Privacy Policy
Last updated Sep 30, 2026
Effective date: 30 September 2026
This Privacy Policy explains how True Library ("True Library", "we", "us" or "our") collects, uses, shares and protects personal data when you use our website https://truelibrary.in, our web application https://app.truelibrary.in, the student portals and library websites we host for our customers, and our mobile apps (together, the "Service").
True Library is library management software for self-study libraries, reading rooms and study centres in India. We are based at Muftiganj, Jaunpur, Uttar Pradesh 222170, India.
We process personal data in line with the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the Information Technology Act, 2000 and the rules made under them.
1. Our role: when we decide and when the library decides
Two kinds of people use the Service, and our role is different for each.
- Library owners and their staff. When you create a True Library account, we decide how your account and billing data is used. For this data, we are the Data Fiduciary under the DPDP Act.
- Students of a library. A library uses the Service to manage its own students, and the library decides what student data it collects and why. For student data, the library is the Data Fiduciary. We process that data only on the library's behalf and on its instructions. If you are a student, please contact your library first about your data. We will help the library respond to you.
2. Information we collect
2.1 Library owners and staff
- Account details: name, email address, mobile number, password (stored only in hashed form), role and permissions.
- Google sign-in: if you sign in with Google, we receive your name, email address, profile photo and Google account ID from Google. We never receive your Google password.
- Library details: library and branch names and addresses, seats, shifts, fee plans, logo, GST number (if you add one to your invoices), the content of your library website, and payment settings such as the UPI ID and payee name that students use to pay you.
- Billing details: your plan, subscription and payment status, the payment and subscription IDs given by our payment partner, and the invoices we issue to you. Card numbers, UPI PINs and net-banking passwords are entered on Razorpay's secure checkout and are never stored by us.
- Support and communication: messages you send us through support tickets, the contact form, email, phone or WhatsApp, and any files you attach.
- Referral program details: if you join a referral or affiliate program we offer, the payout details you give us (such as your UPI ID or bank account name, account number and IFSC) and your PAN where tax law requires it. These are stored encrypted.
2.2 Students (collected by the library)
Depending on the features a library uses, the Service may hold:
- Profile: name, mobile number and, if the library asks for them, email address, address, gender, and the type and number of an ID proof (for example Aadhaar, PAN or Voter ID).
- Membership: seat, shift, plan, dates, locker, fees, invoices and payment records.
- Payment proof: a screenshot of a UPI payment made directly to the library, uploaded by the student as proof of payment.
- Attendance: check-in and check-out times and study time.
- Check-in selfie (optional): if the library turns this on, a photo taken at check-in so the library can confirm who checked in. We do not use selfies for face recognition or any other biometric identification.
- Check-in location (optional): if the library turns this on, the device's location at the moment of check-in or check-out, and its distance from the library, to confirm that the student is at the library. We do not track location at any other time.
- Student portal sign-in: mobile number and a 4-digit PIN. PINs are stored encrypted.
2.3 Collected automatically
- Device and log data: IP address, browser and device type, the pages and features used, and the date and time of access.
- Sign-in and security data: sign-in history (time, IP address and device), failed sign-in attempts, and a device identifier (a coded value created from browser details) used to recognise new devices and prevent misuse.
- Cookies and similar technologies: see our Cookie Policy.
2.4 Mobile apps
When our mobile apps are available, they may ask for the device permissions below. Each one is used only for the feature named, and you can turn it off anytime in your phone's settings.
- Camera: to take a check-in selfie or photograph a document.
- Location: to confirm attendance at the library at check-in or check-out.
- Photos and files: to upload a payment screenshot, logo or other file you choose.
- Notifications: to send reminders and account alerts. We may use Firebase Cloud Messaging, a Google service, to deliver them.
3. How we use information
We use personal data to:
- create and manage accounts, and let you sign in securely;
- provide the features of the Service, such as seat management, fees, invoices, attendance, the student portal and library websites;
- process subscription payments, issue invoices, and manage renewals, failed payments and refunds;
- send service messages, such as password reset links, receipts, trial and renewal reminders, and payment alerts;
- answer support requests and complaints;
- keep the Service secure, for example by detecting unusual sign-in activity and blocking harmful traffic;
- understand how the Service is used, fix errors and improve it, mostly using combined data that does not identify anyone;
- comply with the law, such as tax, accounting and law-enforcement requirements.
