Effective date: 12 August 2026 ·
Operated by: iSHARATH Labs, India ·
Contact: iSHARATHLabs@outlook.com
The short version: Your vault is yours alone. No other user, including organisations whose content you track, can see your profile, stories, roles, notes, or stats. We do not sell your data. We do not share it with advertisers. We keep only the account identity needed to run and support the service. Your work history exists only to serve you.
1. Who We Are
getBylines is a mobile application developed and operated by iSHARATH Labs, a technology company based in India ("we", "us", "our"). getBylines allows media professionals, student media makers, and content creators worldwide to build a private, verified portfolio of their published work and, where official integrations support it, track public performance metrics.
This Privacy Policy applies to all users of the getBylines Android application globally. By creating an account and using getBylines, you acknowledge that you have read, understood, and consented to the practices described in this Policy.
iSHARATH Labs is the data controller and data fiduciary for all personal data processed through getBylines.
2. Applicable Law
getBylines is operated from India and is primarily governed by Indian data protection law, including the Digital Personal Data Protection Act 2023 (DPDPA) and the Information Technology Act 2000. Because getBylines is available to users worldwide, we have designed our data practices to align with major international privacy frameworks:
India: Digital Personal Data Protection Act 2023 (DPDPA)
European Union / EEA: General Data Protection Regulation (GDPR)
United Kingdom: UK GDPR and the Data Protection Act 2018
United States: California Consumer Privacy Act (CCPA) where applicable
All other jurisdictions: We apply the standards of the DPDPA as our baseline, which is consistent with internationally recognised privacy principles.
Note for EU/EEA and UK users: By using getBylines, your personal data is transferred to and processed in India. We rely on your explicit consent, provided at account creation, as the legal basis for this transfer. India's DPDPA provides data protection standards we believe are broadly consistent with international norms, though India has not yet received an EU adequacy decision.
3. What Data We Collect
We collect only what is necessary to provide the service.
Account authentication: Your email address and display name are held by Google Firebase Authentication to manage your login. We also keep a minimal private account record in Firestore containing your user ID, email address, lowercase email address, and account timestamps so support, account deletion, and admin tools can resolve your account. Your email address is not visible to other users.
Story data: URLs of published work you add to your vault, along with platform, title, publisher, public preview metadata, and, where an official integration supports it, public engagement metrics (currently YouTube in Phase 01). Metadata from ordinary web links, Reddit, Quora, LinkedIn, Instagram, Facebook, X, Medium, and publisher sites is treated as public link-preview metadata unless a separate official metrics integration is enabled.
Role and notes: Optional metadata you choose to add to individual stories, such as your role on a piece or personal notes. This data is never used for any purpose other than displaying it back to you.
Device identifier: A unique identifier for your registered device, used solely to enforce the single-device login policy that protects your account from unauthorised access.
Account activity timestamps: The time of your last sync and last login, used to maintain account integrity and support you if you contact us.
Subscription status: Your current plan tier. No payment information is ever seen or stored by getBylines. All billing is handled exclusively by Google Play.
Optional crash diagnostics: If you explicitly enable Share crash reports, Firebase Crashlytics receives crash stack traces, relevant application state, app version, Android version, device model, and installation identifiers. These reports do not include your email address, profile, portfolio links, roles, notes, or story data.
4. What We Do Not Collect
We do not store your email address in any public, cross-user, story, Hive, or analytics data. It appears only in Firebase Authentication and the minimal private account record needed to operate and support your account.
We do not collect your precise or approximate location.
We do not collect your contacts, call logs, or messages.
We do not collect biometric data of any kind.
We do not collect your browsing history outside the app.
We do not access files on your device beyond what is required to generate and share PDF reports at your explicit instruction.
We do not use advertising SDKs, tracking pixels, or third-party behavioural analytics. Optional Firebase Crashlytics reporting is used only for app stability diagnostics after you explicitly enable it.
5. How We Use Your Data
Your data is used exclusively to:
Authenticate your identity and maintain your session securely.
Fetch, display, and update public metadata and supported official engagement metrics for stories in your vault.
Generate PDF audit reports at your explicit request.
Sync your vault when you authorise a device transfer.
Communicate with you about your account, subscription, and service updates, and with your separate consent, product announcements.
Resolve your subscription tier and enforce the features available under that tier.
Diagnose crashes and application-not-responding errors if you explicitly enable Share crash reports.
AI-assisted portfolio insights are planned for Phase 02 and are not active in Phase 01. Before enabling that processing, we will update this Policy and provide any disclosure or consent required at that time.
We do not use your data for advertising, profiling, behavioural analysis, or any purpose beyond operating the getBylines service as described above.
6. The Walled Vault
getBylines is architected so that no user can ever access another user's data. This is enforced at the database security rules level, not merely by policy.
No cross-user visibility: No other user of getBylines can view your profile, vault, stories, roles, notes, or stats under any circumstances.
No organisational surveillance: If your organisation connects their social media accounts to getBylines enterprise features, that connection enables verified stat fetching only. It grants no visibility into any individual member's vault, contribution notes, roles, or usage data.
Export is your choice: The only mechanism by which your data can leave your vault is a PDF report you explicitly generate and choose to share. You decide the contents, the recipient, and the timing. getBylines never automatically shares your data with your organisation or any third party.
The Hive is anonymous: getBylines maintains a shared cache of public link metadata and supported official engagement stats (the "Hive") to reduce redundant API calls. The Hive stores only public URL-level data. It contains no user identity, role, note, or attribution data of any kind. No user can query the Hive to determine what another user has saved.
7. Legal Basis for Processing (GDPR / UK GDPR)
For users in the EU, EEA, and UK, we process your personal data under the following legal bases:
Contract performance: Processing your device identifier, vault data, and subscription status is necessary to provide the getBylines service you have signed up for.
