Sankalp Privacy Policy
Last updated: 2026-07-22
Sankalp is a devotional companion published by Hellovibe Edtech Pvt Ltd, a company registered in India. We are the data controller (under the GDPR) and the data fiduciary (under India's Digital Personal Data Protection Act, 2023) for the personal data described here. This policy explains what we hold, why, and how you can get rid of it.
The short version: Sankalp works fully offline, and holds nothing that identifies you unless you choose to sign in, write to us, or ask us to email you. If you sign in, we hold your account details and the practice records you sync — and a small number of named staff can view those synced records through a private, logged admin console, to answer support requests and keep the service running. If you write to us, we hold your message. If you join the waitlist, we hold your email address until you tell us to stop. Separately, the app and this site count usage — which features get opened, how often — so that we can tell what is worth building. On this site those counts stay anonymous, never tied to your name or contact details. In the app they are anonymous until you sign in, and after you sign in they are linked to your account so we can understand your journey and improve the app — and Account carries a switch that turns them off entirely. On this site there is no such switch, and stopping the counting here is your browser's job. We serve no ads, embed no advertising trackers, and never sell or share your data.
Using Sankalp without an account
Signing in is optional and always skippable. If you use Sankalp without an account, your deities, japa counts, journal reflections, fasting records, streaks, and settings stay on your device and are never transmitted to us. The one thing that does leave is the anonymous usage counts described in the next section — event names under a random per-install ID, with none of your practice in them, and a switch in Account to stop them. Beyond that we receive nothing unless you deliberately write to us, which is covered below.
Two things stay on your device even when you are signed in. Darshan Lock uses Apple's Screen Time (Family Controls), and the tokens representing the apps you choose to rest are device-bound by Apple's design — we cannot read which apps you picked, and that selection is never synced. Panchang timings need an approximate location to be correct for your sky, so if you grant location access the app requests a coarse, roughly city-level fix and uses it on-device only; it is never sent to our servers.
Usage analytics
Sankalp counts how it is used, because building in the dark means guessing. What goes out is a short list of event names — the app was installed or opened, onboarding finished, a sign-in happened, the lock was switched on, a darshan was asked for or completed, a japa or fast was logged, the panchang was opened, feedback was sent — alongside the coarse technical context the SDK attaches: device model, OS version, app version, language, country. Where an event carries detail, that detail is a fixed choice or a count: which of the three sign-in methods you used, how many apps you put behind the lock. Never free text.
What never goes out: your prayers, your journal reflections, which deities you chose, your fasts, your location, your contacts, your email, your phone number, or your name. The event records that a darshan happened. It does not record which God.
Before you sign in, these events carry only a random identifier generated on your device when you install — no account, no name. When you sign in to the app, we link that identifier to your account: the app tells PostHog your user ID and nothing else — not your email, your name, or the content of your practice — so the usage events from that device become part of your account and help us understand your journey through the app and improve it. What each event carries never changes: still the fixed choices and counts above, never your prayers, your deities, or free text. The processor is PostHog, on servers in the United States; session recording, automatic click capture, and anything resembling an advertising identifier are all switched off. PostHog's servers see your IP address arriving, the way every server you connect to does — but the project is set to discard client IPs rather than store them: your country is read off the address, and then the address is dropped instead of being kept against the event. If you would rather not take part at all, open Account and turn off "Share anonymous usage" — analytics is fully disabled and the app behaves identically either way.
This website counts differently: it has no sign-in, so it never links anything to an account and its analytics stay anonymous. getsankalp.app records anonymous pageviews — which page you landed on, and the occasional click on an App Store badge — through that same processor, routed through our own domain. It keeps a random visitor ID in your browser's localStorage rather than setting advertising cookies, there is no session recording here either, and IP addresses are discarded here as they are in the app. One difference is worth stating plainly: the switch is in the app, and this site does not have one. Counting starts when the page loads. If you would rather not be counted here, a content blocker or a browser that blocks trackers will stop it — we do nothing to work around either — and clearing this site's localStorage resets the visitor ID. The site reads exactly the same with or without any of that.
What we collect when you sign in
You can sign in with Apple, with Google, or with your phone number. Whichever you choose, we receive and store an account identifier for you: your email address (Apple or Google), your phone number (one-time-code sign-in), your name if the provider supplies one, and a user ID we generate. Sign in with Apple lets you hide your real email address, and Sankalp works normally if you do.
