Privacy Policy
Last updated 5 October 2026 Version 1.0
The short version
- You can listen without an account. As a guest we keep a random ID made by the app, your age band (13–17 or 18+), your country and language, and your listening progress.
- If you sign in with Google, Apple or email, we also keep that sign-in. With Google or Apple we keep only the account ID they give us. With email we keep your email address and a scrambled (hashed) version of your password.
- Purchases go through Apple or Google. We never see your card or bank details.
- Character chat is optional, for adults only, and starts only after you agree. Your messages go to an AI service run by Microsoft in Sweden (EU) to write the reply and are checked for safety.
- Analytics and ads are not switched on today. If we switch them on, analytics will run only if you agree, and we will update this policy first.
- We do not sell your personal data, and we do not use it for targeted advertising.
- You can download your data or delete your account at any time in the app: Profile → Download my data or Profile → Delete account and data. Deletion happens immediately.
- Questions or complaints: contact@turtletechsai.com. Grievance Officer (India): Akshay Gupta, contact@turtletechsai.com.
1. Who we are
Turtle FM is an audio-drama app for iOS and Android and a web app at https://turtlefmapp.turtletechsai.com (together, the “Service”). It is run by Turtle Techsai, Nagpur, Maharashtra, India (“Turtle Techsai”, “we”, “us”).
We decide why and how your personal data is used. That makes us:
- the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (DPDP Act);
- the controller under the EU General Data Protection Regulation (GDPR) and the UK GDPR;
- the business under the California Consumer Privacy Act (CCPA) and similar US state laws, where those laws apply to us;
- the organization responsible under Canada’s PIPEDA; and
- an APP entity under Australia’s Privacy Act 1988, where it applies to us.
How to reach us about privacy
| Who | Contact |
|---|---|
| Privacy contact / Data Protection Officer | contact@turtletechsai.com (e.g. privacy@turtletechsai.com) |
| Grievance Officer (India) | Akshay Gupta, contact@turtletechsai.com, Nagpur, Maharashtra, India, Nagpur, Maharashtra, India |
| General contact | contact@turtletechsai.com, +91 78418 53298 |
| EU representative (GDPR Article 27) | Not appointed. Contact us at contact@turtletechsai.com |
| UK representative (UK GDPR Article 27) | Not appointed. Contact us at contact@turtletechsai.com |
This policy explains what we collect, why, who we share it with, how long we keep it and what your rights are. It applies to the apps, the web app and our support and grievance channels. It does not apply to Apple, Google or other companies’ services, which have their own policies.
2. What we collect and where it comes from
We collect only what the Service needs. We do not ask for your date of birth, phone number, precise location, contacts, photos or microphone.
2.1 Guest use (no account)
When you first open the app and choose your age band, the app creates a random identifier (a UUID) and stores it on your device. It is not your phone’s hardware ID or advertising ID. We use it to create a guest account so the app can keep your progress and anything you unlock or buy.
With a guest account we hold:
- an internal account number and the random device identifier;
- your age band: “13–17” or “18+” (see section 9);
- your market (country), worked out from your device’s region setting, which decides prices, the catalogue and age rules;
- your app language, the languages you want stories in, and your time zone (used for daily limits such as the daily free episode);
- sign-in tokens: a short-lived access token and a refresh token that lasts up to 60 days. We store refresh tokens only in hashed form.
If you choose “Under 13”, the app shows a block screen and stores only a flag on your device. Nothing is sent to us.
2.2 If you sign in
Signing in is optional. When you sign in, your guest account is upgraded, or, if you already have an account, your guest coins and unlocked episodes are moved into it.
| Method | What we keep |
|---|---|
| The account identifier Google gives us. Google also sends your email address and name in the sign-in token; we do not store them. | |
| Apple (iOS) | The account identifier Apple gives us. We do not store the email address or name Apple may share. |
| Email and password | Your email address; your password, stored only as a salted, one-way hash (scrypt); whether you have verified the address; counts of failed sign-in attempts and any temporary lock-out; one-time 6-digit codes for verification and password reset, stored hashed and valid for 30 minutes. |
| Any method | An optional display name, if you give one. |
2.3 Preferences and choices
- The genres you pick when you start, used to order your home screen.
