Review draft · not yet effective. Account activation is unavailable until reviewed legal releases and service configuration are approved.
Murugan — Privacy Policy
PRE-PUBLICATION DRAFT — not yet effective. Prepared 16 September 2026 for muruga.live and the Murugan Android/iOS apps. This draft describes the proposed Sprint 3 design. Publish only after the actual providers, hosting locations, security controls, retention schedule, permissions and store declarations have been verified. It is not evidence that the proposed controls already exist.
Proposed version: privacy-1.0-draft. Effective date: to be assigned at approved publication.
1. Who is responsible
Prashbi Global Services Pvt. Ltd., CIN U52100KA2020PTC133490, operates Murugan and muruga.live.
Address: Tholons Tower, 346 HIG, 17th Cross Rd, Dollars Colony, R.M.V. 2nd Stage, Bengaluru, Karnataka 560094, India.
Contact info@prashbi.com for privacy questions, access/correction requests, deletion assistance or complaints. We will route the request to the responsible person. Any additional legally required grievance-officer particulars must be completed before publication.
2. Your choices at a glance
You can browse public stories, temple information, prayers and available festival dates without creating an account. You can choose an observance location manually instead of granting device location access.
Personal information saved only on your device is different from information you choose to back up to your account. Signing in does not automatically upload your existing journals.
Phone notifications, journal backup, preference sync, optional diagnostics and public sharing have separate controls. Agreeing to Terms does not opt you into all of them.
Private devotional writing can contain sensitive information, including religious beliefs, wishes and personal circumstances. We do not sell that writing, use it for advertising or send it to an AI service in the proposed release.
3. Information we handle and why
| Information | When and purpose |
| --- | --- |
| Account identity | When you sign in: provider user ID, email and a display name if supplied; used to authenticate, recover and administer the account |
| Limited provisional sign-in information | If the auth provider creates an identity before app-account activation; used only to complete or secure sign-in and removed if abandoned under the schedule below |
| Calendar and app preferences | Language, chosen observance location, saved festivals/prayers and reminder settings; local by default, with account sync when selected |
| Private journal content | Letters, wishes, intention states, gratitude and temple reflections you write; stored locally and backed up only when you choose that feature |
| Personal event information | Reflection dates and calendar items you create; processed for the calendar feature you request |
| Notification information | Permission state, reminder choices and device/push token if the implemented delivery path needs one |
| Optional location information | Only when you choose a location-based feature and grant access; manual selection remains available |
| Support communications | Messages and contact details you choose to send us; used to resolve the request |
| Consent and legal records | The policy/version presented, agreement or withdrawal, time and relevant account/app identifiers; used to honor choices and document them |
| Security and service logs | Limited technical information needed to protect accounts and operate the service; journal contents are excluded |
| Optional diagnostic information | Only if enabled; restricted error/device details, excluding private text and sensitive personal selections |
| Public submissions, if offered | Only the exact story or other fields you explicitly approve for public display |
A selected temple or observance city is a preference and may differ from where you are physically located. We will not quietly use that choice to infer your current precise location.
We do not request Aadhaar, PAN, banking credentials, an email inbox, phone contacts or continuous background location for these features. Do not send such details in a support message unless a specific lawful process makes them necessary and explains why.
4. Local writing and cloud backup
When you keep writing on this device, the journal feature does not upload its content to our servers. The implementation must also control operating-system backup and third-party diagnostics so this statement remains accurate.
Local-only writing can be lost if a device is lost or cleared or storage fails. Cloud recovery is available only for data that has actually been backed up. Exports you keep are your own additional copies.
Before the first cloud journal upload, we explain the data being uploaded, the backup purpose and the providers involved. You can keep entries local instead. Calendar-preference sync and journal backup are separate selections.
You can turn backup off to stop future journal synchronization. The interface separately offers removal of existing cloud copies. Turning backup off alone should not misleadingly be presented as erasing already stored information.
If an old offline device reconnects after deletion or consent withdrawal, the service must reconcile that state before accepting uploads.
5. Private does not mean publicly shared
Your private entries are available only to your authenticated account through normal app features. Other users and community moderators cannot browse them.
