Privacy Policy
1. Who is responsible
Cadre is operated by Pranav Kalambi (India). For any question about this policy or about data held about you, write to pkalambi@gmail.com.
2. What we collect
If you sign in with Google
Cadre requests only your basic profile. From Google we receive, and store:
- Your email address — to identify your account.
- Your name — to show who is signed in.
- A stable Google account identifier (the OpenID
sub) — we key your account on this rather than on your email, so that changing your address does not hand your access to whoever is issued it next.
We do not request or receive access to your Gmail, Drive, Calendar, Contacts, or any other Google service. We ask for no scope beyond sign-in.
If you only browse the demo
Nothing that identifies you. The demo requires no sign-in and creates no account.
Technical data
The web server records ordinary access logs — IP address, timestamp, requested URL, user agent — which is what any web server does and what is needed to run one safely. A session cookie is set only after you sign in.
3. What we do not do
- We do not sell or rent personal data. There is nothing to sell and no arrangement to sell it under.
- We do not use advertising or analytics trackers. There is no Google Analytics, no pixel, no third-party tag on this site.
- We do not use your data to train machine-learning models.
- We do not send marketing email.
4. Cookies
One cookie, set only when you sign in, holding a session token. It is HttpOnly, Secure and SameSite-restricted, so it cannot be read by scripts and does not travel to other sites. It expires when the session does. There are no other cookies.
5. Where it is stored, and for how long
On a single virtual server in Mumbai, India, in a PostgreSQL database that only this application can reach. Session tokens are stored as hashes, not in readable form, so a copy of the database does not let anyone impersonate a signed-in user.
Accounts are kept while they are in use. Ask us to delete yours and we will remove it, and the sessions attached to it, within 30 days. Server access logs rotate on the ordinary system schedule.
6. Who else sees it
| Party | Why | What they get |
|---|---|---|
| Sign-in, if you use it | What Google already knows — that you signed in to this app | |
| Hostinger | Hosts the server | Infrastructure provider; no application-level access |
| Let's Encrypt | TLS certificate | The domain name only |
There are no other processors, and no transfers for any other purpose.
7. Your rights
You can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, and withdraw consent by revoking Cadre's access in your Google account permissions. Write to pkalambi@gmail.com and we will answer within 30 days.
India's Digital Personal Data Protection Act sets out obligations that are being phased in. We aim to meet them; where this policy is less than the Act eventually requires, the Act governs.
8. Children
Cadre is a workplace tool. It is not intended for anyone under 18.
9. Security, stated honestly
Traffic is encrypted in transit. Sessions are hashed at rest. Access between organisations is isolated at the data layer and that isolation is tested in continuous integration.
⚠️ The demonstration instance has no sign-in gate — anyone with the link can view it. That is deliberate, because everything in it is fictional. Do not enter real personal data into it. If you do, delete it or ask us to.
10. Changes
If this policy changes materially we will update the date at the top and, where we hold an address for you, tell you.