Privacy Policy — Rakitra
1. Who provides Rakitra
Rakitra: Co-Parenting Record is provided by Saifullah Ahad (“we”, “us”).
2. What the app does
Rakitra gives two separated parents one shared, append-only record for a child’s handovers, schedule, practical essentials, expenses, agreements, acknowledgements, disputes, and resolutions. The child is never an app user and does not receive an account.
3. Information handled
- Account: adult display name, email address, Firebase user ID, authentication state, and password-reset requests. Google Firebase Authentication handles passwords; Rakitra does not read or store the password itself.
- Shared record: child first name or family label, parent names, handover and schedule details, named places typed by a parent, essentials, agreements, expense amounts, currency, recorded exchange rate, split, partial payments, refunds, disputes, and resolutions.
- Optional photos: a parent may select a supporting or receipt photo. Rakitra removes the original file metadata, compresses the image, signs it into the entry, and shares it with the paired parent.
- Evidence and security: entry hashes, Ed25519 public keys and signatures, acknowledgement signatures, device identifier, device public-key fingerprint, encrypted recovery backup, invite code, timestamps, sync status, App Check signals, and an FCM notification token.
- Safety reports: the reporter ID, reported entry and author IDs, report reason, time, and review status.
- Local settings: quiet mode, reduced motion, app-lock configuration, and encrypted signing-key material. The independent app PIN is stored only as a salted hash.
Do not put an address, live location, legal strategy, or unnecessary sensitive detail into an entry. Use a child’s first name or a family label rather than a full legal identity.
4. Why information is used
Information is used to authenticate each adult, pair exactly two equal members, synchronize their record, calculate settlement in integer minor units, preserve acknowledgements and disputes, detect conflicting schedules, send quiet record notifications, create signed PDF/JSON exports, verify record integrity, prevent abuse, and respond to safety reports.
5. Service providers and sharing
Rakitra uses Google Firebase Authentication, Cloud Firestore, Firebase Cloud Messaging, and Firebase App Check in project rakitra-record-2026. Google processes data to operate those services. Shared record content is disclosed to the other paired parent because that is the app’s core function. A user may also intentionally share an exported PDF or JSON file through Android’s system share sheet.
We do not sell personal information and do not use advertising or analytics SDKs. Rakitra does not include chat, contact upload, social discovery, payment processing, or location tracking.
6. Permissions
INTERNETand network state: account access, synchronization, App Check, and notifications.CAMERA: only while scanning a face-to-face handover QR. Rakitra does not record camera video or infer location.POST_NOTIFICATIONS: quiet alerts about record activity when allowed. Notifications can be denied or disabled.
Supporting photos are chosen through Android’s system photo picker, so Rakitra does not request broad photo-library or storage access.
7. Security and integrity
Network traffic uses encrypted HTTPS/TLS connections. Firebase Security Rules limit a child record to its paired members. App Check helps reject unauthorized clients. Each device generates an Ed25519 signing key; its private key does not leave that device. Entries are canonicalized, hash-chained, and signed. The encrypted recovery backup can be opened only with the recovery words shown to that adult.
No system can promise absolute security. A paired parent can read the shared record and can save or share an export, so each parent should include only practical information needed for co-parenting.
8. Retention, append-only evidence, and deletion
Shared entries and acknowledgements are intentionally append-only: they cannot be silently edited or deleted after sharing. A correction, dispute, or schedule resolution is a new signed entry and the original remains reviewable. This retention is necessary for the integrity function the users requested.
Safety exit closes the shared record to new entries, removes the leaving account’s membership, and wipes that device’s local dossier and signing key. The other parent keeps the evidence already shared. Delete account additionally removes the adult’s Firebase account, profile, device tokens, and recovery backup; shared append-only evidence and submitted safety reports may remain for the paired parent, integrity, safety, fraud prevention, and legal obligations.
Deletion can be started in Rakitra under Dossier tools → Controls → Delete account. A user may also request deletion at www.saifullah.ai@gmail.com from the account email. We may ask for verification before acting.
9. User controls
- Acknowledge, dispute, correct, resolve, report, export, or verify records without changing prior evidence.
- Use quiet mode, deny notifications, revoke camera access, set an independent app PIN, enable device biometrics, or refresh the encrypted recovery backup.
- Use Safety Exit or Delete account as described above.
10. Children and child safety
Rakitra is for adult co-parents and is not directed to children. The child has no account or child-facing feature. Child sexual abuse and exploitation (CSAE), including child sexual abuse material (CSAM), is prohibited. Every shared entry can be reported. Read our separate Child Safety Standards.
11. International processing
Firebase may process information on infrastructure outside the user’s country. The Firestore database is configured in the asia-south1 region. Applicable safeguards and Google’s service terms govern provider processing.
12. Changes and contact
We may update this policy when Rakitra or applicable requirements change. The current version will remain at https://privacy.saifullah.ai/rakitra.html with a revised effective date.
Questions, privacy requests, or complaints: www.saifullah.ai@gmail.com.