Zcribbler Software Labs Private Limited
Privacy Policy
Effective date: August 3, 2026 · Version 2.0
In short
- Everything you make in Zcribbler is private until you send it. You choose the recipients of every single distribution.
- We do not sell or rent your data, we run no advertising, and we collect no advertising identifier on either platform.
- There is no public web page for your profile or your content. Nothing you post is readable by someone who is not signed in to the app.
- We never ask for your phone number or your contacts, and we cannot read them.
- Usage analytics carry no account identifier and no advertising identifier — they tell us which screens open and where the app fails, never who you are or what you wrote.
- You can close your account from inside the app at any time. It takes effect immediately.
This summary is for orientation only. The sections below are the policy.
1. Who We Are
Zcribbler Software Labs Private Limited operates the Zcribbler mobile application and the zcribbler.com website (together, the "Service"). We decide why and how your personal data is processed, which makes us the controller of that data.
- Role under the GDPR (EU/EEA and UK): Data Controller
- Role under the Digital Personal Data Protection Act, 2023 (India): Data Fiduciary
- Registered location: Kannur, Kerala, India
- Privacy contact: [email protected]
This policy applies to the Zcribbler app and to zcribbler.com. It does not apply to Google, Apple, or any other service you reach from inside the app, each of which has its own privacy policy.
2. What Zcribbler Does, So This Policy Makes Sense
Zcribbler is a place to keep your content and distribute it to people you choose. The mechanics matter for privacy, so they are stated here once and referred to throughout:
- A zcribble is something you author — words, photos, video, or a voice recording. It is private when you make it and stays private until you distribute it.
- A distribution is one act of sending a zcribble to an audience. The same zcribble can be distributed more than once, to different people.
- You can send to one person, to an audience you assemble from individuals and your own circles, or to all of your followers.
- A circle is a private list of people you maintain for yourself, so you do not have to reassemble the same audience twice.
- An instant is a short video or photo, distributed the same way.
- Following is one-directional. Someone may follow you without you following them back, and you may turn on approval so that new followers need your permission first.
Section 6 sets out exactly who can see what.
3. Data We Collect
3.1 Data you give us
| Data | Why we have it |
|---|---|
| Name and email address, passed to us by Google or Apple when you sign in | Creating and identifying your account, and contacting you about it |
| Username | Your unique address inside the app; it appears in mentions and in links you share |
| Date of birth | Confirming you meet the minimum age. It is never shown on your profile or anywhere else in the app |
| Profile photo, short bio, accent colour, and any profile links you add | Your profile, as shown to people who can see it |
| Zcribbles and instants — your words, photos, videos, and voice recordings | The core of the Service |
| Your distributions — which zcribble went to which audience, and when | Delivering content to the people you chose, and to no one else |
| Your circles — their names and who is in them | Letting you reuse an audience. Circles are visible only to you |
| Reactions, replies, and mentions | Conversation on content that was distributed to you |
| Your labels — a filing vocabulary you invent | Organising and finding content. Labels are private to you, including labels you put on someone else's content |
| Direct messages — text, voice notes, photos, and reactions to them | Private conversation between two people |
| Follows, blocks, and follow approvals | Building and controlling your side of the follow graph |
| Reports you file about content or people | Safety and moderation. See Section 13 |
| Your settings — who may follow you, who may message you, and your notification preferences | Applying the choices you made |
| A place name, if you choose to tag one | Only when you tap to add a place. The app asks your device for its location at that moment and turns it into a place name. It is never collected in the background, and never when the app is closed |
3.2 Data collected as you use the app
| Data | Why we have it |
|---|---|
| Sign-in records: IP address, device name, operating system, and app version | Keeping you signed in, showing you your logged-in devices, and detecting suspicious sign-ins |
| Which content you have seen, and when | Not marking the same thing unread twice, and telling the person who sent it that it was seen (see Section 6) |
| Counts of your own activity — followers, following, how much you have distributed | Displaying your profile and ordering what people see |
