Legal
Privacy Policy
1. Who We Are
NOEZDAY is a behavioral stabilization and life-discipline mobile application developed and operated by Todoshi Technologies Pvt. Ltd., a company registered in Kolkata, West Bengal, India ("we", "us", "our", "Company").
For privacy-related matters, contact us at [email protected].
2. Scope of This Policy
This Privacy Policy applies to:
- The NOEZDAY mobile application (Android and iOS)
- The website at noezday.com
- Any related waitlist, early-access, or communication services
By using NOEZDAY or signing up for our waitlist, you acknowledge that you have read and understood this Policy and consent to the collection and use of your information as described here.
3. Information We Collect
3.1 Information you provide directly
- Email address — collected when you sign up for the waitlist on noezday.com, and when you create an account in the app
- Password — stored as a bcrypt hash; we never store or see your plain-text password
- Journal entries — text you write in the free-write or guided journaling features. These are stored encrypted on our servers (hosted on AWS, Mumbai region) to enable syncing across your devices
- Mood and state ratings — numerical self-assessments you provide during daily check-ins (e.g., stress level 6/10)
- Profile name — an optional display name you choose; your real name is never required
3.2 Data generated by your use of the app
- Which breathing exercises, grounding sessions, meditations, and challenges you complete, and when
- Your XP earned, current level, streak count, and challenge progress
- Session duration and frequency (not the content of your breathing sessions)
3.3 Data collected automatically
- Device information — device model, operating system version, and app version
- Crash and error reports — when the app crashes, technical diagnostic data (stack traces, device state) is sent to Sentry, our crash reporting provider. This does not include your journal entries, mood ratings, or any personal content
- Analytics — we do not currently use any analytics or tracking tools
3.4 Data we do NOT collect
- Your location (GPS or IP-based)
- Camera or microphone access
- Contacts, calendar, or files
- Biometric data of any kind
- Your real name (unless you choose to add it to your profile)
- Any data from your device beyond what is listed above
4. Sensitive Personal Data
Because NOEZDAY is a behavioral health application, some data you provide — including journal entries about your mental state, mood and stress ratings, and activity patterns — may constitute health-related personal data under India's Digital Personal Data Protection Act 2023 (DPDP Act).
We process this sensitive data only under your explicit, informed consent, which you provide when you create an account. You may withdraw consent at any time by deleting your account. Withdrawal of consent means we will delete your data, and you will no longer be able to use the app.
5. How We Use Your Information
We use your data only for the following specific purposes:
- Providing the service — syncing your journal entries, progress, XP, and settings across your devices
- Personalising your experience — suggesting relevant breathing techniques, meditations, or challenges based on your self-reported state and history
- Technical reliability — using Sentry crash reports to identify and fix bugs in the app
- Communication — sending account-related emails (welcome email, password reset, subscription receipts) and, for waitlist members, a notification when the app launches. You can unsubscribe from marketing emails at any time.
- Processing payments — facilitating your Pro or Premium subscription through Razorpay, the App Store, or Google Play
- Legal compliance — retaining records as required by Indian law (e.g., financial transaction records)
We will never use your journal entries, mood ratings, SOS usage, or any health-related data for advertising, profiling for third parties, or sale to any organisation.
6. Sharing of Your Information
We do not sell your personal data. We share information only in the following limited circumstances:
6.1 Service providers
- Amazon Web Services (AWS), Mumbai region — cloud infrastructure for hosting our backend servers and encrypted database. Your data is stored in India.
- Razorpay — Indian payment gateway for processing Pro and Premium subscription payments. Razorpay receives your payment details directly and is subject to RBI regulations. We do not store your full card or bank details.
- Apple App Store / Google Play — if you subscribe through the App Store or Play Store, billing is managed entirely by Apple or Google. Their privacy policies apply to that transaction.
- Sentry — crash and error reporting. Sentry receives technical diagnostic data (device type, OS version, app version, error stack traces) when the app crashes. No personal content (journal entries, mood ratings) is included in crash reports. Sentry is a US-based company; crash data is processed under their DPA and standard contractual clauses.
