, Ko-fi, PayPal, Stripe, Google Play Billing.Method of Disclosure: Encrypted HTTPS using modern TLS for webhooks and API payloads. Data transmitted is restricted to order verification tokens and subscription status.
2. Cloud Infrastructure & HostingEntities: Google Firebase (public fuel data, server-side aggregate visit counting, and crash reporting), Vercel (static edge deployment), GitHub (source code hosting).Method of Disclosure: Automated encrypted TLS connections governed by enterprise cloud data processing agreements.
3. Statutory & Legal AuthoritiesDisclosed only when strictly required by enforceable judicial warrants, court orders, or applicable Indian statutory obligations under the Information Technology Act, 2000.

5. Security Practices & Safeguards

In accordance with reasonable security practices under Indian and international standards, we implement robust technical, operational, and physical security measures:

HTTPS Encryption

Web traffic and API integrations use HTTPS with modern TLS to encrypt data in transit.

Least-Privilege Access

Access to developer accounts, support inboxes, and cloud dashboards is protected with multi-factor authentication (MFA).

Zero-Storage Model

We do not operate central databases storing customer financial instruments or sensitive personal identification.

6. Data Retention & User Rights (DPDP Act & GDPR)

We retain personal communication and support records only as long as necessary to fulfill support requests or satisfy statutory legal requirements.

Visit-counter deduplication hashes expire after 24 hours and are removed by Firestore's managed TTL cleanup, normally within 48 hours. The aggregate count contains no per-visitor details and is retained while the counter is offered. Session storage ordinarily clears when the browser tab session ends.

Under applicable data protection laws, you possess the following rights:

  • Right to Access: Request a copy of personal information we maintain regarding you.
  • Right to Correction & Erasure: Request the correction of inaccurate data or complete deletion of your support history.
  • Right to Withdraw Consent: Revoke consent for communications or public donor acknowledgments at any time.

To exercise any of these rights, email our designated Grievance Officer at trinadh.thatakula@gmail.com.

7. Grievance Officer & Contact Information

If you have questions, concerns, or grievances regarding our privacy practices or data processing, please contact our Grievance Officer in India:

Officer: Trinadh Thatakula (Grievance & Compliance Officer)
Entity: Trinadh Thatakula (Spectra Apps)
Office Address: Madhapur, HITEC City, Hyderabad, Telangana 500081, India
Domestic Phone (India): +91 82828 24899 (reference line — calls not attended)
Email: trinadh.thatakula@gmail.com (will respond within 24 hours)
Turnaround Time: Acknowledged within 24 hours; resolved within 15 days in accordance with the IT Rules, 2021.

Related Compliance Documents

Explore our Terms of Service, Cancellation & Refund Policy, and Customer Support channels.