Consent: Sending product announcements is based on your explicit consent given at account creation. You may withdraw this consent at any time from your Profile screen without affecting your access to the service.
Consent: Processing optional crash diagnostics is based on the separate Share crash reports setting in your Profile screen. It is disabled by default and can be withdrawn at any time.
Legitimate interests: Maintaining security timestamps is necessary for our legitimate interest in protecting our systems and users from unauthorised access.
8. Data Sharing and Third Parties
We do not sell, rent, or trade your personal data to any third party under any circumstances.
We share limited data only with the following service providers to operate the application:
Google Firebase and Google Cloud (Authentication, Firestore, Cloud Functions, Secret Manager): Our backend infrastructure. Google's data processing terms apply. Firebase infrastructure includes Standard Contractual Clauses for international data transfers.
Firebase Crashlytics (Google LLC): Optional crash and application-not-responding diagnostics. Collection is disabled by default. We do not attach user IDs, email addresses, portfolio URLs, or custom behavioural logs to reports.
Google Vertex AI / Gemini on Vertex AI (Phase 02): This integration is not active in Phase 01. If enabled in Phase 02, its data handling, disclosures, and consent flow will be documented before users can access it.
YouTube Data API (Google LLC): Used to fetch public engagement metrics for YouTube URLs you add to your vault. Only the video URL and required API request data are sent. No getBylines personal profile data is transmitted.
Public link metadata fetches: Used to fetch public title, author, image, date, source, and description metadata for URLs you intentionally add, including ordinary web pages, Reddit, Quora, LinkedIn, Instagram, Facebook, X, Medium, and publisher sites. getBylines does not use your browser cookies, private sessions, or hidden page access.
Google Play Billing: Used to verify your subscription status. getBylines never receives or stores payment information.
9. Government and Legal Requests
We will not voluntarily disclose your data to any government authority or law enforcement agency without a valid court order, judicial warrant, or legal compulsion under applicable law.
When we receive such a request, we will evaluate its legal validity before taking any action. We will challenge requests we believe to be overbroad, unlawful, or inconsistent with applicable privacy law. We will notify you of any request for your data to the maximum extent that applicable law permits. If we are legally prohibited from notifying you at the time of the request, we will do so as soon as that prohibition is lifted.
We publish an annual transparency report disclosing the number of government requests received and the number complied with.
10. International Data Transfers
getBylines is operated from India. If you are accessing the service from outside India, your data will be transferred to and processed in India and on Google's global infrastructure.
For EU/EEA and UK users, we rely on your explicit consent provided during account creation as the transfer mechanism. You may withdraw this consent by deleting your account.
11. Data Retention
Account data is retained for as long as your account is active.
Stories you delete are removed from our servers within 28 days.
If you delete your account, all your data including your vault, profile, device records, and token history is permanently deleted within 28 days. This is irreversible.
Hive data (anonymous public metadata and supported-stats cache) is not tied to your identity and is not deleted when you delete your account.
AI usage logs store operational metadata such as provider, model, mode, selected platform/range, story count, context size, credit cost, and timestamp. They do not store your raw question or model answer in Firestore usage logs.
When enabled, Firebase Crashlytics retains crash stack traces and associated installation identifiers for 90 days before beginning removal from live and backup systems.
12. Your Rights
Regardless of your location, you have the following rights:
Access: Request a copy of the personal data we hold about you.
Correction: Request correction of inaccurate data.
Erasure: Request deletion of your account and all associated data.
Portability: Request your vault data in a structured, machine-readable format.
Objection: Object to processing of your data in certain circumstances.
Withdraw consent: Withdraw consent for product communications at any time from your Profile screen, or withdraw consent for all processing by deleting your account.
Grievance redressal: Raise a complaint with us and receive a response within 72 hours.
Supervisory authority: Lodge a complaint with your local data protection authority. In India: the Data Protection Board of India. In the EU: your national supervisory authority. In the UK: the ICO (ico.org.uk).
To exercise any right, contact us at contact@getbylines.in. We respond within 72 hours.
13. Security
We implement the following technical measures to protect your data:
All data in transit is encrypted using TLS 1.2 or TLS 1.3. The app explicitly enforces this and does not permit cleartext HTTP traffic at the operating system level.
All data at rest is encrypted using AES-256 encryption provided by Google Firebase's infrastructure.
API keys and service credentials are stored in Google Cloud Secret Manager and are never embedded in the application binary.
Your email address is kept only in Firebase Authentication and your minimal private account record. It is never visible to other users or included in public, story, Hive, analytics, or crash diagnostic data.
Access to your data requires a valid Firebase Authentication token, which expires hourly and is automatically rotated.
All backend Cloud Functions reject requests that do not carry a valid authenticated user token.
A single-device login policy limits concurrent access to your account.
No system is completely secure. If you believe your account has been compromised, contact us immediately at contact@getbylines.in.
14. Age Requirements
getBylines is intended for professionals and student media makers aged 16 and above. We do not knowingly collect personal data from anyone under 16. If you are under 16, please do not use this application.
Like most digital services, we rely on self-declaration of age at signup. We do not employ automated age verification. If we become aware that a user is under 16, we will promptly delete their account and associated data.
If you are a parent or guardian and believe your child under 16 has created an account, contact us at contact@getbylines.in and we will delete it immediately.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date and notify you through the application at least 14 days before material changes take effect. Your continued use of getBylines after that date constitutes acceptance of the updated Policy. If you do not agree with the changes, you may delete your account before they take effect.
16. Contact and Grievance Officer
In accordance with the DPDPA 2023 and the Information Technology Act 2000: