Court Master — mobile application for iOS and Android
Effective Date: 20.08.2026 · Last Updated: 20.08.2026 · Version 2.0
IMPORTANT NOTICE — PLEASE READ. This Privacy Policy is a legally binding document. By downloading, installing, accessing or using the Court Master mobile application (the “App”) from the Apple App Store or from Google Play, you confirm that you have read, understood and agreed to this Privacy Policy and to the accompanying End User Licence Agreement / Terms of Use (the “Terms”). If you do not agree, you must not install or use the App and must delete it from your device.
The App is a case-management and cause-list utility for legal professionals. It is not a source of authoritative judicial record.
Contents
Who we are
Scope and application
Nature of the service
Personal data we process
Purposes and legal bases
Consent
Accounts, deletion and withdrawal
Court data and third-party privacy
Disclosure, processors and SDKs
International transfers
Retention and erasure
Security
Your rights
Children
Intermediary due diligence
Apple App Store disclosures
Google Play disclosures
Disclaimers and liability
Indemnity
Governing law and disputes
General
Contact and Grievance Officer
Annexure A — Deleting your account
1.1 The App is owned and operated by Botero Strategies LLP, a limited liability partnership incorporated in India under the Limited Liability Partnership Act, 2008, having its registered office at C-56 Basement, between C-569 and E-64, Neeti Bagh, Opposite Andrewsganj, New Delhi, South Delhi – 110049, India (“we”, “us”, “our”, the “Developer”).
1.2 Court Master is a case and matter-management application that allows advocates, chambers and legal teams to record case details, track hearing dates, manage tasks, and store and share case-related documents such as bare Acts and cause lists. It is distributed through the Apple App Store and through Google Play, and is associated with our website at https://managelit.com.
1.3 References to “you”, “your” and “User” mean the natural person who installs or uses the App. Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) you are a Data Principal and we are a Data Fiduciary. Under the EU/UK General Data Protection Regulation (“GDPR”) you are a data subject and we are a controller. Clause 8.4 explains the one situation in which that relationship is reversed.
1.4 This Privacy Policy explains what information the App collects, how it is used and shared, how it is protected, and the choices and rights available to you. It applies to everyone who accesses or uses the App, including individual advocates, team members, and any support staff granted access. By creating an account, accepting a team invitation, or otherwise using the App, you agree to the collection and use of information as described here.
2.1 This Policy governs personal data processed through the App on both iOS and Android, and through any associated website, backend service or support channel operated by us.
2.2 This Policy does not apply to:
the websites, portals, APIs or services of any court, tribunal, judicial authority, the National Judicial Data Grid, the eCourts Services platform, or any State or High Court IT infrastructure (collectively, “Court Sources”);
Apple Inc.’s App Store, iCloud or any other Apple service, which are governed by Apple’s own privacy policy;
Google LLC’s Google Play, Google Play services, Google Account or any other Google consumer service, which are governed by the Google Privacy Policy — save that where Google acts as our processor (Firebase, see Clause 9.2) our own obligations under this Policy continue to apply;
any third-party website, application or service you reach through a link in the App; or
data you choose to export out of the App and thereafter handle yourself.
We do not control, and accept no responsibility for, the privacy practices of any person or platform referred to in this Clause 2.2.
2.3 Laws and policies applied. This Policy is framed to comply with, without limitation:
the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E) dated 13 November 2025, published 14 November 2025, subject to a phased implementation running to 13 May 2027);
the Information Technology Act, 2000, in particular sections 43A, 72 and 79;
the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), to the extent still operative;
the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“Intermediary Rules”);
the Bharatiya Nyaya Sanhita, 2023, the Bharatiya Nagarik Suraksha Sanhita, 2023 and the Bharatiya Sakshya Adhiniyam, 2023, as to lawful disclosure, reporting bars and record production;
Regulation (EU) 2016/679 (GDPR) and the UK GDPR read with the Data Protection Act 2018;
the California Consumer Privacy Act, 2018 as amended by the California Privacy Rights Act, 2020 (“CCPA/CPRA”);
the Children’s Online Privacy Protection Act, 1998 (“COPPA”), 15 U.S.C. §§ 6501–6506;
the Apple App Store Review Guidelines, in particular Guidelines 5.1.1, 5.1.2 and 5.1.4, and the Apple Developer Program Licence Agreement; and
the Google Play Developer Programme Policies, in particular the User Data policy, the Data safety disclosure requirements, the Permissions and APIs that Access Sensitive Information policy and the Families policy, read with the Google Play Developer Distribution Agreement.
2.4 Conflict. Where a mandatory provision of applicable law confers on you a right greater than this Policy provides, that law prevails to the extent of the inconsistency, and the remainder of this Policy continues in force.
This clause is central to the allocation of risk under this Policy and the Terms.
3.1 What the App does. The App:
retrieves and displays cause lists, case status, orders, judgments and cognate information from Court Sources that are already in the public domain and that the courts concerned are required by law and by judicial policy to publish;
permits you to record and maintain a list of matters, hearing dates, notes, reminders and documents;
permits you to form a Team (for example, a chamber, a set, or a law-firm group) and to share matter information and documents with other Users you invite by email address or mobile number; and
hosts a library of publicly-sourced PDF materials (such as bare Acts, published rules, forms, standing orders and circulars issued by public authorities) for common reference.
3.2 What the App is NOT.
The App is not an official, authoritative or certified source of judicial record. The only authoritative record of any proceeding is the record of the court or tribunal concerned. Certified copies must be obtained from the Registry.
The App does not provide legal advice. Nothing in the App creates an advocate–client relationship between you and the Developer, and no fiduciary or professional duty arises from your use of the App.
The App is not a substitute for verification. Court Sources are frequently delayed, incomplete, mis-keyed, provisionally uploaded, subsequently amended, or unavailable. Cause lists are revised. Board positions change. Supplementary and part-heard lists are issued at short notice.