- Whether you have turned on Mature stories (18+).
- Which series you follow and whether you want to be told about new episodes.
- Your privacy choices (consents) — each one is recorded with the date and the policy version you saw.
2.4 Listening activity
- For each episode you play: how far you got, whether you finished, the language and the story branch you heard.
- Which days you listened (one record per day, used for service health statistics).
- The choices you make in interactive episodes and the story state they produce, so later episodes follow your choices.
- When the app comes back online it sends us the list of episodes you have downloaded, so we can tell it which ones have been removed and must be deleted from your device.
2.5 Coins, unlocks and purchases
- Your coin balance (paid coins and bonus coins kept separately) and a ledger of every coin movement: purchases, bonuses, spending, refunds and corrections.
- Episodes you have unlocked and how (coins, waiting, the daily free episode, or other ways shown in the app), wait-timer start and end times, and daily-free claims.
- Purchase records sent to us by RevenueCat on behalf of Apple or Google: the store, product, price and currency, transaction and event IDs, dates and event type (for example purchase, renewal, cancellation, refund), and the event message itself.
- Your VIP status: plan, start and end dates, and whether it renews.
We never receive your card, bank or UPI details. Apple and Google handle payment.
2.6 Character chat (adults only, optional)
If you are 18+ and agree to chat:
- the messages you send (up to 1,000 characters each) and the character’s replies;
- safety scores for each message from our moderation service, and whether a message triggered our crisis-help response (section 6.3);
- how many free messages you used each day and any coins spent on messages;
- timing information used to show break reminders.
2.7 Reports and complaints
When you report a story, episode, character or chat message, or write to our Grievance Officer: what you reported, the reason, any details you add, and an email address only if you choose to give one. If you are signed in, the report is linked to your account. You can report without an account.
2.8 Device and notifications
If you turn on notifications (for example “Remind me” when a free episode is ready): your device platform, app version, app language and a push token issued by Apple or Google. Push notifications are not switched on yet; they will be once Firebase Cloud Messaging and Apple Push Notification service are set up.
2.9 Technical and security data
Like any online service, our servers receive your IP address, the time and type of each request and basic device and app information. We use this to run the Service, prevent abuse and investigate security problems. We do not use your IP address to track you or to find your precise location.
2.10 Analytics (not switched on today)
We plan to use PostHog to understand how the app is used. It is not switched on. If we switch it on:
- detailed events (for example “episode started”, “series followed”, “purchase completed”) are sent only if you turn on “Personalisation and analytics” in Privacy choices;
- before you agree, the app sends at most three events — app installed, app opened, first audio started — with no account ID;
- events never contain chat text, email addresses or phone numbers.
2.11 Advertising (not switched on today)
There are no ads in Turtle FM today. We may later offer rewarded ads — an optional ad you choose to watch to unlock an episode or earn coins — through Google AdMob. If we do:
- you will only see an ad when you choose to watch one;
- the ad network will collect data on your device under its own privacy policy, which may include your device’s advertising ID and ad interactions;
- personalised ads will run only if you turn on Ad tracking in Privacy choices (and, on iOS, allow tracking in Apple’s prompt). Otherwise ads will be non-personalised where the network supports it;
- we receive from the ad network only a signed confirmation that the ad was completed, with a transaction ID, so we can credit your reward;
- ads will never be shown to anyone under 18 in India, and we will not use personal data of 13–17-year-olds for targeted advertising anywhere.
We will update this policy and name the ad network before ads go live.
2.12 When you contact us
If you email us, we keep your message, your email address and our reply so we can help you and keep a record of complaints.