| Push notification token for your device | Delivering notifications you asked for |
| A device-integrity check at sign-in, run by Google Play Integrity or Apple App Attest | Telling real installations of our app apart from automated abuse. It reports on the app and the device, not on you, and it never blocks a sign-in |
| On Android only: the referral parameter Google Play preserves when you install from a link | Opening the app at the profile whose link you tapped. It is read once and never again |
3.3 Data from Google, Apple, and Firebase
| Service | What is involved | Purpose |
|---|---|---|
| Sign in with Google | A signed identity token containing your email and name | Authentication |
| Sign in with Apple | A signed identity token containing your email and name, plus a one-time authorisation we store encrypted so we can revoke it if you close your account | Authentication, and honouring Apple's account-deletion requirement |
| Firebase Cloud Messaging (Google) | A push token for each device | Delivering push notifications |
| Firebase Crashlytics (Google) | Crash reports and the state of the app when it crashed | Finding and fixing crashes. No account identifier is ever attached to a crash report. |
| Google Analytics for Firebase | Which screens opened, which actions completed or were abandoned, app version, device model, operating system, and country | Understanding where the app is confusing or broken. See below |
What usage analytics do and do not contain. Analytics tell us that a step was reached or abandoned. They never contain your name, your username, your email, your account identifier, anything you wrote, anything you shared, or who you shared it with. We do not attach your account identifier to analytics events, and there is no way for us to do so by accident.
No advertising identifier, and no device identifier. On iOS the advertising framework is not built into the app at all, so the IDFA cannot be read. On Android the advertising-ID permission is removed from the app and advertising-ID collection is switched off. The remaining device-scoped identifiers offered by the analytics tools — Apple's vendor identifier and Android's Settings ID — are switched off as well. What remains is a random identifier for this installation, which is discarded when you uninstall the app and reset when you close your account.
Usage analytics are collected from every installation, and there is no in-app switch for them. We rely on legitimate interests (Art. 6(1)(f)) rather than consent, because these records identify no one: they carry no account identifier, no advertising identifier and no device identifier, and we cannot connect a single event to a single person even if asked to. Product decisions that are made on a sample of users who opted in are made on the wrong sample, and the failures we most need to see — a sign-up abandoned before an account exists, an upload that never reached us — are invisible to us in every other way.
How to stop it. Removing the app from your device stops collection from that installation immediately and discards its identifier. You may also object under Art. 21 by writing to [email protected]; see Section 12. Crash reports are a separate pipeline and continue either way, so that a crash you hit can still be fixed; they carry no identifier for you.
3.4 Photo and video metadata
Photos and videos usually carry hidden metadata — the date and time of capture, GPS coordinates, and the camera and lens used. Zcribbler handles it in two separate ways, and the difference matters:
- The file everyone else receives has it removed. When your device prepares a photo or video for upload, it re-encodes the file, and the re-encoded file carries no capture metadata. Nobody you distribute to receives your GPS coordinates, your capture timestamps, or your camera details.
- A structured copy is kept for you. The same information is read once, at upload, and stored against your own copy of the content. It is owner-only: it is never shown to anyone you distribute to, and it is not used to target, profile, or advertise to you. It is deleted with the content.
3.5 Data we do not collect
We never ask your device for: your phone number, your contacts or address book, your SMS messages, your call logs, your browsing history, your health or fitness data, your financial data, your biometrics, or data belonging to other apps.
We do not use: advertising SDKs, advertising identifiers, tracking pixels, cross-app or cross-site tracking, or third-party data brokers.
We do not track your location in the background or while the app is closed. Location is read only in the moment you ask the app to tag a place.
We do not operate an advertising network, and we do not monetise personal data in any form.
4. How We Use Your Data
- Running the Service: holding your content, delivering each distribution to the people you named and to nobody else, carrying conversation and messages, and showing your profile to those permitted to see it.