3.3 YOUR NON-DELEGABLE PROFESSIONAL DUTY. You acknowledge and agree that the duty to ascertain the correct date, time, bench, board position and status of any matter rests solely and exclusively with you and with no other person. You must independently verify every listing against the official cause list of the court concerned before acting or omitting to act. We accept no liability whatsoever for any adjournment, dismissal for default, ex parte order, decree, limitation bar, abatement, cost, adverse inference, disciplinary consequence, professional-negligence claim, or loss of any kind arising from reliance on information displayed in the App.
3.4 Intermediary status. In respect of (i) matter data you enter, (ii) documents and PDFs you upload, and (iii) content you share with your Team, we act as an intermediary within the meaning of section 2(1)(w) of the Information Technology Act, 2000. We do not initiate, select the receiver of, or select or modify that information. We accordingly claim the protection of section 79 of that Act read with the Intermediary Rules, and we observe the due diligence required of us under Clause 15 below.
3.5 Public-domain court data. Personal data appearing in cause lists, case status displays, cognate court records, orders and judgments is personal data “made or caused to be made publicly available by … any … person who is under an obligation under any law for the time being in force in India to make such personal data publicly available” within the meaning of section 3(c)(ii) of the DPDP Act, and the DPDP Act therefore does not apply to our processing of it. We nonetheless handle such data in accordance with Clause 8 below as a matter of policy and out of respect for the privacy of litigants.
Please read this clause carefully. The App is an account-based, cloud-synchronised service. Matter data and documents that you create in the App are stored on our backend servers, so that they are available across your devices and to the Team members you have chosen to share them with. Some data is additionally cached on your device for offline access. This clause is a complete statement of what we process.
Category
Examples
Where it is held
Account identifiers
Name or display name; mobile number; email address (if provided); the Firebase Authentication user identifier issued to you
Our backend; Firebase Authentication
Verification data
One-time passcodes (OTPs) generated to verify your mobile number, and their expiry
Our backend, transiently; Firebase Authentication
Team data
Team or firm name; your role; the email address or mobile number of a person you invite; invitation status; Team membership records
Our backend
Matter data
Case numbers, CNR numbers, court and bench, party names as entered by you, next hearing date, case status, your notes, updates, timeline entries, tags and reminders
Our backend, and cached on your device
Documents
PDFs, scans, images and files you upload or attach to a matter, and their filenames, types and sizes
Our backend, and cached on your device
Correspondence
Emails, support tickets, bug reports, feedback and any attachments you send us
Our support mailbox
Payment data (if and when a paid tier is offered)
Any subscription is transacted entirely through Apple’s In-App Purchase on iOS and Google Play Billing on Android. We receive only a non-identifying transaction/receipt token and the subscription status. We never receive or store your card number, CVV, UPI ID, bank details or billing address.
Apple; Google; our backend holds only the token
Team sharing is not private to you. Matter data and documents associated with a Team are visible to every member of that Team, and an upload generates a notification to the Team. Do not place material in a Team space unless you are content for every member of that Team to read it. See also Clause 4.5.
Category
Examples
Purpose
Device and technical data
Device model and manufacturer, operating system and version, App version, language, time zone, error logs
Diagnostics, stability, security
Network data
IP address (transient, in server logs), request timestamps and endpoints
Security, abuse prevention, rate limiting
Identifiers
iOS: vendor identifier (IDFV). Android: Firebase installation identifier. Both: push notification token (Expo push token, delivered via APNs on iOS and Firebase Cloud Messaging on Android); session token issued on sign-in
Session continuity, notification delivery
4.3 Data we DO NOT collect. We do not collect, and have not built any facility to collect: precise or coarse geolocation; your Contacts address book; your Photos or media library (other than an individual file you yourself select and upload); SMS messages or call logs (the App requests no SMS or call-log permission, and does not read your messages to auto-fill a verification code); microphone or camera streams; HealthKit, HomeKit or ClassKit data (iOS); Health Connect data (Android); biometric templates (Face ID, Touch ID and Android biometric authentication are performed by the operating system and never leave your device); financial account data; caste, religion, political affiliation or trade-union membership; the Apple Advertising Identifier (IDFA); or the Google Advertising ID (AAID).
4.4 No third-party analytics or advertising SDKs. The App contains no advertising SDK, no attribution SDK and no third-party product-analytics SDK. We do not serve advertising. We do not track you across other companies’ apps or websites, and accordingly the App does not use Apple’s App Tracking Transparency framework and does not request the AAID. We have never sold, and will not sell, share for cross-context behavioural advertising, rent, licence or trade personal data, whether for money or for any other valuable consideration. The only third parties in the App’s binary that receive any data are those listed in Clause 9.2.
4.5 Sensitive data caution. Matter data and documents in the practice of law may contain highly sensitive information about third parties — including in matters attracting section 72 of the Bharatiya Nyaya Sanhita, 2023 (disclosure of the identity of a victim of an offence under sections 64 to 71), section 73 of that Sanhita (printing or publishing court proceedings in such matters without the court’s prior permission), section 366(2) and (3) of the Bharatiya Nagarik Suraksha Sanhita, 2023 (in-camera trial and the bar on publishing such proceedings), section 23 of the POCSO Act, 2012, section 74 of the Juvenile Justice (Care and Protection of Children) Act, 2015, the Medical Termination of Pregnancy Act, 1971, matrimonial proceedings, and sealed-cover proceedings. You are solely responsible for ensuring that your entry, upload, storage or Team-sharing of any such material is lawful, complies with every applicable statutory bar on disclosure, every direction of the court concerned, the Bar Council of India Rules on professional conduct, and your duty of confidentiality to your client. You must not upload material whose disclosure is prohibited. We have no means of knowing the contents of your matters and we do not review them.
