Notice under Section 5 of the DPDP Act (read this first)
This Privacy Policy is a standalone notice. It is not part of the Terms of Use. You should read it before you create an account or pair a device.
qBit Sensor LLP is the Data Fiduciary. You are the Data Principal for your own personal data.
What we collect (itemised): mobile number; display name; city; optional profile photo; home and room labels; device identifiers needed to operate hardware you pair; pairing and command-authentication secrets (held on your phone and on the device, not on our application servers); Wi-Fi network name and password (stored on the device so it can reconnect); household member identifiers and roles on the device; schedules and appliance settings; optional voice input if you use Moon; assistant replies we may cache; invitee name and phone if you send an invite; push-notification tokens; and operational logs needed to run and secure the Service.
Why (itemised purposes and what they enable):
| Purpose | What it enables | Required to use the core Service? |
|---|---|---|
| Create and secure your account (phone OTP) | Sign-in, fraud prevention | Yes |
| Operate paired devices, rooms, schedules, and status | Home control | Yes |
| Store network credentials on the device | The device rejoins your Wi-Fi after power loss | Yes, if you pair hardware |
| Transactional alerts | Device and security notices | Optional (you can disable in phone settings; some alerts will stop) |
| Moon voice and assistant replies | Spoken control and information | Optional |
| Household invites | Sharing access with another adult | Optional |
| First-party product notices | Information about qBit hardware | Part of the Service |
| Affiliate product suggestions | Buy suggestions on third-party sites | Optional — not required for home control |
| Security and abuse prevention | Keep accounts and devices usable | Yes |
| Legal and grievance handling | Comply with Indian law and your rights requests | Yes |
Lawful grounds under the DPDP Act: we process personal data only with your consent (Section 6) or for a legitimate use listed in Section 7 (for example, data you voluntarily give us for a specified purpose, or processing required to comply with Indian law). We do not rely on “contract performance,” “legitimate interests,” or other foreign-law grounds.
Your choices: you may withdraw consent as easily as you gave it (Section 6(4)), by emailing connect@qbitsensor.in or using in-app controls when they are available. Withdrawing consent for optional features (Moon, photo, invites, affiliate cards) does not by itself close your account. Withdrawing consent for processing that is necessary to run the Service means we must stop providing that Service and will close the account.
Rights and complaints: access, correction, erasure, nomination, and grievance — see Sections 9 and 13 of this Policy. Complain to us first via the grievance form or the Grievance Officer at rashmi@qbitsensor.in. If you are not satisfied, you may approach the Data Protection Board of India after exhausting our grievance process (DPDP Act, Section 13(3)).
If you do not agree, do not create an account and do not pair hardware.
1. Who we are
qBit Sensor LLP determines the purpose and means of processing personal data for HomeSense. Our registered office is at the address above. For privacy questions, rights requests, and grievances, use the grievance form, write to the Grievance Officer at rashmi@qbitsensor.in, or write to connect@qbitsensor.in. General support is form and email; the Grievance Officer can also be reached on the published phone number in Section 13. We do not operate a call centre or in-app live chat. If we add other channels, we will say so on qbitsensor.in and in this Policy.
The Service is intended for people in India.
2. Scope and age
The Service is for adults aged 18 or over. You must not create an account, pair hardware, or invite someone as a household member if they are under 18.
We do not knowingly process children’s personal data as account holders. We do not use children’s data for tracking, behavioural monitoring, or advertising directed at children (DPDP Act, Section 9). If we learn that we hold a child’s personal data contrary to this Policy, we will delete it.
Do not name rooms or invite people in a way that is intended to profile a child. Household sharing is for adults only until we publish a verifiable parental-consent flow.
3. Personal data we process
We limit collection to what is needed for the purposes in the notice above.
3.1 Account and profile
- Mobile number — to send a one-time password and create the account. We do not use it for third-party telemarketing.
- Display name — to show who you are in the App and on household lists.
