1. Introduction
Dohvara lets exactly two people draft, sign, update, and verify a home-work agreement. This policy explains the information processed to provide that shared record and the controls available to each person.
2. Information we collect and process
- Account and membership data: Firebase creates an anonymous account identifier. The service stores the two member identifiers assigned to an agreement.
- Agreement data: names, roles, scope lines, material responsibility, amounts, target dates, milestones, objections, amendments, and signatures are encrypted on the phone before transmission. The backend stores ciphertext and cannot read this private text.
- Verification metadata: agreement and event identifiers, event type, sequence and logical timestamps, hashes, public signing keys, signatures, and synchronization timestamps.
- Evidence photos: the camera is used only after a tradesperson chooses “Mark done with photo.” The image remains on the agreement phones. The backend stores a cryptographic hash, not the image. An encrypted photo may pass transiently through the Cloudflare two-peer relay while both people are connected; the relay does not persist it.
- Safety data: if a person files a report or blocks the counterpart, Firebase stores limited identifiers, a report reason, an optional event reference, time, and review status.
- Network information: Firebase and Cloudflare necessarily receive routine connection information such as IP address while providing their services.
Dohvara does not include analytics, advertising, location, contacts access, payment processing, credit scoring, or cloud photo storage.
3. How we use information
Information is used only to authenticate two agreement seats, relay signed encrypted events, synchronize the append-only history, verify integrity, relay an evidence photo directly between the two phones, prevent a third participant from entering an agreement, and review safety reports.
4. Data sharing and service providers
Dohvara does not sell personal information. It uses:
- Google Firebase Authentication and Cloud Firestore for anonymous sign-in, private two-member access control, encrypted event synchronization, block records, and abuse reports.
- Cloudflare Workers and Durable Objects for an authenticated, non-persistent two-peer encrypted relay used by evidence transfer.
- Your email app only if you choose Send Feedback. Dohvara opens a mail draft; the app itself does not send or store the email.
The other party receives the agreement events and evidence that you intentionally add to the shared record.
5. Storage, security, and retention
Private event payloads use AES-256-GCM encryption. Each device signs events with an ECDSA key kept in Android Keystore. Join codes and display names are encrypted in local storage. Firestore rules limit agreement events to the two registered account identifiers.
Local data remains until it is archived, the app data is cleared, or account and local data are deleted in the app. Backend encrypted events remain while the agreement service is required. Safety reports may be retained as needed for review, prevention, and legal obligations. Deletion from one phone cannot erase a legitimate signed copy already received by the other party.
6. Your choices and deletion
You may decline the camera permission and continue using agreement features without photo evidence. In Dohvara, open Privacy → Delete account and local data to delete the anonymous account where possible and clear all local agreements on that phone. You may also email www.saifullah.ai@gmail.com for a privacy or deletion request.
7. Children
Dohvara is designed for adults making direct home-work agreements. We do not knowingly solicit personal information from children. User-generated content that exploits or endangers a child is prohibited. See the separate Dohvara Child Safety Standards.
8. Changes to this policy
Material changes will be posted on this page with a revised effective date. App behavior and Play Console disclosures will be kept consistent with this policy.
9. Contact
Saifullah Ahad
Email: www.saifullah.ai@gmail.com
Website: https://saifullah.ai
For a child-safety concern, use the in-app Report control and the dedicated contact above.