Skip to content
Legal · Draft

Privacy policy

What UtilityHub collects, what it deliberately never touches, where it's stored, and exactly how long each thing is kept.

Draft last updated 8 September 2026
Draft — pending legal counsel review
This document describes, in plain language, what UtilityHub actually does with data, money and files. It has not yet been reviewed by a lawyer, and it is not a final, binding policy until that review is complete and this notice is removed.

Who this covers

This policy covers everyone who uses UtilityHub — as a Guest with no account, on a Free account, or on Pro — wherever in the world you're using it from. It describes the product as it's actually built, not a generic template: where a section names a specific number, timing or mechanism, that's the real one, taken from the same specification the engineering team builds against.

What never leaves your device

28 of UtilityHub's 46 tools run entirely in your browser. For those tools, your file is read into memory on your device, processed there, and the result is offered back to you as a download — it is never uploaded, never touched by a server, and never becomes something we could see even if we wanted to. The remaining tools need a server (heavy conversions, video and audio processing, OCR-adjacent formats, signing) and are covered by the collection and retention sections below.

Every tool page states plainly, before you drop a file, whether it runs on your device or needs a server — this isn't something you have to infer from this policy.

What we collect

We collect the minimum each part of the product needs to function:

  • Account: your email address, and for Google-authenticated trials, your Google identity — used only to establish one trial per person and never to import your Google data.
  • Usage metadata: which tool ran, when, and whether it succeeded — not the content of your files.
  • Files sent to a server tool: held only for the retention windows in the table below, then deleted.
  • Payments: handled entirely by Razorpay. We receive confirmation that a payment succeeded or failed and the last four digits of a card where Razorpay provides them — never a full card or bank account number.
  • QR scans: see the dedicated note below — this one is deliberately limited.
  • Cookies and analytics: only after you consent — see "Cookies and consent" below.

What we never do

  • PDF passwords are never stored or transmitted. When you unlock or protect a PDF, the password is used in memory for that one operation and discarded immediately — it never reaches a database, a log, or an error report.
  • QR scan tracking can't follow a person across codes. When someone scans one of your dynamic QR codes, we hash the scanner's IP address with a salt that rotates every day and discard the raw address — the hash itself is never stored. The analytics you see are city and country level only, and because the salt changes daily, the same phone scanning two different codes on two different days produces two unrelated hashes. There's no way, by design, to build a profile of one visitor across codes or over time.
  • We don't sell personal data, and we don't run third-party trackers on any page before you've consented to them.

Where your data lives

UtilityHub is built for India's Digital Personal Data Protection (DPDP) Act, and data residency follows from that rather than being an afterthought: the database (Supabase) runs in Mumbai, file storage (S3) is in the ap-south-1 (Mumbai) region, and the processing servers run on a VPS in Mumbai. A worker or database sitting outside India would break this claim regardless of what the rest of the stack does, so it's treated as a hard requirement rather than a preference.

Breach notification follows the DPDP Act's timelines; the exact notification workflow is one of the items pending review with counsel (see the draft notice at the top of this page).

How long we keep things

Two clocks run independently: how long a file stays retrievable, and how long a record that a job happened stays in your history. A job can appear in your history after its file has already expired — that's shown to you as "file expired," not hidden or treated as an error.

GuestFreePro
Input file (ephemeral storage)2 hours2 hours2 hours
Output file30 minutes2 hours7 days
History metadataNone kept24 hours7 days

Deletion is checked, not assumed: a sweep runs every 15 minutes, a storage-level backstop rule exists in case that sweep is ever delayed, and a separate reconciliation job confirms files are actually gone rather than just marked for deletion.

If you delete your account, it enters a 30-day restore window and is then permanently purged — backups included, so a deleted identity cannot be recovered from them after that point. The one exception is signature audit trails, which survive account deletion in anonymised form, because they exist to prove a document was signed, a purpose that outlives the account that did the signing.

Your rights

You can export or delete your data yourself, in-app, at any time — both actions are self-service and complete, not a support ticket that may or may not get actioned. This applies to every user, not only to those covered by a specific law, because building it once for everyone is simpler and fairer than building it twice.

GDPR applies to UtilityHub because people outside India are welcome to use it. If you're in the EEA, UK or Switzerland, using UtilityHub means your data is transferred to and processed in India. Our intended basis for that transfer is the EU Standard Contractual Clauses (or an equivalent recognised safeguard); the exact mechanism and any additional transfer impact assessment are among the specific items pending counsel review.

Cookies and consent

Non-essential scripts — analytics included — do not load until you've made a choice in the cookie banner. Consent is asked before those scripts run, not after, so declining actually prevents the script from loading rather than merely opting you out of its output afterwards.

Payments

All payments are processed by Razorpay. We never see or store your full card number, UPI PIN, or net banking credentials — those go directly to Razorpay and its banking partners. Because Razorpay is our only payment gateway, paying for Pro or a credit pack currently requires an Indian payment method; the pricing page states this plainly. Using UtilityHub itself has no such restriction.

Grievance officer

The DPDP Act requires a named grievance officer for data-protection complaints. This is a placeholder to be filled in with a real name and contact details before launch — it is not a working contact yet:

Grievance Officer: [Name to be appointed]Email: [grievance-officer@utilityhub.in — placeholder]Postal address: [Registered office address — placeholder]Response timeline: [Per DPDP Act requirements — to confirm with counsel]

Changes to this policy

If this policy changes in a way that matters to how your data is handled, we'll say so on this page with an updated date, and notify account holders by email for anything material — never a silent edit to a live legal document.

Contact us

Questions about this policy can go to [privacy@utilityhub.in — placeholder] once the mailbox is live. Until then, treat every address on this page as a draft placeholder, consistent with the notice at the top.