# Privacy Policy for KK SPRING
**Last updated:** 11 May 2026
This privacy policy describes how KK SPRING ("the app", "we", "us") collects, uses, and protects information when you use our mobile application on Android devices.
By using KK SPRING, you agree to the practices described in this policy.
---
## 1. Who we are
KK SPRING is operated by Shani Chaun. If you have any questions about this policy or your data, contact us at:
**Email:** sunnychaun9@gmail.com
---
## 2. Information we collect
We collect only the minimum information needed to operate the app.
### 2.1 Information you provide
- **Phone number** — required for sign-in. We use Firebase Phone Authentication to send a one-time password (OTP) to your phone and verify it.
- **Business data** — companies, machine setups, spring/material data, and any notes you enter in the app. This is the operational data the app exists to manage.
### 2.2 Information collected automatically
- **Device identifier** — a unique device ID is stored when you log in. We use it to bind your account to one device at a time, so a stolen credential cannot be used on another phone without administrator approval.
- **Authentication tokens** — Firebase issues a session token after successful OTP verification. We store it on the device only.
- **Crash and error logs** — limited diagnostic logs may be generated by Google Play Services if the app crashes. These contain technical details about the failure but no business data.
### 2.3 Information we do NOT collect
- Location data
- Contacts
- Photos, files, or media
- SMS messages, call history, or any system data not listed above
- Advertising identifiers
---
## 3. How we use your information
We use the information we collect only to:
- Verify your identity at sign-in (phone number + OTP).
- Bind your account to a single device, to prevent unauthorised access.
- Store your business data securely so you can access it across app restarts and after reinstalling the app on the same device (or a new device, after admin approval).
- Sync your business data to the cloud so multiple authorised users in your organisation can collaborate.
- Provide subscription management — activating, extending, or expiring access based on your administrator's actions.
We do **not** use your data for advertising, profiling, or sale to third parties.
---
## 4. Where your data is stored
- **On your device** — business data is stored locally in an encrypted SQLite database. Your authentication session is stored in your device's secure local storage.
- **In the cloud** — business data and member records are stored in Google Cloud Firestore (a Google-managed database). Phone numbers and device IDs are stored alongside member records to enforce access control.
All data in transit between your device and our cloud servers is encrypted using TLS. Data at rest in Firestore is encrypted using AES-256 by Google's infrastructure.
---
## 5. Third-party services we use
The app relies on the following third-party services, each with their own privacy practices:
| Service | Purpose | Privacy policy |
|---|---|---|
| Firebase Authentication (Google) | Phone-number sign-in via OTP | https://firebase.google.com/support/privacy |
| Cloud Firestore (Google) | Cloud database for business data and member records | https://firebase.google.com/support/privacy |
| Google Play Services | Standard Android platform services | https://policies.google.com/privacy |
We do **not** share your data with any other third party for marketing, analytics, or any other purpose.
---
## 6. How long we keep your data
- **Active accounts** — your data is retained for as long as your account is active.
- **Inactive or removed accounts** — when an administrator removes your member record, your account is deactivated immediately. Your business data is soft-deleted (marked as deleted but retained for a short window in case the action is reversed). Permanent deletion happens within 90 days.
- **Local data** — when you uninstall the app, all local data on your device is removed by the operating system. Cloud data is unaffected and remains accessible after reinstall + re-login.
---
## 7. Your rights and how to exercise them
You have the right to:
- **Access** your data — log in to the app and view all data associated with your account.
- **Correct** your data — edit any record directly in the app.
- **Delete** your data — contact your administrator or email us at sunnychaun9@gmail.com to request account deletion. We will process the request within 30 days.
- **Object** — stop using the app at any time. Uninstalling removes all local data; cloud data deletion is handled per the request flow above.
---
## 8. Children's privacy
KK SPRING is a business application intended for use by adults (18+) in industrial settings. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
---
## 9. Security
We protect your data with industry-standard practices:
- TLS encryption for all network traffic.
- Encrypted storage at rest in Firebase / Google Cloud.
- Server-side access control rules that restrict every read and write to authenticated, active members of the correct organisation.
- Device binding — a stolen account credential cannot be used on a new device without administrator approval.
- Tokens are refreshed regularly so a compromised session has a limited useful lifetime.
No system is completely secure. If we become aware of a breach affecting your data, we will notify affected users within 72 hours of confirming the incident.
---
## 10. Changes to this policy
We may update this policy occasionally. When we do, we will:
- Update the "Last updated" date at the top of this page.
- For material changes (new data collected, new third parties, expanded use), notify users in-app or by email before the change takes effect.
Continuing to use the app after a change indicates your acceptance of the updated policy.
---
## 11. Contact us
For any question about this policy, your data, or to exercise any of the rights above:
**Email:** sunnychaun9@gmail.com
We respond to all genuine privacy enquiries within 7 business days.