Privacy
Policy
This policy explains what personal information Insyd collects, why we collect it, who we share it with, and the controls you have over it — across our website and every app we publish.
1. Who we are and what this covers
Insyd (“Insyd”, “we”, “us”, “our”) is a design and engineering studio based in India. This Privacy Policy applies to:
- our website at insyd.in, including the contact and call-booking forms;
- the mobile and desktop applications we publish under the Insyd name on the Apple App Store and other app stores (each, an “App”); and
- any related support, email and communication channels we operate.
Together these are the “Services”. For the purposes of the EU/UK General Data Protection Regulation and India's Digital Personal Data Protection Act, 2023, Insyd is the data controller (Data Fiduciary) for personal information processed through the Services.
Individual Apps may publish a supplementary privacy notice that describes data practices unique to that App. Where a supplementary notice conflicts with this policy, the App-specific notice governs for that App. Your use of the Services is also subject to our Terms & Conditions.
2. Information we collect
2.1 Information you give us
- Account information.When you create an account in an App, we collect your name, email address, and the authentication identifier associated with your chosen sign-in method (for example email one-time codes, Sign in with Apple, or Google Sign-In). We may also collect optional profile details such as a username, avatar, pronouns, date of birth or location where an App's functionality requires it.
- User content. Content you create, upload or submit through an App — including photos, videos, audio, text posts, comments, messages, documents and files — together with any metadata you choose to attach to it.
- Enquiries and bookings. When you use the contact or call-booking form on insyd.in, we collect your name, email address, company name (optional), the services you are interested in, your indicated budget range, your project description, and your selected call date and time.
- Support correspondence. The contents of emails and support messages you send us, and our replies.
2.2 Information collected automatically
- Usage and analytics data. How you interact with the Services — screens and pages viewed, features used, session length, referring page, and approximate coarse location derived from your IP address (city or region level, not precise GPS).
- Device and diagnostic data. Device model, operating system and version, app version, language and region settings, and crash reports containing stack traces and the device state at the time of a crash.
- Identifiers.A randomly generated installation or device identifier used to associate analytics and crash events with a single installation. We do not use Apple's Advertising Identifier (IDFA) and we do not request App Tracking Transparency permission, because we do not track you across apps or websites owned by other companies.
- Push notification tokens.If you enable notifications, we store the token your device's push service issues so we can deliver notifications to you.
- Server logs. IP address, request timestamps, and requested URLs, retained for security, abuse prevention and debugging.
2.3 Purchases and subscriptions
Where an App offers in-app purchases or subscriptions, the payment itself is processed by the platform operator — Apple for the App Store, or Google for Google Play. We never receive or store your full card number, CVV, or bank details. We receive only a transaction receipt, product identifier, purchase and renewal dates, and subscription status, which we use to unlock and maintain your entitlements. Where an App accepts payment outside an app store, payment is handled by a PCI-DSS compliant processor and we receive only the transaction reference, the last four digits of the card, and the payment status.
2.4 Information we do not collect
We do not knowingly collect government identification numbers, precise background location, health or biometric data, or special category data, unless an App explicitly requests it, explains why, and obtains your consent first.
3. Why we use your information
We process personal information only where we have a lawful basis to do so. The table below sets out each purpose and the corresponding basis under GDPR; under the DPDP Act we rely on your consent or on legitimate uses as defined in that Act.
- To provide the Services — create and authenticate your account, store and display your content, deliver core App functionality, and process your enquiry or booking. Basis: performance of a contract.
- To communicate with you — send transactional emails such as booking confirmations, account notices, and replies to your enquiries. Basis: performance of a contract; legitimate interests.
- To send push notifications about activity relevant to you. Basis: consent, which you may withdraw at any time in your device settings.
- To improve and debug the Services — analyse aggregate usage, diagnose crashes, and measure the performance of features. Basis: legitimate interests; consent where required by local law.
- To process payments and manage entitlements — validate receipts and maintain subscription status. Basis: performance of a contract.
- To keep the Services safe — detect and prevent fraud, abuse, spam and security incidents, and enforce our Terms. Basis: legitimate interests; legal obligation.
- To comply with law — respond to lawful requests and meet tax, accounting and regulatory obligations. Basis: legal obligation.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles. We do not use your content to train machine learning models without your separate, explicit, opt-in consent.
4. How your information is shared
We share personal information only in the circumstances described below.
- With other users. In Apps with social or collaborative features, the profile details and content you choose to make visible are shown to other users as described in that App. Your email address, date of birth and precise location are never displayed to other users unless you explicitly publish them.