3. Why we use your data, and our legal bases
The legal-basis column matters mainly in the UK and EU (GDPR). Under the DPDP Act in India we rely on your consent (given through this notice and the in-app choices) or on a legitimate use allowed by Section 7 of the Act, such as where you have voluntarily provided data for a purpose and not objected, or to comply with law.
| Purpose | Data used | GDPR / UK GDPR basis | India (DPDP) |
|---|---|---|---|
| Create and run your guest or signed-in account; keep you signed in | Identifiers, sign-in data, tokens | Contract (Art. 6(1)(b)) | Consent; voluntary provision (s.7(a)) |
| Apply age rules: block under-13s, limit 13–17s, enforce 18+ in India and for mature stories and chat | Age band, market | Legal obligation (Art. 6(1)(c)); legitimate interests in protecting young people (Art. 6(1)(f)) | Consent; compliance with law |
| Play stories, remember your place, follow your story choices, deliver downloads | Listening activity, choices | Contract | Consent; voluntary provision |
| Show the right catalogue, prices and daily limits for your country and time zone | Market, language, time zone | Contract | Consent; voluntary provision |
| Order your home screen by the genres you picked | Genre picks | Contract | Consent |
| Personalised recommendations and analytics (when switched on) | Listening activity, app events | Consent (Art. 6(1)(a)) | Consent |
| Sell and deliver coins and VIP; handle refunds; keep financial records | Purchase and wallet data | Contract; legal obligation (tax and accounting) | Consent; voluntary provision; compliance with law |
| Character chat: send your messages to the AI model, check them for safety, keep the conversation | Chat messages | Consent (Art. 6(1)(a)); explicit consent (Art. 9(2)(a)) where a message reveals health or other special-category information | Consent |
| Show crisis-help resources when a message suggests risk of self-harm | Chat messages | Explicit consent; vital interests (Art. 6(1)(d), 9(2)(c)) in an emergency | Consent; legitimate use for medical emergency (s.7(f)) where it applies |
| Send notifications you asked for | Push token, device data | Consent | Consent |
| Rewarded ads (when switched on) | Ad reward confirmations; ad network data | Contract for the reward; consent for personalised ads | Consent |
| Handle reports, complaints and takedowns; meet intermediary and consumer-law duties | Reports, contact details | Legal obligation; legitimate interests in a safe service | Compliance with law; consent |
| Security, fraud and abuse prevention (for example refund abuse, brute-force sign-in attempts) | Technical data, sign-in counters, wallet ledger | Legitimate interests | Compliance with law; legitimate uses |
| Email you codes for verification and password reset | Email address | Contract | Consent; voluntary provision |
| Respond to legal requests and protect our rights | Any relevant data | Legal obligation; legitimate interests | Compliance with law; s.7 legitimate uses |
Where we rely on legitimate interests, we have weighed them against your rights, and you can object (section 12).
We do not use your personal data for automated decisions that have legal or similarly significant effects on you. Some things are decided automatically: the age gate, whether a story is available in your country, and whether a chat message is blocked by moderation or answered with crisis resources. If you think one of these got it wrong, contact us and a person will review it.
4. Consent and how to withdraw it
Optional processing is off until you turn it on. In the app, open Profile → Privacy and data → Privacy choices:
| Choice | What it controls | Default |
|---|---|---|
| Essential | Guest ID and listening progress. Needed for the app to work. | Always on |
| Personalisation and analytics | Using what you listen to for suggestions and to improve the app (analytics only once switched on) | Off |
| Notifications | Reminders such as “your free episode is ready” | Off |
| Ad tracking | Letting ad partners personalise ads (only once ads are switched on) | Off |
| Chat | Sending your messages to the AI service and keeping your chat history so characters remember your conversation | Off; asked the first time you open a chat |
You can withdraw any consent at any time, as easily as you gave it. Withdrawing does not affect processing that already happened. If you withdraw chat consent, you can no longer send messages; your existing chat history stays in your account until you delete your account.
In India you may also give, manage or withdraw consent through a Consent Manager registered with the Data Protection Board, once that system is available.
5. Notice for India (DPDP Act and Rules)
This section gives the information Section 5 of the DPDP Act and the DPDP Rules, 2025 require. It applies to you if you use the Service in India.
- What we process and why: the itemised list in section 2 and the purposes in section 3. Each item is used only for the purposes listed next to it.
- The goods or services this enables: listening to stories, keeping your progress and purchases, character chat if you choose it, and handling your complaints.
- How to withdraw consent: section 4. Withdrawing is as easy as giving consent.
- Your rights: to obtain a summary of your personal data and the processing activities, and the identities of others we share it with (in the app: Download my data, or by email); to correct, complete, update or erase it; to grievance redressal; and to nominate another person to exercise your rights if you die or become unable to do so. See section 12.2.
- Grievances: contact our Grievance Officer (section 1 and the Grievance Redressal page). We will respond within 90 days at the latest, and aim for much sooner.
- Data Protection Board of India: if you are not satisfied with our response, you can complain to the Data Protection Board of India. The Act expects you to use our grievance process first.
- Language: you can ask for this notice in English or in any language listed in the Eighth Schedule to the Constitution of India. A Hindi version is being prepared.
- Age: in India the Service is only for adults (18+). We do not offer a parental-consent process, so we do not knowingly process the personal data of anyone under 18 in India (section 9).
- Your duties: the Act asks you not to impersonate anyone, not to hide material information, and not to file false or frivolous complaints.
6. AI processing
6.1 How stories are made
Stories are planned and edited by people, drafted with the help of AI language models (Azure OpenAI), voiced with licensed AI voices (Azure Speech and, for some characters, ElevenLabs) and illustrated with AI-generated artwork. No personal data about listeners is used to make stories. Story production sends only story material (outlines, scripts) to these services. See AI Transparency.
6.2 Character chat
When you send a message to an AI character:
- your message is checked by Azure AI Content Safety;
- if it is allowed, it is sent to an Azure OpenAI model together with the character’s description, what that character knows about the story up to the last episode you finished, and your last 20 messages in that conversation;
- the reply is checked by Content Safety again before you see it;
- the conversation is stored in our database in India so you can see it later and the character can stay consistent.
The AI model runs in Microsoft’s Sweden Central region, so your chat messages are processed in the EU. Microsoft acts as our processor. Under Microsoft’s terms for Azure OpenAI, customer prompts and replies are not used to train OpenAI’s or Microsoft’s models. Microsoft may keep prompts and replies for a limited time (we understand up to 30 days) to detect abuse, unless we are approved for an exemption.
We do not use your chat messages to train any AI model, and we do not sell them or use them for advertising.
Our staff do not routinely read chat conversations. A person may look at a specific message if you or someone else reports it, if we need to investigate misuse or a safety issue, or if the law requires it.
6.3 Crisis messages
If a message suggests you may be thinking about suicide or self-harm, the character does not reply and the message is not sent to the AI model. Instead, the app shows helplines for your country. The message is stored with a flag. We do not contact anyone on your behalf. See AI Transparency for the full protocol.
7. Who we share data with
We do not sell your personal data, and we do not share it for targeted (“cross-context behavioural”) advertising. We share data only as follows.
7.1 Service providers (processors)
These companies process data for us, on our instructions, under contracts that require them to protect it.
| Provider | What they do for us | Data they receive | Where |
|---|---|---|---|
| Microsoft Azure (Microsoft Corporation and affiliates) | Hosting, database, file storage, cache, logs | All data described in this policy | India (Central India region) |
| Microsoft Azure OpenAI Service | Writing character chat replies; drafting story scripts | Chat messages and conversation context; story material (no listener data) | Sweden (Sweden Central region, EU) |
| Microsoft Azure AI Content Safety | Checking chat messages for harmful content | Chat messages | Sweden (EU) |
| Microsoft Azure Speech | Producing AI voices for stories | Story scripts only | Sweden (Sweden Central region, EU) |
| Microsoft Azure Communication Services | Sending verification and password-reset emails | Your email address and the code | India (data at rest); delivery is global |
| RevenueCat, Inc. | Managing in-app purchases and subscriptions | Your internal account number, store receipts and transaction data, product and price, device and app information | United States |
| Google (Google LLC / Google Ireland) | Google Sign-In; Google Play billing; push notifications via Firebase Cloud Messaging when enabled | Sign-in token exchange; purchase data handled by Google; push token and notification content | United States and other locations |
| Apple (Apple Inc. / Apple Distribution International) | Sign in with Apple; App Store billing; push notifications via Apple Push Notification service when enabled | Sign-in token exchange; purchase data handled by Apple; push token and notification content | United States and other locations |
| ElevenLabs | AI voices for some characters (not currently in use) | Story scripts only, never listener data | United States (not currently in use) |
| PostHog, Inc. | Product analytics — not switched on; only with your consent | App events as described in 2.10 | EU (Frankfurt, Germany) |
| Google AdMob | Rewarded ads — not switched on | Ad reward confirmations; data the ad SDK collects on your device | United States |
Apple and Google are also independent controllers for the data they collect when you use their stores, accounts and devices; their own privacy policies apply.