We send promotional messages only if you have agreed to receive them, and you can opt out anytime. We do not sell personal data, and we do not use student data for our own marketing.
4. Legal basis
We process personal data:
- on the basis of the consent you give, which you can withdraw anytime;
- for legitimate uses allowed by the DPDP Act, such as providing a service you asked for when you gave us the data voluntarily for that purpose;
- to comply with the law.
Withdrawing consent does not affect processing that took place before it, but some features may stop working.
5. Who we share information with
We share personal data only as described below.
- Within a library: student data is visible to that library's owner and to the staff members the owner authorises. A student can see their own data in the student portal.
- Service providers who work for us, under confidentiality and security obligations:
- Razorpay Software Private Limited, to process payments and auto-pay mandates;
- Hostinger, our hosting provider, whose servers store the Service's data and backups;
- Google, for Google sign-in and, where we use them, Google Play billing, Firebase and Google Analytics;
- email delivery providers, to send service emails.
- WhatsApp reminders: when a library owner or staff member taps a reminder, the Service opens WhatsApp on their own device with a pre-written message. That message, which may include a student's name and the amount due, is sent by the library from its own WhatsApp account and is subject to WhatsApp's terms.
- Legal reasons: to a court, government or law-enforcement authority when the law requires it, or to protect the rights, property or safety of True Library, our users or the public.
- Business transfer: if True Library is merged, sold or reorganised, personal data may pass to the new owner, who must protect it under this policy. We will tell you before this happens.
6. Where data is stored and how we protect it
- Data is stored on the servers of our hosting provider. Some service providers, such as Google, may process data outside India. Where this happens, we transfer data only as permitted by Indian law.
- All data travels over encrypted connections (HTTPS).
- Passwords are hashed. Sensitive values such as portal PINs, payout bank details and PAN are encrypted at rest.
- Access is limited by roles and permissions. Our own administrator accounts are protected by two-factor authentication.
- We monitor sign-in activity and temporarily block suspicious sign-in attempts.
- Our hosting provider takes automated backups.
No method of storing or sending data is completely secure. If a personal data breach occurs, we will inform the affected users and the Data Protection Board of India as the law requires.
7. How long we keep information
We keep personal data only for as long as it is needed for the purposes in this policy.
- Account data: while your account exists. If your subscription ends, your account becomes read-only and your data is kept so you can continue later. We may delete the data of an account that stays inactive for a long time, after telling you by email at least 30 days in advance.
- After you delete your account: your data is permanently deleted 7 days after your request. Signing in during those 7 days cancels the request. See how to delete your account.
- Billing records: payment and invoice records are kept even after an account is deleted, for as long as tax and accounting laws require (generally up to 8 years).
- Check-in selfies: deleted automatically after the period the library sets (60 days by default).
- Attendance, logs and support records: kept for a limited period for record-keeping, security and troubleshooting, and then deleted.
- Backups: copies in backups are removed as the backups rotate.
8. Your rights
Under the DPDP Act, you have the right to:
- get a summary of the personal data we hold about you and how we use it;
- correct, complete or update your data;
- have your data erased when it is no longer needed and the law does not require us to keep it;
- withdraw consent you gave earlier;
- have your complaints resolved (see our Grievance Redressal page);
- nominate another person to use these rights on your behalf in case of death or incapacity.
You can update most account details in the app, and you can delete your account from Settings → Account. For any other request, email us from your registered email address. We may need to verify your identity first. Students should contact their library first, because the library controls student data.
9. Children
Library owners and staff must be at least 18 years old. Some students of a library may be under 18. A library that adds a student under 18 must first get verifiable consent from the student's parent or lawful guardian, as the DPDP Act requires. We do not track or monitor the behaviour of children, and we do not target advertising at them.
10. Third-party services and links
The Service links to services run by other companies, such as Razorpay's checkout, Google sign-in and WhatsApp. Their own privacy policies apply to the data you give them. A library website hosted on the Service is controlled by that library.
11. Changes to this policy
We may update this policy from time to time. The effective date at the top shows when it last changed. If a change is significant, we will tell you by email or in the app before it takes effect.
12. Contact us
- Email: anand44yadav@gmail.com
- Phone / WhatsApp: +91 96488 17847
- Address: True Library, Muftiganj, Jaunpur, Uttar Pradesh 222170, India
To make a complaint, see our Grievance Redressal page.