Privacy Policy

Last updated: 2026-08-13

UTILS-NITTISH ("we", "us") is operated by Nittish Baboria, an individual developer based in India. This policy explains what data UTILS-NITTISH collects, why, and the rights you have over it, in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and its 2025 Rules.

1. What this app does

UTILS-NITTISH is a set of utility tools: file storage backed by Google Drive and Cloudinary, a text-snippet keeper, and a QR code generator. Every tool has two modes:

  • Global mode — no account required. Anything you upload, save, or generate in Global mode is stored with no login and is visible to every visitor of the site, not just you. Treat Global mode as a public shared space, not private storage.
  • Personal mode — requires sign-in. Content you save in Personal mode is only shown to you (and site admins) within the app.

2. What we collect

Account holders (sign-up/sign-in):

  • Name, email address, and a hashed password (email/password sign-up).
  • Name, email, and profile picture (Google sign-in).
  • Optional profile fields you choose to fill in (university, degree, branch).
  • Basic technical data: IP address and request metadata, used for rate-limiting and abuse prevention.

Content you create (Global or Personal mode):

  • Files you upload (stored via Google Drive or Cloudinary), their titles, and folder names.
  • Text snippets you save.
  • QR code values you generate.
  • An optional per-file access password, if you set one (stored hashed, not in plain text).

We do not require or intentionally collect sensitive personal data (financial details, government ID numbers, health information). Do not upload such data yourself, especially not in Global mode — see Section 5.

3. How we use this data

  • To operate the tools: storing, organizing, and returning the files, text, and QR codes you create.
  • To authenticate you and keep your account secure (login, OTP email verification, password reset).
  • To send transactional emails: OTP codes and password-reset links.
  • To detect and prevent abuse, through IP-based rate limiting.
  • If you use the AI query tool, your query text is sent to Google's Gemini API to generate a response. Query results are cached briefly (60 seconds) on our server to avoid duplicate requests.

We do not sell personal data and do not use it for advertising.

4. Legal basis and consent

We process account-holder data on the basis of your consent, given when you create an account. Consent is specific, informed, and requires an affirmative action — we do not use pre-checked boxes. You may withdraw consent at any time by deleting your account (see Section 7).

Global-mode content requires no account and no consent step, by design — it is public contribution to a shared space, not personal-account data processing.

5. Global mode and storage-link limitations — read before uploading anything sensitive

Two things you should know plainly before using this app for anything you care about the privacy of:

  • Global uploads are public and permanent by default. There is currently no automatic expiry or cleanup of Global-mode files, text, or QR codes — they persist until manually deleted by an admin or the person who created the containing folder.
  • A per-file password only gates access through this app's own interface — it does not fully lock down the underlying file. Files are stored on Google Drive or Cloudinary, and the direct storage link returned by those services is not currently restricted by your in-app password. Anyone who obtains that direct link (e.g. if it were shared, logged, or guessed) could access the file without going through the app or the password. We are addressing this at the storage layer in a future update; until then, do not rely on the in-app password as strong protection for sensitive files, and do not upload anything you would not be comfortable being accessed via a leaked or guessed direct link.

6. Who we share data with

We use the following third-party service providers. Each only receives the data needed to perform its function:

  • Google — for Google sign-in (OAuth), Google Drive file storage (via a service account), and the Gemini AI query tool.
  • Cloudinary — for storing and serving files uploaded through the Cloudinary tool.
  • Neon (PostgreSQL) — our database host, where account and content metadata is stored.
  • Upstash (Redis) — used only for rate limiting; no content is stored there.
  • Gmail SMTP — used to send OTP, password-reset, and contact-form emails.
  • Vercel — hosting infrastructure for the application.

We do not sell or rent personal data to third parties.

7. Your rights and account deletion

Under the DPDP Act, you have the right to:

  • Access the personal data we hold about you.
  • Withdraw consent at any time.
  • Request correction or erasure of your data.
  • Delete your account and your Personal-mode content directly from your profile page, or by emailing us at the address below.

Deleting your account removes your account record and everything you saved in Personal mode. It does not remove content you contributed to Global mode, since Global content is a shared public space rather than data tied to your account — if you need a specific Global item removed, contact us and we will remove it manually.

8. Data retention

  • Account data is retained until you delete your account.
  • Personal-mode content is retained while your account exists, and deleted with it.
  • Global-mode content has no automatic expiry (see Section 5).
  • Signup OTP codes and password-reset tokens expire and are purged automatically within minutes.

9. Cookies

We only use functional cookies: a session cookie to keep you signed in and a CSRF-protection cookie for authentication. We do not use advertising, tracking, or analytics cookies. A small amount of navigation-usage data is kept locally in your browser to speed up the app — it is never sent to our servers or any third party.

10. Security

Passwords are hashed (bcrypt) and never stored in plain text. Per-file access passwords are also hashed. We use rate limiting to reduce automated abuse of authentication and upload endpoints. See Section 5 for a specific, current limitation around direct storage links. No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable technical measures to protect your data as required under the DPDP Rules.

11. Children's data

UTILS-NITTISH is not directed at children and is not knowingly used to collect data from children.

12. Changes to this policy

We may update this policy as the service evolves. Material changes will be reflected by updating the date at the top of this page.

13. Contact us / grievance officer

For any privacy questions, data access/deletion requests, or grievances regarding processing of your personal data, contact:

Nittish Baboria nittishbaboria123@gmail.com