What we hold, and what we cannot.
Most privacy policies describe how carefully a company guards what it collected. This one is mostly a list of things that were never collected, because the design refused them. Where we do hold something, it is named here.
Last updated 12 September 2026. This policy applies to the KnownSquare mobile application and to knownsquare.com, both operated by SSDittah Innovations LLP, No 60A, Artha Reviera, Chandapura Anekal Main Road, Marsur, Anekal, Bangalore 562106, Karnataka, India ("we", "us").
The short version
We do not know who you are. There is no phone number, email address, username or password, because the app never asks for one. Your name and photograph stay on your phone and are shared only with people you accept. We cannot read your messages, and we do not keep them once they are delivered. What we hold is an anonymous account identifier, your public keys, which anonymous identifiers exchange messages with which, and, once paid features exist and you subscribe, a record that the account is paid.
The long version below says the same thing with the detail a careful reader deserves, including the parts that are less flattering.
1. What the app asks you for
No identifier of any kind. Creating an account generates a cryptographic key on your device. There is no phone number, no email address, no username, no password and no social login. Nothing you type is checked against a directory, because there is no directory.
A name and a photograph, held on your device. The app asks you once for a name and a picture of your face, so that people you connect with can see who they are talking to. These are stored on your phone and shared, encrypted, only with people you have accepted. They are never uploaded to us in any form, encrypted or otherwise. We made that choice deliberately: our servers must already know which anonymous account talks to which in order to deliver anything, and adding real names and faces to that would turn a set of meaningless identifiers into a map of who knows whom.
Permissions we do not request. The app does not ask for access to your contacts, so it cannot read your address book. It does not ask to read SMS. Camera, microphone, storage and location access are requested only at the moment you use a feature that needs them: scanning a code, recording a voice note, attaching a document, or tapping “I’m here” to send where you are as a single reading taken at that moment. The app never reads your location in the background.
2. What our servers hold
This is what our servers hold today.
- An anonymous account identifier, generated randomly. It is not derived from you, your device or anything you typed.
- Public keys for your account and your device, so that messages can be routed and signatures verified.
- Connection records: which account identifiers have an accepted connection, which belong to a group, and, where a connection was made through an introduction, which account made it. We need this to deliver anything at all. It is pseudonymous, meaning it links one random string to another, and it is the single most sensitive thing we hold. We say so plainly rather than leaving it out.
- Recovery relationships: which account identifiers you have chosen to help recover your account, and, while a recovery is in progress, the record of that recovery session. These are links between the same random identifiers: we can say which accounts could recover yours, and we cannot say who any of them are. The recovery shares themselves travel inside ordinary encrypted messages, so we cannot tell which messages carried one.
- Messages awaiting delivery, as encrypted blobs we cannot read, deleted as soon as the recipient's device confirms receipt, and in any case after three days.
- A push notification token for your device, used to wake your phone when something is waiting.
- Invitation codes you have created, which expire and are then deleted.
- Event invitation links you have opened for guests outside KnownSquare: the link's locator, which account it delivers to, when it expires and how many answers it has drawn. Not the event, not the guest and not the answer, which are sealed between your phone and the guest's browser. Deleted when you close the link or it expires.
- Subscription status, once paid features exist and you subscribe: an expiry date and a reference from the app store. Today there is nothing to buy, and we hold no such record. See section 5.
- Reports: if one account reports another, we hold which account reported which, a reason chosen from a fixed list, and when. There is no field for message content, so a report can never carry what was said. Kept until either account is deleted.
- Operational logs, including IP addresses at the moment of connection, retained for 180 days, the period India's cyber-security directions (CERT-In, 2022) require security logs to be kept, and used for security and abuse prevention.
3. What we cannot hold, as a matter of design
These are not promises of restraint. They are consequences of how the system is built.
- Message content. Everything is encrypted on your device with keys we never possess. This includes text, voice notes, photographs, documents, plans, guest lists, lists, polls and expense records.
- Your Locker. Documents you save are encrypted on your phone and are not uploaded to us.