- Ordering what you see: deciding the order of your feed and which people to suggest you might know. This is described in Section 13.
- Authentication and account security: keeping you signed in, showing you your active devices, and detecting abusive or automated access.
- Notifications: sending the push notifications you have enabled, and grouping bursts so one event does not produce twenty alerts.
- Safety and moderation: reviewing reports, acting on content and accounts that break our Terms, and meeting our legal obligations on child safety.
- Fixing and improving the app: crash reports and anonymous usage analytics, as described in section 3.3.
- Legal compliance: meeting our obligations under the DPDP Act, the GDPR, the Information Technology Act, 2000 and the rules made under it, and other applicable law.
- Answering you: handling support requests, appeals, grievances, and data-rights requests.
We do not use your content, your messages, or your social graph to train artificial-intelligence models, and we do not send them to any third-party AI service. No part of the Service analyses your photos, videos, or writing to infer things about you.
5. Legal Bases for Processing
Under the GDPR, we rely on the following bases:
| Basis | What we rely on it for |
|---|---|
| Performance of a contract Art. 6(1)(b) | Creating your account, holding your content, delivering your distributions, messaging, replies and reactions, your profile, and your settings |
| Consent Art. 6(1)(a) | Push notifications, camera, microphone, and location. Each is a separate choice you can make and unmake at any time, from your device's system settings. Withdrawing consent does not affect processing carried out before you withdrew it |
| Legitimate interests Art. 6(1)(f) | Keeping the Service secure and free of automated abuse, diagnosing crashes, anonymous usage analytics that carry no identifier for you (section 3.3), ordering the feed, and suggesting people you may know. We have weighed these against your rights and interests, and you may object under Art. 21 |
| Legal obligation Art. 6(1)(c) | Age verification, acting on content reports, retaining child-safety records, and cooperating with lawful requests |
Under the DPDP Act, 2023, we process your personal data on the consent you give when you create your account and accept this policy, and for the legitimate uses set out in Section 7 of that Act.
6. Who Can See What
Most privacy questions about Zcribbler are really questions about this. The full answer is below.
6.1 Your content
- A zcribble you have not distributed is visible to you alone. There is no setting to get wrong; unshared content simply has no audience.
- A zcribble you distribute is visible to exactly the people in that audience. Distributing the same zcribble twice creates two separate audiences with two separate conversations, and neither can see the other.
- If you send something to one person, it stays in that person's Library for as long as they keep it. If you send to an audience or to your followers, it appears in their feed and scrolls away; they cannot file it.
- If you turn on follower approval, only people you have approved can see your profile's content. If you leave it off, your profile is visible to anyone signed in to the app.
6.2 What other people learn about you
- The sender is told when you have seen something. Someone who distributes content to you can see that you viewed it, and roughly when. This applies to zcribbles and instants distributed to you. It does not apply to your Library or to anything you did not receive.
- Reactions are public within the audience. Everyone who received a distribution can see which emoji were used and by whom.
- People in the same audience can see each other. If you receive a distribution sent to several people, the app tells you who else received it. Assume that anyone you share with can see the rest of that audience.
- Follower and following lists are visible to people who can see your profile, as are your follower and following counts.
- Your username appears in links. If you share your profile link, the page it opens names your username. It shows nothing else — no photo, no bio, and none of your content.
6.3 What stays private to you
- Your circles. Their names, who is in them, and the fact that they exist are visible to you and nobody else. People are not told when you add them to a circle, and they never see what you called the group.
- Your date of birth. It appears nowhere in the app.
- Your labels, including labels you apply to other people's content.
- Photo and video capture metadata, as described in section 3.4.
- Your blocks. The person you blocked is not notified.
- Your reports. The person you reported is not told who reported them.
