Last updated: 2026-09-15 Product: Semper DIC Android app, optional cloud sync backend, and web console Data controller (data fiduciary): [OPERATOR LEGAL NAME], [REGISTERED ADDRESS], Chennai, Tamil Nadu, India Privacy contact: the support mailbox configured as SUPPORT_EMAIL for the deployment Grievance Officer (Digital Personal Data Protection Act, 2023): [GRIEVANCE OFFICER NAME], [GRIEVANCE OFFICER EMAIL]
This policy describes personal data processed by Semper when you use the app and, if enabled, the Semper cloud backend. Analysis itself runs on-device; the cloud path is optional and only active when the app is built with an API base URL.
| Role | Who |
|---|---|
| Controller / data fiduciary | [OPERATOR LEGAL NAME], Chennai, India — the organization that distributes your build and operates the GCP/Firebase project |
| Subprocessors (typical) | Google (Firebase Auth, Firestore, Google Drive, Firebase Crashlytics, Cloud Logging / Cloud Run), Resend (transactional email for access-request notifications) |
No large-language-model or generative-AI provider is integrated. Subprocessors are bound by written data-processing terms that require them to protect your data and to process it only on our instructions.
The service is operated from India and is not offered to residents of the European Union, the European Economic Area, or the United Kingdom. We nevertheless apply the safeguards described here — a separate, withdrawable consent for any use of your content beyond providing the service, purpose limitation, data minimisation, the rights in section 5, and breach handling — as our standard for every user.
.dat / CSV) stored in a company Shared Drive under the Cloud Run service account — bytes are uploaded by the device directly to Drive, not through Cloud Run.audit_logs in Firestore record security-relevant actions (auth denials, approvals, deletes, exports). They intentionally retain the fact of actions after account erasure and do not store analysis content..dat displacement/strain fields, reports, session metadata (specimen label, parameters, engine metrics) — and metrics derived from them. Content that stays on your device and is never synced is never used.| Purpose | Examples | Basis (typical) |
|---|---|---|
| Provide the product | Sign-in, sync, restore, quotas | Contract / legitimate interest |
| Access control | Pending approval, admin approve/revoke | Legitimate interest / compliance |
| Security | Device attestation, rate limits, audit | Legitimate interest |
| Reliability (server) | Cloud Logging, readiness probes | Legitimate interest |
| Reliability (app diagnostics) | Crashlytics / Analytics crash reports | Consent — opt-in, withdrawable in Settings |
| Support onboarding | Resend access-request mail | Legitimate interest |
| Product improvement — your synced content | Regression datasets, tuning, accuracy studies (section 2.8) | Consent — separate option, pre-selected but declinable before continuing, withdrawable in Settings |
| Product improvement — aggregate metrics | De-identified engine/operational statistics | Legitimate interest — objection honoured via the same toggle |
| Contract and consent records | Terms version accepted, consent changes | Contract / legitimate interest (evidence of agreement) |
| Legal compliance | Responding to lawful requests, tax and accounting records | Legal obligation |
Where the law of your country names different bases, the closest equivalent applies. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
Cloud data is stored in the Google Cloud region selected by the operator for your deployment ([GCP REGION, e.g. asia-south1 (Mumbai)]) and may be processed by Google in other regions for redundancy and support. Transactional email is processed by Resend in the United States. Where data leaves India or your country, we rely on the subprocessors' contractual data-protection commitments and comply with applicable cross-border transfer rules, including those under the Digital Personal Data Protection Act, 2023, and any restrictions notified by the Government of India.
| Data | Retention |
|---|---|
| Firebase Auth account | Until you delete the account or an admin removes it |
| Firestore profile, devices, sessions, file docs | Until account/session erasure via the app/API |
| Drive artifacts | Deleted with session or account erasure (Shared Drive trash may retain per Workspace policy) |
| Crashlytics | Per Firebase project retention settings (UNKNOWN until verified in console) |
| Cloud Logging | Per GCP log retention (UNKNOWN until verified; default often 30 days) |
| Resend message content | Per Resend retention (UNKNOWN until verified) |
| Audit logs | Retained after erasure for security/compliance; not included in user export of analysis content |
Scheduled Firestore exports / PITR, where enabled, follow FIRESTORE_DATA_PROTECTION.md.
You have the following rights over your personal data, subject to applicable law. We answer requests within 30 days (extendable where the law allows for complex requests, and we will tell you if so). To protect your account we verify requests through the app's device attestation or by re-authentication.
India (Digital Personal Data Protection Act, 2023). You may access, correct, update, and erase your personal data, obtain grievance redressal through the Grievance Officer named above within the statutory period, and nominate a person to exercise these rights if you die or are incapacitated.
Other jurisdictions. If the law where you live gives you equivalent rights (for example, rights to know, delete, or correct, and non-discrimination for exercising them), we honour them on request. We do not sell personal data and do not share it for cross-context behavioural advertising.
GET /v1/me/export, which returns profile, devices, and complete session manifests — complete: true is written last, so a truncated download is detectable.) Binary artifacts are downloaded via GET /v1/files/{id}/content (or the app Restore flow).DELETE /v1/sessions/{id} removes Drive folder + Firestore metadata for that analysis.DELETE /v1/me removes the Drive user subtree and Firestore user/session/device/file docs. Audit logs remain.Data is shared with subprocessors above to operate the service. It is not sold. Admin operators of your deployment can approve users and view operational logs according to project IAM.
If a breach of security affects your personal data, we will notify the competent authority within the period required by law (in India, as prescribed under the Digital Personal Data Protection Act, 2023) and will inform affected users without undue delay, describing the nature of the breach, the likely consequences, and the measures taken.
TLS in transit (Cloud Run / Gateway), deny-all client Firestore rules (server SDK only), device attestation for high-consequence mutations, rate limits, security headers, and opaque client error bodies on Cloud Run. See CLOUD_ARCHITECTURE_GCP.md.
Semper is a professional / research tool offered to adults (18 or the age of majority where you live) acting in a business or professional capacity. It is not directed at children and we do not knowingly process children's data; if you believe a child has created an account, contact us and we will delete it.
Material changes will update the “Last updated” date and will be announced in-app or in release notes. Any change that would expand consent-based processing (sections 2.4 and 2.8) is not applied to you until you consent to it again in the app.
Use the in-app support / help action or the configured support email for privacy requests (export, deletion, access questions). Grievances under the Digital Personal Data Protection Act, 2023 go to the Grievance Officer named at the top of this policy.