Privacy Policy
Last updated 14 August 2026
The short version. Your contacts are stored on your own device, not on our servers. We hold your email address and a hashed password so you can sign in. We do not sell your data, show you ads, or load third-party trackers on this website.
1. Who we are
GullyContacts is a contact management service operated by Gully System Private Limited, #257, 3rd Floor, Sri Nanjundeshwara Complex, Nagarbhavi 8th Block, Outer Ring Road, Bengaluru – 560072, Karnataka, India.
In this policy, “we” means Gully System Private Limited and “you” means the person using GullyContacts. For the purposes of the Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the personal data described below.
2. What we collect
| Data | When | Why |
|---|---|---|
| Email address | When you create an account | To identify your account and send verification and password reset codes |
| Password | When you create an account or reset it | Stored only as a salted hash. We never store or see your actual password |
| Verification codes | At signup and password reset | To confirm you control the email address. Short-lived |
| Session tokens | While signed in | To keep you signed in without re-entering your password |
| Server logs | On each request to our API | Diagnosing errors and abuse. May include IP address, timestamp and which endpoint was called |
We do not use advertising identifiers, we do not build behavioural profiles, and this website loads no third-party analytics, scripts or fonts.
3. Your contacts, and where they are held
This is the part most people care about, so we will be precise.
The contact records you create or import — names, phone numbers, email addresses, addresses, notes, tags and the relationship details you add — are stored locally on the device you are using. On the web that means your browser’s local storage; in the mobile and desktop apps it means a file in the application’s own storage.
When you are signed in, an encrypted copy is also stored on our servers so that the same contacts appear on every device you use. Records are encrypted on your device before they are sent. The key that decrypts them is held with your account, which is what allows a new device to sync as soon as you sign in, without a passphrase. We do not read your contacts, profile them, or use them to train anything.
Consequences worth understanding:
- Because we hold the key alongside the encrypted copy, we are not in a position to claim we could never decrypt your contacts. We commit to not doing so, and to disclosing any legally compelled access to the extent the law allows.
- Deleting a contact on one device deletes it everywhere, including the copy on our servers.
- Deleting your account erases the copy we hold. See section 8.
You can download everything we hold at any time from Account → Download my data, as a complete JSON file, or export to vCard or CSV.
4. Why we process it
We process the data in section 2 to provide the service you asked for: creating and securing your account, verifying your email address, letting you sign in, keeping the service running, and preventing abuse. Where the law requires a lawful basis, ours is the performance of our contract with you and our legitimate interest in operating a secure service.
5. Who else sees it
We do not sell your personal data, and we do not share it for anyone else’s marketing. We use a small number of service providers who process data strictly on our instructions:
| Provider | What they handle |
|---|---|
| DigitalOcean | Hosting for our servers and the database holding account records |
| Brevo (Sendinblue) | Sending verification and password reset emails. Receives your email address and the message content |
We may disclose data where we are legally required to, for example in response to a valid order from a court or authority of competent jurisdiction.
6. How long we keep it
- Account data — for as long as your account exists.
- Verification codes — minutes; they expire quickly by design.
- Server logs — a limited period for diagnostics, after which they are rotated out.
- Encrypted contact copies — for as long as your account exists, or until you delete the contact.
- Tax invoices — for the period Indian GST law requires the seller to retain them, which outlasts your account. See below.
You can delete your account yourself, from Account → Delete my account in the app; no email to us is needed. Deleting erases the encrypted contact copies we hold, your sign-in, your billing address and any subscription, and wipes the local copy on the device you do it from.
Two things survive, and we would rather name them than have you discover them. Tax invoices already issued to you are statutory records the seller must retain, and they carry your name and address by law (Rule 46 of the CGST Rules). And contacts held locally on your other devices stay there until you sign out or remove the app on each — we have no way to reach into a device you are holding.
7. Your rights
Subject to applicable law, you may ask us to:
- confirm what personal data of yours we hold, and get a copy of it;
- correct it if it is wrong or incomplete;
- delete your account and the data associated with it;
- withdraw consent where we relied on it, without affecting past processing.
Two of these need no request at all: Download my data gives you a complete copy on the spot, and Delete my account carries out the deletion immediately. For anything else, write to us using the details in section 11 and we will respond within the period the law allows. We may need to verify your identity first, which protects you from someone else making a request in your name.
8. Security
Traffic between your device and our servers is encrypted in transit with TLS. Passwords are stored as salted hashes, never in readable form. Our database requires encrypted connections and is not reachable from the public internet without authorisation.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data, we will notify you and the relevant authority as required by law. If you believe you have found a security problem, please write to us before disclosing it publicly — see Contact.
9. Children
GullyContacts is not directed at children, and we do not knowingly create accounts for anyone under 18 without verifiable parental consent as required under the Digital Personal Data Protection Act, 2023. If you believe a child has created an account, tell us and we will remove it.
10. Changes to this policy
If we change this policy we will update the date at the top of the page. Where a change materially affects how we handle your data — for example if contacts began to be stored on our servers — we will make that clear rather than relying on you noticing a new date.
11. Contact and grievances
For any question about this policy, or to exercise the rights in section 7, write to hello@gullycontacts.com or to Gully System Private Limited at the address in section 1.
If you are not satisfied with our response, you may escalate to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.