Welcome to the Jana Legal Hub. This page outlines the guidelines, terms of service, and privacy commitments that govern your use of the Jana mobile application.
Last Updated: 06/25/2026 Version: 1.0
This Privacy Policy explains how Jana ("we," "us," or "our"), the operator of the Jana mobile application ("App"), collects, uses, stores, shares, and protects your personal data.
It is issued under:
By creating an account or using the App, you acknowledge that you have read and understood this Policy.
This Policy applies to all registered users ("you" or "Data Principal") of the Jana App, including visitors who interact with the App for the purpose of creating an account.
We collect the following categories of personal data directly from you:
| Data | Purpose | Mandatory? |
|---|---|---|
| Email address | Account creation, authentication, OTP verification | Yes |
| Password (hashed by Supabase Auth) | Authentication | Yes |
| Gender | Profile creation | Yes |
| Data | Purpose | Mandatory? |
|---|---|---|
| Full name | Displayed on your profile cards | Yes |
| Profession | Displayed on your profile cards | Yes |
| Company | Displayed on your profile cards | No |
| Personal bio | Displayed on your casual card | No |
| Professional bio | Displayed on your professional card | No |
| Profile photo (avatar) | Displayed on your profile | No |
| Personal phone number | Shared with connections per your access settings | No |
| Professional phone number | Shared with connections per your access settings | No |
| Professional email address | Shared with connections per your access settings | No |
| Instagram handle | Shared with connections per your access settings | No |
| LinkedIn handle | Shared with connections per your access settings | No |
| Twitter/X handle | Shared with connections per your access settings | No |
| Spotify profile | Shared with connections per your access settings | No |
| Custom links (name + URL) | Shared with connections per your access settings | No |
show_profile_to_connections flag)We do not collect:
Under Rule 3 of the SPDI Rules, 2011, the following data we collect qualifies as Sensitive Personal Data or Information (SPDI):
SPDI is processed only with your free, specific, informed, and unambiguous consent, and is subject to the security practices described in Section 9 of this Policy.
We use your personal data only for the purposes for which it was collected:
| Purpose | Legal Basis (DPDP Act) | Legal Basis (IT Act / SPDI Rules) |
|---|---|---|
| Creating and managing your account | Consent (Section 6) | Rule 5(3) |
| Displaying your profile to connections you approve | Consent (Section 6) | Rule 5(3) |
| Facilitating direct messaging between connected users | Consent / Contractual necessity | Rule 5(3) |
| Sending push notifications for new messages | Consent (Section 6) | Rule 5(3) |
| Enforcing Monk Mode (blocking/hiding selected connections) | Consent (Section 6) | Rule 5(3) |
| Enabling QR-based and invite-code-based connections | Consent (Section 6) | Rule 5(3) |
| Security, fraud prevention, and technical debugging | Legitimate use (Section 7) | Rule 8 |
| Complying with legal obligations | Legitimate use (Section 7) | Section 67C, IT Act |
We do not sell your personal data. We do not use your data for advertising, profiling for commercial recommendations, or automated decision-making that produces legal or similarly significant effects.
Profile data you share with a connection is disclosed only to that specific connection, and only at the card access level (casual or professional) that you configure. Connections cannot see fields you have not assigned to the card type you shared with them.
Chat messages are visible only to the sender and the intended recipient.
We engage the following sub-processors who process your data solely on our behalf and under our instructions:
| Processor | Data Processed | Purpose | Privacy Reference |
|---|---|---|---|
| Supabase, Inc. (USA) | Account credentials, profile data, messages, connection data | Database, authentication, real-time communication | supabase.com/privacy |
| Google LLC / Firebase (USA) | FCM device token | Push notification delivery | policies.google.com/privacy |
| Google LLC (USA) | Google account details (only when you use Google Sign-In) | OAuth-based authentication | policies.google.com/privacy |
These processors are bound by agreements requiring them to process your data only for the purposes above and to maintain appropriate security standards. Data may be transferred outside India to the servers of these processors. Such transfers are made in reliance on the contractual safeguards these processors maintain and, when applicable, any adequacy determinations or standard contractual clauses.
