Palette Vault Privacy Policy
Last updated: September 16, 2026
This Privacy Policy explains how Lakshmanan ("we", "us", or "our") collects, uses, stores, and discloses information when you use the Palette Vault mobile application (the "App"). The App's technical backend identifier is colorhunt and its Android package name is com.frontendforever.colorhunt.
Information we collect
Account and authentication information
If you create an account or sign in, we may process:
- your email address;
- your name or display name;
- an optional profile photo URL;
- your selected sign-in provider and a Firebase account identifier when Google/Firebase sign-in is used; and
- a securely hashed password for accounts that use email and password sign-in. We do not store your plain-text password.
Email verification and password-reset requests may also create a short-lived verification code and related delivery record.
App activity and purchase information
To provide Palette Vault features, our backend may store:
- palette codes you save as favorites;
- the date and count of palette downloads used for free-tier limits;
- membership status, product identifiers, subscription dates, order identifiers, and purchase-verification results; and
- messages or feedback that you choose to send to us, including your name, email address, message, and optional images or attachments when supported by the App.
The palette catalog and palette popularity counters are app content. They are not used to create a personal profile of you.
Device, notification, and technical information
If notifications are enabled, we process the Firebase Cloud Messaging (FCM) registration token needed to deliver notifications. Device registration may also include the device identifier, platform, model, operating-system version, app version, language, and time zone.
Our authentication and security systems may record the IP address, user-agent information, token timestamps, and related request metadata. Firebase Analytics and Firebase Crashlytics may collect app events, diagnostics, crash reports, and performance information in the App's release builds. Analytics collection can be disabled in the App's settings; crash reporting is used to investigate stability issues.
How we use information
We use information to:
- create and authenticate accounts and verify email addresses;
- provide palettes, favorites, downloads, premium features, and account support;
- verify and restore purchases through the applicable app store;
- deliver optional push notifications;
- prevent fraud, abuse, and unauthorized access;
- diagnose crashes, improve performance, and understand aggregate feature usage; and
- respond to questions, feedback, deletion requests, and legal obligations.
How information is shared
We do not sell or rent personal information. We disclose information only as needed to operate Palette Vault, including to:
- Google Firebase, for authentication, analytics, crash diagnostics, and push notifications where those services are enabled;
- Google Play, or the applicable app store, to process and verify in-app purchases; and
- hosting, email, security, and technical-service providers that process information on our behalf under contractual or legal confidentiality obligations.
We may also disclose information when required by law, to protect the App or its users, or in connection with a business transfer. We do not use account information for third-party targeted advertising in the current Palette Vault build.
Data stored on your device
The App may store authentication tokens, a cached account profile, preferences, cached palettes, favorites, purchase state, and other local app data. This local data can be removed by signing out where applicable, clearing the App's storage, or uninstalling the App. Removing local data does not by itself delete server-side account data; use the deletion options below for that.
Retention
We retain account and associated service data while your account is active. When you delete your account, we remove the account record and associated server-side favorites, download history, notification registrations, memberships, and authentication records from our systems as part of the deletion process.
We normally complete an in-app deletion immediately after successful authentication. Requests submitted through the public deletion page are verified and processed within 30 days. We may retain the minimum information needed to process or document a deletion request, comply with tax, accounting, fraud-prevention, security, or legal requirements, or resolve disputes. Google Play and Firebase may retain information under their own policies and legal obligations.
Your choices and rights
Depending on your location, you may request access to, correction of, or deletion of your personal information. You can:
- manage notification permission in your device settings;
- disable analytics collection in the App's settings;
- update profile information through the App; and
- delete your account in the App or use the public Account Deletion Request page, which does not require you to sign in.
To ask a privacy question or exercise a right, contact lakshmanan.coder@gmail.com and include the email address associated with your account.
Children's privacy
Palette Vault is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and remove it where required.
Security
We use HTTPS for API traffic, access controls, password hashing, and other reasonable safeguards. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.
Third-party links and policies
The App may link to websites or services that we do not operate. Their privacy practices are governed by their own policies. For more information, see Google's Privacy Policy and Firebase's Privacy and Security documentation.
Changes to this policy
We may update this policy when the App or applicable requirements change. The current version and its effective date will be posted on this page.
Contact
For privacy questions or requests, contact lakshmanan.coder@gmail.com.