6.4 Direct messages
Direct messages are private between the two people in the conversation. We do not read them in the ordinary course of running the Service, and they are not used for analytics, suggestions, or ranking. We access a message only when it is reported to us, or where the law requires it. Direct messages are not end-to-end encrypted — they are encrypted in transit and at rest, but we hold the keys, which is what makes moderation of a reported message and lawful disclosure possible. Please do not treat Zcribbler messages as a secure channel for information that would harm you if disclosed.
You control who may message you in Settings → Privacy & account → Who can message you.
6.5 Nothing is public on the web
There is no public web page for a Zcribbler profile and no public web page for Zcribbler content. Your content cannot be read by a search engine, by a scraper, or by anyone who is not signed in to the app.
7. Who We Share Data With
7.1 We do not sell your data
We do not sell, rent, lease, or trade your personal data. We do not share it with advertisers or data brokers, and we do not run advertising of any kind.
7.2 Service providers
We use a small number of infrastructure providers — for hosting, storage and delivery, push notifications, and crash reporting — and each of them processes data only on our instructions, under a data processing agreement.
7.3 Legal requirements
We may disclose data where we are legally required to, or where it is necessary to:
- Comply with a valid court order, subpoena, or lawful government request.
- Report child sexual abuse material to the competent authorities, including the National Center for Missing and Exploited Children and Indian law-enforcement authorities.
- Protect someone from an imminent risk of serious harm.
- Establish, exercise, or defend a legal claim, or enforce our Terms.
Where we are permitted to tell you about such a request, we will.
7.4 Business transfers
If we are involved in a merger, acquisition, or sale of assets, your data may transfer to the acquirer. Your personal data will remain subject to the commitments in this policy, or you will be given notice and an opportunity to close your account before any material change takes effect.
8. Where Your Data Is Held
Your account, your content, and everything that describes who may see it are held in India. Some data necessarily leaves India, as set out below.
| Data | Where it is held |
|---|---|
| Your account, profile, content records, distributions, messages, and settings | India |
| Database backups | India, replicated to a second Indian region |
| Photos, videos, and audio files | Asia-Pacific |
| Deleted media, during its retention period | India |
| Cached media, while it is being delivered to you | Edge locations worldwide, close to the person requesting it |
| Push notification tokens, crash reports, and usage analytics | United States and other Google locations |
Safeguards
- GDPR: transfers outside the EEA and the UK are made under the European Commission's Standard Contractual Clauses, which form part of our agreement with each provider, together with the technical measures described in Section 10.
- DPDP Act, 2023: transfers out of India are permitted except to countries restricted by notification of the Central Government under Section 16(1). No such restriction applies to any transfer described above as at the effective date of this policy.
- Data is encrypted in transit and at rest wherever it is held.
9. How Long We Keep Data
| Data | How long | Why |
|---|---|---|
| Your account and everything in it | For as long as your account is open | Providing the Service |
| Content and account records, after you close your account | Erased within 180 days | See Section 11 |
| Photos, videos, and audio files, after you delete them or close your account | Removed from delivery immediately; the retained copy is destroyed within 190 days | Recovering from mistakes and errors, and answering legal requests |
| Sign-in sessions | Expire on their own after a period of inactivity, and in any case at a fixed maximum age. You can end any session yourself | Security |
| Database backups | Up to 35 days | Disaster recovery |
| Server logs | 30 days | Diagnosing faults and abuse |
| Reports of content or accounts | Kept while the matter is open and for a reasonable period afterwards for safety record-keeping | A report is a record about the reported account; it is not deleted because the reporter left |
| Child-safety records | Retained as long as the law requires | Legal obligation, including under the POCSO Act, 2012 |
| Records of account bans | Retained for as long as the ban is in force | Preventing a banned account from returning |
| Crash reports and usage analytics held by Firebase | Up to 14 months, under Google's own retention policy | Diagnosing crashes and understanding usage |
When a retention period ends, the data is deleted. We do not keep personal data for longer than the purpose it was collected for requires.