6.2 Legal obligations
We may disclose your personal data if required to do so by applicable Indian law, a valid court order, or a legitimate request from a government authority. We will notify you of such requests where legally permissible.
6.3 Business transfers
If Todoshi Technologies Pvt. Ltd. is acquired, merges with another entity, or transfers assets, your data may be transferred to the acquiring entity. We will notify you via email at least 30 days before any such transfer and give you the opportunity to delete your account before it occurs.
7. Your Rights Under the DPDP Act 2023
As a data principal under India's Digital Personal Data Protection Act 2023, you have the following rights:
- Right to access — request a summary of the personal data we hold about you and how it is being processed
- Right to correction — request correction or updating of inaccurate or incomplete data
- Right to erasure — request deletion of your personal data. Upon account deletion, all your journal entries, activity data, XP history, and profile information will be permanently and irreversibly deleted within 30 days
- Right to grievance redressal — raise a complaint with us at [email protected]. We will acknowledge your complaint within 48 hours and resolve it within 30 calendar days
- Right to nominate — nominate another person to exercise your rights in the event of your death or incapacity, in accordance with the DPDP Act
To exercise any of the above rights, email [email protected] with the subject line "Data Rights Request" and your registered email address. We will respond within 30 calendar days.
8. Data Retention
- Active accounts — your data is retained for as long as your account remains active
- Deleted accounts — all personal data (journal entries, mood ratings, XP history, profile) is permanently deleted within 30 days of account deletion. Payment transaction records are retained for 8 years as required under the Indian Income Tax Act and accounting regulations.
- Waitlist emails — retained until you unsubscribe or the app launches and you either create an account or opt out
- Crash logs (Sentry) — automatically purged after 90 days per Sentry's standard data retention policy
- Inactive accounts — accounts with no activity for 3 consecutive years may be marked for deletion. We will notify you via email 60 days before taking any action.
9. Data Security
We implement the following technical and organisational measures to protect your data:
- All data transmitted between the app and our servers is encrypted using TLS 1.2 or higher
- Passwords are hashed using bcrypt with a work factor of 12 or higher; we never store plain-text passwords
- Journal entries and sensitive health data are encrypted at rest in our AWS database
- Our API uses short-lived JWT access tokens and secure refresh token rotation; tokens are invalidated on logout
- Database access is restricted to authorised personnel only, with role-based access control and audit logging
- Our AWS infrastructure is configured within India (Mumbai region), keeping your data within Indian jurisdiction
No system can guarantee 100% security. In the event of a data breach that is likely to result in a risk to your rights or interests, we will notify you and the appropriate authorities within 72 hours of becoming aware of the breach, as required by applicable law.
10. Children and Minimum Age
NOEZDAY is intended for users who are 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has registered an account or provided us with personal data, please contact [email protected] immediately and we will delete the account and all associated data.
11. Cookies and Tracking
The noezday.com website does not use advertising cookies, tracking pixels, or third-party analytics. We use only a minimal session cookie necessary for the waitlist form submission. The NOEZDAY mobile app does not use browser cookies.
12. International Data Transfers
Your primary data (journal entries, account information, activity data) is stored on AWS servers in the Mumbai (ap-south-1) region, within India. Crash diagnostic data is processed by Sentry, which may involve transfer to the United States. Such transfers are governed by Sentry's Data Processing Agreement and standard contractual clauses in compliance with applicable data protection laws.
13. Third-Party Links and Services
The app's SOS feature links to third-party crisis helplines. The app's Adventure Activities section (when launched) will connect to third-party activity providers. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before sharing any information with them.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Send an email notification to all registered users
- Display a notice in the app for at least 14 days
Continued use of NOEZDAY after the effective date of changes constitutes acceptance of the updated Policy. If you disagree with any changes, you may delete your account before the effective date.
15. Contact & Grievance Officer
For privacy questions, data rights requests, or complaints:
- Email: [email protected]
- General enquiries: [email protected]
- Company: Todoshi Technologies Pvt. Ltd.
- Address: Kolkata, West Bengal, India
We aim to acknowledge all privacy-related queries within 48 hours and resolve them within 30 calendar days.