Privacy Policy
Mileage India ("the app," "we," "us") is operated by NeuralPath Technologies ("the Company"). This policy explains what data we handle, why, and the rights you have under India's Digital Personal Data Protection (DPDP) Act, 2023 and its Rules. We are the Data Fiduciary; you are the Data Principal.
1. What we collect
| Data | When | Why | Stored where |
|---|---|---|---|
| Vehicle, refuel, reminder, service and cost records | Always, as you use the app | Core features | On your device. Mirrored to our cloud only if you sign in for backup |
| Name and email address | Only if you sign in with Google or Apple | Account identity, backup & sync, essential service messages | Supabase Auth (our processor) |
| City | If you set it | Show your local fuel price | On device (synced with settings if signed in) |
| Anonymous, aggregate usage events | Only if you opt in | Improve the product | Analytics store - never tied to your name/email |
| Crash reports (personal data scrubbed) | If a crash occurs | App stability | Crash-reporting service |
We do NOT collect: precise location / GPS, contacts, phone number, advertising ID, biometrics, or any special-category data. We use no advertising SDKs and do no cross-app tracking.
2. How we use your data
Name and email are used only for account identity, authentication, backup/sync, and essential communications. We do not use your data for advertising, profiling, or any purpose beyond those stated without your fresh consent.
3. Consent
If you choose to sign in, we show a clear notice and ask for your explicit, affirmative consent first (never a pre-ticked box). You can withdraw consent as easily as you gave it - by deleting your account in the app or emailing us. Withdrawing consent stops future processing and triggers deletion as described below.
4. Sharing
We do not sell or share your personal data with third parties for their own purposes. We use Supabase as our backend processor to store your backed-up data securely on our behalf; it is bound to process data only on our instructions. All cloud communication is encrypted in transit (TLS).
5. Storage & retention
Your logs live primarily on your device. Backed-up personal data is retained only while your account and consent stand. When you delete your account, we purge your rows (see section 7). We retain no backups of personal data beyond a short security/audit window.
6. Your rights (DPDP)
You have the right to: access a summary of the data we hold and who it is shared with; correct your profile; erase your account and data; withdraw consent; nominate someone to exercise your rights in case of death or incapacity (contact us); and raise a grievance.
7. Account & data deletion
- In the app: More → Settings → Backup & sync → Delete account & data. This deletes your account and, by database cascade, every row you own, then wipes the local copy on your device.
- On the web / by request: visit our account deletion page or email us from your signed-in address.
8. Children
The app is intended for users 18 and older. We do not knowingly collect data from children.
9. Security
Per-user data isolation (row-level security), encrypted transport (TLS), secure token storage on device, and least-privilege access. In the event of a personal-data breach, we will notify affected users and the Data Protection Board without delay, with a fuller report to the Board within 72 hours.
10. Grievance redressal
Questions or complaints? Contact our Grievance Officer: contact@neuralpath.app. We respond within 90 days (usually much sooner), as required by the DPDP Act. You may also complain to the Data Protection Board of India.
11. Changes
We will update this policy as the app evolves and post the new "last updated" date here. Material changes affecting signed-in users will be notified in-app.
Contact: NeuralPath Technologies · contact@neuralpath.app