- Your backup. On Android, if backup is on, your phone seals your messages and your Locker with a key made from your account and keeps that sealed copy in a hidden folder of your own Google Drive that only this app can reach. It never passes through our servers and we cannot read it. Google can see that the file exists, its size and when it changed. The app deletes it when you delete your account, if this phone can still reach it.
- Names and faces. Neither yours nor those of people you connect with.
- Nicknames you give people. They never leave your phone.
- Guests you invite from outside. If you invite someone who is not on KnownSquare to an event, the name and number you type stay on your phone and are never sent to us. The link you send them carries the invitation and its key in a part of the address that no browser sends to any server, so we cannot read the invitation, and a guest's answer reaches us sealed and is deleted when your phone collects it.
- Your address book and your SMS. We never had permission to look.
- Your location. If you tap “I’m here”, your phone takes one reading and sends it, encrypted, to the people you chose, like any other message. It is never read in the background, and it never reaches us in a form we can read.
The practical consequence is worth stating: if we are compelled to disclose what we have about a user, what exists is the list in section 2. We cannot produce message content, because we do not have it and cannot decrypt it.
4. Platform services: notifications and place search
To wake your phone when a message arrives, the app uses Firebase Cloud Messaging on Android and the Apple Push Notification service on iPhone. We send a signal containing no message content, but the fact that a signal was sent, and its timing, is visible to Google or Apple as the operator of that service. This is true of essentially every messaging app on both platforms, and it is a limit of the phone rather than a choice of ours. We mention it because a privacy policy that omitted it would be incomplete.
When you search for a place while creating an event or poll, your phone asks its own platform’s map service for matches. This happens only on your device and only when you search; seeing a place someone sent you never looks anything up. The search query goes to the platform’s map service as a request from your phone, the same way it would if you searched in the phone’s own map app; it never passes through our servers, and we cannot see it. Similarly, when you share or paste a map link while writing a message, your phone may open that link once, at that moment, to read the exact location out of it, so the people you send it to reach the right spot. That request goes from your device to the map service the link belongs to; it never happens when you merely read a place someone sent.
On iPhone you can also drop a pin on a map rather than search for a name, for a corner or a gate or a house with no listing. When you tap to use that spot, your phone asks the same map service what it is called, so the person you send it to reads a place rather than a pair of numbers. That is one lookup, when you tap, and it is the only moment it happens: moving the map looks nothing up.
On iPhone, that search may ask for your location. A search for a restaurant by name is close to useless if the phone has no idea which town you are in, so the app asks once, the first time you tap search in a place box, and you may say no. If you allow it, your approximate location is used to look near you and for nothing else: it is not stored, not attached to anything you send, and never reaches our servers. If you say no, the search still works and you add the town yourself, which is what the app does on Android too. Background location is never requested, and there is no setting anywhere that would let it be.
5. Payment
Nothing in the app costs money today. If paid features are introduced, they will be sold through Google Play and the Apple App Store. Your payment will be made to them, using details you have already given them, and they will act as merchant of record. We will never see your name, billing address, card or bank details. What will reach us is a purchase reference we use to verify that an anonymous account identifier is entitled to the paid feature, and the date that entitlement ends. Refunds, cancellations and renewals will be handled by the store under its own policies and privacy terms.
6. This website
knownsquare.com serves its own fonts and images and calls no third party. There are no advertising trackers, no analytics scripts and no cookies set by us. The site keeps two small things on your device, stored by your browser: your choice of dark, light or automatic theme, and, if you answer an invitation, which answer you picked and how many are coming, so the page can show it if you open the link again. Both are choices you made, both stay on your device and go nowhere, and that is why this site has no consent banner to click through. Your answer stays until you clear your browser's data, and the page drops any answer older than 30 days whenever you open an invitation. Our hosting provider, Cloudflare, processes standard request logs, including IP addresses, in order to serve the site and defend it from attack. If we ever add analytics, this section will say so, and it will say what is collected.