- With service providers (processors) who operate infrastructure on our behalf under written contracts that restrict them to processing data only on our instructions. These include cloud hosting and database providers, authentication and file storage providers, email delivery providers (we use Resend for transactional email from insyd.in), push notification delivery services, and analytics and crash reporting providers.
- With platform operators. Apple and Google process purchases, subscriptions and app-store account functions in accordance with their own privacy policies.
- For legal reasons. Where we believe in good faith that disclosure is required by applicable law, legal process or an enforceable governmental request, or is necessary to protect the rights, property or safety of Insyd, our users, or the public.
- In a business transfer. If Insyd is involved in a merger, acquisition, financing or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.
5. International transfers
Insyd operates from India and our service providers may store and process data in the United States, the European Union and other countries. Where we transfer personal information out of the EEA, the UK or another jurisdiction with transfer restrictions, we rely on appropriate safeguards — typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision. You may request a copy of the safeguards we use by emailing ishan@insyd.in.
6. How long we keep information
- Account and content data: for as long as your account is active. On deletion, we remove or irreversibly anonymise it within 30 days, except where retention is legally required.
- Enquiry and booking data: up to 24 months from your last contact with us, so we can maintain continuity of the conversation.
- Analytics and crash data: up to 14 months, in aggregated or pseudonymised form.
- Server and security logs: up to 90 days.
- Transaction records: for the period required by applicable tax and accounting law, typically 8 years in India.
Backups are cycled on a rolling schedule and residual copies are purged within 90 days of deletion.
7. Your rights and choices
7.1 Deleting your account
Every Insyd App that supports account creation provides in-app account deletion, normally under Settings → Account → Delete Account. Deleting your account permanently removes your profile and the content associated with it. You may also request deletion at any time by emailing ishan@insyd.in from the address associated with your account; we will action verified requests within 30 days.
7.2 Rights under GDPR, the DPDP Act and similar laws
Depending on where you live, you may have the right to: access the personal information we hold about you; correct inaccurate or incomplete information; request erasure; restrict or object to processing; receive your data in a portable, machine-readable format; withdraw consent at any time without affecting the lawfulness of prior processing; nominate another person to exercise your rights in the event of death or incapacity (DPDP Act); and not be subject to solely automated decision-making with legal or similarly significant effects — which we do not carry out.
To exercise any of these rights, email ishan@insyd.in. We respond within 30 days and will never charge you or degrade your service for making a request. If you are unsatisfied with our response, you may complain to your local supervisory authority, or in India to the Data Protection Board established under the DPDP Act.
7.3 Rights under US state privacy laws
If you are a resident of California, Colorado, Connecticut, Virginia or another US state with a comprehensive privacy law, you have the rights to know, access, delete, correct and port your personal information, and to opt out of sale, sharing and targeted advertising. As stated above, we do not sell or share personal information and do not conduct targeted advertising, so there is nothing to opt out of. We do not discriminate against you for exercising any right.
7.4 Notifications, tracking and cookies
You can disable push notifications at any time in your device settings, and analytics collection where an App offers that control. insyd.in uses only strictly necessary storage: a single localStorage entry (insyd-theme) that remembers your light or dark theme preference. We set no advertising or tracking cookies. The site loads fonts from Google Fonts, which receives your IP address as part of serving those files.
8. Security
We protect personal information with encryption in transit (TLS), encryption at rest for stored content, authenticated access with row-level authorisation so users can only reach their own data, least-privilege access controls for our team, and secrets held in managed environment configuration rather than source code. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If a personal data breach is likely to result in a risk to your rights, we will notify you and the relevant authorities within the timeframes required by applicable law — 72 hours under GDPR, and as prescribed under the DPDP Act.
9. Children's privacy
Our Services are not directed to children under 13(or the higher minimum age set in an App's store listing or supplementary notice, and the minimum digital consent age in your country — 16 in parts of the EEA). We do not knowingly collect personal information from children below that age. Where the DPDP Act applies, we do not process the personal data of a child under 18 without verifiable parental consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us information, email ishan@insyd.in and we will delete it promptly.
10. Third-party links and services
The Services may link to third-party websites, apps or integrations that we do not control. This policy does not apply to them, and we are not responsible for their content or privacy practices. Review their policies before providing information.
11. Changes to this policy
We may update this policy as our Services evolve or as the law changes. We will revise the “Last updated” date at the top of this page, and for material changes we will provide prominent notice in the affected App or by email before the change takes effect. Continued use of the Services after that date constitutes acceptance of the updated policy.
12. Contact us
For any privacy question, request or complaint — including to reach our privacy contact and grievance officer — email ishan@insyd.in. Please include enough detail for us to identify your account and the nature of your request. We acknowledge requests within 7 days and resolve them within 30 days.
See also our Terms & Conditions.