#
Purpose
Data used
DPDP Act basis
GDPR Art. 6 basis
1
Create and authenticate your account; verify your mobile number
Account identifiers, verification data
Consent, s.6
Art. 6(1)(b) — contract
2
Deliver core functionality (matter list, reminders, storage, synchronisation)
Matter data, documents
Consent, s.6
Art. 6(1)(b) — contract
3
Operate Team features and send invitations
Team data, invitee email or mobile number
Consent, s.6
Art. 6(1)(b) and 6(1)(f)
4
Send service and hearing-date notifications
Push token, matter data
Consent, s.6
Art. 6(1)(b)
5
Provide support and respond to you
Correspondence
Consent, s.6
Art. 6(1)(b) and 6(1)(f)
6
Diagnose errors, maintain security, prevent abuse
Device, network data
Legitimate use, s.7(a)/(i)
Art. 6(1)(f)
7
Improve and develop the App
Aggregated / de-identified data
Legitimate use, s.7
Art. 6(1)(f)
8
Comply with law; respond to lawful process; establish, exercise or defend legal claims
As required
Legitimate use, s.7(b)–(g)
Art. 6(1)(c) and 6(1)(f)
9
Administer subscriptions and manage refunds or chargebacks
Receipt token, subscription status
Consent / contract, s.6
Art. 6(1)(b)
5.1 Purpose limitation. We will not use personal data for any purpose materially different from those listed above without first giving you notice and, where the law so requires, obtaining your fresh consent.
5.2 No automated decision-making. We do not carry out any automated decision-making, profiling or scoring that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 of the GDPR.
5.3 No AI training on your content. We do not use your matter data, notes, documents or Team content to train, fine-tune or evaluate any machine-learning or artificial-intelligence model, whether our own or a third party’s, and we do not transmit that content to any third-party AI service. Should this ever change, we will obtain your prior express opt-in consent and update this Policy before doing so.
6.1 Consent notice. In accordance with section 5 of the DPDP Act, this Policy, together with the in-App consent screen, constitutes the notice given to you. It is available in English and, on request to managelit@aglaw.in, will be made available in any language specified in the Eighth Schedule to the Constitution of India.
6.2 Nature of consent. Your consent is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and is limited to the personal data necessary for the specified purpose.
6.3 Withdrawal. You may withdraw consent at any time, and doing so is as easy as giving it. Because every purpose in Clause 5 that rests on your consent is a purpose the account itself exists to serve, withdrawal is effected by deleting your account — in the App at Profile → Delete account, on the web at Annexure A to this Policy, or by writing to managelit@aglaw.in. If you wish to withdraw consent to a particular purpose while keeping your account, write to us and we will tell you which parts of the App will stop working. On withdrawal we will, within a reasonable period, cease processing and erase your personal data, and will require our Data Processors to do the same, except where retention is required by law (see Clause 11). Withdrawal does not affect the lawfulness of processing before withdrawal, and will render some or all of the App unusable.
6.4 Consent Managers. Section 6(7) of the DPDP Act entitles you to give, manage, review and withdraw consent through a Consent Manager. Where a Consent Manager is registered with the Data Protection Board of India under section 6(9) of the DPDP Act read with rule 4 and the First Schedule to the DPDP Rules, 2025, we will honour instructions received through it.
7.1 Use without an account. Consistently with Apple Guideline 5.1.1(v) and the Google Play User Data policy, browsing of public court data and of the publicly-sourced PDF library is available without creating an account. An account is required only for saving matters, cloud storage and synchronisation, and Team features, which are genuinely account-based.
7.2 In-App account deletion. You may delete your account from within the App at Profile → Delete account. Because a Team's matters are a shared professional record, deletion from within the App is requested there and takes effect when a partner in your Team approves it; where your Team has no partner other than you, there is no one else to ask and the request is yours to approve. You may withdraw a pending request at any time before it is decided. On deletion we erase your account record, your name and mobile number, your authentication record (including the verified phone number held by Firebase Authentication), your push tokens, and any invitation addressed to you that was still pending, on the timetable set out in Clause 11. Where you are the last active member of a Team, the Team is deleted with your account, together with every matter, note, timeline entry and document in it. Where other members remain, Clause 7.4(a) applies.
7.3 Web-based deletion (no installation required). As required by the Google Play Data deletion requirements, you may also request deletion of your account and data without installing or re-installing the App, at Annexure A to this Policy, or by writing to managelit@aglaw.in from the email address or mobile number registered with us. We will verify the request and act on it within the periods stated in Clause 11.
This route is not subject to anyone's approval. The in-App approval step in Clause 7.2 exists to protect a Team's shared record, and it cannot be used to keep you in the App against your will. If a partner declines your in-App request, or does not decide it, you may require deletion by writing to us at the address above and we will give effect to it — your right of erasure under section 12 of the DPDP Act and Article 17 of the GDPR is not capable of being waived or overridden by another User.
7.4 What survives deletion. Deletion is permanent and irreversible. Two things do not disappear on deletion, and you should understand them before you ask us to delete:
Team content. Matter data and documents that you contributed to a Team remain available to that Team, because they form part of that Team’s shared record and other members rely on them. If you require that content to be removed as well, say so in your request and we will remove it, subject to the rights of the Team owner.
Records we must keep by law — see Clause 11 (tax and transaction records, records preserved under a lawful direction, and records needed to establish or defend a legal claim).
7.5 No dark patterns. We do not use deceptive design, pre-ticked boxes, nagging, obstruction or any other dark pattern to obtain consent or to obstruct withdrawal or deletion, and we comply with the Central Consumer Protection Authority’s Guidelines for Prevention and Regulation of Dark Patterns, 2023.
8.1 Source and character. Court data displayed in the App is retrieved from Court Sources that publish it in the discharge of a legal and constitutional obligation of open justice. We add no personal data of our own to it.
8.2 We are not the publisher of record. We do not author, certify, verify, curate or vouch for court data. Errors, omissions, delays and subsequent amendments in Court Sources are reproduced in the App. We have no power to correct the record of any court.