Ordinary support and editorial staff do not have a private-journal browsing tool. Exceptional technical access, if necessary for a specific security incident, lawful request or authorized support process, is restricted, approved and audited.
The proposed initial cloud service uses encryption in transit and at rest; it is not advertised as end-to-end encrypted. That distinction matters because an authorized service operator may technically be able to decrypt server-held content under controlled conditions.
If you choose a public community feature, it presents a separate preview and consent step. Your private journal, personal notes, exact location and account email are not automatically included. Public copies saved by other people cannot always be recalled after removal.
6. Blessings, personalisation and AI
Daily blessings can be selected from reviewed content using the chosen language, festival location, saved preferences and a rotation. Private journal text is not read to infer your mood or generate advertising profiles.
Wish states and monthly reflections are based on actions you choose, such as marking an intention “Fulfilled.” They are not predictions or assessments of your faith.
No third-party AI receives private journal content in Sprint 3. A future AI feature would need a clear explanation of the provider, data, purpose and handling, plus explicit permission before the relevant transfer. Acceptance of this Privacy Policy or the Terms alone would not authorize it.
7. Service providers and other recipients
We use providers where necessary to operate the features you choose, such as authentication, hosting/database storage, email delivery and notifications. They must be governed by suitable contractual protections, confidentiality, security and deletion arrangements.
The production policy must identify the actual vendors or provide a complete, accessible processor schedule before cloud features launch. The following is an implementation checklist, not a completed disclosure:
| Service | Proposed relationship | Publication prerequisite |
| --- | --- | --- |
| Google sign-in | Provider of chosen login; receives its own login interaction | Confirm scopes, IDs and applicable privacy terms |
| Sign in with Apple | Provider of chosen login; may supply a relay email | Confirm token lifecycle and deletion/revocation |
| Account authentication and database | Provider not yet selected/verified for this release | Enter vendor, data processed, region and contract |
| App/web hosting | Provider not yet selected/verified | Enter vendor, region and log practices |
| Email delivery | Provider not yet selected/verified | Enter vendor, sender configuration and retention |
| Apple/Google push delivery and any intermediary | Only if used by the shipped notification design | Record actual payloads/tokens and intermediaries |
| Optional diagnostics | No private-text collection; vendor undecided | List exact SDK behaviour before enabling |
Do not publish the preceding table with “not yet selected” rows. Complete it and align the policy with the shipped configuration.
We may disclose narrowly necessary information to comply with a valid legal obligation, protect rights or investigate a security incident, subject to applicable law. Such exceptions are not permission for routine marketing or unrestricted access.
If you open maps or share an export to another app, that service handles the information you deliberately send under its own practices. We do not control a copy you choose to export.
A corporate reorganization may require a lawful transfer of the service's records. Any transfer must maintain applicable protections and provide required notice; it is not a licence to repurpose journals without a lawful basis or necessary consent.
8. Permissions and device access
We request access when it is relevant to the action you choose.
- Notifications: for selected blessings and reminders. You can turn them off in the app or system settings.
- Location: for a chosen nearby-temple feature. Manual location entry remains available; background tracking is not part of this release.
- Calendar: only for the selected calendar operation that requires permission. The app does not need to read your whole personal calendar just to show festivals.
- Biometric/device unlock: for an optional app lock, using the operating system's authentication result. The app should not receive your biometric template.
- Files/photos/microphone: no broad access is needed for text journals. A future photo or voice feature requires its own limited access and disclosure.
Permission refusal does not block unrelated reading. Revoking an OS permission does not necessarily erase information already stored; the relevant privacy/deletion control explains how to do that.
We use generic reminder text by default. A private wish title or personal circumstance should not unexpectedly appear on a lock screen.
9. Tracking, cookies and diagnostics
Sprint 3 does not introduce advertising tracking, sale of personal information, advertising identifiers or cross-app behavioural profiling.
The website may need essential session/security storage for sign-in and deletion requests. Public legal pages must remain accessible without nonessential cookies or marketing consent.
Optional diagnostics, if implemented, must be separately controlled and exclude private writing, sensitive titles, account secrets and detailed devotional selections. Minimal service-security logs are handled only for their disclosed operational purpose.
