Skip to content
Dwaari

Privacy policy

Last updated 2026-07-28

Dwaari is housing-society software used by residents, committee members and guards. This policy says what we collect, why, who else sees it, how long we keep it and how you get rid of it. It is written to be read.

We do not sell your personal data, we do not share it with advertisers or data brokers, and there are no ads in the app. That is the product, not a concession.

What we collect, and why

You give us some of this. The rest is created as you and your society use the app.

Mobile number — required
It is your identity in Dwaari and how you sign in: we send a one-time code to it. It is also how your society finds you when they add you.
Name — required
So your committee, your guards and your neighbours know who they are dealing with at the gate and on the noticeboard.
Email address — optional
Used only to send invitations and receipts, if you give one. Everything else works without it.
Society, block, flat and role
Whether you are an owner, a tenant, a committee member or a guard. This decides what you are allowed to see and do, so it is the backbone of the app rather than a profile detail.
Language and theme preference
So the app opens in the language, and the light or dark mode, that you chose.
Visitor and gate activity
Visitors recorded in and out at your gate, and the pre-approval codes you create for guests you are expecting. This is the society security log.
Complaints you raise
What you reported, and the record of who acted on it and when, so a ticket can be followed through to its close.
Maintenance invoices and payments
Bills raised against your flat, what was paid and the receipts. These are the society accounts.
SOS alerts you raise
Your name as recorded at that moment, and any note you add. The app does not ask for location permission, so it does not send your coordinates.
Notices, polls and votes
What the society published, and how a vote went.
Reports about a member
If a resident reports another member to the committee, we keep what was written and what the committee decided, so the committee can act on it and account for the decision afterwards.
Push-notification token
A per-device identifier issued by Google that lets a notification reach that phone. It is not an advertising id and it says nothing about you.
SMS delivery logs
The number a one-time code was sent to, when, which provider carried it and whether it arrived, so a failed login can be diagnosed.

What we do not collect

Stated as flatly as we can, because this is the part people actually want to know:

  • No location. The Android app does not request location permission and does not track you, in the foreground or the background.
  • No contact list, no photo library, no file access. The app asks you to grant exactly two permissions: the camera, to scan gate QR codes, and permission to show notifications. It also declares the routine ones Android grants at install without asking you — internet access, vibration for the SOS siren, and the ability to show a full-screen alert.
  • No advertising identifier, no ad network and no analytics SDK in the mobile app.
  • No password for residents. Sign-in is by one-time code, so there is no password of yours for anyone to steal.

This website

Separate from the app. If you fill in the form on this site we keep the name, phone, email, society, city and role you typed, so that we can reply to you. This site also loads Google Tag Manager where it is configured, which measures visits; the app does not. Nothing links a visit to this website with an account in the app.

Who else sees your data

A short list, and it stays short.

Your society
Committee members see the member directory, complaints, billing and notices for their own society. Guards see only what the gate needs: expected visitors, pre-approval codes and SOS alerts. One society can never see another society data — that separation is enforced by the database itself on every single query, not by application code remembering to filter.
Our SMS provider
2Factor.in, with MSG91 as a fallback, receives your mobile number and the one-time code in order to deliver the SMS. No other personal data of yours is sent to them.
Google, for push notifications
Firebase Cloud Messaging receives your device token and the contents of a notification in order to deliver it to your phone.
Nobody else
We do not sell personal data. We do not share it with advertisers, data brokers or lead sellers. We do not run ads. If we are ever compelled to disclose something by law we will comply with the law, and we will say so here.

Where your data is stored

In India. The application database runs on Oracle Cloud in Mumbai. Nightly backups are encrypted on the server before they leave it, and are then stored with Backblaze B2. This website runs separately, on Cloudflare.

How it is protected

Specifically, and only what is actually true today:

  • Every society is isolated at the database level by PostgreSQL row-level security. A query that strays outside its own society returns nothing at all, rather than relying on application code to remember a filter.
  • Residents sign in with a one-time code sent by SMS. There is no resident password to leak.
  • Traffic between the app and our server is encrypted in transit over HTTPS.
  • Backups are encrypted before they leave the server, and restoring from them has been tested.
  • Gate logs, complaint histories and accounting entries are append-only: database rules physically refuse an edit or a delete, including from us.
  • Access to production data is limited to the person who operates Dwaari.

What we do not claim: we hold no ISO 27001, SOC 2 or comparable certification; we have not commissioned a third-party security audit; and your data, while encrypted in transit and in backups, is not end-to-end encrypted — we can read it in order to run the service. If any of that changes, this page changes with it.

How long we keep it

There is no single number, and pretending otherwise would be false:

  • While your account is active we keep it, because the app does not function without it.
  • When you delete your account, your identity is erased immediately and permanently. The deletion page sets out what is erased, what your society keeps and why, and the traces that can remain afterwards.
  • The society financial and accounting records — invoices, payments, receipts, vouchers and ledger entries — are kept as the society books. How long a co-operative housing society must keep those is fixed by the co-operative societies law of your state, and it differs from state to state and by type of record, so we do not invent a single period of our own. Your committee or your society auditor can tell you what applies to you.
  • Gate logs, complaint histories and accounting entries cannot be deleted at all once written, by anyone including us. That is deliberate: a security or audit log you can quietly edit is not one.
  • SMS delivery logs, which record the number a login code was sent to, are kept for troubleshooting and are not cleared on a fixed schedule today. Deleting your account does not clear them.
  • Backups are taken nightly, kept encrypted and rotated. A backup made before a deletion still holds the earlier state until it ages out of the rotation, so deletion is immediate in the live system rather than instantaneous in every copy of it.
  • Words a person typed — a complaint, a notice, a poll question, an SOS note — are kept for as long as the record they sit in is kept, exactly as they were written. Deleting an account replaces names in the fields that hold them, but it cannot pick a name out of a sentence somebody wrote, so a name typed into a complaint or a notice stays there.

Deleting your account

You can delete your Dwaari account yourself from inside the app, or ask us by email if you no longer have it. Deletion is immediate and permanent — no grace period, no freeze, no undo. The full instructions, what is removed, what your society keeps and why, and the traces that can remain, are all on the account deletion page.

How to delete your account

Your rights

Under India Digital Personal Data Protection Act, 2023 you may ask for a copy of your personal data, ask us to correct it, and ask us to delete it. Write to us and we will reply within 3 working days. If you are unhappy with how we handled it, say so in the same thread — it reaches the person who runs Dwaari, not a queue.

hello@dwaari.in

Children

Dwaari is intended for adult residents and society staff. We do not knowingly create accounts for children. If you believe a child account exists, write to us and we will remove it.

Changes to this policy

If this policy changes we update the date at the top of this page, and for anything that materially affects you we will also say so in the app.

Contact

Dwaari is built and operated in India. Write to us about anything on this page — what we hold, deleting it, or a complaint about either.

hello@dwaari.in