Privacy Policy — Radhe Radhe
Effective date: 25 May 2026
Radhe Radhe ("the app", "we", "us") is operated by HouseofTech Innovation ("HouseofTech"). This Privacy Policy explains what personal information we collect when you use the Radhe Radhe Android, iOS, or web client, how we use it, who we share it with, and the choices you have. It applies to the app package com.houseoftech.radheradhe and the supporting backend service at https://radheradhe-api-*.asia-south1.run.app.
1. Information we collect
We collect the minimum personal data needed to operate the service.
You give us:
- Phone number. A 10-digit Indian mobile number is required to create an account. We use it to send a one-time password (OTP) for sign-in and to identify your account on future sign-ins.
- Language preference. You pick a content language on first launch and can change it any time in Settings.
- Display name (optional). You may enter a display name in your profile. It is shown only to you within the app.
- Profile photo (optional). If you upload a profile photo, we store it in a private cloud storage bucket. It is shown only to you within the app and is served through short-lived signed URLs.
- Payment information. Subscription payments are processed by Razorpay Software Private Limited. We do not receive or store your UPI handle, card number, or bank details. Razorpay returns a subscription identifier, plan, status, and period dates to us so we can grant entitlement.
We generate when you use the app:
- Session token. When you verify an OTP, we issue a signed JWT session token that the app sends with subsequent requests.
- OTP issuance records. For each OTP we send, we store a hash of the code (not the code itself), the expiry time, and an attempts counter so we can rate-limit verification.
- Subscription state. Plan, status, and current period dates returned by Razorpay.
- Webhook event log. Razorpay subscription events we have already processed, used to prevent duplicate handling.
Advertising attribution (Meta SDK + Conversions API). The Meta SDK and backend Conversions API are enabled for the launch build so we can measure which installs and registrations result in a paid subscription. The events we send are:
- App install (handled by the SDK).
- Registration completion — sent once when OTP verification creates your account. Includes hashed copies of your user ID and phone number for server-side attribution.
- Checkout/subscription start — sent when you tap a subscribe button and when the backend creates a Razorpay mandate. Includes the plan slug, price in INR, attribution event ID, and hashed copies of your user ID and phone number for server-side attribution.
- Purchase — sent once when your subscription is confirmed as active. Includes the plan slug, price in INR, attribution event ID, and hashed copies of your user ID and phone number.
Meta receives your Android Advertising ID (AAID) and the standard mobile signals their SDK reads on initialisation. We do not send your name, profile photo, content interactions, or device contacts.
We do NOT collect:
- Location, GPS, or coarse-network location.
- Contacts, calendar, SMS history, or call logs.
- Per-user analytics about which posters, wallpapers, or ringtones you view. Aggregate view and download counts are tracked at the content level, not against your account.
- Crash analytics from third-party SDKs. The app does not integrate Firebase Analytics, Google Analytics, Crashlytics, AppsFlyer, Branch, or other crash/diagnostics SDKs beyond the Meta SDK noted above.
2. How we use your information
We use the data above only to:
- Sign you in and keep you signed in.
- Show you content in your chosen language and tier (free or premium).
- Charge and renew your subscription through Razorpay and unlock premium content while the subscription is active.
- Detect and prevent abuse (OTP brute-force, replay of payment webhooks, attempts to download premium content without entitlement).
- Measure which marketing channels drive installs, registrations, and paid subscriptions through the Meta SDK and Conversions API events described in Section 1. We use this only for attribution; we do not retarget you with personalised ads from inside the app.
- Comply with applicable Indian law and respond to lawful requests.
We do not sell your data. We do not use your data to serve personalised advertising within the app.
3. Who we share it with
We share data only with service providers strictly needed to operate the service:
- Google Cloud Platform (project
august-victor-496112-b8, regionasia-south1) — hosts the API service (Cloud Run), the user and content database (Firestore), and the media storage (Cloud Storage). Account data lives in India. - Razorpay Software Private Limited — processes subscription payments. Razorpay's own privacy policy applies to data you provide directly to Razorpay during checkout. See
https://razorpay.com/privacy/. - voicensms.in (DLT-registered SMS broker) — delivers OTP SMS to your phone number. The broker receives only your phone number and the OTP message text.
- Meta Platforms, Inc. — receives the advertising-attribution events described in Section 1 (hashed user ID, hashed phone number, Android Advertising ID, event name, attribution event ID, plan, and purchase amount in INR). Meta's own data policy applies. See
https://www.facebook.com/privacy/policy.
We do not share your data with data brokers or with analytics providers other than Meta as disclosed above.
We may disclose information when required by law, by valid legal process, or to protect the rights, property, or safety of HouseofTech, our users, or others.
4. Where your data is stored and how long we keep it
Account and content metadata is stored in Firestore in the asia-south1 (Mumbai) region. Media files are stored in Google Cloud Storage in the same region. Backups stay in India.
- Your account record (phone, language, optional name, profile photo reference, subscription state) is retained until you delete your account.
- OTP records are deleted after the OTP expires or is used.
- Webhook event log entries are retained for 90 days for replay protection.
- Razorpay payment records are retained by Razorpay per their own retention schedule, independent of us.
When you delete your account (Settings → Delete account in the app), we permanently delete your user record, profile photo, OTP records, and subscription mapping immediately. Backups roll out the deleted row within 30 days. Aggregate counters on content items are not tied to your account and are not deleted. See the separate Account Deletion page for the full purge procedure and retention windows.
5. Security
- All network traffic between the app and our service uses HTTPS (TLS 1.2+).
- OTP codes are stored as a salted HMAC-SHA256 hash, never in plain text.
- Premium media is served through one-hour signed URLs after we verify your entitlement; the underlying objects are not publicly accessible.
- Profile photos are stored in a private bucket; the public web does not have direct access.
- Session tokens are signed with a server-side secret rotated on each deploy.
No system is perfectly secure. Use a phone number you control, and keep your device locked.
6. Your rights
Under applicable Indian law, including the Digital Personal Data Protection Act, 2023, you may:
- Access the information we hold about you. Use Settings → Account to view your profile; for the rest, contact us at the address below.
- Correct your name and language in Settings; contact us to correct anything else.
- Delete your account in Settings → Delete account. This removes your personal data.
- Withdraw consent by deleting your account.
- Complain to the Data Protection Board of India if you believe we have mishandled your data.
We will respond to written requests within 30 days.
7. Children
Radhe Radhe is rated for users 13 and older. We do not knowingly collect data from anyone under 13. If you believe a child under 13 has registered, contact us and we will delete the account.
8. Changes
We may update this policy. The effective date at the top will change when we do. Material changes will be highlighted in the app on next launch.
9. Contact
For privacy questions or data requests:
- Email: yash@houseoftech.ai
- Postal address: F-118, Adani Galeria, Sector 89A, Gurgaon, Haryana, 122505, India
This Privacy Policy is governed by the laws of India. Disputes are subject to the exclusive jurisdiction of the courts in Delhi.