Privacy Policy
How Bargad handles your family’s information, and the choices you have.
Last updated: 24 July 2026
Who we are
Bargad (“Bargad”, “we”, “us”) is a private app for families to keep their plans, memories, documents, and everyday household life in one calm, shared place. This policy explains what information Bargad collects, how we use and protect it, who we share it with, and the choices you have. It applies to the Bargad mobile app and the Bargad website at bargad.app. You can reach us at [email protected].
Our privacy promises
- No advertising. Bargad contains no ads and no advertising SDKs.
- No behavioural or marketing analytics. Bargad does not run behavioural or marketing analytics, advertising tracking, or session replay. Optional error monitoring is disclosed below.
- We don’t sell your data and we don’t share it for advertising.
- Data minimisation. We collect what the features you use need, and no more.
Information we collect
Account and profile
You sign in to Bargad with Google. During sign-in we receive your Google account identifier, your name, your profile picture, and, when Google supplies it in the signed identity token, your email address. We store those details to recognise your account and deliver requested service messages. The email address is not exposed in ordinary household or person responses. It is deliberately available to the allowlisted operator/support console for owner-contact lookup. Adults can add other family members — including managed profiles for children (see Children and families) — with details such as a display name, birth date, and, if you choose, dietary or allergy notes.
Content you create
Bargad stores the content you and your family add. Depending on which features you use, this can include family-tree records and stories; notes; trips; messages and chat; calendar events; photos, documents, and receipts; videos and voice or sound recordings; shared expenses and money you track; and Family Vault entries for household continuity. Family-tree facts can include religious information, nationality, and other biographical details that you choose to record. Access follows each feature’s permissions. Some records are more narrowly scoped, while selected Vault records can be shared deliberately through limited, revocable, read-only links.
Expense capture stores the raw bank or UPI SMS text you choose to paste or share so Bargad can extract a draft expense and retain its source. The current Play release does not request permission to read your SMS inbox. The optional household contacts directory stores the names, roles, organisations, phone numbers, email addresses, and notes you enter for people such as an accountant, lawyer, banker, or nominee. Bargad does not read your device address book.
Search, activity, and recommendations
When you use discovery search, Bargad stores a redacted search query log tied to your account and family circle. The log can include the redacted query, extracted topics, the model used when applicable, the number of results, and the time of the request. If redaction is unavailable, Bargad stores a placeholder instead of the original query. Bargad also stores feature interactions, feedback, and other actions needed to provide the features you use and to personalise the results and recommendations you request. We do not use this information for advertising or behavioural marketing.
Google Calendar connection (optional)
Google sign-in and a Google Calendar connection are separate choices. If you choose to connect a calendar, Bargad stores an account label and encrypted OAuth credentials that grant read-only access to Google Calendar events. A successful connection does not mean imports are running. When the separately gated import service is enabled and runs, Bargad copies read-only provider events into your circle, including their title, times and all-day state, location, description, and provider identifiers. Those copies are ordinary circle calendar records, not Family Vault field-encrypted records. Disconnecting removes the connection and the provider events imported through it. Calendar connection and import availability depends on how a Bargad installation is configured. A saved connection by itself does not show that imports are running.
Payments
If you subscribe to a paid plan, payments are processed by Razorpay. Your card, UPI, or other payment details are handled by Razorpay and are never stored by Bargad. Bargad keeps only your subscription reference and plan status (for example, active or expired) so we know what your household is entitled to.
Health and fitness (optional)
If you choose to use fitness features, the app can read health and activity data from Apple Health or Android Health Connect — for example steps, workouts, sleep, or weight — only when you explicitly grant permission and only for the categories you allow. This data is used to show your own trends and goals. Children’s health and behavioural data is never used for profiling and never sent to any AI provider.
Technical and security data
To keep your account secure we store a hashed sign-in token for each active session (not the token itself), along with the device type and expiry. If you opt in to device push, we also store the device push token, platform, and last-seen time as a delivery address bound to the human session that registered it. Expiry or revocation of that session makes the token ineligible for delivery. We do not store your IP address alongside your session. Our servers keep operational logs to run and troubleshoot the service.
How we use your information
- To provide Bargad and keep your family’s content available.
- To keep your account and data secure and prevent abuse.
- To process your subscription and manage your plan.
- To send notifications and essential service messages you’ve asked for, when the relevant delivery provider is configured.
- To provide and personalise the searches, results, and recommendations you request.
- To power the optional AI features described below.
AI features and de-identification
Some optional features use artificial intelligence provided by Anthropic (Claude) — for example reading a receipt or invitation you select. We’ve built safeguards around this:
- De-identification before sending. Before any text is sent to the AI provider, personal identifiers — names, emails, phone numbers, and IDs such as card, UPI, PAN, or Aadhaar numbers — are automatically detected and replaced with placeholders. If that removal step cannot run for any reason, the request is cancelled rather than sent.
- Selected images and documents. Only in a reading flow you consent to, the selected image or document itself — including a selected PDF — is sent to Anthropic to be read. The file itself is not de-identified; text extracted or reused by Bargad follows the text safeguards above.
- Children are excluded. Children are kept out of Bargad’s AI features, and children’s identifying and health data is never sent to the AI provider — this is enforced in the software itself, not left to judgement.