7.2 Other disclosures
- Legal requirements: to courts, police, regulators or other authorities when the law requires it, including valid orders under Indian law (for example the IT Act and IT Rules) and lawful requests in other countries. Where allowed, we will tell you.
- Safety: to protect someone’s life or safety, or to prevent fraud or serious harm.
- Advisers: to our lawyers, accountants and auditors, under confidentiality.
- Business changes: if we merge, are acquired or sell the Service, data may pass to the new owner, who must respect this policy or tell you about changes.
- With your instruction: for example when you share your data export with someone.
8. International transfers
We are based in India and store your data in Microsoft Azure’s Central India region. Some processing happens elsewhere:
- EU (Sweden): character chat messages (Azure OpenAI), and story scripts for voice production (Azure Speech);
- United States: purchase data (RevenueCat), and data handled by Apple and Google; analytics (PostHog) and ads if switched on and if those providers process in the US;
- other countries where our providers operate.
How transfers are protected:
- From India: the DPDP Act allows transfers outside India except to countries the Government restricts. We will follow any such restriction.
- From the UK and EU: India does not have an EU or UK “adequacy” decision. Where the GDPR or UK GDPR treats our processing as a transfer, we use the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or our providers’ equivalent safeguards, plus additional measures such as encryption in transit. You can ask us for a copy (section 12).
- Canada and Australia: we remain accountable for data we send to providers abroad and require them, by contract, to protect it to a comparable standard.
9. Children and teenagers
- Under 13: Turtle FM is not for children under 13. The age screen blocks them, and we send nothing to our servers when “Under 13” is chosen. We do not knowingly collect personal information from children under 13, and the Service is not directed to children, so we do not seek parental consent under the US Children’s Online Privacy Protection Act (COPPA). If we learn that we have collected data from a child under 13, we delete it. Parents can contact contact@turtletechsai.com.
- India — under 18: the DPDP Act treats everyone under 18 as a child and requires verifiable parental consent. We do not collect parental consent. In India the Service is for adults (18+) only, and the app refuses to create an account when someone in India selects “13–17”.
- Teens aged 13–17 (outside India): can listen to stories rated 13+. They cannot see stories rated 16+ or 18+, cannot turn on Mature stories, and cannot use character chat. Their optional settings (analytics, notifications, ad tracking) are off by default, and we will not use their data for targeted advertising.
- Age is self-declared. We do not verify identity documents.
More detail: Age and Children’s Safety.
10. How long we keep data
We keep data only as long as we need it for the purposes above or as the law requires. When you delete your account, most data is erased immediately (section 12.1 and Delete your account). A clean-up job runs every 30 minutes to apply the periods below.
| Data | How long |
|---|---|
| Account, preferences, listening activity, story choices, library, unlocks, wait timers | Until you delete your account. Guest accounts (never signed in) with no listening for 24 months are erased automatically |
| Character chat messages | 12 months from when each message was sent, or until you delete your account if sooner |
| Email sign-in data (email, password hash) | Until you delete your account |
| One-time email codes | Valid for 30 minutes; the hashed record is deleted 7 days after it expires, and immediately when you delete your account |
| Refresh tokens (hashed) | Valid for up to 60 days; revoked on sign-out, password reset and deletion; deleted 30 days after expiry or revocation |
| Coin ledger and purchase records | 8 years after the transaction, for tax, accounting and refund handling. After account deletion they are kept linked only to an internal account number with no sign-in details |
| Sign-in identifiers of a deleted account (email address or Google/Apple account ID) and the deletion date, in a restricted record no product feature uses | 180 days after deletion, as required by the IT Rules 2021 (rule 3(1)(h)), then deleted automatically |
| Consent records | For as long as your account exists and then 3 years after the account is closed to prove what you agreed to |
| Reports, complaints and takedown records | 3 years; and at least 180 days where the IT Rules require it. If you delete your account, your name and contact details are removed from reports you filed, but the report text is kept |
| Server and security logs (including IP addresses) | 180 days; at least 180 days in India where CERT-In directions require it |
| Database backups | Rolling 7 days; deleted data disappears from backups when they expire |
| Analytics events (when switched on) | 12 months |
| Support emails | 3 years |
11. How we protect your data
- Data is encrypted in transit (HTTPS/TLS). Data at rest is encrypted by Microsoft Azure’s storage and database encryption.