- City — chosen from a list, to show local weather and related context. We do not continuously track GPS for weather.
- Profile photo (optional) — stored on your phone and in our private cloud storage if you upload one.
3.2 Home, devices, and on-device data
- Room and home labels, and which devices are linked to your account.
- Hardware identifiers needed to operate and support the unit.
- Appliance settings and schedules (for example, temperature or fan mode).
- Pairing and command-authentication secrets — held on your paired phone (in the phone’s platform secure storage) and on the hardware. They are not stored on qBit application servers. A new phone usually needs local re-pairing.
- Wi-Fi name and password — sent to the device during setup over a local connection and kept on the device so it can reconnect after a reboot. They are not kept as a long-term field in your cloud profile.
- Household access list on the device (member identities and roles such as owner, family, or guest; a small number of members).
- A security lock state on the device if theft/loss lock is used.
3.3 Moon assistant (optional)
- Microphone audio only while you are talking to Moon.
- Short conversation text and related usage signals on the phone, kept for about 30 days, then deleted.
- Spoken replies generated by the assistant may be cached on the phone and in private cloud storage so common phrases can be replayed without synthesising them again. This cache is not a store of your incoming voice queries, is not used to build advertising profiles, and is not sold.
Voice features may be processed by our subprocessors (see Section 6), including speech services operated by Google.
3.4 Household invites (another person’s data)
If you invite someone, you type or pick their name and phone number. That is their personal data. We use it only to send the invite, let them join if they choose, and record membership.
We will give the invitee a notice (for example by message or when they open the invite) and they must agree for themselves before we treat them as a member. Unaccepted invites are deleted after a short period. You must only invite adults, and only people who have agreed you may share their details with us. We do not check family relationships.
3.5 Phone permissions
- Bluetooth and, on some Android versions, location permission — to find a nearby device and read Wi-Fi names during pairing, not to track you.
- Local network (iOS) — to talk to the device on your home network.
- Microphone — Moon only.
- Notifications — transactional alerts.
- Contacts — only if you pick an invitee from the address book; we do not upload your whole address book.
3.6 What we do not do
- We do not sell, rent, or trade personal data.
- We do not use third-party advertising SDKs or cross-app ad tracking.
- Affiliate suggestions are optional and disclosed; tapping a merchant link takes you to that merchant’s own terms and privacy policy.
4. Purposes and lawful grounds (DPDP Act)
| Personal data | Purpose | Ground | Required? |
|---|---|---|---|
| Phone number and OTP | Account, sign-in, fraud prevention | Section 6 consent | Yes |
| Name and city | Profile and local weather | Section 6 consent; city also Section 7(a) where you volunteer it for that purpose | Name: yes. City: needed for weather |
| Profile photo | Avatar | Section 6 consent | No |
| Home layout, device ids, settings | Control and sync | Section 6 consent | Yes |
| Pairing / command secrets | Authorise commands | Section 6 consent | Yes (on phone and device only) |
| Wi-Fi credentials | Device reconnects to your router | Section 6 consent | Yes, on the device if you pair |
| Household access list | Shared control | Section 6 consent | If you use sharing |
| Voice to Moon | Spoken commands | Section 6 consent (optional feature) | No |
| Assistant reply cache | Deliver Moon without re-synthesising every phrase | Section 6 consent for Moon | Only if you use Moon |
| Invitee name and phone | Send and manage the invite | Section 6 consent of the invitee (and your confirmation that you may share their details) | No |
| Push tokens | Transactional alerts | Section 6 consent via OS permission | No |
| Device status events | Keep the App in sync and debug faults | Section 6 consent | Yes, for connected features |
| Security and abuse logs | Protect accounts and APIs | Section 6 consent as part of a secure Service; Section 7 where Indian law requires us to retain or disclose | Yes |
| Grievance and legal correspondence | Handle rights and legal duties | Section 7 (obligation under law) and Section 6 where you write to us | As required |
Consent is specific. Ticking that you have read this notice is not consent to unrelated future uses. Optional features (Moon, photo, invites, affiliate cards) require a separate choice. We will not refuse the core home-control Service only because you declined affiliate suggestions.
