Privacy Policy

What our applications collect, why, and what we never do with it.

Last updated 27 September 2026

Who this covers

This policy is issued by Famulus Technologies and covers this website and the business applications we publish, including the Famulus mobile app and its web counterpart, which are used by the staff of our client organisations.

These are workplace applications, not consumer products. Accounts are created by an administrator at the organisation that licenses the software; there is no public sign-up, and nobody can register themselves. Where we hold information on behalf of a client organisation, that organisation decides what is collected and why, and we process it on their instructions.

What we collect

Your account

  • Your name, work email address and, optionally, a phone number.
  • The roles and permissions your administrator has given you.
  • Who you report to, where your organisation uses that to route approvals.

Signing in uses either a one-time code emailed to your work address or a password your administrator has set. We do not use social logins and we never ask for a personal email account.

Your device and sessions

  • A randomly generated installation identifier. It is created by the app on first run, it is not your device's hardware identifier, it is not an advertising identifier, and it ceases to exist when the app is uninstalled. It exists so a session can be tied to one handset and so an administrator can revoke a lost or stolen one.
  • The platform (iOS or Android) and the app version, so support can recognise a device in a list.
  • Sign-in times and the IP address a request comes from, where your organisation restricts access to its own network or VPN.

Your app lock

If you set a PIN, the PIN itself is never stored or transmitted. What is stored, in your device's own secure keystore, is a salted cryptographic hash of it. If you enable Face ID or a fingerprint, that check is performed by your device: the biometric never leaves the handset and we never receive it. We record only that a lock is set and which kind, so an administrator can see that a device is protected.

How the app performs

The mobile app reports its own performance to Expo's EAS Observe service, which we use to keep it fast on the networks our users are actually on. What that sends is about the SOFTWARE, not about you: how long the app took to start, how long a screen took to render, how long an over-the-air update took to download, the device model and operating system version, and the details of any error or crash.

It carries no advertising identifier, records no session, and builds no profile. It is not used to decide anything about you, and we do not combine it with your account to study your behaviour.

The work you do in the application

The applications exist to hold your organisation's business records - customers, contacts, enquiries, costings, quotations, orders and the documents attached to them. Some of that content is personal information about third parties, typically the name, telephone number and email address of a contact at a customer, entered by your organisation's staff. It belongs to your organisation; we hold it for them.

What we do not do

  • No advertising, and no advertising identifiers.
  • No behavioural analytics and no session recording. Nothing watches what you tap, replays your screen, or builds a profile of you. We measure how the software performs, which is described below, and nothing about you as a person.
  • We never sell personal information, and we never share it for advertising.
  • No location collection. No access to your contacts, photos, camera, microphone or files.
  • No profiling, and nothing decided about you automatically.

Permissions the app asks for

PermissionWhy
Face ID / biometricsTo unlock the app on your device. The check happens on the device; no biometric data reaches us.
Internet accessTo reach your organisation's server. All traffic is encrypted with HTTPS.

The app asks for nothing else. Documents you download are written to the app's own private storage and shared through your device's standard share sheet, which needs no storage permission.

Why we hold it, and on what basis

To provide the service your organisation licenses: to sign you in, to show you the work assigned to you, to record who did what - an approval is only meaningful if it carries a name - and to keep the account secure. Nothing is collected for any other purpose.

Who else sees it

Only people at your own organisation, according to the permissions your administrator sets, and the service providers we use to run the software - cloud hosting and email delivery - who act on our instructions, may not use the data for their own purposes, and are bound by contract. We do not disclose it to anyone else.

How long we keep it

Business records are kept for as long as your organisation licenses the service, because a quotation or an approval has to remain auditable years after it was made. For the same reason, user accounts are archived rather than deleted: an archived account cannot sign in and disappears from active lists, while the work it produced keeps the name of whoever did it. When a client relationship ends, we return or delete their data on their instruction.

Security

  • All traffic is encrypted in transit with HTTPS; the mobile app enforces this at the operating-system level.
  • Passwords are stored only as bcrypt hashes. PINs are stored only as salted hashes, and only on your device.
  • Tokens are held in the device's Keychain or Keystore, never in ordinary storage.
  • Access is controlled per role, enforced on the server rather than merely hidden in the interface.
  • Organisations may restrict access to their own network or VPN, and may revoke any individual device.

Your choices

You may ask for a copy of your personal information, ask us to correct it, or ask for it to be deleted. Because your employer is the controller of the records held in these applications, the quickest route is your own administrator, who can act immediately. You may also write to us at tech@famulus.co.in and we will respond within 30 days, coordinating with your organisation where the request concerns their records.

Uninstalling the app removes its local data, including the installation identifier and your app lock, from that device.

Children

These are workplace applications. They are not directed at children, and we do not knowingly collect information from anyone under 18.

International transfers

Data is hosted in the region agreed with each client organisation. Where information is transferred across borders, we use providers that offer appropriate safeguards for such transfers.

Changes

If this policy changes in a way that affects how we handle personal information, we will update the date at the top of this page and, where the change is significant, tell your organisation directly.

Contact

Famulus Technologies - tech@famulus.co.in. Write to us with any question about this policy or to exercise any of the rights described above.