- Passwords are stored only as salted scrypt hashes. Refresh tokens and email codes are stored only as hashes.
- Sign-in is protected against guessing: five wrong passwords lock email sign-in for 15 minutes.
- Audio files are served through links that expire within an hour.
- The admin site is reachable only from approved network addresses; every admin action and configuration change is recorded in an audit log.
- Staff access is limited to people who need it for their role.
- We never store payment card details.
No system is perfectly secure. If you think your account has been compromised, contact contact@turtletechsai.com.
12. Your rights
12.1 Rights everyone has with us
Wherever you live, you can:
- Download a copy of your data — in the app, Profile → Privacy and data → Download my data. You get a machine-readable (JSON) file you can save or share.
- Delete your account and data — in the app, Profile → Delete account and data; on the web, sign in and go to Profile → Delete account; or email us. See Delete your account.
- Change your privacy choices at any time (section 4).
- Correct your data — change your language, genres and settings in the app, or email us for anything you cannot change yourself.
- Complain to us and, if unsatisfied, to your regulator.
How we handle requests. For requests by email, we may ask you to prove the account is yours. For email accounts we reply to the address on the account. Because we do not store the email address of Google, Apple or guest accounts, we may ask you to make the request from inside the app, which proves it is your account. We respond within the time the law sets (section 12.2 onwards) and do not charge, unless a request is clearly unfounded or excessive where the law allows a fee or refusal.
12.2 India (DPDP Act)
You have the right to: access a summary of your personal data and processing; know who we have shared it with; correct, complete, update and erase it; grievance redressal; and nominate someone to exercise your rights on your behalf if you die or are incapacitated. To nominate, email contact@turtletechsai.com with the nominee’s name and contact details. Complaints first go to our Grievance Officer; then you may approach the Data Protection Board of India.
12.3 UK and EU/EEA (UK GDPR and GDPR)
You have the right to: access; rectification; erasure; restriction; data portability; object to processing based on legitimate interests; withdraw consent at any time; and not be subject to solely automated decisions with legal or similarly significant effects. We respond within one month, extendable by two further months for complex requests. You can complain to the UK Information Commissioner’s Office (ico.org.uk) or the data protection authority in the EU country where you live or work. We would appreciate the chance to resolve your concern first.
12.4 United States — California and other states
California Notice at Collection and CCPA disclosures. In the last 12 months we have collected the following categories of personal information. We collect them directly from you or your device, and from Apple, Google and RevenueCat (purchase and sign-in confirmations).
| CCPA category | Examples from Turtle FM | Collected | Business purposes | Disclosed for a business purpose to | Sold or shared |
|---|---|---|---|---|---|
| Identifiers | Random device ID, internal account number, Google/Apple account ID, email address, IP address, push token | Yes | Account, security, service delivery, purchases | Microsoft, RevenueCat, Google, Apple | No |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Email address, display name | Yes | Account, support | Microsoft, Azure Communication Services | No |
| Characteristics of protected classifications | Age band (13–17 or 18+) | Yes | Age rules | Microsoft | No |
| Commercial information | Coin purchases, VIP subscriptions, coin ledger, unlocked episodes | Yes | Delivering purchases, refunds, accounting | Microsoft, RevenueCat, Apple, Google | No |
| Internet or other electronic network activity | Listening progress, story choices, app events (analytics only if switched on and consented) | Yes | Service delivery, personalisation, analytics with consent | Microsoft; PostHog when enabled | No |
| Geolocation data | Country (market) and time zone only — not precise location | Yes (coarse) | Prices, catalogue, age rules, daily limits | Microsoft | No |
| Audio, electronic, visual or similar | Not collected from you (we do not record your voice) | No | — | — | — |
| Professional, employment or education information | Not collected | No | — | — | — |
| Inferences | Genre preferences | Yes | Ordering your home screen | Microsoft | No |
| Sensitive personal information | Account log-in (email and password) | Yes | Signing you in only | Microsoft | No |
| Contents of communications | Character chat messages (we are the intended recipient) and reports | Yes | Chat replies, safety, complaints | Microsoft (Azure OpenAI, Content Safety) | No |
Retention periods are in section 10.