Withdrawal (Section 6(4)–(6)): email connect@qbitsensor.in or use in-app settings when available. We will stop, and require our processors to stop, processing that depends on the withdrawn consent, within a reasonable time, except where Indian law still requires us to keep or process the data. Withdrawal does not make past lawful processing unlawful.
5. Processors and other parties
We use processors only to run the Service, on our instructions:
- Google (Firebase / Google Cloud) — account authentication (phone OTP), databases and file storage for your profile and home setup, push delivery on Android, background functions (for example weather lookup), and speech/synthesis for Moon.
- Apple — push notifications on iOS.
- Cloudflare (Turnstile) — bot check on the Associate with Us form on this website. Cloudflare may see the challenge token and the visitor IP for that check.
- Affiliate merchants — only if you leave our App and use their site; their privacy policy applies there.
This is not a sale of personal data. Processors must not use your data for their own advertising.
We may disclose data if Indian law or a competent authority requires it.
6. Where data is stored (without internal paths)
Personal data sits in three places:
- Your phone — App data and platform secure storage for pairing secrets; cleared on sign-out wipe, uninstall, or account erasure, as the App implements.
- The hardware — pairing secrets, Wi-Fi credentials, member list, schedules, language preference, lock state, and factory identity needed for the unit to reach our cloud later. Consumer data on the device is cleared when you unpair or reset a reachable unit. Turning off the device or deleting only the cloud account does not wipe an offline unit. Factory identity on the unit may remain for the life of the hardware so it can be set up again.
- Our cloud systems (with Google as processor) — account, home setup, invites, notification tokens, and assistant reply cache.
We do not publish bucket names, database paths, memory-partition names, or key names. Those are internal engineering details.
7. How long we keep data
| Data | Where | How long |
|---|---|---|
| Moon conversation and related local signals | Phone | About 30 days, then deleted |
| Weather cache | Phone | About 1 hour |
| Account, home setup, photo | Cloud | While the account is open, or until you replace/delete the item |
| Notification tokens | Cloud | Until the phone unlinks, the token changes, or the account is closed |
| Assistant reply cache | Phone and cloud | While useful for Moon, or until account erasure |
| Invite records | Cloud | While the invite or membership is active, then deleted; unaccepted invites after a short period |
| Operational logs | Cloud | About 30–90 days, then deleted, unless law requires longer |
| Pairing secrets on the phone | Phone secure storage | Until unpair, sign-out wipe, or uninstall |
| Pairing secrets, Wi-Fi, members, schedules on hardware | Device | Until you unpair or reset a reachable device |
| Factory device identity | Device | Life of the unit |
8. Security
We use reasonable technical and organisational measures as required under the DPDP Act (including encryption in transit, access control, and processor contracts). Commands to hardware are authenticated on the device. Pairing and command-authentication secrets are not on our application servers.
No system is perfectly secure. If someone has your unlocked phone or physical access to a paired device, they may be able to use what is stored there.
If our cloud is affected: names, phone numbers, room labels, photos, notification tokens, and cloud logs may be exposed. Pairing secrets, Wi-Fi passwords, and local schedules are not designed to sit on application servers, so a cloud-only incident is not intended to yield silent control of your appliances. This is defence in depth, not a guarantee.
Personal data breach (DPDP Act Section 8(6) and Rule 7): when we become aware of a personal data breach we will, without delay, inform affected individuals in plain language (what happened, when, likely effects, what we are doing, what you can do, and who to contact) and inform the Data Protection Board. We will send the Board a detailed report within 72 hours of becoming aware, or such longer period as the Board allows. There is no “low risk” exemption of the kind found in some foreign laws — we treat personal data breaches as notifiable under Indian law.