We may disclose your personal data to a government authority or law enforcement agency if required by a valid court order, applicable law (including Sections 69 and 69B of the IT Act), or to protect the safety of any person.
We will not otherwise disclose your personal data to any third party.
The App stores a local SQLite database (connect_chat.db) on your device containing:
This data is stored on your device to enable offline access and faster loading. It is not accessible to third parties through the App. If you uninstall the App or clear App data, this local database is deleted from your device.
| Data Category | Retention Period |
|---|---|
| Account and profile data | Until you delete your account, plus 30 days for backup recovery purposes |
| Chat messages (server copy) | Until you delete the message or your account |
| Chat messages (local device copy) | Until you clear app data or uninstall the App |
| FCM push token | Refreshed automatically by Firebase; deleted from our servers when your account is deleted |
| Invite codes (redeemed) | 30 days after redemption |
| Connection data | Until you disconnect from the other user or delete your account |
| Monk Mode settings (server) | Until you disable Monk Mode or delete your account |
When an account is deleted, we will delete or anonymize all associated personal data within 30 working days, except where retention is required by applicable law.
We implement the following reasonable security practices as required under Rule 8 of the SPDI Rules and Section 8 of the DPDP Act:
Despite these measures, no system is completely secure. You are responsible for maintaining the confidentiality of your account credentials.
The App is not intended for use by individuals under the age of 18 years. We do not knowingly collect personal data from children.
Under Section 9 of the DPDP Act, processing the personal data of a child requires verifiable parental consent. If you are under 18, please do not register or use the App.
If we become aware that we have inadvertently collected personal data from a child, we will delete it promptly. To report such a case, contact our Grievance Officer (Section 13 below).
Under the DPDP Act, 2023, and the SPDI Rules, 2011, you have the following rights:
You may request a summary of the personal data we hold about you and the purposes for which it is being processed.
You may correct or update inaccurate or incomplete profile data directly within the App. For data you cannot edit in-app, submit a written request to our Grievance Officer.
You may delete your account at any time from within the App. Deleting your account initiates deletion of your profile, connection data, and server-stored messages. Data retained for legal compliance will be clearly identified.
You may withdraw consent for specific processing activities (e.g., push notifications) through your device settings. Withdrawing consent does not affect the lawfulness of processing that occurred before withdrawal. Note that withdrawing consent for core processing (authentication, profile storage) will result in you being unable to use the App and may require account deletion.
You may file a complaint with our Grievance Officer (Section 13 below). If your grievance is not resolved within the prescribed period, you may approach the Data Protection Board of India under Section 16 of the DPDP Act once it is constituted.
To exercise any of the above rights, contact the Grievance Officer with your registered email address and a clear description of your request.
Your profile may contain custom links to external websites (e.g., personal portfolios). We are not responsible for the privacy practices or content of those external sites. Access them at your own discretion.
As required under Rule 9 of the SPDI Rules, 2011, and Section 13 of the DPDP Act, 2023, we have appointed a Grievance Officer:
Name: Santosh patil Designation: founder Organisation: Jana App Email: santoshpatil@joinmandala.in Address: Bangalore, Karnataka, India Response Time: We will acknowledge your grievance within 24 hours and resolve it within 30 days of receipt, as required under the SPDI Rules.
We may update this Privacy Policy to reflect changes in the App, our practices, or applicable law. When we make material changes, we will notify you through an in-app notice before the change takes effect. Continued use of the App after the effective date constitutes acceptance of the updated Policy.
For any privacy-related questions that do not constitute a formal grievance, you may reach us at:
Email: santoshpatil@joinmandala.in Address: Bangalore, Karnataka, India
Last Updated: 06/25/2026 Version: 1.0
These Terms of Service ("Terms") constitute a legally binding agreement between you and Jana ("we," "us," or "our"), governing your access to and use of the Jana mobile application ("App").