8.3 Requests for masking, redaction or removal (“right to be forgotten”). If you are a litigant, accused, victim, witness or other person whose personal details appear in court data displayed in the App and you wish those details masked or removed, write to managelit@aglaw.in with the case particulars and the basis of the request. We will:
acknowledge within 24 hours and dispose of the request within 15 days;
immediately give effect, without requiring any further order, to any direction of a court or tribunal, and to any statutory bar on identification or publication (including under sections 72 and 73 of the Bharatiya Nyaya Sanhita, 2023, section 366(3) of the Bharatiya Nagarik Suraksha Sanhita, 2023, section 23 of the POCSO Act, 2012, and section 74 of the Juvenile Justice (Care and Protection of Children) Act, 2015);
mask or suppress the entry in the App where a court has ordered masking of its own record, or where the statutory bar plainly applies; and
where the request is not supported by a court direction or a statutory bar, inform you of our decision with reasons, and direct you to the Registry of the court concerned, which alone can alter the record.
8.4 Third-party data you upload. Where you enter or upload personal data of clients, opponents, witnesses or any other person, you are the person who determines the purpose and means of that processing as between you and that person. In relation to that data we act as your Data Processor (DPDP Act) / processor (GDPR Art. 28) and process it only on your documented instructions. You warrant that you have a lawful basis for that processing and you indemnify us in respect of it. This does not affect our status as Data Fiduciary / controller in respect of your own account data, described in Clause 1.3.
9.1 We do not sell data. See Clause 4.4.
9.2 Categories of recipient. We disclose personal data only as follows. This table is intended to correspond exactly to the SDKs present in the App binary, to the App Store Privacy Nutrition Label and to the Google Play Data safety section.
Recipient
Role
Data disclosed
Location
Botero Strategies LLP — our own application and database servers
Controller / Data Fiduciary infrastructure
All backend data: account identifiers, Team data, matter data, uploaded documents, notifications, server logs
New Delhi, India
Google LLC — Firebase Authentication
Processor
Mobile number; the SMS one-time passcode used to verify it; Firebase user identifier; authentication timestamps and device signals used for abuse prevention
United States and other Google regions
Google LLC — Firebase Cloud Messaging (Android push transport)
Processor
Push token, Firebase installation identifier, notification payload
United States / global
650 Industries, Inc. (Expo) — Expo push notification service
Processor
Expo push token, device platform, notification title and body
United States
Apple Inc. — App Store, In-App Purchase, Apple Push Notification service
Platform
Purchase and subscription data; APNs push tokens and notification payloads
United States / global
Google LLC — Google Play, Google Play Billing
Platform
Purchase and subscription data; installation and crash data collected by Google Play itself
United States / global
Team members you invite
Other Users
The matter data and documents in the Team you share with them, and your display name
Wherever they are
Professional advisers, insurers, auditors
Recipients
Only as strictly necessary
India
Successor in a merger, acquisition or asset sale
Recipient
Account and matter data, under equivalent protections and after notice to you
As applicable
Courts, tribunals, law-enforcement and regulators
Recipients
As compelled — see Clause 9.4
As applicable
9.3 Contractual protection (Apple Guideline 5.1.1(i); Google Play User Data policy). Every third party with whom we share user data is bound by a written agreement which requires it to provide the same or equal protection of user data as is stated in this Privacy Policy and as is required by the Apple App Store Review Guidelines and the Google Play Developer Programme Policies, to process such data only on our documented instructions and solely for the purpose for which it was disclosed, to implement appropriate technical and organisational security measures, to impose equivalent obligations on any sub-processor, to assist us with Data Principal and data-subject requests and with breach notification, and to delete or return the data on termination. These agreements incorporate, as applicable, standard contractual clauses satisfying Article 28 of the GDPR.
9.4 Compelled disclosure. We may disclose personal data where compelled by a valid and binding order, summons, warrant, notice or direction of a court, tribunal or authority of competent jurisdiction, or where disclosure is required to comply with law, to enforce our Terms, or to protect the rights, safety or property of any person. Our policy is to:
satisfy ourselves that the demand is lawful, in writing, from an authorised officer, and specific rather than a fishing enquiry;
notify you before disclosure wherever we are lawfully permitted to do so, and give you a reasonable opportunity to challenge it;
disclose the narrowest set of data responsive to the demand; and
resist over-broad, vague or unlawful demands.
9.5 Legal professional privilege. Matter data and documents may attract privilege under sections 132, 133 and 134 of the Bharatiya Sakshya Adhiniyam, 2023, corresponding to sections 126 to 129 of the Indian Evidence Act, 1872 (section 132(3) absorbing the former section 127, which has no standalone successor). Privilege belongs to your client, not to us and not to you. Where a demand for disclosure appears to reach privileged material, we will, so far as lawfully able, decline to produce it, notify you, and leave the claim of privilege to be asserted by you or your client before the authority concerned. We give no assurance that privilege will be upheld, and we accept no liability for any loss of privilege arising from your decision to store privileged material in the App rather than offline.
10.1 Our own servers and database are located in New Delhi, India. However, as Clause 9.2 shows, certain processors and platforms (Google, Apple, Expo) operate globally, and personal data disclosed to them may be processed outside India, including in the United States.
10.2 DPDP Act. Section 16 of the DPDP Act permits transfer of personal data outside India except to a country restricted by notification of the Central Government. We do not transfer personal data to any country so restricted, and we will cease any transfer that becomes restricted.
10.3 GDPR / UK GDPR. Where personal data of a person in the European Economic Area or the United Kingdom is transferred to a third country, we rely on the Standard Contractual Clauses adopted by the European Commission (and the UK International Data Transfer Addendum, where applicable) under Article 46 of the GDPR, supplemented by a transfer risk assessment and the technical measures described in Clause 12. A copy of the relevant clauses is available on request to managelit@aglaw.in.
