Privacy Policy — Koldari
1) What Koldari does
Koldari coordinates private cold-chain custody records for authorized teams. Owners manage a workspace, coordinators prepare shipment plans and dispositions, handlers record observations from external equipment and complete handoffs, and auditors review accepted evidence.
Scope: Koldari does not measure temperature with the phone, certify calibration or compliance, decide product quality or fitness, provide medical advice, or replace local procedures and qualified staff.
2) Data we collect
Koldari collects the following data because its authenticated, multi-device workflow cannot operate without it:
- Account and profile: email address, display name, Firebase user identifier, workspace memberships, roles, access status, and account-deletion state.
- Operational records: workspace name and retention choice; shipment label; protocol reference; permitted range; custody legs and assignments; checkpoint times; temperature observations entered by members; equipment label; handoff, exception, disposition, and closure records.
- User-entered and safety content: operational notes, member display names, invitations, reports, blocks, moderation decisions, and associated audit metadata.
- Reliability and security data: command and idempotency identifiers, expected revision, retry state, event sequence, receipt digest, request identifier, bounded timestamps, actor/organization pseudonymous digests, App Check attestation, IP-based rate-limit state, app version, and an app-scoped Firebase Installation ID used for notification delivery.
- Local device data: authorized shipment cache, form drafts, and queued command envelopes are kept in the app's private Room database. Koldari does not read or upload a hardware device identifier. A one-way digest of the app-scoped Firebase Installation ID names its notification-registration document.
Firebase Authentication processes the password used to sign in. Koldari's application records never receive or store the password.
Koldari does not collect precise or approximate location, contacts, photos, files, camera or microphone input, advertising identifiers, payment data, health records, patient data, or sensor readings. It includes no advertising, analytics, or third-party crash-reporting SDK.
3) How we use data
- Authenticate the user and enforce current workspace membership and role permissions.
- Synchronize authorized shipment state and accepted events across devices.
- Queue commands during outages, prevent duplicate events, detect revision conflicts, and recover safely.
- Deliver generic custody, handoff, exception, and overdue-checkpoint notifications.
- Receive and resolve safety or access-misuse reports while preserving the operational record.
- Prepare requested exports, apply retention settings, and complete account or workspace deletion.
- Rate-limit abuse, verify app integrity, investigate failures, and protect the service from unauthorized requests.
4) Service providers and data disclosure
Koldari uses these processors only to operate the service:
- Firebase Authentication / Identity Platform: account authentication and session identity.
- Cloud Firestore: real-time authorized application state, membership, shipment, event, report, export, and deletion-job records.
- Firebase Cloud Messaging: device registration and generic push delivery.
- Firebase App Check with Play Integrity: app and device-integrity attestation used to reduce unauthorized clients.
- Google Cloud: server-authoritative commands, scheduled processing, notification dispatch, protected secrets, structured security logs, and cleanup when that production component is available.
- Cloudflare: the public API gateway, Firebase-token verification, input validation, duplicate-event guard, global rate limiting, safe errors, and request routing.
These providers process data on our behalf. We do not sell personal information, provide it to advertisers, create advertising profiles, or use it for cross-app tracking. We may disclose narrowly relevant records when legally required, to address imminent safety, or to investigate abuse.
5) Security and access
Network traffic uses HTTPS. Firebase tokens and, where supported, App Check tokens are verified at the public edge and again at the protected command service. Firestore Security Rules restrict reads to active members and block application clients from privileged shared-state writes. Role changes, moderation decisions, custody transitions, exports, and deletion commands are server-authoritative.
Commands use idempotency keys, expected revisions, transactions, replay protection, bounded retries, and immutable accepted events. Notification text is generic so shipment details are not exposed on a lock screen. No Internet service can be guaranteed completely secure, so members should avoid entering patient names, secrets, or information not needed for the operational record.
6) Retention
- Workspace owners choose 30, 90, or 365 days for closed-shipment evidence.
- Active operational records remain while needed for the current workspace workflow.
- Invitation and handoff codes are stored only as digests, expire after their short validity period, and cannot be reused.
- Command receipts retain pseudonymous replay-prevention data for 30 days.
- Firebase installation notification registrations are removed on sign-out, an unregistered-installation response, account deletion, or after extended inactivity.
- Security logs contain bounded metadata rather than passwords, email, free-text notes, readings, or one-time codes and follow the configured Google Cloud or Cloudflare retention.
7) Export and deletion
Authorized owners, coordinators, and auditors can request a source-complete JSON export from Data controls → Request complete export.
A member can request account deletion in Data controls → Delete account. This removes the profile, devices and notification tokens, pending invitations, blocks, and active assignments after server verification. A last owner must transfer ownership or delete the workspace first. Where an organization must retain its operational history, accepted events keep only a pseudonymous actor digest rather than the deleted profile.
An owner can request workspace deletion in Data controls → Delete workspace. A server tombstone denies new commands before resumable bounded cleanup removes the workspace data and verifies completion.
If the app cannot be accessed, follow the public account and data deletion instructions.
8) Permissions and choices
- Notifications: requested after joining a workspace. Members may deny or revoke this permission in Android Settings; real-time foreground state and the command outbox still operate.
- Sign out: removes this device's token, signs out the Firebase session, and clears private local shipment, outbox, and draft data.
- Reports and blocks: every member may report a shipment, event, or member and block another member from direct assignment interactions. Authorized moderators can resolve reports or suspend access without rewriting history.
9) Children's privacy and safety
Koldari is designed for adult operational teams and is not directed to children under 13. Because members can enter shared notes and display names, our separate Child Safety Standards prohibit child sexual abuse and exploitation (CSAE), child sexual abuse material (CSAM), grooming, sextortion, and conduct that endangers a child. In-app reporting, blocking, suspension, and restricted moderation are available.
10) International processing
Firebase, Google Cloud, and Cloudflare operate global infrastructure, so data may be processed outside the member's country. We limit the data sent to what is necessary for the functions described above and apply the same access controls to every request.
11) Changes to this policy
We may update this policy when Koldari's real data practices or legal obligations change. The current version will remain at https://privacy.saifullah.ai/koldari.html with a revised effective date.
12) Contact
Saifullah Ahad
Email: www.saifullah.ai@gmail.com
Website: https://saifullah.ai
Location: Dhaka, Bangladesh