Privacy Policy
Effective Date: March 29, 2026 | Last Updated: March 29, 2026
One91 Networks Pte. Ltd. ("we", "us", "our") operates the DigiSoundBox mobile application ("the App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
1. Information We Collect
1.1 Notification Content (On-Device Only)
The App reads notification content from payment apps and SMS applications that you explicitly select. This data is processed entirely on your device to generate voice announcements and transaction records. Raw notification text and SMS content are never transmitted to our servers.
1.2 Anonymous ML Correction Data
When you correct a transaction classification (e.g., marking a balance alert as "Not a Transaction"), we generate an anonymous numerical feature vector (20 floating-point numbers) representing the pattern of that message. This vector is synced to our servers to improve classification accuracy for all users.
What is NEVER synced: SMS text, notification content, sender names, amounts, account numbers, phone numbers, or any personally identifiable information.
1.3 Device Information
We collect basic device metadata during sync: app version, country code (from phone settings), Android version, and device model. This helps us optimize the app for different devices and regions.
1.4 Team Sync Data (Firebase)
If you use the Team Sync feature, transaction metadata is shared with your invited team members via Google Firebase Realtime Database. This includes: amount, transaction type (received/sent/failed), sender name, bank/app name, account last 4 digits, and timestamp.
OTP messages are NEVER shared with any team member under any circumstances, regardless of settings.
1.5 Threat Reports
When the App detects a phishing or fraud attempt, an anonymous threat report is queued for sync. This includes: threat type, confidence score, and detection reason. No SMS content or sender identity is included.
2. How We Use Your Information
- To provide voice announcements for payment notifications
- To improve ML classification accuracy using anonymous correction data
- To enable team sync features between owner and invited members
- To detect and warn about phishing and fraud attempts
- To generate analytics and transaction summaries on your device
- To send daily broadcast messages (optional feature)
3. Data Storage and Security
On-Device: All transaction data, notification content, and ML models are stored locally on your device using encrypted Android Room database. Data extraction is blocked from cloud backup.
Our Servers: Anonymous ML correction data is stored on our servers (hosted in Germany, Hetzner Cloud) with PostgreSQL database. Data is transmitted via HTTPS (TLS 1.2+).
Firebase: Team sync data is stored in Google Firebase Realtime Database (Asia-Southeast region). Firebase security rules restrict access to authenticated users only.
4. Third-Party Services
The App uses the following third-party services:
- Google Firebase — Authentication, Realtime Database (team sync), Analytics
- Google Play Services — Credential Manager for sign-in
- Google AdMob — Advertising (when enabled)
- OneSignal — Push notifications
Each service has its own privacy policy. We encourage you to review them.
5. Data Retention
- On-device data: Retained until you uninstall the app or clear app data
- Firebase team sync: Transaction data is automatically deleted after 7 days
- ML correction data: Retained on our servers indefinitely in anonymized form
- Device registration: Retained until you request deletion
6. Your Rights
You have the right to:
- Access your data — all transaction data is visible in the app
- Delete your local data — uninstall the app or clear app data
- Request deletion of server-side data — email us at support@digisoundbox.com
- Opt out of ML sync — disable in Settings
- Revoke team sync access — owner can remove any member anytime
- Export your data — use the CSV/PDF export feature in the app
7. Children's Privacy
The App is not intended for use by children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with data, please contact us and we will delete it promptly.
8. International Data Transfers
Our servers are located in Germany (EU). Firebase services are hosted in Asia-Southeast (Singapore). If you are accessing the App from outside these regions, your anonymous correction data may be transferred internationally. By using the App, you consent to such transfers.
9. GDPR Compliance (EU Users)
If you are located in the European Economic Area, you have additional rights under GDPR including the right to access, rectification, erasure, restriction, data portability, and objection. Our legal basis for processing anonymous correction data is legitimate interest (improving app accuracy for all users). Contact our Data Protection contact at support@digisoundbox.com for any GDPR-related requests.
10. Singapore PDPA Compliance
In accordance with the Singapore Personal Data Protection Act 2012 (PDPA):
- Purpose: Personal data is collected solely for providing the App's notification reading, ML improvement, and team sync services as described above
- Consent: By using the App and granting notification access, you consent to the collection and use of data as described in this Policy. You may withdraw consent at any time by disabling specific features or uninstalling the App
- Access & Correction: You may request access to or correction of your personal data by emailing support@digisoundbox.com. We will respond within 30 business days
- Data Protection Officer: For PDPA-related queries, contact our DPO at support@digisoundbox.com
- Do Not Call Registry: The App does not make calls or send marketing messages. This provision is not applicable
- Transfer: Anonymous ML data may be transferred to servers outside Singapore (Germany). Firebase data is hosted in Singapore (Asia-Southeast). You consent to such transfers by using the App
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the App after changes constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy, contact us:
One91 Networks Pte. Ltd.
276 Yishun Street 22, #03-260, Singapore 760276
Email: support@digisoundbox.com