Data
Retention
Account and profile data
For the life of the account; erased within 30 days of deletion or consent withdrawal
Matter data, notes, updates and uploaded documents
For the life of the account; erased within 30 days of deletion, subject to Clause 7.4(a)
One-time passcodes (OTPs)
Expire within 10 minutes; purged within 24 hours
Data cached on your device
Under your control; removed when you delete the App or clear its data
Encrypted backups
Purged on rotation, in all cases within 60 days of primary erasure
Diagnostic and error logs
90 days
Server and security logs (including IP address)
180 days
Support correspondence
24 months from closure of the ticket
Transaction and subscription records
8 years (section 34(3) of the Limited Liability Partnership Act, 2008; rule 6F of the Income-tax Rules, 1962; and section 36 of the Central Goods and Services Tax Act, 2017, as applicable)
Records required for a legal claim, investigation or lawful direction
Until final disposal and expiry of limitation
11.1 Inactivity. Rule 8 of the DPDP Rules, 2025 read with the Third Schedule prescribes a three-year erasure period, but does so only for e-commerce entities and social media intermediaries with two crore or more registered users in India, and online gaming intermediaries with fifty lakh or more. We do not meet those thresholds and rule 8 does not presently bind us. We nonetheless adopt its standard voluntarily. Where you have not approached us for the specified purpose, nor exercised any right, for a continuous period of three years, we will erase your personal data, having first given you not less than 48 hours’ notice (in practice, reminders at 30 days, 7 days and 48 hours) to the email address or mobile number registered with us.
11.2 De-identified data. We may retain indefinitely data that has been irreversibly aggregated or de-identified such that it can no longer be associated with you. We will not attempt to re-identify it.
12.1 Measures. We implement reasonable security safeguards proportionate to the risk, including: TLS 1.2 or higher in transit; encryption at rest; platform-provided secure storage for on-device credentials and cached files (iOS Keychain and Data Protection on iOS; the Android Keystore and encrypted app-private storage on Android); short-lived signed session tokens; role-based access control on the principle of least privilege, with Team data scoped to the Team; multi-factor authentication for administrative access; audit logging; network isolation; vulnerability patching; periodic backups; and an incident response procedure. This constitutes our statement of reasonable security safeguards for the purposes of section 8(5) of the DPDP Act read with rule 6 of the DPDP Rules, 2025, and of reasonable security practices and procedures for the purposes of section 43A of the Information Technology Act, 2000 read with rule 8 of the SPDI Rules.
12.2 Your responsibilities. You must keep your device passcode and account credentials confidential, enable device encryption and a biometric or passcode lock, keep your operating system and the App updated, not use a jailbroken or rooted device, and notify us immediately at managelit@aglaw.in of any suspected compromise. We are not liable for any unauthorised access resulting from your act, omission, or failure to observe this Clause 12.2, or from the loss, theft or compromise of your device.
12.3 No absolute guarantee. No method of electronic transmission or storage is completely secure. While we apply the measures described above, we do not and cannot warrant that the App or our systems are impenetrable, and, to the fullest extent permitted by law, we exclude liability for any security breach not caused by our own gross negligence or wilful misconduct.
12.4 Breach notification. In the event of a personal data breach we will, in accordance with rule 7 of the DPDP Rules, 2025, notify each affected Data Principal without delay and give the Data Protection Board an initial description without delay, followed by the detailed report prescribed by rule 7(2) within 72 hours (or such longer period as the Board allows on request). Where the GDPR applies we will notify the competent supervisory authority within 72 hours under Article 33 and, where the breach is likely to result in a high risk to your rights and freedoms, notify you under Article 34. We will also comply with the CERT-In Directions dated 28 April 2022 (No. 20(3)/2022-CERT-In), including reporting of specified cyber incidents within 6 hours.
You may exercise any right in this clause by writing to managelit@aglaw.in, or through the corresponding control in the App where one is provided. We will not discriminate against you, or degrade the App, because you exercised a right. Exercising these rights is free; we may charge a reasonable fee only for a manifestly unfounded or excessive repeat request, and will tell you before we do.
13.1 Verification. To protect you, we will verify that a request comes from you — ordinarily by confirming control of the mobile number or email address registered with your account. We may decline a request we cannot verify, and will tell you why.
Right to access information (s.11): a summary of the personal data we process about you, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom it has been shared.
Right to correction, completion, updating and erasure (s.12): we will correct inaccurate or misleading data, complete incomplete data, update it, and erase personal data no longer necessary for the purpose, unless retention is required by law.
Right of grievance redressal (s.13): you may complain to our Grievance Officer (Clause 22) before approaching the Data Protection Board of India. We will acknowledge within 72 hours and respond within 30 days.
Right to nominate (s.14): you may nominate another individual to exercise your rights in the event of your death or incapacity. Write to us to record a nomination.
Right to withdraw consent (s.6(4)–(6)): see Clause 6.3.
Right to complain to the Board: you may complain to the Data Protection Board of India if you are not satisfied with our response.
You also have duties under section 15 of the DPDP Act, including not to impersonate another person, not to suppress material information, and not to file a false or frivolous grievance.
Access (Art. 15), including a copy of your personal data;
Rectification (Art. 16);
Erasure / “right to be forgotten” (Art. 17);
Restriction of processing (Art. 18);
Data portability (Art. 20) — a structured, commonly used, machine-readable export of the data you provided to us;
Objection (Art. 21), including to processing based on our legitimate interests;
Not to be subject to solely automated decisions (Art. 22) — we take none (Clause 5.2);
Withdrawal of consent (Art. 7(3)), without affecting prior lawfulness; and
Complaint to a supervisory authority (Art. 77) in your country of residence, place of work or place of the alleged infringement — in the UK, the Information Commissioner’s Office.
We will respond within one month, extendable by a further two months for complex or numerous requests, in which case we will tell you within the first month.
Right to know the categories and specific pieces of personal information collected, the sources, the business purpose, and the categories of third parties to whom it is disclosed — set out in Clauses 4, 5 and 9;
Right to delete personal information, subject to statutory exceptions;
Right to correct inaccurate personal information;
Right to opt out of the sale or sharing of personal information — we do not sell or share personal information for cross-context behavioural advertising, and have never done so (Clause 4.4), so there is nothing to opt out of and we provide no “Do Not Sell or Share My Personal Information” link;
Right to limit the use of sensitive personal information — we use sensitive personal information only for the purposes permitted by §7027(m) of the CCPA Regulations, namely to provide the service you requested and to secure it;
Right to non-discrimination for exercising any of these rights; and
Authorised agents may submit a request with proof of authorisation.