Once you are signed in, your practice records sync so they survive a lost phone and reach your other devices. That means: your chosen deities, your onboarding profile (the name you enter, your region, the goals you pick, the rough hours you said you spend on your phone, and the deity of your sankalp vow), your fasting plans and logs, the free-text reflections you write in your journal, your japa counts, and your darshan records — each stamped with the day it happened.
We do not collect device identifiers for advertising, contacts, photos, health data, or precise location, and Sankalp contains no advertising SDK. It does measure usage, described above — anonymous until you sign in, and linked to your account afterwards so we can understand how you use the app and improve it. Those events still carry only fixed choices and counts, never the content of your practice: linking lets us see that a darshan happened and that it was on your account, never which God it was for. You can turn this off entirely in Account.
When you write to us
If you send us feedback — from the form in the app, or the one on this site — we store your message, the topic you picked, and any contact detail you chose to give, so that we can answer you and fix what you told us about. You don't need an account to write to us, and you don't have to leave a contact detail unless you'd like a reply.
We keep messages while we work through them and for a reasonable period after, because a bug report is often still useful months later. If you were signed in when you wrote, your message is tied to your account and is deleted along with it. If you wrote to us without an account, tell us and we'll delete your message — but do include enough for us to find it, since an anonymous message has nothing linking it to you.
When you ask us to email you
This site has a waitlist for early access to Sankalp. If you join it, we hold the email address you give us, the name you give us if you choose to give one, and the date you signed up. That is all of it. We use it to send you your invitation to the test build and, later, to tell you when Sankalp reaches the App Store — and for nothing else.
This list stands entirely apart from the app. It is not joined to an account, and it never touches your practice: if you later sign in, we do not connect the two, so nothing you pray, log, or fast is ever visible to the list or the service that sends it. Joining the waitlist tells us an email address is interested in Sankalp. It tells us nothing about you.
Our lawful basis here is your consent, given by typing your address into the form and asking us to write to you. Because Sankalp is a Hindu devotional app, asking for that invitation says something about what you are interested in — so we treat this list with the same care as the rest, and ask rather than assume. You can withdraw at any time: every email we send carries a one-click unsubscribe, and you can also write to us and we will remove you. We keep your address until you unsubscribe or until the launch list has served its purpose, whichever comes first; we do not sell it, rent it, or hand it to anyone for their own use.
The service that stores this list and sends these emails is Loops (Loops Email Inc.), on servers in the United States, acting on our behalf under their data processing terms. Delivery itself runs through Amazon Web Services from our own mail subdomain. Neither is given the right to use your address for their own purposes.
Your religious data, and why we ask for consent
The records above reveal your religious beliefs and practice. Under the GDPR that is special-category data (Article 9); under the DPDP Act it is personal data deserving particular care. We treat it that way.
Our lawful basis is your explicit consent, given when you choose to sign in and sync — which is why sync is opt-in rather than the default, and why the app is fully usable without it. That consent covers two things together: that we store these records to give them back to you, and that our own named staff can view them through the admin console for the support, safety, and operational purposes set out below and under Security. Because the app is fully usable without ever signing in, declining is real — you simply keep everything on your device. You can withdraw at any time by signing out (which stops further syncing) or by deleting your account (which removes what we hold). Withdrawing does not affect processing that already happened, and it never costs you access to the app.
What we use it for
We use your account identifier to sign you in and to keep your records separate from everyone else's. We use your synced records to give them back to you — restoring your practice on a new device, keeping your streaks honest across devices, and personalising what the app shows you, such as ranking the deity library by your region and surfacing your chosen Gods. To answer your support requests, investigate problems you or others report, and operate the service safely, identified staff may view your account and the records you have synced — including your chosen deities and your practice logs — through the private admin console described under Security. We do this only for those purposes, never to advertise to you or to build a profile about you, and every such view is recorded.
That is the entire list for the data above. The usage counts described earlier serve one purpose — to see which features earn their place. Before you sign in they are anonymous; after you sign in they are linked to your account, and while we read them in aggregate to improve the app, our support staff may also look at your individual usage history when helping you or investigating a problem — turning them off in Account stops the counting. We do not build advertising or scoring profiles of you, make automated decisions about you, or use your data to train models. Staff may view your records individually for the support, safety, and operational purposes described above — but that is a person answering a question, not a profile we assemble, sell, or feed to a machine. Nor do we market to you off the back of any of it: your account, your practice records, and your messages are never used to email you anything promotional, and are never added to a mailing list. The one place we do send email is the waitlist described below, which you have to ask for, and which knows nothing about your practice.
