Zivprime
  • Home
  • Support
  • Privacy Policy
  • Terms & Conditions
  • Refund Policy

Privacy Policy

App Name: Sanatan Bhakti  |  Parent Studio: Zivprime  |  Last Updated: August 26, 2026
The short version
  • We never sell your data. Not to advertisers, not to data brokers, not to anyone.
  • We don't collect your location, contacts, call logs, SMS, microphone, camera, or photo gallery.
  • Your payment details never reach us. Google and Razorpay handle those directly.
  • Your devotional preferences only pick your content. We never profile your religion, caste or community.
  • Delete everything, anytime — from Settings in the app, or by email. We verify it's you first.
  • 18 and over only. We don't knowingly collect data from anyone younger.
  • Complaints answered in 24 hours, resolved within 15 days.

This summary is here to help you, not to replace what follows. The full policy below is the part that legally applies.

Welcome to Sanatan Bhakti, developed by Zivprime ("we," "our," or "us"). We are committed to protecting your privacy and to being straightforward about exactly what we collect and why. This Privacy Policy explains how we collect, use, store, share, and safeguard your data when you use our mobile application, our websites, our payment flows, and our support services.

By installing, accessing, or using the Sanatan Bhakti application, you consent to the practices described in this policy. If you do not agree with any part of it, please do not use the application.

Where This Policy Applies

This Privacy Policy covers the Sanatan Bhakti mobile application, our main website zivprime.com, and our subscription checkout at bhakti.zivprime.com. It is the single authoritative version; any copy hosted elsewhere is for convenience only.

1. The Laws We Follow

We operate from India and design our practices to comply with:

  • the Digital Personal Data Protection Act, 2023 ("DPDP Act") — under which we act as a Data Fiduciary and you are a Data Principal;
  • the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
  • the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, so far as they apply to our grievance redressal obligations;
  • the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020;
  • the EU / UK General Data Protection Regulation (GDPR) for users in those territories; and
  • the California Consumer Privacy Act (CCPA/CPRA) for California residents.

2. Information We Collect

A. Information You Provide

  • Profile details: your name and age group, given voluntarily during onboarding, used to personalise daily quotes and spiritual targets.
  • Authentication data: your mobile number, verified by a one-time password (OTP) through Firebase Authentication. This is the only way to sign in — there is no email or social login — and it is also what we use to link and unlock your premium access where you subscribe on our website.
  • Support correspondence: anything you send us by email, including in a refund, deletion, or grievance request.

B. Usage and Preference Data

  • Devotional preferences: the goals you pick (for example Peace & Calm, Better Sleep, Spiritual Growth) and the categories you choose (Chants, Mantras, Bhajans, Sleep Sounds, Wallpapers), used to order your feed. See Section 3.
  • Engagement data: app settings, playback and caching activity, jaap counts, and daily progress used to calculate streaks and badges.

C. Technical Device Information

  • Device and diagnostic details: operating-system version, device model, screen and connection parameters, app version, language, and crash and performance logs — used to keep background playback and downloads working and to diagnose faults.

D. What We Do Not Collect

We do not collect, and the app does not ask for, any of the following:

  • your precise or GPS location;
  • your contacts, call logs, SMS messages, or call recordings;
  • microphone or camera input, or any voice recording;
  • your photo library contents, health data, or biometric data;
  • your card number, CVV, UPI PIN, bank credentials, or any other payment credential;
  • your email address — the app has no email or social login at all. You sign in with your mobile number and an OTP, and nothing ever asks you for an email. We only ever see one if you choose to write to us yourself.

We do not sell your personal data, and we do not share it with data brokers or advertising networks for the purpose of selling it. We have never done so.

3. Devotional Preferences and Religious Belief

We want to be explicit about this, because it matters and because most apps in our category say nothing about it.