We will confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days on notice to you.
Whatever your jurisdiction, you may in every case: withdraw consent (Clause 6.3), delete your account in the App or on the web (Clauses 7.2 and 7.3), obtain an export of your matter data, and complain to our Grievance Officer (Clause 22).
14.1 The App is a professional tool intended for advocates, chambers and legal teams. It is not directed at children and you must be at least 18 years of age to create an account or otherwise use the App.
14.2 We do not knowingly collect personal data of a child. Under section 9 of the DPDP Act we do not process the personal data of a person under 18 without verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children — none of which the App performs for any user (Clause 4.4). Under COPPA, we do not knowingly collect personal information from a child under 13.
14.3 In Google Play terms, the App’s target audience is adults only (18+) and it is not enrolled in the Designed for Families programme. In App Store terms, it is not a Kids Category app.
14.4 If we learn that we hold personal data of a person under 18 without the required consent, we will delete it promptly. If you believe a child has provided us with personal data, write to managelit@aglaw.in and we will act within 7 days.
15.1 Pursuant to rule 3 of the Intermediary Rules, you must not host, upload, store, share or transmit through the App any information which: belongs to another person and to which you have no right; is obscene, paedophilic, or invasive of another’s privacy; is defamatory; infringes any patent, trademark, copyright or other proprietary right; violates any law for the time being in force; impersonates another person; threatens the unity, integrity, defence, security or sovereignty of India; contains software viruses; or is prohibited from publication by any statute or by any order of a court.
15.2 On receipt of actual knowledge in the form of an order by a court of competent jurisdiction, or on being notified by the appropriate Government or its agency, that any information hosted through the App is being used to commit an unlawful act, we will remove or disable access to it as early as possible and in no case later than 36 hours (rule 3(1)(d)), and will preserve the information and associated records for 180 days for investigation, or longer if so directed (rule 3(1)(g)).
15.3 We have appointed a Grievance Officer under rule 3(2) of the Intermediary Rules, whose name and contact details are at Clause 22. Complaints will be acknowledged within 24 hours and disposed of within 15 days; a complaint concerning content of the nature described in rule 3(2)(b) will be acted on within 24 hours.
15.4 We are not a Significant Social Media Intermediary within the meaning of rule 2(1)(v) of the Intermediary Rules, and do not meet the threshold of fifty lakh registered users in India notified by S.O. 942(E) dated 25 February 2021. The additional due diligence prescribed by rule 4 therefore does not apply to us. We will comply with it if and when the threshold is crossed.
16.1 Where you obtain the App from the Apple App Store, your relationship with Apple is governed by the Apple Media Services Terms and Conditions and the Apple Privacy Policy, over which we have no control.
16.2 Apple independently receives certain data in connection with your download, purchase, subscription and crash reporting. Analytics you choose to share with Apple through Settings → Privacy & Security → Analytics & Improvements may be shared with us by Apple in aggregated or anonymised form.
16.3 Privacy Nutrition Label. The disclosures on the App’s App Store product page are made by us and are intended to be consistent with this Policy. In the event of any inconsistency, this Policy prevails, and we undertake to correct the product page within 7 days of becoming aware of the inconsistency.
16.4 Third-party beneficiary. Apple and its subsidiaries are third-party beneficiaries of the Terms accompanying this Policy and may enforce them against you. Apple has no obligation whatsoever to furnish any maintenance or support services in respect of the App, and Apple is not responsible for addressing any claim by you or any third party relating to the App, including product liability claims, any claim that the App fails to conform to any legal or regulatory requirement, any claim arising under consumer protection or privacy legislation, and any claim of intellectual property infringement.
16.5 Required Reason APIs. Where the App uses an API designated by Apple as requiring a declared reason, the reason is declared in our privacy manifest and the use is limited to that declared reason.
16.6 Sign in with Apple. The App does not offer any third-party or social login service, and authenticates you by mobile number. Sign in with Apple is therefore not offered and Guideline 4.8 is not engaged. Should we add a third-party login in future, we will offer Sign in with Apple alongside it and update this Policy.
16.7 Payments. Any paid tier on iOS is transacted through Apple In-App Purchase. We do not receive your payment instrument (Clause 4.1).
17.1 Where you obtain the App from Google Play, your relationship with Google is governed by the Google Play Terms of Service and the Google Privacy Policy, over which we have no control.
17.2 Data safety section. The disclosures in the App’s Data safety section on Google Play are made by us and are intended to be consistent with this Policy and with the SDKs actually present in the App. In the event of any inconsistency, this Policy prevails, and we undertake to correct the Data safety section within 7 days of becoming aware of the inconsistency. As at the date of this Policy we declare, in Data safety terms, that:
we collect: Personal info (name, email address, phone number, user IDs); Files and docs; App activity (in-app search and actions relating to your own matters); App info and performance (diagnostics); and Device or other IDs;
we share data only with the processors and platforms listed in Clause 9.2, and with Team members you yourself invite;
data is encrypted in transit;
you can request that data be deleted, both in the App and at the web address in Clause 7.3; and
we do not collect or share data for advertising or marketing, and we do not use the Advertising ID.
17.3 Permissions. On Android the App requests only the following, and uses each only for the stated purpose:
Permission
Why it is requested
INTERNET / ACCESS_NETWORK_STATE
To reach our servers and Court Sources
POST_NOTIFICATIONS (Android 13+)
To deliver hearing-date reminders and Team notifications you have asked for
VIBRATE
Notification alerts
READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE (Android 12 and below only)
To let you attach a document you individually select, and to save an exported or printed file. On Android 13 and above the App uses the system document picker and requests no storage permission. The App does not read your media library or scan your files.