9. Your rights (Chapter III of the DPDP Act)
Write to connect@qbitsensor.in. Tell us the mobile number on the account. We may need to verify it is you.
- Access (Section 11): a summary of personal data we process and with whom it has been shared, as prescribed.
- Correction and erasure (Section 12): correct inaccurate data; ask us to erase data that is no longer needed for the purpose, subject to law.
- Nomination (Section 14): name one or more nominees to exercise your rights if you die or become incapacitated. Email us with the nominee’s details and proof we reasonably need.
- Grievance (Section 13): see Section 13 of this Policy.
- Withdraw consent: see Section 4.
You can also correct profile fields in the App where that screen exists.
Account closure and erasure
You may ask us to erase your account by email, and through the App when that control is available.
To avoid accidentally locking household equipment, we may use a short confirmation window (up to 72 hours) during which you can cancel the request. Canceling restores normal use. This window is a safeguard, not a refusal of your statutory right. If you tell us you want erasure to proceed without waiting, we will complete cloud erasure within a reasonable time as required by the Act.
While a request is pending, we may lock owned devices when they can be reached on your local network (Bluetooth or home Wi-Fi). We do not use a remote internet command for that lock step. Unpair every device while it is powered and nearby before you confirm erasure. Devices left unpaired or offline may stay locked and may need authorised recovery. Contact connect@qbitsensor.in — we will not treat factory recovery as a penalty for exercising erasure.
After erasure we delete or anonymise cloud personal data, instruct processors to delete their copies where applicable, and clear pairing secrets on the phone as the App implements. Hardware factory identity may remain on the unit as described in Section 6.
10. Cross-border processing
We are an Indian entity. Google / Firebase may process or store personal data on systems outside India.
Under Section 16 of the DPDP Act, the Central Government may restrict transfers to specified countries. We will follow those restrictions as they apply. We do not claim that foreign processing is “equivalent” to Indian law in the sense of EU adequacy decisions.
11. Moon, language packs, and product suggestions
Moon is assistive. It does not take legal, medical, or similarly significant decisions about you without a human. If it mishears you, use manual controls in the App or on the appliance.
Language and speech quality improve over time. Report errors in good faith to connect@qbitsensor.in.
First-party notices may tell you about qBit hardware. Affiliate cards are a separate, optional purpose: we may earn a commission if you buy on a third-party site. They are not a sale of your personal data. You can decline affiliate suggestions and still use home control.
12. Firmware updates
Owners may install firmware updates we issue for security, fixes, or compatibility. The device checks that an update is authentic before installing. Updates may cause a short interruption. We do not promise user rollback to an old version. Family or guest profiles cannot authorise these updates.
13. Grievance redressal
Grievance form: qbitsensor.in/grievance
Grievance Officer: Rashmi Kumari
Email: rashmi@qbitsensor.in
Phone: +91-8789251093
Entity: qBit Sensor LLP
Address: Desk No. NNRK 46, Unit No. 603–604, 6th Floor, Tower B, Bhutani Alphathum, Sector 90, Noida, Gautam Buddha Nagar, Uttar Pradesh – 201305, India
Hours: Monday–Friday, 10:00–18:00 IST, excluding gazetted holidays.
We will acknowledge privacy complaints and rights requests within 48 hours and aim to resolve them within 30 days of receipt (stricter than the 90-day outer limit under the Rules).
You must use this process before approaching the Board (Section 13(3)). If you are not satisfied, you may complain to the Data Protection Board of India.
14. Changes
We will post updates at /privacy with a new “Last Updated” date. If a change materially alters how we process personal data, we will give prior notice (in-app, email, or at next sign-in) and take fresh consent where Section 6 requires it. Continued use is not, by itself, consent to a new purpose.
By creating an account you confirm that you are 18 or over and that you have read this notice. Optional features require a separate choice in the App or a later request from you.