- Minimal logging. We store metadata about each AI request (which feature, which model, token counts, and cost) for operating and auditing the service — not your content or the AI’s response.
Children and families
Bargad is designed for whole families, including children. Children do not create their own accounts and do not sign in with Google. Instead, a parent or guardian creates and manages a child’s profile within the family circle and controls what the child can see and do. Sensitive details about a child (such as birth year and dietary or allergy notes) are withheld from general members and shown according to the feature’s guardian and curator permissions.
For children we apply extra protections: their information is never used for behavioural profiling, their health and identifying information is never sent to any AI provider, and the content a child can see is limited to items a guardian has approved. A parent or guardian can review information exposed by current features, use available feature exports, or request correction or deletion of a child’s information by contacting us. We follow the principles of Google Play’s Families policy and India’s Digital Personal Data Protection Act, including its protections for children.
How your information is shared
We do not sell your information. When you deliberately share a supported record or answer a request, the recipient receives the information that action describes under that feature’s access rules. We also send information to the service providers we rely on to run Bargad, only as needed to provide the service:
- Hostinger (Mumbai, India) — hosts Bargad’s API and primary database on a self-managed virtual server.
- Google — sign-in. We receive your Google account identifier, name, profile picture, and, when supplied in the signed identity token, email address. If you separately connect Google Calendar, Bargad stores an account label and encrypted OAuth credentials and may request the event fields described above when the import service runs.
- Amazon Web Services S3 (Mumbai, India) — primary media storage for photos, documents, and receipts. Family Vault documents are encrypted by Bargad itself before they are saved, so the saved Vault file is unreadable to the storage provider. An upload passes through a temporary staging area on the way in, which Bargad removes once the document is saved.
- Cloudflare — serves the website and secures the connection to our servers. Cloudflare R2 stores off-box database backups. Primary media remains in AWS S3.
- Anthropic — powers optional AI features. It receives de-identified text and, only in a consented reading flow, the selected image or document itself, including a selected PDF. Children’s data is excluded as described above.
- Razorpay — processes subscription payments; your payment details stay with Razorpay.
- Resend (optional) — when transactional email is configured, it receives the destination email address and the subject and message needed to deliver the requested service email.
- Expo (optional) — when device push is configured, it receives the destination device token and the title, body, and routing data needed to deliver an eligible service notification.
- Sentry (optional) — when browser or server error reporting is configured, the reconstructed event payload is limited to a generic error message and level, event identifiers and timestamps, fixed platform, surface, and deployment-environment labels, plus a server-generated request reference and finite HTTP method for API failures or a fixed error-boundary label for web failures. Bargad omits the original error message and stack, URL and path, query, headers, cookies, authorization value, request body, user/context data, breadcrumbs, browser history and referrer, and Next.js error digest from that event payload. Separately, like any network service, Sentry can still receive ordinary connection metadata such as source IP, networking headers, site origin, and transmission time. Browser error transport sends no referrer and explicitly omits browser credentials such as cookies and HTTP authentication. Performance tracing and session replay are disabled.
We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the service.
Where your data is stored and how it’s protected
Bargad’s API and primary database are self-hosted on a Hostinger server in Mumbai, India. Primary media is stored in AWS S3 in Mumbai, and database backups are stored off-box in Cloudflare R2. Connections to Bargad are encrypted in transit (HTTPS). Stored files are held in access-restricted storage with encryption at rest, and Family Vault documents are additionally encrypted by Bargad itself before they are saved — an upload passes through a temporary staging area at that provider first, which Bargad removes once the document is saved. Sign-in tokens are stored only in hashed form. No method of storage or transmission is ever completely secure, but we work to protect your information using appropriate technical and organisational measures.
How long we keep your data
- Your account and content are kept for as long as your account is active.
- Metadata about AI requests is stored for operating and auditing the service. We do not promise a fixed automatic removal period.
- Redacted search-query logs and interaction records are kept with your account until they are erased through the applicable account or data-rights process. We do not promise a fixed automatic removal period.
- Database backups rotate on an operational schedule; information removed from the primary service can remain in a backup until that backup ages out.
- Operational server logs are kept for running and troubleshooting the service. We do not promise a fixed automatic removal period.
Deleting your account and data
You can request account deletion at any time. A request or scheduled date is not confirmation that deletion has completed. See Delete your account and data for how to request it, what a completed request removes or anonymises, and what may be retained.
Encrypted circle archives fall under the same shared-family-history exception. A circle owner on a paid plan can make an archive: a stored, encrypted copy of that circle's shared photos, family-tree pictures and the files attached to notes shared with the whole circle, as they were on the day it was made. A member's private items and Family Vault documents are not included, and Bargad holds the key to the copy. An archive belongs to the circle rather than to any one member, so a completed deletion request does not remove content from an archive that already exists, and the circle owner can still download it. Only a circle owner can delete one of their circle's archives, which removes that archive in full.
Your rights and choices
Subject to applicable law, you can ask to access, correct, export, or delete your personal information, and a parent or guardian can exercise these rights on behalf of a child in their care. To make a request, or if you have a privacy concern or grievance, contact us at [email protected]. We’ll respond within the time required by applicable law.
Changes to this policy
We may update this policy from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, let you know in the app.
Contact us
Questions, requests, or grievances about privacy? Email us at [email protected].