AGAMA Privacy Policy
How AGAMA protects your local-first practice and explains every optional connection.
This policy describes AGAMA's local records, optional account and backup features, service providers and privacy choices in plain language.
Overview
Blue Sparrow is a solo developer based in India and operates AGAMA, a Jain reading, spiritual-practice and mindful app-blocking companion. This policy explains what information the app handles, why it is needed, where it goes and the choices available to you. AGAMA is designed around data minimisation, purpose limitation, transparency and the rights provided by the EU General Data Protection Regulation and other applicable privacy laws.
AGAMA does not use a Blue Sparrow-operated server to synchronise your prayer, meditation, japa, favourite, note, blocked-app or unlock-history database. That working database stays on your device unless you deliberately use the optional Google Drive backup described below.
Data we handle
AGAMA may handle the following categories:
- Practice records that you create, including prayer completion, meditation and japa sessions, goals, streaks, favourites and notes attached to passages.
- App-blocker records on Android, including selected application names and package identifiers, unlock times, durations and any intention you choose. Usage access lets AGAMA detect a selected app; overlay access lets it present the mindful pause.
- Preferences such as language, theme, reminder times, notification settings, sound choices, onboarding goals and strict-mode choices.
- Optional account information from Google and Firebase Authentication, including an account identifier, email address, display name and profile image URL.
- Limited Firebase profile and subscription records for signed-in users, including account timestamps, entitlement state, product identifiers and expiry information.
- Purchase and entitlement information handled by Google Play and RevenueCat, such as product, transaction, renewal and subscription status. Blue Sparrow does not receive your full payment-card details.
- Information you deliberately submit through support or feedback, including reply email, optional name and subject, message, app version, platform and locale. Extra diagnostics are included only when you select that option.
- Technical security information used by Firebase App Check and Google Play Integrity to verify that requests come from a genuine installation.
AGAMA does not need contacts, SMS content, call history, precise location, microphone recordings, camera media or browsing history. It removes Android advertising-ID permission and does not create a cross-app advertising profile.
Religious practice, reflections and app-use choices can be sensitive. They remain in the local database and optional encrypted backup rather than being added to the Firebase profile.
How we use data
Information is used only as reasonably necessary to:
- Provide passages, saved items, notes, practice tracking, statistics, reminders, widgets, app pauses and user-selected backups.
- Authenticate an optional account and keep premium access associated with the correct user.
- Process purchases, restore entitlements and prevent subscription abuse.
- Receive and answer a support or feedback request that you choose to send.
- Protect AGAMA and connected services, diagnose a request you explicitly accompany with diagnostics and maintain reliability.
- Meet applicable record-keeping, privacy, consumer-protection and security obligations.
AGAMA does not sell or rent personal information. It does not use personal information for targeted advertising. Firebase Analytics and Firebase Crashlytics components are included in the application. Depending on the release configuration and provider defaults, they may process limited app-interaction, device, performance or crash information. AGAMA does not intentionally attach practice notes, selected-app lists, unlock intentions or passage content to those services. Blue Sparrow is reviewing the production collection state and will keep this disclosure and any required controls current.
Cloud and backups
Guest use does not upload your practice database. If you sign in, Firebase receives the optional account and limited profile or entitlement information described above. This is separate from your local practice records.
If you request Google Drive backup, AGAMA exports supported local records, encrypts the backup on your device using AES-256-GCM, and uploads the encrypted archive to AGAMA's hidden app-data folder in your own Google Drive account. AGAMA requests only the Drive app-data scope, not general access to your visible Drive files. Automatic backup is opt-in and associated with the signed-in user. AGAMA is configured to retain up to five of its most recent backup archives by removing older AGAMA archives on a best-effort basis.
Google controls the physical storage and regional handling of your Drive account. Your account settings and Google's terms therefore govern that copy. Signing out disables AGAMA's user-scoped automatic-backup setting on the device but does not itself erase archives already held in Drive. You can manage them through the app's backup controls or your Google account.
Retention
Local information remains until you delete it with app controls, clear app storage or uninstall the app. Uninstall behaviour can vary where an operating-system backup is enabled.
Google Drive archives remain until removed by you, by AGAMA's best-effort backup rotation, or under Google's retention rules. Firebase account and entitlement records are kept while the account or subscription relationship is active and for a limited period afterwards where needed for security, purchase reconciliation or applicable obligations. Support messages and delivery logs are kept only for support, abuse prevention and operational record needs, then deleted or de-identified according to the relevant retention process.
The in-app Delete all data action clears supported information from that device, resets device preferences and signs out. It does not delete Firebase Authentication, the Firestore profile, RevenueCat records, Google Play purchase records, support messages or existing Drive archives. Contact [email protected] for an end-to-end account-data request, and use Google Play, Google Drive or RevenueCat-facing controls where those providers require direct action.
Security
AGAMA uses proportionate safeguards including platform security, HTTPS for network requests, Firebase App Check, scoped Drive permission, encrypted backup archives and access rules for signed-in Firebase records. Access within Blue Sparrow is limited to the solo operator and service providers that need it for their assigned purpose.
No device, transmission or connected service can be guaranteed completely secure. Keep your device lock, Google account and purchase account protected, install trusted updates and avoid including unnecessary sensitive information in a support message.
Your rights
Depending on where you live and subject to applicable exceptions, you may have rights to know or access personal information, correct it, obtain a portable copy, delete it, restrict or object to processing, and withdraw consent where consent is the basis. You may also have a right to complain to your local data-protection authority. These protections include, where applicable, the EU GDPR and EEA rules, UK GDPR, India's Digital Personal Data Protection framework, California and other US state privacy laws, Brazil's LGPD, Canada's privacy laws, and comparable laws in other regions.
Most practice information can be viewed, changed or removed locally. You can disable reminders, revoke Android usage or overlay access, stop using app blocking, sign out, disable backup and clear app data through app or device settings. Store subscriptions must be managed through Google Play.
To exercise a privacy right, email [email protected] with the app name and enough detail to identify the relevant account or request. Blue Sparrow may ask for proportionate verification and will respond within the period required where you live. There is no charge for an ordinary request, although clearly excessive or repeated requests may be handled as permitted by applicable law.
Children
AGAMA is intended for a general audience interested in personal spiritual practice and is not designed to collect children's information. A parent or guardian should supervise use by anyone who cannot validly make their own privacy choices. Do not create an account, enable cloud features or submit support information for a child unless the responsible adult has a valid basis and provides any required permission. Contact [email protected] if you believe a child's personal information has been provided inappropriately.
International transfers
The main practice database stays on your device. Optional Google, Firebase, RevenueCat, Google Play and support connections may process limited information outside your country or region. For transfers that require safeguards, Blue Sparrow and relevant providers rely on appropriate contractual, adequacy or other lawful mechanisms and apply data-minimisation and security measures.
Blue Sparrow does not claim that every item of AGAMA information remains exclusively in the European Union. EU users receive the protections required by the EU GDPR, while provider-controlled account, purchase, security and backup information follows the provider's disclosed infrastructure and transfer safeguards.
Changes
This policy may change when AGAMA, its providers or applicable requirements change. Material updates will be presented in the app or on the website where appropriate, and the updated date will be revised. Earlier processing remains governed by the version applicable at that time unless a change must apply sooner for security or legal reasons.
Contact
Blue Sparrow is the developer and privacy contact for AGAMA. For privacy questions, rights requests or account-data deletion, email [email protected]. For general help, email [email protected]. Product and policy information is available at https://bluesparrow.dev.