Last updated:
1. Who we are
"The Case Diary", "we", "us" means [registered business name], [registered address], operator of the website thecasediary.in, the web app at app.thecasediary.in and the Android app "Case Diary" (package com.thecasediary.app). This policy applies to all of them and is written to meet the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and its rules.
2. Our role: you are in charge of your clients' data
- For your own account data (name, mobile number, email, sign-in details) we decide how it is used, so we are the Data Fiduciary.
- For information about your clients and cases that you type or upload, you decide what goes in and why. We only store and process it on your behalf, to provide the service you asked for (we act as your Data Processor). As an advocate you remain responsible for your professional duty of confidentiality and for having a lawful basis to record that information.
3. What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Name, mobile number, chamber name, optional email, optional Bar registration number, password (stored only as a one-way hash) | Create and secure your account, sign you in, contact you about it |
| Your case-diary content | Cases (title, number, court, dates, stage), hearing notes, fee entries (amounts charged / received), remarks and tasks, client details (name, phone, email, address, notes), uploaded documents (PDF, images) | Provide the diary, fees, sharing and reminder features |
| Sharing | Share links you create, the mobile number or email you enter for the recipient, who accepted and with what access | Let a colleague open one case, and let you revoke it |
| Message records | One-time codes (stored hashed, expire in 10 minutes), and for every SMS / WhatsApp / email we send: recipient, type, template, delivery status, time | Deliver messages, prevent abuse, fix delivery problems, and meter separately-billed WhatsApp / SMS usage |
| Technical | IP address, device / browser type, app version, request logs, error logs | Keep the service secure and working, detect fraud and abuse |
| Support | What you write to us and our replies | Help you |
The Android app asks only for internet access. It does not read your contacts, location, SMS, call log, camera or microphone. When you attach a document it uses the system file picker, so it sees only the files you choose. We do not use advertising identifiers and have no advertising or cross-app tracking SDKs.
4. How we use it, and on what basis
- To provide the service you signed up for: showing your cases, dates, fees, notes and documents to you and the people you authorise.
- To verify and protect your account: OTP checks, rate limiting, sign-in and password-change alerts.
- To send service messages by SMS, WhatsApp and (only to an email you verified) email: one-time codes, a welcome message, a sign-in alert, a new case or chamber added, a case shared with you, hearing reminders. These are triggered by actions in your account; we do not send advertising. If we ever want to send promotional messages we will ask for your separate consent first.
- To bill you (when paid plans and payment go live) and to meter WhatsApp / SMS usage.
- To maintain and improve reliability and security, and to comply with law.
We process your data based on your consent (given when you create an account and use the features) and for the "legitimate uses" the DPDP Act allows, such as complying with law and responding to emergencies. You can withdraw consent by deleting your account; this does not affect what was done before.
We do not sell your data, do not show advertising, do not build advertising profiles, and do not use the content of your cases, notes or documents to train AI or machine-learning models. Our staff do not read the content of your cases except where needed to operate or secure the service, to help you with a support request you make, or where the law requires.
5. Who can see your information
- Your chamber. Members of a chamber see that chamber's cases, clients and fees according to their role (owner, associate, clerk).
- People you share a case with. A shared case is visible only to the account that accepted your share link, with the access you chose (view or edit). Anyone holding a link can open its preview page (case title, chamber name, who shared it) but must sign in and accept before seeing the case. You can revoke a share at any time. When you type someone's mobile number or email to share with, you confirm you are allowed to give it to us for this purpose.
- Service providers who process data for us under contract, only to deliver their service:
Provider Purpose Data involved Hosting provider [name, location] Servers and database All service data (encrypted in transit) MSG91 (Walkover) SMS and WhatsApp delivery Recipient mobile number, message text (codes, alerts) Meta (WhatsApp Business Platform) WhatsApp delivery Recipient number, message text Brevo Transactional email delivery Verified email address, message text Google (Play Store, Play review / Fonts) App distribution, optional in-app review prompt; web fonts on this website Standard Play / browser data handled by Google under its own policy Payment gateway [Razorpay / Cashfree — when payments launch] Card / UPI payments Payment details go to the gateway directly; we do not store card or UPI details - Authorities. If the law or a valid order from a court or government authority requires, we may have to disclose information. We will tell you where we are allowed to, and we will resist requests that are not valid.
- Business changes. If the business is sold or merged, your data would move to the new owner, bound by this policy; we would tell you first.
6. Where data is stored, and transfers outside India
Service data is stored on servers at [hosting location]. Some providers above (for example Brevo and Meta) process data in other countries. We transfer personal data abroad only as the DPDP Act permits, and only to the extent needed to deliver the message or service you triggered.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account, cases, clients, fees, notes, documents | While your account is active. Deleted when you delete your account (see section 9). |
| One-time codes | 10-minute validity; removed after use or expiry. |
| Message records (recipient, type, status) | Up to [24] months for billing, abuse prevention and dispute handling, then deleted. When you delete your account, the link to you is removed and the recipient is masked. |
| Server and security logs | Up to 90 days. |
| Backups | Nightly backups are overwritten after 14 days. A deleted account can therefore remain in backups for up to 14 days, and is not restored except after a disaster. |
| Records we must keep by law (e.g. tax invoices once payments launch) | For the period the law requires. |
8. Security
We protect data with encryption in transit (HTTPS), hashed passwords and codes, per-chamber access control checked on every request, rate limiting, private document storage, and nightly backups. The full list, including what we have not done yet, is on our Data Security page. No system is perfectly secure; please use a strong password and tell us promptly if you suspect misuse.
If a personal-data breach affects you, we will tell you and the Data Protection Board of India as the law requires, describing what happened and what you can do.
9. Your rights and choices
- Access and correction. You can see and edit your profile, cases and clients in the app. For anything else, write to us.
- Erasure / delete your account. In the app: Account → Delete account (also available in the web app). Or follow these steps, or email us from your registered address. Deleting removes your account, the chambers you solely own, and all their cases, clients, fees, notes and documents, and stops all messages. It cannot be undone.
- Withdraw consent / stop emails. Remove your email under Account → Email alerts. Service messages about your account (like one-time codes) cannot be switched off while you have an account.
- Grievance and nomination. Under the DPDP Act you may have the right to grievance redressal and to nominate another person to exercise your rights in case of death or incapacity.
We aim to acknowledge requests within 2 working days and resolve them within 30 days. If you are not satisfied you may approach the Data Protection Board of India.
10. Children
The Case Diary is for professionals and is not intended for anyone under 18. We do not knowingly collect children's data.
11. Cookies and similar technologies
The website and web app use only what is strictly necessary to work (for example keeping you signed in, stored in your browser). We use no advertising or analytics cookies. Pages load fonts from Google Fonts, which means your browser contacts Google when you open them.
12. Changes to this policy
If we make material changes we will update the date above and notify you in the app or by message before they take effect.
13. Contact and Grievance Officer
Grievance Officer: [name], [designation]
Email: hello@thecasediary.in (subject: "Privacy")
Address: [registered address]