Last updated: July 21, 2026
When you sign in with Google, we store your email address, display name, and avatar URL. If you connect Gmail for payment verification, we store an OAuth refresh token that lets our server request short-lived read-only access to your inbox — we never store your Gmail password, and we never receive it in the first place, since authentication happens entirely through Google.
We also log API requests (endpoint, IP address, timestamp) against your account, for rate limiting, abuse prevention, and the usage charts on your dashboard.
With your permission, our server uses the Gmail API in read-only mode to search for UPI payment confirmation emails from famapp.in when you call the payment verification endpoint. We read only what's needed to confirm a specific payment (matching a purpose code and amount) — we do not read, store, or forward the full contents of your inbox, and we do not use this access for advertising or profiling of any kind.
You can revoke this access at any time from your Profile page in the dashboard, or directly at myaccount.google.com/permissions.
Account data, payment records, and API logs are stored in a MySQL database on our hosting infrastructure, alongside the application server itself. We do not sell or share your data with third parties, other than the minimal third-party services this app depends on to function: Google (OAuth sign-in and Gmail verification) and ImgBB (hosting the generated QR code images, which contain only a UPI payment link — no personal information).
We retain account and payment data for as long as your account is active, so your payment history and analytics remain available to you. You can request deletion of your account and associated data at any time by contacting us; this also revokes any stored Gmail refresh token.
API keys and webhook secrets are treated as sensitive credentials. We recommend rotating your API key if you believe it has been exposed, using the "Regenerate" option on the API Keys page. Webhook payloads are signed with HMAC-SHA256 so your server can verify they genuinely came from us.
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Questions about this policy or your data? Reach out through the support channel listed in your dashboard.