Legal

Privacy Policy

Last updated: 30 August 2026
At August, your privacy is not a compliance checkbox — it is a core product decision. This policy explains, in plain language, exactly what data we collect, why we collect it, how we protect it, and what rights you have over it. We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable Indian data protection laws.

1. Who We Are

August is a personal productivity application operated by August (referred to as "August", "we", "our", or "us"). Our registered contact is hey@myaugust.app. We are a data fiduciary under the DPDP Act, 2023, responsible for the personal data you provide to us.

2. Data We Collect

We collect only what is necessary to provide the August experience.

Account data: When you sign up, we collect your first name, last name, email address, and (optionally) your phone number, date of birth, city, and country. If you sign in with Google, we receive your name and email from Google.

Transaction and expense data: When you log an expense — manually or via receipt scan — we store the merchant name, amount, date, category, and any note you add. This data is stored in our secure database and is never shared with third parties for advertising purposes.

Receipt images: When you photograph or upload a receipt, the image is sent to Google Gemini's vision API for text extraction (OCR). We have enabled zero data retention on all Gemini API calls, meaning your receipt image is processed and immediately discarded by Google — it is never stored on Google's servers. The compressed receipt image is stored in our secure Cloudflare R2 object store under your private folder and is automatically deleted after 30 days. Only the extracted structured data (merchant, amount, date, category) is retained in our database.

Important: By using the receipt scanning feature, you consent to your receipt image being transmitted to Google Gemini's API for OCR processing. No image data is retained by Google after processing. You may instead use the manual entry option if you prefer not to use AI-powered scanning.

Task data: Task names, due dates, reminder settings, folder names, and completion status are stored in our database and are private to your account.

Device and usage data: We collect basic analytics including screen views, feature usage events, and session data via PostHog to understand how August is used and improve the product. This data is anonymised and aggregated where possible.

Push notification tokens: We collect your device's FCM (Firebase Cloud Messaging) token to send you task reminders and notifications you have explicitly enabled. You can disable notifications at any time in your device settings or within August.

Payment data: Subscription payments are processed by Razorpay. We do not store your card details. Razorpay processes payment data under their own privacy policy and PCI-DSS compliance.

3. How We Use Your Data

We do not sell your personal data. We do not use your data for targeted advertising. We do not share your expense or task data with any third party except as described in this policy.

4. Data Storage and Security

Your structured data (tasks, expenses, profile) is stored in a MongoDB database hosted on Emergent's managed infrastructure. Receipt images are stored in Cloudflare R2 object storage. Both are encrypted at rest and in transit using industry-standard encryption (TLS 1.2+, AES-256).

Access to your data is restricted to authenticated sessions only. We use Firebase Authentication to manage user identity and session tokens. Your credentials are never stored in plain text.

Receipt images are automatically deleted from Cloudflare R2 after 30 days via a lifecycle policy. You may request earlier deletion by contacting us at hey@myaugust.app.

5. Third-Party Services

August uses the following third-party services to operate:

Each of these providers operates under their own privacy policies and data processing agreements. Where required, we have executed Data Processing Agreements (DPAs) with these providers.

6. Cross-Border Data Transfers

Some of our third-party providers (including Google and Cloudflare) process data on servers outside India. By using August, you consent to the transfer of your data to these providers for the purposes described in this policy. We take reasonable steps to ensure such transfers comply with the DPDP Act, 2023, including reviewing the data protection practices of our providers.

7. Your Rights Under DPDP Act, 2023

As a data principal under the Digital Personal Data Protection Act, 2023, you have the following rights:

To exercise any of these rights, contact us at hey@myaugust.app with the subject line "Data Rights Request".

8. Children's Privacy

August is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us immediately at hey@myaugust.app and we will delete it promptly.

9. Data Retention

We retain your account data for as long as your account is active. Receipt images are deleted after 30 days. If you delete your account, we will delete or anonymise all associated personal data within 30 days, except where we are required to retain it by law.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via the app and update the "Last updated" date at the top of this page. Your continued use of August after such changes constitutes your acceptance of the updated policy.

11. Contact Us

For any privacy-related questions, requests, or complaints, please contact:

August — Data Privacy
Email: hey@myaugust.app
Website: myaugust.app