By creating an account, you confirm that you are at least 18 years old, that you have read and understood these Terms, and that you agree to be bound by them. If you do not agree, do not use the App.
Jana is a private networking application that enables users to build intentional, QR-based connections and communicate through direct messaging. Core features include:
You must be at least 18 years old to use the App. By using the App, you represent and warrant that you meet this requirement. We reserve the right to suspend or delete accounts found to belong to individuals under 18.
You agree to:
One person may maintain one primary account. Creating multiple accounts to circumvent a suspension or ban is prohibited.
You agree not to:
You retain ownership of all content you create in the App, including your profile information, messages, and custom links.
By providing content to the App, you grant us a limited, non-exclusive, royalty-free licence to store and transmit that content solely for the purpose of operating and providing the App to you and your connections. We claim no ownership over your content.
You are solely responsible for the accuracy of the information you provide in your profile. We do not verify user-provided data.
Messages sent between users are stored on our servers (Supabase) and cached locally on devices for delivery purposes. We do not monitor message content except where required by law or to investigate a specific complaint of a legal violation.
The connection and data-sharing features of the App are designed to operate under your explicit control. You initiate every connection by scanning a QR code or redeeming an invite code, and you control what data each connection can see through your card access settings.
You agree not to scan another user's QR code without that user's knowledge and consent.
Monk Mode is a focus feature that allows you to temporarily hide selected connections. When Monk Mode is active, hidden connections will not be able to message you and you will not receive notifications from them for the duration. This feature is stored locally on your device and synced with our servers. You are responsible for the settings you configure in Monk Mode.
All intellectual property rights in the App, including the Jana brand, its design, code, and all materials we create, are owned by or licensed to us. Nothing in these Terms transfers any intellectual property rights to you.
You may not copy, modify, reverse engineer, disassemble, or create derivative works of the App.
You may delete your account at any time from within the App settings. Upon deletion, your profile, connections, and server-side messages will be removed in accordance with our Privacy Policy.
We may suspend or terminate your account, with or without notice, if:
Upon termination, your right to use the App ends immediately.
The App is provided "as is" and "as available." To the fullest extent permitted by law:
To the maximum extent permitted under the IT Act and applicable Indian law, our aggregate liability to you for any claim arising out of or relating to the App or these Terms shall not exceed INR 500 or the amount you paid us in the preceding 12 months, whichever is lower.
We shall not be liable for any indirect, incidental, consequential, or punitive damages, including loss of data, loss of revenue, or reputational harm, even if we have been advised of the possibility of such damages.
Nothing in this clause limits our liability for death or personal injury caused by our negligence, fraud, or any liability that cannot be excluded by law.
You agree to indemnify and hold harmless Jana and its founders, officers, and employees from any claims, losses, damages, liabilities, and expenses (including legal fees) arising out of your use of the App, your violation of these Terms, or your violation of any applicable law or third-party rights.
These Terms are governed by the laws of the Republic of India, including the IT Act, 2000, and the DPDP Act, 2023. The courts of Bangalore, India shall have exclusive jurisdiction over any dispute arising out of or in connection with these Terms.
Before initiating any legal proceeding, you agree to notify us in writing at santoshpatil@joinmandala.in and allow 30 days for us to attempt to resolve the dispute amicably.
We may modify these Terms at any time. When we make material changes, we will provide in-app notice at least 1 days before the changes take effect. Continued use of the App after the effective date constitutes your acceptance of the modified Terms.
Jana Bangalore, India Email: santoshpatil@joinmandala.in
Purpose: This notice is to be presented to users at the point of registration (before they submit the sign-up form) under Section 5 and Section 6 of the DPDP Act, 2023.
Implementation note. Display this notice as a modal or scrollable text block before the user taps "Create Account." Require an explicit checkbox tap (the checkbox must be unchecked by default) accompanied by the declaration text below. Do not pre-tick the checkbox. Link to the full Privacy Policy and Terms of Service from within this notice.