The contact form is the one place this website collects anything. When you write to us we store the name, email address, subject and message you send, and email them to the team so that a person can reply. We keep a one-way hash of your IP address, never the address itself, purely to stop one sender flooding the form. Messages are kept for 12 months and then deleted. They are not used for marketing, not shared with anybody, and cannot be linked to any account in the app, because the app gives us nothing to link them to.
Worth stating plainly, because the rest of this policy might suggest otherwise: the app collects nothing about you, and this website has an ordinary contact form. A website that answers bug reports has to know where to send the answer. The two are different things and we would rather say so than blur it.
7. How long things are kept
- Undelivered messages: until delivery, and at most three days.
- Event invitation links for guests outside KnownSquare: until you close them or they expire, at most 30 days. A guest's sealed answer: until your phone collects it, and at most three days, like any message.
- Connection records: for as long as the connection exists. Delete a connection and the record goes.
- Account record: kept while the account exists. We have no policy of deleting accounts for inactivity, because an account here is an identity your family depends on, and a quiet expiry would take it away at the worst possible moment. You can delete your account from inside the app, under Settings. It happens immediately: the records described in section 2 are gone from our live systems by the time the app tells you it is done, and there is no waiting period during which we could be asked to put it back. Copies inside our encrypted database backups age out within 30 days.
- Reports: until either account involved is deleted.
- Operational logs: 180 days, as India's CERT-In directions require. Counts of how busy the service was (how many operations of each kind in an hour, tied to no account) may be kept longer, because they contain nothing about any person.
- Subscription records: for as long as tax and accounting law requires, which in India is currently at least six years.
8. Your rights, and an honest limit on them
Depending on where you live, you may have rights to access, correct, delete or export your personal data, including under India's Digital Personal Data Protection Act 2023 and, where it applies to you, the GDPR.
There is an unusual wrinkle here, and it works in your favour. Because we hold no identifier for you, we cannot find your account from a name, an email or a phone number, and neither can anyone claiming to be you. A request is proved by your device signing it, which is done from within the app, which is also why deletion lives there: Settings, at the bottom, and it takes effect the moment you confirm it. How deletion works, and what to do if you no longer have your phone, is explained at knownsquare.com/delete-account/. Data held about you by people you talked to lives on their phones, and is beyond our reach, in the same way that a letter you posted is.
To exercise a right, or to ask what is held, write to [email protected]. If you are in India and we have not dealt with a complaint properly, you may raise it with the Data Protection Board of India after first putting it to our Grievance Officer, named below.
9. Sharing
We do not sell personal data and we do not share it for advertising. We use a small number of processors to run the service: Cloudflare for this website, our DNS and the edge that sits in front of our servers, Amazon Web Services for those servers and the database behind them, which run in Amazon's Mumbai region, Zoho for the mail you send to our support and security addresses, Resend to deliver the email a contact form message becomes, and Google and Apple for push notifications and, when paid features exist, payment. The servers holding anything in section 2 are in India. Resend is based in the United States, so a message you send through the form is processed there as well as here. We may disclose the information in section 2 where we are legally required to, and we will resist requests that exceed what the law requires.
10. Children
KnownSquare is not intended for children under 13, and anyone under 18 needs a parent or guardian's agreement, who should also be a guardian on the account. A younger family member's account may be set up and watched over by a parent as a guardian, in which case the parent is responsible for that consent.
11. Changes
If this policy changes in a way that affects what we collect, we will say so in the app before the change takes effect, and the date at the top will change. If you want to read an earlier version, write to [email protected] and we will send it to you.
12. Contact
SSDittah Innovations LLP, No 60A, Artha Reviera, Chandapura Anekal Main Road, Marsur, Anekal, Bangalore 562106, Karnataka, India. Privacy enquiries: [email protected]. Grievance Officer, as required under India's Information Technology Rules 2021: Sukesh Shetty, [email protected], No 60A, Artha Reviera, Chandapura Anekal Main Road, Marsur, Anekal, Bangalore 562106, Karnataka, India. Complaints are acknowledged within 24 hours and resolved within 15 days.