Who else processes it
We keep the chain short. Supabase hosts our database and authentication, and stores your account, your synced records, and the waitlist on our behalf under their data processing terms. Vercel Inc., on servers in the United States, hosts this website and the internal admin console our staff use; when a staff member views an account, the read that renders it runs on Vercel, so it processes the same data on our behalf under its data processing terms. Apple and Google act as identity providers when you use their sign-in buttons — they tell us who you are, and we tell them nothing about your practice. If you sign in by phone, Supabase's SMS provider delivers your one-time code. PostHog, Inc. receives the usage events described above, and nothing else — on this site anonymous, and in the app anonymous until you sign in and linked to your account afterwards by your user ID alone, never your email, your name, or the content of your practice. Loops (Loops Email Inc.) holds the waitlist and sends those emails, delivering them through Amazon Web Services; it receives the email address and name you gave the waitlist form, and nothing else — not your account, not your deities, not a single thing you have prayed or logged. Apple also processes your data as the App Store operator and, for Screen Time, entirely on your own device.
That is the whole chain. None of them is given the right to use your data for their own purposes, and we do not sell or share personal data with anyone.
Our servers may sit outside India and outside the EEA, so signing in involves transferring your data across borders — as does the usage analytics, which goes to the United States whether or not you have an account. Where the GDPR applies, such transfers rely on the European Commission's standard contractual clauses; where the DPDP Act applies, transfers go only to countries the Indian government has not restricted.
How long we keep it
We keep your account and synced records for as long as your account exists, because their purpose is to still be there when you come back. There is no automatic expiry — a fast you kept three years ago is part of your practice, not stale data.
When you delete your account, we delete your records from our live database immediately; the app deletes its local copy on that device at the same time. We keep the admin-console access log — the record of which staff member viewed an account and when — for up to 12 months for security and accountability, after which it is purged; the entries naming you are removed when you delete your account. Your usage-analytics records hold only an internal account identifier and counts, never your name, email, or the content of your practice; you can ask us to delete them and we will. Residual copies can persist in encrypted backups for a short period before being overwritten in the ordinary course. If you never sign in, there is nothing for us to keep or delete.
Your rights
You can ask us for a copy of what we hold about you, correct anything wrong, delete it, get it in a portable form, ask us to restrict or object to how we use it, and withdraw your consent. These rights come from the GDPR if you are in the EEA or UK and from the DPDP Act if you are in India; we honour them for everyone regardless of where you live, because drawing that line would be petty.
The fastest route to deletion is in the app: open Account and tap Delete account. It removes your account and every record we hold for you, on every device, straight away — no email, no waiting. The admin-console access log naming you is cleared with your account, and you can ask us to remove your usage-analytics records as well. For anything else, write to us and we will respond within 30 days.
If we get it wrong, please tell us first — our Grievance Officer is named below and will answer you. You also have the right to complain to a regulator without coming to us at all: the Data Protection Board of India, or your local supervisory authority if you are in the EEA or UK.
Children
Sankalp is not directed at children, and we do not knowingly hold data about anyone under 18. Under the DPDP Act, processing a child's data needs verifiable parental consent, which we are not set up to obtain. If you believe a child has signed in, write to us and we will delete the account.
Security
Your data travels over encrypted connections and is encrypted at rest by our host. Every table is protected by row-level security, so the key shipped inside the app can only reach your own rows and never another person's — one signed-in device cannot read another's account. Separately, a small number of named staff at Sankalp can read your account details, the records you sync, and your in-app usage history in our analytics tool through a private, password-protected admin console we use to answer support requests, investigate problems, and keep the service safe and running. That access uses a privileged key that row-level security does not restrain, so we restrain it ourselves: it is limited to a named list of people, it is never used for advertising or profiling, and every time a staff member opens an individual's record the system records who looked and when. No system is perfect, and we will not pretend otherwise, but the less we hold, the less there is to lose — that remains the strongest privacy measure we have.
Changes
If we change what we collect, we will update this page and its date, and tell you in the app when the change is material. Where the change needs your consent, we will ask before it takes effect rather than assume.
Contact
For questions or requests about your data, write to hello@hellovibe.in and a real person will read it.
If you want to raise a grievance formally, our Grievance Officer under the DPDP Act is Sai Krishna Korukanti, Director of Hellovibe Edtech Pvt Ltd — crishna@hellovibe.in.
Postal address: Hellovibe Edtech Pvt Ltd, 104, Kamala Baghya Nilayam, Jyothinagar, Karimnagar, Telangana, India.