Privacy Policy
App: Verse Overlay
Data Controller: Surya Ganesh — suryaganeshdc@gmail.com
Last updated: June 2026
1. Introduction
Verse Overlay is an Android application that displays sacred scripture verses as
on-screen overlays, enabling personal spiritual reflection throughout your daily
activities. The app uses Android's Accessibility Service to detect when you open a
new application and surfaces a relevant verse at that moment.
We are committed to protecting your privacy and handling your personal data with
transparency and care. This Privacy Policy explains what data we collect, why we
collect it, how we use it, and the rights you hold over it under the General Data
Protection Regulation (GDPR) and India's Digital Personal Data Protection Act 2023
(DPDPA 2023).
2. What We Collect
-
Google Account UID and email address — collected via Firebase
Authentication when you sign in with Google. Used to identify your account and
synchronise your settings.
-
Chosen religious tradition — the tradition (e.g., Hinduism,
Christianity, Islam, Buddhism) you select during onboarding. This is a
special category of personal data under GDPR Article 9 and sensitive
personal data under DPDPA 2023, as it reveals information about your religious
beliefs. It is stored in Firebase Firestore under your account UID and is never
sold or shared with third parties for marketing.
-
App-open events (via Accessibility Service) — when you open an
application on your device, the Accessibility Service detects the event so the
overlay can be triggered. We anonymise this data before any use: unknown
applications are replaced with a SHA-256 hash of the package name; known
applications are mapped to a general category such as "social", "productivity",
or "entertainment". No raw package names are stored or transmitted to our servers.
-
Crash reports — collected via Firebase Crashlytics. Reports
include device model, Android OS version, app version, and stack traces. They do
not include your name, email, or any personally identifying information unless
you have explicitly set a custom user identifier in the app.
-
Anonymised usage events — collected via Firebase Analytics.
Examples include
overlay_shown, verse_bookmarked,
app_open, and settings_changed. These events help us
understand how the app is used so we can improve it. Analytics collection is
optional and can be disabled in Settings → Privacy.
3. Legal Basis for Processing (GDPR Art. 6 and 9)
-
Religious tradition data — processed on the basis of your
explicit consent (GDPR Art. 9(2)(a)). You provide this consent during
onboarding. You may withdraw consent at any time by deleting your account
(see Section 9).
-
Account authentication data — processed on the basis of
contract performance (GDPR Art. 6(1)(b)), as it is necessary to provide
the personalised service you have requested.
-
Crash reports — processed on the basis of our
legitimate interest (GDPR Art. 6(1)(f)) in maintaining a stable,
secure application. Our legitimate interest does not override your rights; crash
data is aggregated and does not identify you personally.
-
Analytics events — processed on the basis of your
consent (GDPR Art. 6(1)(a)). You can opt out at any time in
Settings → Privacy → Analytics.
4. Cross-Border Data Transfers
Verse Overlay uses Firebase and Google Analytics, services operated by Google LLC,
headquartered in the United States. Your data may be processed on servers located
outside your country of residence, including the United States and other countries
where Google operates data centres.
For transfers from the European Economic Area (EEA) or the United Kingdom, Google
LLC relies on Standard Contractual Clauses (SCCs) as the lawful
transfer mechanism under GDPR Chapter V. For transfers from India, Google complies
with applicable data localisation and transfer requirements under DPDPA 2023.
Google's data processing terms and SCCs are available at
business.safety.google/processorterms.
5. Data Retention
-
Account data (UID, email, religious tradition, bookmarks,
settings) — retained until you delete your account.
-
Analytics events — retained for 14 months,
which is the default Google Analytics 4 retention period. Events older than
14 months are automatically deleted.
-
Crash reports — retained for 90 days in
Firebase Crashlytics, after which they are automatically purged.
-
Deletion audit record — a minimal record containing only a
timestamp and a one-way hash of your email address is retained indefinitely for
GDPR compliance purposes. It cannot be used to re-identify you.
6. Your Rights Under GDPR (Art. 15–22)
If you are located in the European Economic Area or the United Kingdom, you have
the following rights regarding your personal data:
- Right of Access (Art. 15) — request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16) — request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17) — request deletion of your personal data ("right to be forgotten").
- Right to Restriction (Art. 18) — request that we limit how we process your data.
- Right to Data Portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21) — object to processing based on legitimate interest.
- Right to Withdraw Consent — withdraw consent for religion data or analytics at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at
suryaganeshdc@gmail.com. We will respond
within 30 days.
You also have the right to lodge a complaint with a supervisory authority. If you
are in the EU, contact your local Data Protection Authority. If you are in the UK,
contact the Information Commissioner's Office (ICO).
7. India-Specific Rights (DPDPA 2023)
Data Fiduciary: Surya Ganesh
Grievance Officer:
suryaganeshdc@gmail.com
If you are located in India, the Digital Personal Data Protection Act 2023 grants
you the following rights:
- Right to Information — to know what personal data we hold and how it is processed.
- Right to Correction and Erasure — to correct inaccurate or misleading data and to erase data no longer needed for the stated purpose.
- Right to Grievance Redressal — to raise a grievance with our Grievance Officer. We will acknowledge your grievance within 48 hours and resolve it within a reasonable time.
- Right to Nominate — to nominate another individual who may exercise your data rights on your behalf in the event of your death or incapacity.
To exercise your rights or raise a grievance, email
suryaganeshdc@gmail.com.
Please include "DPDPA Request" in the subject line.
8. Accessibility Service Declaration
Verse Overlay uses Android Accessibility Services solely to detect when a new
application is opened. It does not read, record, or transmit any
on-screen content, text, keystrokes, passwords, or personal communications. The
name of the application opened is anonymised before any use — unknown apps are
replaced with a SHA-256 hash of their package name; known apps are mapped to a
general category (e.g., "social", "productivity"). No raw package names are
stored or transmitted.
The Accessibility Service permission is used exclusively for overlay triggering. It
is not used for monitoring, surveillance, data harvesting, or any purpose beyond
detecting app-open events to display a verse.
9. Account Deletion
You can delete your account at any time by navigating to
Settings → Account → Delete Account within the app.
Upon account deletion, the following data is permanently deleted:
- Your Firebase Authentication account (UID and linked Google account association).
- All locally stored data, including bookmarked verses, notes, and app settings.
- Your Firestore profile document, including your religious tradition preference.
- The association between your device and any analytics events.
The following data is retained after deletion:
-
A deletion audit record containing only a timestamp and a
one-way SHA-256 hash of your email address. This record is retained to
demonstrate compliance with GDPR erasure obligations and cannot be used to
re-identify you.
10. Children
Verse Overlay is intended for users 18 years of age and older.
We do not knowingly collect personal data from individuals under the age of 18.
If you believe that a minor has provided us with personal data, please contact us
at suryaganeshdc@gmail.com and we will
take steps to delete the data promptly.
For questions about this Privacy Policy, contact
suryaganeshdc@gmail.com.