Introduction
WebCloudNest ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what we collect, how we use it, with whom we share it, and what choices you have.
This Policy applies to all users of WebCloudNest (the "Service", "App"), including our website, mobile applications, and any related services.
Information We Collect
We collect information you provide directly to us, information collected automatically when you use the Service, and information from third parties where applicable.
Information you provide:
- Account information (name, email address, password hash, profile picture, phone number where applicable).
- Communications you send us (support requests, feedback, survey responses).
- Content you create or upload while using the Service.
- Payment information (processed by our payment processor — we do not store full card numbers).
Information collected automatically:
- Device information (model, OS version, unique device identifiers, language settings).
- Log data (IP address, access times, pages or screens viewed, crash reports).
- Usage data (features used, session duration, interaction events).
- Cookies and similar technologies (see "Cookies" below).
Information collected via Accessibility Services:
- WebCloudNest requests access to the AccessibilityService API solely to perform its core function — for example, to detect the foreground app, present a security overlay (such as a PIN screen or app lock), or assist users with navigation.
- Accessibility events are processed locally on your device and are NOT transmitted to our servers, sold, or shared with third parties.
- We do not capture screen content, typed text, passwords, or any sensitive information from other apps via accessibility events beyond the minimum metadata required to identify the active app package name.
- You may revoke accessibility permission at any time from your device settings; doing so may disable certain core features.
Biometric & PIN data:
- When you set a PIN, password, pattern, or enable biometric authentication (fingerprint/face), these credentials are stored locally on your device using the platform-provided secure storage (e.g. Android Keystore / iOS Keychain).
- We never transmit your biometric data, PIN, password, or pattern to our servers.
- Biometric authentication is handled by your device’s operating system; we receive only a success/failure signal.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service.
- Authenticate users and prevent fraud or abuse.
- Process transactions and manage subscriptions.
- Respond to support requests and communicate with you about the Service.
- Send service announcements, security alerts, and (with consent where required) marketing communications.
- Improve the Service through analytics, A/B testing, and crash diagnostics.
- Comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information.
Legal Basis for Processing (GDPR)
If you are in the European Economic Area, United Kingdom, or another GDPR-equivalent jurisdiction, we process your data on the following legal bases:
- Performance of a contract — to provide the Service you requested.
- Legitimate interests — to operate, secure, and improve the Service, provided your rights do not override these interests.
- Consent — for optional marketing communications and certain cookies.
- Legal obligation — to comply with applicable law and regulatory requirements.
You may withdraw consent at any time without affecting the lawfulness of prior processing.
Data Retention
We keep personal information only as long as necessary for the purposes described in this Policy, or as required by law.
Typical retention periods:
- Account data — for the lifetime of your account plus a reasonable wind-down period after deletion.
- Transaction records — as required by applicable tax and accounting law (typically 7 years).
- Logs and analytics — usually 90 days to 13 months, depending on the data type.
- Backups — securely retained for limited periods before automated purge.
When data is no longer needed, we delete or anonymize it.
Your Rights & Choices
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Deletion ("right to be forgotten") — request that we delete your data, subject to legal exceptions.
- Restriction — ask us to limit how we process your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interests or for direct marketing.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint — with your local data protection authority.
Security
We implement reasonable administrative, technical, and physical safeguards to protect your information, including encryption in transit (TLS), encrypted storage of sensitive data at rest, access controls, regular security testing, and employee training.
No method of transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your personal data, we will notify you and the relevant authorities as required by law.
Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us at webcloudnest@gmail.com and we will delete it.
International Data Transfers
Your information may be processed in countries other than your country of residence, including India and other jurisdictions where our service providers operate. We rely on appropriate safeguards — such as Standard Contractual Clauses and adequacy decisions — to protect your data when transferred internationally.
App Permissions (Mobile)
Where applicable, our mobile applications request only the permissions needed to deliver the features you use. Each permission is explained at the moment it is requested, and most can be revoked at any time from your device settings.
Examples of permissions we may request:
- Notifications — to deliver alerts you opt into.
- Camera / Photos — to upload images or scan codes (only when you initiate the action).
- Storage — to save files you create or download.
- Biometrics — for secure authentication, processed only by your device.
- Accessibility — used strictly for the documented purpose of providing the core security/automation feature; not used to read, exfiltrate, or store screen content.
Do Not Track
Some browsers offer a "Do Not Track" (DNT) signal. There is currently no consistent industry standard for responding to DNT signals, and we do not change our practices based on DNT signals at this time. We do offer the cookie controls described above.
Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, where the changes are material, provide additional notice (such as via email or an in-app banner). Your continued use of the Service after the update means you accept the revised Policy.
Contact Us
For privacy-related questions, requests, or complaints, contact our Data Protection contact at:
Email: webcloudnest@gmail.com
Address: WebCloudNest, Surat, Gujarat, India