10. Security
- No passwords. You sign in with Google or Apple. We never see, handle, or store a password.
- Encryption in transit. All connections use current transport-layer encryption, and unencrypted connections are refused.
- Encryption at rest. The database and all media storage are encrypted at rest with industry-standard encryption.
- Sign-in secrets are never stored in readable form. Session tokens are stored hashed, and the authorisation we hold for Apple sign-in is stored encrypted.
- A private database. Our production database is not reachable from the public internet. Only our application servers can reach it.
- Media is not publicly addressable. Photos, videos, and audio are served only through short-lived signed links, which stop working once they expire.
- Abuse protection. Rate limits and a web application firewall sit in front of the Service, and a device-integrity check helps us tell real installations from automated abuse.
- Access control. Credentials and keys are held in a managed secrets store, never in our source code. Operator tools that can act on accounts and content are not reachable from the internet at all.
- Minimal logging. Our server logs are written to hold identifiers and request information, not names, email addresses, or the content of anything you wrote.
- Metadata stripping. Capture metadata is removed from every photo and video file before anyone else can receive it.
We will notify you and the relevant supervisory authority of a personal data breach where the law requires it, and within the deadlines the law sets.
No method of transmission or storage is completely secure. We take the measures above seriously, but we cannot guarantee absolute security.
11. Closing Your Account
You can close your account yourself, from Settings → Account → Delete account. You re-authenticate with Google or Apple to confirm, which is what stops someone else from doing it.
Closing your account is immediate and cannot be undone. There is no waiting period during which you can change your mind, and we cannot restore an account once it is closed. Signing in again with the same Google or Apple identity creates a completely new, empty account. It does not bring the old one back.
At the moment you confirm:
- Your profile and your username stop existing across the Service. Your username is released and may later be taken by someone else.
- Your zcribbles, your instants, and every distribution of them stop existing — including things you sent to one person, which leave that person's Library.
- Every device is signed out and stops receiving notifications.
- Your Apple sign-in authorisation is revoked with Apple, where you signed in with Apple.
- Your follows are severed in both directions.
- Your media files are withdrawn from delivery and queued for destruction.
What remains, and why. Replies, reactions, and direct messages you sent on other people's content stay where they are, under your name. What you said on someone else's content is part of that content's record and is not yours to withdraw by leaving. Your own content is a different matter, and it goes.
Erasure. Underlying records of a closed account are held in a deactivated state, unreachable by any other user and returned by no part of the Service, and are erased within 180 days of closure. Media files are destroyed within 190 days. Backups age out on their normal rotation, within 35 days. Records we are legally required to keep — child-safety records and records of an account ban — are retained as described in Section 9.
Full step-by-step instructions, including how to request closure if you have lost access to your device, are on the Delete Your Account page.
12. Your Rights
12.1 Under the GDPR (EU, EEA, and UK)
- Access (Art. 15): a copy of the personal data we hold about you.
- Rectification (Art. 16): correction of inaccurate data. You can edit your profile in the app at any time.
- Erasure (Art. 17): deletion of your data. Use the in-app account closure, or write to us.
- Restriction (Art. 18): a pause on how we process your data while a dispute is resolved.
- Portability (Art. 20): your data in a structured, machine-readable format. Write to [email protected] and we will prepare an export.
- Objection (Art. 21): you may object to processing we base on legitimate interests, including usage analytics, feed ordering, and people suggestions. For analytics, removing the app from your device is the immediate and complete way to stop it — we hold no identifier that would let us switch off collection for one person from our side.
- Automated decisions (Art. 22): we make no decision about you by automated means that produces a legal or similarly significant effect. See Section 13.
- Complaint: you may complain to your national data protection supervisory authority at any time. You do not have to come to us first.
12.2 Under the DPDP Act, 2023 (India)
- Access to information (Sec. 11): a summary of the personal data we process and what we do with it.
- Correction and erasure (Sec. 12): correction of inaccurate or incomplete data, and erasure of data we no longer need.
- Grievance redressal (Sec. 13): raise a grievance with the officer named in Section 15, before approaching the Data Protection Board.
- Nomination (Sec. 14): nominate someone to exercise your rights if you die or become incapacitated. Write to [email protected].
12.3 How to exercise them
- In the app: edit your profile to correct data; Settings → Account → Delete account to erase it; your device's system settings to withdraw camera, microphone, location, or notification permissions.
- By email: [email protected] for access, portability, restriction, objection, nomination, or anything else.
- Verification: we confirm that a request comes from the email address on the account before we act on it.
- Response time: within 30 days. If a request is complex we may extend that, and we will tell you why before the 30 days are up.
- Cost: free, unless a request is manifestly unfounded or excessive.
Withdrawing consent. Notifications, camera, microphone, and location can each be withdrawn individually, from your device's system settings, without affecting the rest of the Service. Usage analytics do not run on consent — see the objection right above, and section 3.3. Because using Zcribbler at all depends on accepting these Terms and this policy, the way to withdraw consent entirely is to close your account.
13. Automated Systems, and What They Do Not Do
13.1 Ordering, not deciding
The order of your feed and the people we suggest you might know are chosen automatically. These systems use signals such as who you follow, who you interact with, and how recent something is.
They affect order and suggestion only. They never decide who is allowed to see your content — that is decided by the audience you chose, and by nothing else. They do not restrict your account, do not affect your rights, and produce no legal or similarly significant effect. A small selection of broadcast content is also chosen by people at Zcribbler rather than automatically, and shown separately from your feed.
13.2 Moderation is done by people
No content is hidden and no account is restricted automatically. Every moderation decision is made by a person at Zcribbler who has looked at the report and the content it names. There is no report threshold that removes content on its own.
If we act against your content or your account, you can appeal by email — the address is shown to you in the app at the point you are told. See Terms, Section 8.
14. Children
- Zcribbler is for people aged 16 and over. You must enter your date of birth to finish creating an account, and an account cannot be created if it shows you are under 16.
- We do not knowingly collect personal data from anyone under 16. If we learn that we have, we will close the account and delete the data.
- If you are 16 or 17, you must have permission from a parent or legal guardian to use Zcribbler, and by using it you confirm you have it. See Terms, Section 4.
- Parents and guardians may contact [email protected] to ask about, or ask us to delete, an account belonging to someone in their care. We will verify the relationship before acting.
- No advertising or profiling, at any age. We do not advertise to anyone, we build no advertising profiles, we collect no advertising identifier, and we do not sell personal data. This is not a special rule for minors; it is how the Service works for everyone.
These measures are designed to meet our obligations under Section 9 of the DPDP Act, 2023, and Article 8 of the GDPR.
15. Changes to This Policy
We may update this policy. When a change is material — a new purpose, a new category of data, a new provider, or a shorter protection for you — we will:
- give at least 30 days' notice before it takes effect;
- notify you in the app, and by email where we can; and
- publish the updated policy with a new effective date and version number.
Continuing to use Zcribbler after the effective date means you accept the updated policy. If you do not, you may close your account.
16. Grievance Officer and Data Protection Contact
Appointed under Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and Section 13 of the DPDP Act, 2023:
- Office: Grievance Cell, Zcribbler Software Labs Private Limited
- Designation: Grievance Officer and Data Protection Contact
- Email: [email protected]
- Location: Kannur, Kerala, India
We acknowledge a grievance within 24 hours and resolve it within 15 days of receipt.
If you are not satisfied with our response, you may approach the Data Protection Board of India, or — in the EU, EEA, or UK — your national supervisory authority.
17. Contact Us
- Privacy, data rights, and grievances: [email protected]
- Support and appeals: [email protected]
- Everything else: [email protected]
Zcribbler Software Labs Private Limited, Kannur, Kerala, India.