Before you create your account, please read the following:
By creating a Jana account, you give Jana your free, specific, informed, and unambiguous consent to collect and process the following personal data for the purposes stated:
| Data | Purpose |
|---|---|
| Email address | To create and authenticate your account |
| Password | To secure your account (stored in hashed form; never visible to us) |
| Gender | To create your profile |
| Name, profession, and optional profile details | To display on the profile cards you choose to share with connections |
| Profile photo | To display on your profile |
| Chat messages | To deliver messages to your connections |
| Device push token | To send you notifications about new messages |
| Connection data | To display and manage your list of connections |
Your data is processed by:
Your rights: You may access, correct, or delete your data at any time through the App settings. You may withdraw this consent at any time, though doing so for core data will prevent you from using the App. You may also contact our Grievance Officer at santoshpatil@joinmandala.in.
This notice is issued under Section 5 of the Digital Personal Data Protection Act, 2023.
For full details, read our Privacy Policy and Terms of Service.
Declaration (checkbox — unchecked by default):
☐ I am at least 18 years old. I have read and understood the Consent Notice, Privacy Policy, and Terms of Service. I give my free, informed, and unambiguous consent to the collection and processing of my personal data as described above.
Fill each placeholder before publishing:
| Placeholder | What to enter |
|---|---|
Jana |
Your registered company or LLP name (e.g., XYZ Technologies Private Limited) |
25 June 2026 |
The date you publish the document (DD Month YYYY) |
santosh patil |
Full name of the designated Grievance Officer |
Founder and CEO |
Their role (e.g., Founder, Co-Founder, Chief Privacy Officer) |
santoshpatil@joinmandala.in |
A monitored email for privacy complaints (e.g., privacy@yourdomain.com) |
santoshpatil@joinmandala.in |
General contact email |
Bangalore |
Your GSTIN-registered or ROC-registered address |
Bangalore |
City with exclusive jurisdiction for disputes |
500 |
Your liability cap in INR (typically INR 500 or equivalent to subscription paid) |
30 days (retention grace period) |
How many days post-deletion before data is fully purged (typical: 30 days) |
30 days (invite code retention) |
How long you keep redeemed invite codes (typical: 30 days) |
7 days (Terms change notice) |
Notice period before new Terms take effect (typical: 7–14 days) |
| Reference | What It Requires for This App |
|---|---|
| IT Act, 2000 — Section 43A | Maintain reasonable security for SPDI (password, gender) |
| IT Act, 2000 — Section 72A | Prohibition on unauthorized disclosure of personal information |
| SPDI Rules, 2011 — Rule 4 | Publish a Privacy Policy (this document) |
| SPDI Rules, 2011 — Rule 5 | Inform users of what is collected and why; obtain written consent for SPDI |
| SPDI Rules, 2011 — Rule 6 | Do not disclose SPDI to third parties without consent (except sub-processors under contract) |
| SPDI Rules, 2011 — Rule 7 | Ensure any international data transfer maintains equivalent protection |
| SPDI Rules, 2011 — Rule 8 | Implement IS/ISO/IEC 27001 or equivalent security practices |
| SPDI Rules, 2011 — Rule 9 | Designate and publish Grievance Officer details |
| DPDP Act, 2023 — Section 5 | Provide a consent notice before collecting personal data |
| DPDP Act, 2023 — Section 6 | Obtain free, specific, informed, unconditional, and unambiguous consent |
| DPDP Act, 2023 — Section 8 | Ensure data accuracy, storage limitation, and security safeguards |
| DPDP Act, 2023 — Section 9 | Do not process personal data of children under 18 without verifiable parental consent |
| DPDP Act, 2023 — Sections 11–13 | Honour rights to access, correction, erasure, and grievance redressal |
| DPDP Act, 2023 — Section 16 | Users may escalate unresolved complaints to the Data Protection Board |