We request no permission for location, contacts, camera, microphone, SMS, call logs, phone state, nearby devices or background location.
17.4 Account and data deletion. As required by the Google Play Data deletion requirements, deletion is available both in the App (Clause 7.2) and, without installing the App, at Annexure A to this Policy (Clause 7.3). What is deleted, what is retained and for how long is set out in Clauses 7.4 and 11.
17.5 Payments. Any paid tier on Android is transacted through Google Play Billing. We do not receive your payment instrument (Clause 4.1).
17.6 Families policy. The App’s target audience is adults only. See Clause 14.
PLEASE READ THIS CLAUSE CAREFULLY. IT LIMITS OUR LIABILITY TO YOU. Nothing in this clause excludes or limits liability which cannot lawfully be excluded or limited, including liability for death or personal injury caused by negligence, for fraud, or under the Consumer Protection Act, 2019.
18.1 “As is”. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, THE APP AND ALL DATA IN IT ARE PROVIDED “AS IS” AND “AS AVAILABLE”, WITHOUT WARRANTY OF ANY KIND, EXPRESS, IMPLIED OR STATUTORY, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, COMPLETENESS, TIMELINESS, NON-INFRINGEMENT, OR UNINTERRUPTED OR ERROR-FREE OPERATION.
18.2 No warranty as to court data. WE DO NOT WARRANT THAT ANY CAUSE LIST, CASE STATUS, HEARING DATE, BENCH ALLOCATION, BOARD POSITION, ORDER, JUDGMENT OR OTHER COURT INFORMATION DISPLAYED IN THE APP IS ACCURATE, CURRENT, COMPLETE OR AVAILABLE. SUCH INFORMATION IS DERIVED FROM COURT SOURCES OVER WHICH WE EXERCISE NO CONTROL AND WHICH WE HAVE NO POWER TO CORRECT.
18.3 Excluded losses. TO THE FULLEST EXTENT PERMITTED BY LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE OR EXEMPLARY DAMAGES, NOR FOR ANY LOSS OF PROFIT, REVENUE, BUSINESS, GOODWILL, REPUTATION, CLIENT, RETAINER, OPPORTUNITY, DATA OR ANTICIPATED SAVING, HOWSOEVER ARISING, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STATUTORY DUTY, RESTITUTION OR OTHERWISE, AND WHETHER OR NOT WE WERE ADVISED OF THE POSSIBILITY OF SUCH LOSS.
18.4 Specific exclusions. WITHOUT LIMITING CLAUSE 18.3, WE SHALL HAVE NO LIABILITY WHATSOEVER FOR:
any adjournment, dismissal for default, ex parte order or decree, striking off, abatement, limitation bar, or adverse order of any kind arising from a missed, mistaken or unnotified hearing date;
any professional negligence claim, disciplinary proceeding before a Bar Council, contempt proceeding, or costs order brought against you or any person;
any error, delay, omission, downtime, amendment or discontinuance in or of any Court Source;
any failure of a push notification or reminder to be generated, transmitted, received or displayed, including by reason of device settings, notification permissions, battery optimisation, Doze or App Standby, Focus modes, aeroplane mode, network unavailability, or failure of the Apple Push Notification service, Firebase Cloud Messaging or the Expo push service;
any loss, corruption or unauthorised disclosure of data resulting from your device being lost, stolen, shared, unlocked, jailbroken, rooted or otherwise compromised;
any act or omission of a Team member you invite, or any onward disclosure by them;
any breach by you of client confidentiality, legal professional privilege, a statutory reporting bar, a court direction, or the Bar Council of India Rules;
any act, omission, outage or security failure of Apple, Google, any Court Source, or any telecommunications or internet service provider; and
any event beyond our reasonable control, including act of God, flood, fire, epidemic, pandemic, war, civil disturbance, terrorism, strike, court closure, government or regulatory action, power failure, cyber-attack, or failure of public infrastructure.
18.5 Aggregate cap. SUBJECT TO THE OPENING WORDS OF THIS CLAUSE 18, OUR TOTAL AGGREGATE LIABILITY ARISING OUT OF OR IN CONNECTION WITH THE APP AND THIS POLICY, WHETHER IN CONTRACT, TORT, STATUTE OR OTHERWISE, SHALL NOT EXCEED THE GREATER OF (i) THE TOTAL AMOUNT YOU PAID US FOR THE APP IN THE TWELVE MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM AND (ii) RS. 1,000.
18.6 Limitation period. ANY CLAIM ARISING OUT OF OR IN CONNECTION WITH THE APP MUST BE COMMENCED WITHIN ONE (1) YEAR OF THE DATE ON WHICH THE CAUSE OF ACTION ACCRUED, FAILING WHICH IT IS PERMANENTLY BARRED, SAVE WHERE A LONGER PERIOD IS MANDATORILY PRESCRIBED BY LAW.
19.1 You agree to indemnify, defend and hold harmless the Developer and its partners, employees, contractors, agents and successors (the “Indemnified Persons”) from and against all claims, demands, proceedings, liabilities, damages, penalties, fines, costs and expenses (including reasonable legal fees) arising out of or in connection with:
your use of the App;
your breach of this Policy or of the Terms;
your entry, upload, storage, sharing or disclosure of any personal data of a third party, including any client, opponent, witness, victim or child;
your breach of client confidentiality, legal professional privilege, any statutory bar on disclosure or identification, any direction of a court or tribunal, or the Bar Council of India Rules;
your breach of any applicable data protection law in your capacity as the person determining the purpose and means of processing under Clause 8.4;
any claim by a Team member, client, or third party arising from content you shared through the App; and
your infringement of any intellectual property or other right of any person.
19.2 We will notify you of any claim to which this indemnity applies and will not settle it without your consent, such consent not to be unreasonably withheld or delayed. We reserve the right to assume the exclusive defence and control of any matter subject to this indemnity, at your expense, in which event you will cooperate with us.
