SharePoster — Privacy Policy
Effective date: 30 April 2026 · Version 1.0
SharePoster is a mobile app that helps you create personalized Hindi shayari and festival
greeting templates. This page explains what we collect, why, and your rights.
1. Who we are
SharePoster is operated by Vaibhav (independent developer, India). Contact for any
privacy-related question, data-access request, or account-deletion request:
prompt.vaibhav@gmail.com.
2. What we collect
- Name and email — when you sign in with Google, we receive your
Google account name and email so we can create your SharePoster account and let you
save your work across devices.
- Phone number — only if you choose the phone-OTP sign-in fallback
instead of Google Sign-In. We use it to verify the device and to identify your
account.
- Photos you upload — when you personalize a template with your
photo, the image is uploaded to our server so we can composite it onto the
template and return the final image.
- Custom text you enter — your name, business name, custom message
or other text you type into a template, so we can render it on the image.
- Saved renders — copies of templates you save to your in-app
Library, stored against your account.
- Basic usage events — share-button taps and similar in-app
events, used only to count which templates are popular. No advertising
identifiers are linked to these events.
- Standard server logs — IP address, user-agent, request path,
timestamp. Kept short-term for security and debugging.
3. What we do not collect
- We do not access your phone contacts, SMS messages, call logs, files outside
the photos you explicitly pick, location, microphone, or camera (beyond the
image you choose).
- We do not sell your personal data to anyone.
- We do not use your photos or text to train AI models.
4. How we use your data
- To run the core app: personalize templates, save your library, return your
renders to your account.
- To verify your identity when you sign in.
- To improve the app: see which templates are popular and which categories need
more content.
- To respond to support questions you email us.
5. Third-party services we use
SharePoster uses a small number of third-party services. Each one only sees the data
it needs:
- Google Sign-In (Google LLC) — verifies your Google identity.
Subject to Google's privacy policy.
- SMS OTP provider (MSG91) — used only if you choose phone sign-in.
Receives your phone number to deliver the verification code.
- AI generation providers (OpenRouter / xAI Grok for shayari,
Black Forest Labs Flux for backgrounds) — when you tap "Generate", the prompt
text you enter is sent to these providers to produce the image or text. They do
not receive your name, email, or saved-library content.
- Google AdMob — the app initializes the AdMob SDK so we can
show occasional ads in future updates. AdMob may collect device-level identifiers
per Google's Ads policy.
No banner ad is wired into the UI in this initial release.
- Hosting (Hostinger VPS, India region) — our servers and
database run on a single managed VPS. Backups stay on the same server.
6. Where your data lives, and for how long
- All data is stored on our server in India.
- Data is encrypted in transit using HTTPS.
- We keep your account data until you delete the account. Saved renders stay
until you delete them from your Library or delete your account.
- Server logs are kept up to 30 days, then rotated out.
7. Your rights
You can:
- Access — ask us for a copy of the data linked to your account.
- Correct — ask us to fix something that is wrong.
- Delete — ask us to delete your account and all associated
data. We will action the request within 7 days.
- Withdraw consent — sign out and uninstall the app.
To exercise any of these rights, email
prompt.vaibhav@gmail.com from the
address linked to your account.
8. Children
SharePoster is intended for users aged 18 and above. We do not knowingly collect data
from children under 13. If you believe a child has used the app, email us and we
will delete the account.
9. Security
We follow standard practices: HTTPS for every request, password-less sign-in
(Google or OTP), short-lived JWT access tokens, and server-side validation for
every upload. No system is perfectly secure; if we ever detect a breach affecting
your data we will notify affected users by email.
10. Changes to this policy
If we change this policy in a way that affects how your data is handled, we will
update the "Effective date" at the top and post a notice in the app before the
change takes effect.
11. Compliance
We aim to comply with the Information Technology (Reasonable Security Practices and
Procedures and Sensitive Personal Data or Information) Rules, 2011, and India's
Digital Personal Data Protection Act, 2023. For users outside India, we honour
equivalent rights under your local law.