Legal
Privacy policy
How Grace Apps Private Limited handles personal data across graceapps.in and our applications. We have tried to write this in plain language rather than the usual fog.
Effective 1 September 2026Last updated 1 September 2026
1. The short version
Most of our applications keep your information on the device you entered it on. They do not require an account, they do not carry advertising, and as of the effective date above none of them include third-party advertising or analytics software.
Two things are exceptions worth knowing about before you read further. Grace offers an optional account, and if you create one, some of your Grace content is stored in our cloud so it can follow you between devices. Bap offers a paid subscription, and subscriptions are processed by Apple, Google and our billing provider rather than by us.
If you would rather ask a person than read fourteen sections, write to hello@graceapps.in.
2. Who we are
Grace Apps Private Limited (“Grace Apps”, “we”, “us”) is a company registered in India, with its registered office at Sr. No. 15/3, Flat No. 303, Lakewood, Ambegaon Budruk, Pune, Maharashtra 411046, India, CIN U58200PN2026PTC253537.
For the purposes of the Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for personal data described in this policy, and you are the Data Principal. Where this policy is read by someone in a jurisdiction using different words — data controller and data subject, for instance — those terms map onto the same roles.
You can reach us at hello@graceapps.in or +91 98927 71910.
3. What each app collects
Our applications differ a great deal, so it is more honest to describe them one at a time than to write a single paragraph that is vague enough to cover all of them.
Grace — wellness
Grace can be used without an account. Used that way, your activity history, preferences and written reflections stay on your device.
If you choose to create an account, we collect the email address you sign up with, and the following is stored in our cloud so that it is available on your other devices: your profile and preferences, your written reflections, and a notification token that lets us deliver reminders you have asked for. Only your signed-in account can read or write your own records; this is enforced at the database level, not merely by the app.
If you add a photograph or video to an activity, that file is stored in our cloud storage under your account.
Grace also offers an optional stress awareness feature. See section 5 — it deserves its own treatment.
Bap — tasks
Bap has no account and no sign-in. Your tasks live on your device. If you subscribe to Bap+, see section 6 on payments — the subscription itself is handled outside the app.
HeartBeat — blood pressure and medication
HeartBeat holds health information: blood pressure readings, medicines and reminder schedules. This information is stored on your device, protected by your device’s biometric lock, and is not transmitted to us. Where you permit it, HeartBeat reads from and writes to Apple Health on your device; that exchange happens locally between two apps on your phone.
When you export your readings — to send to a doctor, for example — the export is created on your device and you choose where it goes. We never receive a copy.
NumeroMe — numerology
NumeroMe uses the name and date of birth you enter to perform its calculations. These are stored on your device. Generated reports are produced on the device.
CloudFrame — photos on Apple TV
CloudFrame asks permission to read your photo library so it can display it. Browsing happens on your device, against your own library. We do not upload, copy or index your photographs, and we cannot see them.
EmojiMemory — game
EmojiMemory collects nothing. There is no account, no advertising, no leaderboard and no network call.
4. This website
When you use the enquiry form on our Work with us page, we receive the name, email address, company and message you type, so that we can reply. We keep enquiries so we have a record of conversations with prospective clients.
If you ask to be told when an app is released, we keep your email address for that purpose alone, and every message we send you will include a way to stop receiving them.
Our web host records standard server logs, which include IP addresses, for security and to keep the site running. This website does not use advertising cookies or third-party analytics.
5. Health and biometric data
Two of our apps touch health information, and we hold it to a higher standard than the rest.
HeartBeat keeps blood pressure readings and medication records on your device only, as described above.
Grace includes an optional stress awareness feature. It is off until you turn it on. When enabled, and only with the permissions you grant, it reads heart rate information from Apple Health or from a connected smartwatch in order to notice periods of elevated stress and offer you an activity at a useful moment.
This information is used to help you in the moment. It is not used for advertising, it is not sold, and it is not shared with anyone for their own purposes. You can turn stress awareness off at any time in the app’s settings, and you can withdraw the underlying health permission through your device’s own privacy settings.
6. Payments
Where an app offers a paid subscription — Bap+ today, possibly others later — the purchase is made through the Apple App Store or Google Play and is subject to their terms. We use RevenueCat to tell the app which features you are entitled to.
We never see or store your card number, bank details or billing address. What we receive is limited to what is needed to know whether a subscription is active, and an anonymous identifier for your installation.
7. Who else processes data
We use a small number of providers, each for a stated purpose and none for their own marketing:
- Google (Firebase) — accounts, cloud storage of Grace account data, file storage and delivery of notifications you have asked for.
- RevenueCat — determining subscription entitlements.
- Apple and Google — app distribution, in-app purchases and, where you use them, their own health platforms on your device.
- Netlify — hosting graceapps.in and delivering enquiry-form messages to us.
We do not sell personal data. We do not share it for anyone else’s advertising. We may disclose information where the law requires it, and we will tell you if that happens unless we are prohibited from doing so.
8. Where data is stored
Grace account data is held in our Firebase project in the United States (Google Cloud multi-region nam5). This means that if you create a Grace account, the data described in section 3 is transferred outside India and stored on servers in the United States, processed by Google as our provider.
We transfer only what the feature needs, and we rely on the contractual protections Google offers for that processing. Data that stays on your device never leaves your country, because it never leaves your phone.
9. How long we keep it
- On-device data — for as long as you keep the app installed. Deleting the app deletes it. We cannot recover it for you.
- Grace account data — until you delete your account, after which we remove it within 30 days, excluding anything we must retain by law.
- Enquiries and support email — 24 months from our last exchange.
- Release notification list — until you unsubscribe.
10. Your rights
Under the Digital Personal Data Protection Act, 2023, you may ask us to:
- tell you what personal data of yours we hold and who we have shared it with;
- correct anything inaccurate, complete anything incomplete, or update anything out of date;
- erase your personal data where we no longer need it for the purpose you gave it for;
- nominate another person to exercise these rights on your behalf if you die or become incapacitated;
- withdraw consent you previously gave, as easily as you gave it.
Write to hello@graceapps.in with “Data request” in the subject line. We will respond within 30 days and may need to verify your identity first — not to obstruct you, but so we do not hand your data to somebody else.
Deleting a Grace account can also be done from within the app itself, without writing to us.
11. Children
Our applications are not directed at children, and we do not knowingly collect personal data from a child. Under Indian law, processing a child’s personal data requires verifiable parental consent, and we do not undertake it. If you believe a child has provided us with personal data, write to us and we will delete it.
12. Security
Grace account data is protected by database rules that permit only the signed-in owner of a record to read or write it, and everything else is denied by default. Health information in HeartBeat sits behind your device’s biometric lock. Traffic between our apps and our providers is encrypted in transit.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that affects your personal data, we will notify the Data Protection Board of India and affected users as the law requires.
13. Changes to this policy
When we change this policy we will update the date at the top. If a change materially affects how we handle your personal data, we will tell you in the app or by email before it takes effect, rather than quietly editing this page.
14. Grievance officer
If you are unhappy with how we have handled your personal data or your request about it, you may contact our Grievance Officer:
Babasaheb Damale
Grace Apps Private Limited
Sr. No. 15/3, Flat No. 303, Lakewood, Ambegaon Budruk, Pune, Maharashtra 411046, India
hello@graceapps.in · +91 98927 71910
If you remain dissatisfied, you may complain to the Data Protection Board of India.