Sanatan Bhakti is a devotional app, so the preferences you set (a chosen deity, a category of chant, a devotional goal) may reveal something about your religious beliefs. Under the GDPR this is a special category of personal data, and it is treated with particular care under Indian law too. Our position is:

  • we use these preferences for one purpose only — deciding what content to show you in the app;
  • we do not infer, derive, score, or profile your religious belief, caste, community, or affiliation from them;
  • we do not share them with advertisers, data brokers, or any third party for marketing, targeting, or audience building;
  • where the GDPR applies, we rely on your explicit consent, given when you choose these preferences during onboarding, and you may withdraw it at any time by changing or clearing your preferences or by deleting your account; and
  • these preferences are deleted together with your account, with no residual copy kept for analytics.

4. How We Use Your Information, and On What Basis

We process your data only for the purposes below. For users protected by the GDPR, the legal basis for each is shown in brackets.

  • Personalising your home feed with relevant tracks, sleep sounds, and wallpapers. [consent; explicit consent for devotional preferences]
  • Signing you in, securing your session, and keeping your premium access working across devices. [performance of a contract]
  • Taking payment, activating your subscription, and handling renewals, cancellations, and refunds. [performance of a contract]
  • Answering support tickets and resolving billing disputes and grievances. [performance of a contract; legal obligation]
  • Tracking streaks, jaap counts, and badges. [consent]
  • Diagnosing crashes, preventing fraud and abuse of trials or payment instruments, and keeping the service secure. [legitimate interests]
  • Meeting our tax, accounting, and other legal obligations. [legal obligation]

We do not use your personal data to train artificial-intelligence models. Our devotional content is created separately, as described in Section 10.

5. Third-Party Services and Data Sharing

We share data only with the processors listed below, only to the extent each needs it, and each handles it under its own privacy policy:

  • Firebase Authentication & Cloud Firestore (Google): verifies your identity, manages your session, and syncs your profile, preferences, and progress.
  • Firebase Cloud Functions (Google): runs our own server-side code for subscription activation, entitlement checks, and webhook handling.
  • Firebase App Check (Google): device-attestation signals used to confirm that requests come from a genuine, unmodified copy of our app, protecting your account and our servers from abuse.
  • Firebase Crashlytics & Analytics (Google): crash diagnostics, performance reports, and aggregate usage statistics.
  • Google Play Services — Phone Number Hint: when you restore a website purchase, Android shows you a chooser listing the mobile numbers already on your device so you do not have to type one. The app cannot read your SIM or your number unless you tap one and choose it; nothing is collected if you dismiss the chooser.
  • Meta / Facebook SDK (Meta Platforms, Inc.): measures app installs and campaign performance, and logs a small number of custom events. Meta receives device specifications, IP address, and your device Advertising ID (AAID/IDFA). You can reset or limit that identifier in your device privacy settings.
  • Google Play Billing (Google LLC): processes in-app purchases and manages subscriptions. Google handles the payment credentials directly; we never see them.
  • Razorpay (Razorpay Software Private Limited): processes subscription payments made inside the app by UPI or card and on our website, and manages recurring UPI AutoPay, card, and net-banking mandates. Your mobile number is shared with Razorpay so checkout can complete and the subscription can be linked to your account. Razorpay is PCI-DSS compliant and collects payment details directly under its own Privacy Policy.

Beyond these, we disclose personal data only where we are legally required to — in response to a valid order from a court, law-enforcement agency, or regulator — or where it is strictly necessary to establish, exercise, or defend a legal claim, or to prevent fraud or an imminent threat to someone's safety. If our business is ever sold or restructured, your data may transfer to the acquirer, who will remain bound by this policy; we will notify you before that happens.

6. Payments & Subscriptions

Premium can be purchased through Google Play Billing, or through Razorpay by UPI or card — inside the app or on our website. In every case, we never collect, see, or store your card number, CVV, bank credentials, UPI PIN, or any other payment credential. These are captured and processed entirely by the payment provider on their own secure infrastructure.

To activate and manage your premium access we store only:

  • Subscription status & plan: whether your subscription is active, in its introductory period, cancelled, or expired, and the next renewal date.
  • Transaction references: non-sensitive identifiers such as the Google Play Order ID or the Razorpay payment, subscription, and mandate IDs, with the amount and date — used for support, reconciliation, and refunds.
  • Mobile number (Razorpay purchases): the number linked to your account or entered at checkout, so we can unlock premium for it, restore it if you reinstall or change device, and contact you about your subscription.

We use this only to provide, activate, support, and manage your subscription and to meet our legal, tax, and anti-fraud obligations. We do not sell it and do not use it for advertising.

Communications about your subscription: for Razorpay purchases, your payment provider and/or we may send transactional messages by SMS, email, or WhatsApp — including the pre-debit notification required before each recurring charge, receipts, and renewal or failure notices. These are service messages tied to your subscription, not marketing, and they continue even if you opt out of marketing (see Section 8).

7. Cookies and Website Tracking

  • zivprime.com — our main website, including this page — sets no cookies and runs no analytics or advertising trackers of any kind. Nothing you do here is tracked or profiled.
  • bhakti.zivprime.com — our subscription checkout — runs the Meta Pixel so we can measure whether our advertising actually leads to purchases. It sets Meta's _fbp and _fbc cookies, records a page view, and on successful payment sends Meta a purchase event containing the amount and currency only. It does not send Meta your name, mobile number, email address, or devotional preferences. The checkout page also loads Razorpay's own checkout script, which may set cookies necessary to process your payment.

You can block or clear these cookies in your browser settings, or limit Meta's use of them through your Meta ad preferences. Blocking them does not prevent you from subscribing.

8. Marketing Communications and Opt-Out

If we send you promotional or devotional marketing messages, every one will carry a way to stop them, and you can opt out at any time by emailing support@zivprime.com with the word "UNSUBSCRIBE".

Opting out of marketing does not stop essential service messages — payment receipts, the pre-debit notification required before each renewal, security notices, refund updates, and changes to these policies. Those are part of providing the subscription and cannot be switched off while your subscription is active.

9. App Permissions and On-Device Storage

Below is the complete list of permissions the app declares, and what each is for. Several are granted automatically by Android; the rest are only ever requested when you use the feature that needs them, and you can decline or revoke any of them in your device settings.

  • INTERNET — to stream audio and load wallpapers from our servers.
  • WAKE_LOCK — to keep audio playing when the screen dims during meditation or sleep sessions.
  • FOREGROUND_SERVICE and FOREGROUND_SERVICE_MEDIA_PLAYBACK — to continue playback when the app is in the background and to show the playback notification with its play, pause, and skip controls.
  • POST_NOTIFICATIONS — to display that playback notification and any daily reminder you have chosen to enable. You can refuse this and the app still works.
  • SCHEDULE_EXACT_ALARM — to fire daily devotional reminders at the exact time you set.
  • READ_MEDIA_IMAGES, READ_MEDIA_VIDEO, READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE — to save a wallpaper or ringtone to your device when you ask us to, and to read it back so it can be applied. We do not scan, index, upload, or transmit your gallery, photos, or any other file on your device. These permissions are used only for the file the app itself creates at your request, and older permissions in this group apply only to older Android versions.

On-device caching: audio you play (sleep sounds, chants, ringtones) is cached in the app's private storage so it plays back smoothly and uses less data. This cache stays on your device, is never uploaded to us, and is removed when you clear the app's storage or uninstall it.

10. AI-Generated Original Content

All audio tracks, wallpapers, images, and visual assets in Sanatan Bhakti are our own original works, created using generative AI (artificial intelligence) technologies for devotional and entertainment purposes. They do not reproduce any third-party copyrighted recordings or artwork, and all such assets remain the exclusive intellectual property of Zivprime. Users may not copy, redistribute, or commercially exploit them.

Your personal data is not involved in creating this content. We do not use your data, preferences, or activity to train, fine-tune, or prompt any AI model.

11. How Long We Keep Your Data

We keep personal data only as long as we need it. Specifically:

  • Account, profile, preferences, streaks and progress — for as long as your account is active. Deleted when you delete your account.
  • Inactive accounts — if you have not opened the app for 24 consecutive months and hold no active subscription, we may delete your account and its data.
  • Crash and diagnostic logs — retained by Firebase Crashlytics for up to 90 days, then deleted automatically.
  • Aggregate analytics — retained for up to 14 months in identifiable form, after which only anonymised, non-identifying counts remain. Anonymised data is not personal data and may be kept indefinitely.
  • Financial and transaction records — invoices, payment references, and subscription history are retained by us and by our payment providers (Google Play and Razorpay, who are the record-keepers for the payments they process) for 8 years, as required by Section 128 of the Companies Act 2013 and applicable tax law. This applies even after you delete your account, and it is a legal obligation we cannot waive.
  • Support, grievance, and refund correspondence — retained for 3 years from resolution, so we can evidence how a dispute was handled.

12. Account Deletion

You own your data and can have it erased. We comply with the DPDP Act, the GDPR, and Google Play's data-deletion requirements:

  • In the app: go to Settings and tap Delete Account. This permanently erases your authentication record, profile, preferences, streaks, and related database records.
  • By email: if you have uninstalled the app, email support@zivprime.com with the subject line "Account Deletion Request", quoting the mobile number registered on your account so we can verify it is really you. Your account is identified by that number — we hold no email address for you, so the number is what we match against. We verify identity before deleting anything — this protects you from someone else deleting your account. We complete verified requests within 7 business days, and in all cases within 30 days.
  • What survives deletion: only the financial and fraud records described in Section 11, which we are legally required or permitted to keep. Everything else goes.
  • Deletion is irreversible. Your progress, streaks, and history cannot be recovered afterwards.
⚠️ Deleting your account does not cancel your subscription

Account deletion removes your data from our systems, but it does not automatically stop an active auto-renewing subscription — the payment mandate sits with Google Play or with your bank/UPI app, not with us. Please cancel your subscription first, then delete your account, otherwise you may continue to be charged ₹399 per month. See How to Cancel for the exact steps.

Already deleted your account and still being charged? You can stop it yourself: open your UPI app (GPay / PhonePe / Paytm) → AutoPay or Mandates → select Sanatan Bhakti → Cancel; or cancel in the Play Store for Google Play purchases. That mandate belongs to your bank, so it works whether or not you still have an account with us. Full steps are on our Delete Account page. Because this is shown to you before you delete and you can stop the charges yourself at any time, charges taken after deletion are not refundable.

13. Where Your Data Is Processed

Our own databases are hosted on Google Cloud infrastructure. Some of our processors — Google and Meta in particular — operate globally, so your data may be processed on servers outside your country, including in the United States and the European Union.

Where data leaves the EU or UK, our processors rely on the European Commission's Standard Contractual Clauses or an equivalent approved transfer mechanism. Under the DPDP Act, we do not transfer personal data to any territory restricted by the Central Government. Wherever it is processed, your data remains protected by this policy and by our contracts with each processor.

14. Data Security

We use technical and organisational measures appropriate to the risk. Your data is encrypted in transit (HTTPS/TLS) and at rest (within Firestore). Access to production data is restricted to the operator's own administrator account and used only where needed for maintenance and support — we are a small team and no third party is given standing access to your records. Firebase App Check helps ensure requests reach our servers only from a genuine copy of the app, and payment credentials never touch our systems at all.

No system can be guaranteed completely secure, and we cannot promise absolute security. Please help protect your account by keeping your device locked and your login OTPs private, and by telling us immediately if you suspect unauthorised access.

