Privacy Policy — Koldari

Developer: Saifullah Ahad · Package: ai.saifullah.koldari · Effective date: 2026-07-25

1) What Koldari does

Koldari coordinates private cold-chain custody records for authorized teams. Owners manage a workspace, coordinators prepare shipment plans and dispositions, handlers record observations from external equipment and complete handoffs, and auditors review accepted evidence.

Scope: Koldari does not measure temperature with the phone, certify calibration or compliance, decide product quality or fitness, provide medical advice, or replace local procedures and qualified staff.

2) Data we collect

Koldari collects the following data because its authenticated, multi-device workflow cannot operate without it:

Firebase Authentication processes the password used to sign in. Koldari's application records never receive or store the password.

Koldari does not collect precise or approximate location, contacts, photos, files, camera or microphone input, advertising identifiers, payment data, health records, patient data, or sensor readings. It includes no advertising, analytics, or third-party crash-reporting SDK.

3) How we use data

4) Service providers and data disclosure

Koldari uses these processors only to operate the service:

These providers process data on our behalf. We do not sell personal information, provide it to advertisers, create advertising profiles, or use it for cross-app tracking. We may disclose narrowly relevant records when legally required, to address imminent safety, or to investigate abuse.

5) Security and access

Network traffic uses HTTPS. Firebase tokens and, where supported, App Check tokens are verified at the public edge and again at the protected command service. Firestore Security Rules restrict reads to active members and block application clients from privileged shared-state writes. Role changes, moderation decisions, custody transitions, exports, and deletion commands are server-authoritative.

Commands use idempotency keys, expected revisions, transactions, replay protection, bounded retries, and immutable accepted events. Notification text is generic so shipment details are not exposed on a lock screen. No Internet service can be guaranteed completely secure, so members should avoid entering patient names, secrets, or information not needed for the operational record.

6) Retention

7) Export and deletion

Authorized owners, coordinators, and auditors can request a source-complete JSON export from Data controls → Request complete export.

A member can request account deletion in Data controls → Delete account. This removes the profile, devices and notification tokens, pending invitations, blocks, and active assignments after server verification. A last owner must transfer ownership or delete the workspace first. Where an organization must retain its operational history, accepted events keep only a pseudonymous actor digest rather than the deleted profile.

An owner can request workspace deletion in Data controls → Delete workspace. A server tombstone denies new commands before resumable bounded cleanup removes the workspace data and verifies completion.

If the app cannot be accessed, follow the public account and data deletion instructions.

8) Permissions and choices

9) Children's privacy and safety

Koldari is designed for adult operational teams and is not directed to children under 13. Because members can enter shared notes and display names, our separate Child Safety Standards prohibit child sexual abuse and exploitation (CSAE), child sexual abuse material (CSAM), grooming, sextortion, and conduct that endangers a child. In-app reporting, blocking, suspension, and restricted moderation are available.

10) International processing

Firebase, Google Cloud, and Cloudflare operate global infrastructure, so data may be processed outside the member's country. We limit the data sent to what is necessary for the functions described above and apply the same access controls to every request.

11) Changes to this policy

We may update this policy when Koldari's real data practices or legal obligations change. The current version will remain at https://privacy.saifullah.ai/koldari.html with a revised effective date.

12) Contact

Saifullah Ahad
Email: www.saifullah.ai@gmail.com
Website: https://saifullah.ai
Location: Dhaka, Bangladesh