Privacy Policy for DOTY Day of the Year 2 ("DOTY")

Last Updated and
Effective Date:
July 23, 2026

This Privacy Policy describes how DOTY Day of the Year 2 ("DOTY") ("We", "Us", "Our", or the "Company") collects, processes, uses, and protects your personal data when you use our mobile application and related services.

We are committed to protecting your privacy in strict accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the Information Technology Act, 2000, and Google Play Data Safety guidelines.

🛡️ Core Commitment: 100% Offline & Zero Tracking

DOTY Day of the Year 2 ("we", "our", or "the app") is engineered from the ground up as an offline-first, zero-tracking application. We respect that your personal schedules, daily alarms, mission milestones, and year-progress trackers are private information that belongs solely to you.

1. Roles Under the DPDP Act, 2023

Data Fiduciary: Because DOTY operates entirely locally on your device without transmitting, processing, or storing personal data on cloud servers or sharing data with third parties, we do not act as a server-side Data Fiduciary under the DPDP Act.
Data Principal: You (the user accessing our Application) act as the Data Principal under Section 2(j) of the DPDP Act. Your local storage consent is provided by using the offline utility, and you retain full autonomy to modify or erase your data instantly within the app.

2. Notice of Itemized Data Collection (Section 5, DPDP Act)

We collect and process the following specific categories of personal data with your explicit consent:

A. No Cloud Servers or Remote Databases

What is collected: None (Zero server-side harvesting).
Purpose: We do not own, maintain, or operate any remote servers that collect, transmit, or store your personal information.

B. No Third-Party Analytics SDKs

What is collected: None.
Purpose: We do not embed analytics tracking libraries (such as Google Analytics, Firebase Analytics, Mixpanel, or Amplitude) to monitor your behavior or usage patterns.

C. No Crash Exfiltration SDKs

What is collected: None.
Purpose: We do not use third-party crash reporters (such as Crashlytics or Sentry) that silently upload device logs or hardware fingerprints to external servers.

D. No Advertising SDKs or Identifiers

What is collected: None.
Purpose: We do not serve advertisements, track user activity across other apps, or access unique device advertising IDs (ADID, Android ID, or IMEI).

E. 100% Local Device Storage

What is collected: Custom mission trackers, countdown timers, alarm configurations, UI theme settings, and home screen widget preferences.
Purpose: All data generated inside the application is saved locally on your personal device using encrypted/device-bound local storage (Hive and SharedPreferences). You retain 100% ownership and autonomy over all your data at all times.

Device Permissions & Justifications

To perform its advertised core functionality as an advanced time tracker, mission countdown tool, and exact alarm clock, our application requests specific operating system permissions:

POST_NOTIFICATIONS (Local Notifications)
Used strictly to display countdown timers, mission overflow alerts, Day of the Year progress updates, and exact alarm notifications directly on your device screen. No notification data is sent over the internet.
SCHEDULE_EXACT_ALARM & USE_EXACT_ALARM (Exact Alarms)
Required under Android 12+ (API 31–36) so your scheduled alarms, mission milestones, and timers trigger at precise timestamps, even when your device rests in Doze power-saving mode. Because accurate timing is the fundamental utility of the application, these permissions are essential for core functionality.
WAKE_LOCK (Keep Screen Awake)
Used optionally when you explicitly toggle on the "Keep Screen On" preference during active mission focus sessions to prevent the display from turning off.
RECEIVE_BOOT_COMPLETED (System Reboot)
Used to automatically reschedule your local alarms and notifications when your phone reboots after being powered down.
VIBRATE (Haptic Feedback)
Used to trigger tactile vibrations when pressing UI buttons and when your local alarms ring.

3. Consent & Right to Withdraw Consent (Section 6, DPDP Act)

Your local storage consent is provided by using the offline utility, and you retain full autonomy to modify or erase your data instantly within the app at any time.

Right to Withdraw Consent (Section 6(4))

You have the absolute right to withdraw your consent at any time. You can withdraw consent by:

To Edit or Delete Specific Items: You can modify or delete any mission, alarm, timer, or preference directly within the app UI at any time.
To Erase All App Data Instantly: You can permanently wipe all locally saved data by going to your device's Settings > Apps > DOTY > Storage > Clear Data, or simply by uninstalling the application.

Deletion happens instantly on your phone without needing to submit server-side deletion requests or wait for processing.

4. Right to Erasure / Account Deletion (Section 12(3), DPDP Act & Google Play)

Because all your data resides exclusively inside your personal device's storage, you have total and immediate control over its lifecycle.

In-App Deletion: To Edit or Delete Specific Items: You can modify or delete any mission, alarm, timer, or preference directly within the app UI at any time.
Manual Deletion: To Erase All App Data Instantly: You can permanently wipe all locally saved data by going to your device's Settings > Apps > DOTY > Storage > Clear Data, or simply by uninstalling the application. Deletion happens instantly on your phone without needing to submit server-side deletion requests or wait for processing.

5. Third-Party Data Processors & Disclosure (Section 8 & Section 16)

We adhere strictly to data minimization and zero server-side harvesting. We do not sell, share, transmit, or disclose any of your personal data to any third-party data processors, cloud servers, or external services. All data remains strictly and exclusively on your personal device at all times.

6. Data Security & Storage (Section 8(5))

All data generated inside the application is saved locally on your personal device using encrypted/device-bound local storage (Hive and SharedPreferences). You retain 100% ownership and autonomy over all your data at all times.

7. Children's Privacy

DOTY does not collect personal data from anyone, including children under the age of 13. The application is completely safe for children, students, and families (COPPA compliant).

8. External Links & Third-Party Websites

Our app’s Developer Info section contains voluntary external links (such as the developer’s GitHub profile or Ko-fi support page). If you choose to tap these links, you will navigate away from DOTY to third-party websites governed by their own independent privacy policies. We do not transmit or share any app data with those external websites.

9. Developer Contact & DPDP Act Compliance (Section 8(9) & Section 13)

In compliance with Section 8(9) and Section 13 of the Digital Personal Data Protection Act, 2023, the contact details of the Developer are published below:

Name: Tanay Mishra
Role: Solo Developer
Address: India
Response Timeline: If you have any questions, regulatory inquiries, or feedback regarding this Privacy Policy or our data safety practices, please reach out directly via email at tanayanandmishra@gmail.com.

Right to Approach the Data Protection Board (Section 13(3))

If your inquiry or grievance is not resolved to your satisfaction by the Developer, you have the statutory right to file a formal complaint with the Data Protection Board of India (DPBI).

10. Changes to this Privacy Policy

We may update our Privacy Policy periodically to reflect changes in legal or technical requirements. Any updates will be displayed directly within the application or published alongside new version releases.

11. European Union (GDPR) & California (CCPA) Privacy Rights

GDPR Legal Basis: European Union & UK GDPR: Under GDPR Article 6(1)(b) and ePrivacy Directive Article 5(3), local device storage (Hive / SharedPreferences) used solely to deliver the specific functional features requested by the user (storing alarms and countdown missions) is strictly necessary and exempt from tracking consent banners. No personal data of European Economic Area or UK citizens is transferred across borders or shared with third parties.
CCPA "Do Not Sell or Share My Personal Information": California Consumer Privacy Act (CCPA / CPRA): DOTY does not collect, sell, share, rent, or monetize any personal information of California consumers to third parties under any circumstances. Therefore, no "Do Not Sell or Share My Personal Information" opt-out link is required.