An Apple ATT prompt is required if tracking is actually introduced under Apple's definition; requesting ATT is not a substitute for accurately assessing SDK behaviour. Future analytics or marketing changes need a fresh privacy review and any required consent.
10. Retention and deletion
The following are proposed operational commitments requiring engineering, processor and legal approval before publication. They are not statements of a universal statutory period.
| Information | Proposed retention |
| --- | --- |
| Active account and backed-up personal data | While you use the account/feature, unless you delete it sooner or a disclosed rule applies |
| Provisional sign-in abandoned before activation | Remove within 24 hours |
| Verified account or cloud-content deletion request | Block relevant service access promptly; remove from active systems within 30 days |
| Backups containing deleted information | Expire or purge within 90 days of the verified deletion request |
| Routine security logs | Up to 90 days |
| Closed support correspondence | Up to 90 days after closure, unless needed for an active dispute |
| Minimal consent/contract evidence | Up to three years after account closure where necessary and legally justified; excludes journal bodies |
| A valid legal preservation requirement | Only the necessary records, restricted to that purpose until the obligation ends |
A deleted entry should be hidden from normal use immediately. Necessary asynchronous removal must be tracked to completion. Processors holding our service's data must also receive the relevant deletion instruction.
We do not retain an entire private journal merely to prove that someone accepted the Terms. Backup retention is not permission to restore deleted entries into active use.
Copies on another offline device may remain until that device reconnects or the user clears it. Files you exported and calendar events you independently imported into another service are outside our deletion controls.
11. Account deletion and your data controls
You can start account deletion in Settings → Account → Delete account, or through the public delete-account page on muruga.live. The website request route must work without reinstalling the app.
We may verify your identity to prevent another person deleting your account. We do not require a reason, a purchase or a support conversation as the normal deletion path. Export is offered but optional.
Deletion removes the account and associated personal data, including private journals, preferences, saved items, notification tokens and public user-generated content, except the specifically justified retained records described above. Disabling or freezing an account alone is not deletion.
Where Sign in with Apple was used, the process includes applicable token revocation. Deleting the Murugan account does not delete the underlying Google or Apple account.
You can ask to access, correct, export or delete your information, withdraw an optional consent or raise a complaint through the app controls or info@prashbi.com. We will explain any identity-verification step, applicable legal limitation or additional right available in your location. We will not treat withdrawal as a reason to block unrelated public reading.
12. Security and operational access
The implementation must use encrypted transport, suitable protected storage, owner-level access checks, secure session handling, restricted staff access and tested backup/deletion processes.
No system can promise absolute security. We will respond to incidents and provide notifications required by the applicable law and circumstances. The plan does not claim that every security control has already been audited.
App lock reduces casual access; use your device's own lock and protect exported files. Do not share sign-in links or verification codes with support staff.
13. Children and launch regions
The proposed initial account, cloud-journal and community service is for adults aged 18 or over, subject to the actual applicable age and consent rules. Public reading does not require an account. No child-account service or child-directed advertising is introduced by this release.
Do not describe a simple age checkbox as proof of compliance with every child-data law. The launch review must establish an appropriate age/consent approach and any required safeguards.
Country availability, hosting regions, international transfers and applicable rights must be reviewed before launch. The service must not claim universal compliance merely because one policy is published. India is the operator's home jurisdiction; any additional requirements for the actual countries served remain applicable.
14. International processing
The final policy must list the actual storage and processing locations or clearly explain how to find them, along with the applicable safeguards for cross-border processing. Hosting and auth regions were not confirmed when this draft was prepared.
Consent to journal backup must be informed by the completed provider and transfer explanation. Do not promise that all data remains in India until every relevant provider, backup, support and notification flow supports that statement.
15. Policy changes and contact
Published policies have an effective date and version. We will explain significant changes and obtain renewed permission where required before using information for a new purpose.
An update cannot silently convert a private journal into public content, an advertising profile or AI training data. Old versions remain available for the record of what was presented.
Contact info@prashbi.com, or write to Prashbi Global Services Pvt. Ltd., Tholons Tower, 346 HIG, 17th Cross Rd, Dollars Colony, R.M.V. 2nd Stage, Bengaluru, Karnataka 560094, India.
© 2020–2026 Prashbi Global Services Pvt. Ltd. All rights reserved.