We do not sell or share personal information, as “sell” and “share” are defined by the CCPA, and have not done so in the last 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16. We use sensitive personal information only to sign you in and keep your account secure, which the CCPA permits without offering a right to limit.
Your California rights: to know what we collect, use and disclose; to access and receive a copy; to delete; to correct; to opt out of sale or sharing (we do neither); to limit use of sensitive personal information (we use it only for permitted purposes); and not to be discriminated against for using these rights. You can use them in the app or by emailing contact@turtletechsai.com with “California privacy request” in the subject. You may use an authorised agent; we may ask the agent for signed permission and ask you to confirm your identity. We confirm receipt within 10 business days and respond within 45 calendar days (extendable by 45 days with notice).
Global Privacy Control (GPC): if your browser sends a GPC signal to our web app, we treat it as a request to opt out of sale and sharing for that browser, and we will not switch on optional analytics for that browser. Because we do not sell or share personal information, this does not change anything else today.
Shine the Light (Cal. Civ. Code § 1798.83): we do not disclose personal information to third parties for their own direct marketing.
Other US states (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others with consumer privacy laws): you have similar rights to access, correct, delete and obtain a copy of your data, and to opt out of targeted advertising, sale and profiling with significant effects. We do not sell personal data, do not use it for targeted advertising and do not profile you in ways that produce legal or similarly significant effects. If we refuse a request, you can appeal by replying to our decision with “Appeal” in the subject; we will answer within the time your state’s law requires, and if you disagree you may contact your state Attorney General.
Do Not Track: our Service does not track you across other websites or apps.
12.5 Canada (PIPEDA)
You can access and correct your personal information and withdraw consent, subject to legal and contractual limits. Contact contact@turtletechsai.com; we respond within 30 days. If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information.
12.6 Australia (Privacy Act 1988)
You can access and correct your personal information. Contact contact@turtletechsai.com; we aim to respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). We may disclose personal information to recipients overseas as described in sections 7 and 8, mainly in India, Sweden and the United States.
13. Data breaches
If a personal data breach happens, we will contain it, assess it and notify as the law requires, including:
- India: the Data Protection Board of India and each affected person, without delay, with a detailed report to the Board within the time the DPDP Rules set (we understand 72 hours); and CERT-In within 6 hours of noticing a reportable cyber security incident;
- UK and EU: the relevant supervisory authority within 72 hours where required, and you without undue delay if the breach is likely to result in a high risk to you;
- US: affected people and authorities as state breach-notification laws require;
- Canada: the Privacy Commissioner and affected people where there is a real risk of significant harm;
- Australia: the OAIC and affected people for an eligible data breach.
We will tell you what happened, what data was involved, what we are doing and what you can do.
14. Changes to this policy
We will update this policy when the Service changes — for example before we switch on analytics, rewarded ads, web payments or a new provider. The “last updated” date and version at the top will change. For material changes we will tell you in the app before they take effect and, where the law requires, ask for your consent again. Previous versions are available on request.
15. Contact
- Privacy questions and requests: contact@turtletechsai.com
- Grievance Officer (India): Akshay Gupta, contact@turtletechsai.com
- General: contact@turtletechsai.com, +91 78418 53298
- Post: Turtle Techsai, Nagpur, Maharashtra, India, Nagpur, Maharashtra, India
Related pages: Terms of Use · Cookies and Local Storage · Delete your account · Age and Children’s Safety · AI Transparency · Grievance Redressal · Contact