15. If There Is a Data Breach

If a personal data breach occurs that affects you, we will:

  • notify the Data Protection Board of India and every affected user without delay, as required by Section 8(6) of the DPDP Act;
  • notify affected users within 72 hours of becoming aware of the breach wherever it is practicable to do so, by email, SMS, or in-app notice — and if the full facts are not yet established, tell you what we know at that point and follow up;
  • where the GDPR applies, notify the relevant supervisory authority within 72 hours under Article 33; and
  • tell you plainly what happened, what data was involved, what we have done about it, and what you should do to protect yourself.

Nothing in this section limits any shorter notification period that the law requires of us.

16. Age Requirement

You must be 18 or older

Sanatan Bhakti is intended only for users aged 18 and above. Under Section 9 of the DPDP Act 2023, anyone under 18 is a child whose data may be processed only with verifiable parental consent, and under the Indian Contract Act 1872 a minor cannot enter into a binding subscription. We therefore do not knowingly collect personal data from anyone under 18, and we do not permit under-18s to hold an account or subscribe.

We do not carry out any tracking, behavioural monitoring, or targeted advertising directed at children.

If you believe a person under 18 has given us personal data, email support@zivprime.com and we will delete the account and its data promptly. Where a minor uses the app on a shared family device, a parent or guardian is responsible for supervising that use.

17. Your Rights

Whatever your location, you may exercise all of the following by emailing support@zivprime.com. We do not charge for this, and we will never treat you differently for asking.

  • Access — obtain a copy of the personal data we hold about you and a summary of how it is processed.
  • Correction — have inaccurate or incomplete data corrected or completed.
  • Erasure — have your data deleted, as described in Section 12.
  • Withdraw consent — withdraw any consent you have given, at any time and as easily as you gave it. This does not affect processing already carried out.
  • Portability (GDPR) — receive your data in a structured, machine-readable format.
  • Object or restrict (GDPR) — object to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved.
  • Nominate (DPDP Act) — nominate a person to exercise your rights on your behalf in the event of your death or incapacity.
  • Do not sell / do not share (CCPA) — we do not sell or share personal information as those terms are defined under the CCPA, so there is nothing to opt out of; you retain the right to know, delete, correct, and to be free from discrimination for exercising these rights.

We respond to rights requests within 30 days. We may ask you to verify your identity first, and we may decline a request only where the law permits — for example where retaining the data is legally required, as with the financial records in Section 11. If we decline, we will tell you why.

18. Changes to This Policy

We may update this policy. Changes are posted on this page with a revised "Last Updated" date. Where a change materially affects your rights or how we use your data, we will give you notice in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.

19. Grievance Officer & Contact

For any privacy concern, data request, or complaint, contact our Grievance Officer, appointed under the DPDP Act 2023 and the IT Rules 2021:

Name: Harshal Rathod

Designation: Grievance Officer & Data Protection Contact, Zivprime

📧 Email: support@zivprime.com

🏢 Address:

Rathod Niwas, Ramnagar,
Karanja Lad, Maharashtra 444105, India

Our response times: we acknowledge every complaint within 24 hours of receiving it, and resolve it within 15 days, in line with the IT Rules 2021. Complex matters that need longer will be explained to you in writing before that deadline passes.

If you are still not satisfied: you may complain to the Data Protection Board of India under the DPDP Act 2023. Users in the EU or UK may complain to their local supervisory authority. Nothing in this policy limits your right to do so, or your rights under the Consumer Protection Act 2019.

Zivprime

Zivprime is a mobile app development studio committed to building premium mobile experiences and high-quality utility apps.

Support & Info

  • App Support & Help Center
  • Privacy Policy
  • Terms & Conditions
  • Refund Policy
  • Account Deletion

Our Focus

  • Sanatan Bhakti App
  • Subscriptions & Billing Help
  • Generative Design Graphics

© 2026 Zivprime. All Rights Reserved. Hosted at zivprime.com

Registered Office: Rathod Niwas, Ramnagar, Karanja Lad, Maharashtra 444105, India

Support contact: support@zivprime.com