Privacy Policy

Effective date: 22 May 2026

This Privacy Policy explains how Zyntragram (“we”, “us”, “our”) collects, uses, and shares information when you use the Zyntra mobile application and related services (the “Service”). Zyntragram is operated from India and complies with the Digital Personal Data Protection Act, 2023 (“DPDPA”) and applicable rules under the Information Technology Act, 2000.

By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.

1. Information we collect

1.1 Information you provide

When you create an account or use the Service, we collect:

1.2 Information collected automatically

1.3 Information from third parties

We may receive limited information from Firebase and other service providers we use to operate the app — for example, device-integrity signals from Firebase App Check.

2. Lawful basis for processing

Under the Digital Personal Data Protection Act, 2023, we process your personal data on the following lawful bases:

3. How we use information

We use the information we collect to:

4. Sharing and disclosure

We do not sell your personal information. We share information only in the following circumstances:

5. Third-party services

We rely on the following providers to deliver the Service:

Each provider has its own privacy and data-handling practices. We recommend reviewing their policies for details.

6. Your rights under DPDPA

As a Data Principal under the DPDPA, you have the following rights:

To exercise any of these rights, email support@zyntragram.com from the email address associated with your account.

7. In-app choices and controls

8. Age requirement

The Service is intended for individuals who are at least 18 years old. You must be 18 or older to create an account or use the Service. We do not knowingly collect personal information from anyone under 18, consistent with the Digital Personal Data Protection Act, 2023 (India). If you believe a person under 18 has provided us information, please contact us at support@zyntragram.com and we will take reasonable steps to delete that information.

9. Security and breach notification

We follow “reasonable security practices and procedures” as required by Section 43A of the IT Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the security obligations under the DPDPA. These include encryption in transit (HTTPS/TLS), hashed password storage, device-bound session tokens, principle-of-least- privilege access controls, and routine review of our safeguards.

Account recovery uses a one-time recovery code (shown only once at setup) and, for accounts with a verified email, an email-based OTP. Keep your recovery code somewhere safe.

Breach notification: in the event of a personal data breach, we will notify the Data Protection Board of India and affected users in the manner and within the timelines prescribed by the DPDPA and its rules.

No method of transmission or storage is 100% secure; we cannot guarantee absolute security but work continuously to improve our safeguards.

10. Data retention

10.1 While your account is active

We retain your account information and content for as long as your account remains active.

10.2 If you deactivate your account

Deactivation hides your profile and content from other users but does not delete any data. Signing in again automatically reactivates the account and restores everything to the state it was in before deactivation.

10.3 If you delete your account

Deletion is processed in two stages so you have time to change your mind:

  1. Grace period. Your account enters a pending-deletion state and your profile, messages, and content are immediately removed from public view. The grace period lasts up to 30 days depending on your account tier (shorter for guest / temporary accounts). Signing back in during the grace period cancels deletion and fully restores your account.
  2. Permanent deletion. When the grace period ends, your personal information is deleted from our active systems or irreversibly anonymized.

Some information may be retained beyond permanent deletion for limited and legitimate purposes, including:

11. International transfers

Zyntragram operates from India, and our service providers (such as AWS and Google) may process your information in regions outside India. Section 16 of the DPDPA permits such transfers except to countries restricted by the Central Government by notification. We rely on contractual safeguards and the providers’ own security commitments for cross-border processing.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the app or by other reasonable means. The “Effective date” at the top reflects the latest version.

13. Grievance Officer

In accordance with Section 8(10) of the DPDPA and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the following officer has been designated to address your grievances:

We acknowledge complaints within 24 hours and aim to resolve them within 15 days of receipt, as required under applicable law.

14. Contact us

For general questions about this policy or your data, email us at support@zyntragram.com. For grievances, please contact our Grievance Officer (see Section 13).