20.1 Governing law. This Policy and any dispute or claim arising out of or in connection with it, including any non-contractual dispute or claim, is governed by and construed in accordance with the laws of India.
20.2 Grievance first. You must first raise the matter with our Grievance Officer under Clause 22 and allow 30 days for resolution.
20.3 Arbitration. Any dispute not resolved through the Grievance Officer within 30 days shall be referred to arbitration by a sole arbitrator under the Arbitration and Conciliation Act, 1996. The seat and venue shall be New Delhi, India; the language shall be English; and the award shall be final and binding. Nothing in this clause prevents either party from seeking urgent interim or injunctive relief from a competent court.
20.4 Jurisdiction. Subject to Clause 20.3, the courts at New Delhi, India have exclusive jurisdiction.
20.5 Consumer and regulatory forums preserved. Nothing in this Policy ousts the jurisdiction of any consumer commission constituted under the Consumer Protection Act, 2019, of the Data Protection Board of India, or of any data protection supervisory authority competent under the GDPR or UK GDPR. Clauses 20.3 and 20.4 do not apply to the extent that mandatory law entitles you to bring proceedings in the courts of your country of residence.
21.1 Changes. We may amend this Policy. The “Last Updated” date will change. For any material change — including a new purpose, a new category of data, a new recipient, or a reduction in your rights — we will give at least 14 days’ prior notice by in-App notification and, where we hold it, by email, and where the law requires, obtain your fresh consent. Continued use after the effective date constitutes acceptance of non-material changes.
21.2 Severability. If any provision is held invalid, illegal or unenforceable, it is severed and the remainder continues in full force. Any provision held excessive in scope shall be read down to the maximum permissible extent rather than struck out.
21.3 No waiver. No failure or delay in exercising any right operates as a waiver of it.
21.4 Entire agreement. This Policy and the Terms constitute the entire agreement between us in relation to their subject matter and supersede all prior representations, whether oral or written.
21.5 Assignment. You may not assign your rights. We may assign this Policy to a successor in interest on notice to you.
21.6 Language. This Policy is executed in English, which prevails over any translation.
21.7 Headings. Headings are for convenience only and do not affect construction.
For any question about this Policy, to exercise a right under Clause 13, or to make a complaint:
Data Protection / Grievance Officer (appointed under section 13 of the DPDP Act and rule 3(2) of the Intermediary Rules)
Email: managelit@aglaw.in
Telephone: +91 99711 08527
Address: Botero Strategies LLP, C-56 Basement, between C-569 and E-64, Neeti Bagh, Opposite Andrewsganj, New Delhi, South Delhi – 110049, India
We acknowledge every grievance within 24 hours and aim to resolve it within 15 days, and in any event within the periods stated in Clause 13.
Account and data deletion: Annexure A to this Policy
Court Master · published by Botero Strategies LLP · Android package the.law.team
This Annexure is the account-deletion notice required by the Google Play Data deletion requirements and by Apple Guideline 5.1.1(v). It restates Clauses 7.2 to 7.4 and Clause 11 in plain terms. You can delete your account at any time, either in the App or by written request, and you do not need to install the App to make a request.
Open Court Master and sign in.
Tap Profile in the bottom bar.
Tap Delete account.
Read what will be removed, type DELETE to confirm, and tap Request deletion.
Because the matters in a Team are a shared professional record, your request goes to a partner in your Team to approve. Your account stays active until they decide, and you may withdraw the request at any time before then. On approval the account is erased immediately and you are signed out. If your Team has no partner other than you, there is nobody else to ask and you approve your own request on the same screen — the confirmation step still applies.
This route needs nobody's approval. The approval step above exists to protect your Team's shared record; it cannot be used to keep you in the App against your will. If a partner declines your request, or never decides it, write to us and we will delete your account regardless. Your right of erasure under section 12 of the DPDP Act and Article 17 of the GDPR is yours alone and cannot be overridden by another User.
Write to managelit@aglaw.in stating that you require deletion of your Court Master account, and include:
the mobile number registered with the account;
the name on the account;
your Team or firm name, if you know it; and
whether you also want the matters, notes and documents you contributed to your Team deleted (see below).
Verification. To protect your account against deletion by someone else, we will confirm that you control the registered mobile number before we act. We acknowledge every request within 24 hours and complete it within 30 days, usually much sooner.
Your profile: name, mobile number and account record.
Your ability to sign in — the number is released and can no longer log in.
Your device registration and push notification tokens.
Your Firebase Authentication record, which holds the verified phone number.
Any invitations addressed to you that were still pending.
Your name wherever it appeared on Team activity and shared documents.
If you are the last active member of your Team, the Team is deleted together with every matter, note, timeline entry and shared document in it. Nothing survives and nothing can be recovered. Export anything you need first.
If other members remain in your Team, the matters, notes and documents in it stay with them — they are the Team's shared working record and the remaining members still depend on them. Your personal identifiers are removed from that content, so nothing in it identifies you any more. If you want the material you contributed deleted as well, say so in your request and we will remove it, subject to the rights of the Team's owner.
A small amount of data outlives deletion, either because the law requires it or because it no longer identifies you. This is the same table as Clause 11.
Data
Kept for
Account and profile data
Erased within 30 days
Encrypted backups containing your data
Purged on rotation, within 60 days of erasure
Server and security logs (including IP address)
180 days
Support correspondence with you
24 months from closure of the ticket
Transaction and subscription records, if you ever paid
8 years, as required by Indian tax and LLP law
Records needed for a legal claim, investigation or lawful direction
Until final disposal and expiry of limitation
Irreversibly aggregated or de-identified data
Indefinitely — it can no longer be linked to you
Leave a Team — ask a partner of that Team to remove you. Your account and any other Teams you belong to are unaffected.
Turn off notifications — in your device settings, without deleting anything.
Request an export of your matter data before you delete, by writing to managelit@aglaw.in.
© 2026 Botero Strategies LLP. All rights reserved. Court Master is a trade mark of Botero Strategies LLP.