Legal & Privacy Transparency

Privacy Policy for SDdev

Last Updated: September 14, 2026

Welcome to SDdev (accessible at https://sddev.in). We value your trust and are committed to protecting your privacy. This Privacy Policy details how SDdev ("we", "our", or "us") collects, uses, stores, shares, and protects your information when you access our platform, use our tools, or authenticate via email or third-party providers like Google.

By accessing or using SDdev, you agree to the collection and handling of your data in accordance with this Privacy Policy and our Terms of Service.

1. Information We Collect

1.1 Google Account & OAuth Data

When you choose to sign in to SDdev using Google Sign-In (OAuth 2.0), we request read-only access to standard identity scopes (openid, email, profile). The specific information we receive and store includes:

  • Google User ID: A unique numerical identifier assigned by Google to link your SDdev session.
  • Email Address: Your primary Google account email, used as your SDdev login identity and for essential account notifications.
  • Display Name: Your full name associated with your Google account, used to personalize your user dashboard.
  • Profile Picture URL: Your public Google avatar thumbnail, displayed in your account profile and navigation bar.

We do not request access to your Google Drive files, Google Contacts, emails, calendars, or any other private Google service data.

1.2 Email & Password Registration

If you register directly with an email address and password, we collect your name, email address, and a securely salted and hashed password. We never store plain-text passwords.

1.3 Application & Usage Data

To maintain system stability, enforce fair use, and manage tool credits, we log metadata including:

  • Tool execution counts and credit deductions.
  • Timestamp of requests and IP addresses (used strictly for rate limiting, DDoS mitigation, and safety verification).
  • Shortened URL destination links and aggregated click counts for users of our URL Shortener tool.

1.4 Payment Details

When you purchase tool credits, payments are processed directly by our compliant payment gateway partner, Razorpay. SDdev does not receive or store your credit card numbers, CVVs, or net banking passwords.

2. How We Use Collected Information

We use the collected information strictly for operational and account management purposes:

  • Authenticating your identity and maintaining your active login session.
  • Allocating and managing your SDdev tool credits, usage balances, and API keys.
  • Delivering tool outputs (e.g., generating QR codes, formatting developer payloads, processing file conversions).
  • Providing responsive customer support and responding to inquiries submitted via our contact forms.
  • Detecting, preventing, and addressing security threats, spam, or terms violations.

3. Google API Services User Data Policy & Limited Use Disclosure

SDdev complies with the Google API Services User Data Policy, including the Limited Use requirements.

SDdev's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We do not use Google user data to serve advertisements, including personalized, re-targeted, or interest-based advertising.
  • We do not sell, license, or rent Google user data to third parties, data brokers, or external advertising networks under any circumstances.
  • We do not use Google user data to train or fine-tune generalized machine learning or artificial intelligence models.
  • Humans are not permitted to read your data unless you have given explicit consent for troubleshooting, it is necessary for security investigations, or it is required to comply with applicable law.

4. Third-Party Service Providers

We only share data with essential third-party service providers necessary to operate the application:

Third-Party Service Purpose Privacy Policy Link
Google OAuth User authentication and profile identity policies.google.com/privacy
Razorpay Secure payment gateway for purchasing credits razorpay.com/privacy
Cloud Infrastructure Providers Encrypted hosting, database storage, and SSL delivery Standard SOC-2 compliant hosting agreements
Google Analytics Anonymized website traffic and performance analytics policies.google.com/privacy

5. Data Storage, Security & Retention

We implement industry-standard technical measures to safeguard your information:

  • Encryption in Transit: All communications between your browser and SDdev servers are encrypted using modern HTTPS (TLS/SSL).
  • Encryption at Rest: Account information and session identifiers are stored in access-controlled, encrypted databases.
  • Zero Document Retention for Utilities: Files uploaded to client-side tools (e.g. image converters, PDF tools) are processed directly in memory and not stored permanently on our servers.
  • Retention Period: We retain your account data for as long as your account remains active. If an account is inactive or requested to be deleted, data is permanently erased within 30 days.

6. User Rights, Data Deletion & Revoking Access

You have full control over your personal data:

How to Revoke Google Access

You can revoke SDdev's access to your Google account at any time by visiting your Google Account Third-Party Permissions page and clicking "Remove Access" for SDdev.

How to Request Account & Data Deletion

You have the right to request the complete deletion of your account, email, profile details, and history. You can initiate account deletion by:

Upon receiving your request, your account and associated records will be permanently deleted from our primary databases within 30 business days.

7. Account Suspension, Banning & Abuse Enforcement

To safeguard the platform and protect internet users from fraud, phishing, and malware, SDdev enforces automated and administrative security policies:

  • Grounds for Suspension & Banning: Accounts engaged in creating or distributing phishing links, deceptive brand-impersonation URLs, malware, scams, or attempting to circumvent safety filters are subject to immediate and permanent termination without prior notice.
  • Data Handling Upon Account Ban: Once an account is banned, active login sessions and API tokens are revoked immediately, and all shortened URLs or redirect pathways created by the user are permanently disabled and purged to prevent harm to the public.
  • Security Log & Blacklist Retention: In accordance with our legitimate interest in fraud prevention and security, minimal identifier records (such as account IDs, email addresses, and incident logs) may be retained in our restricted abuse blacklist strictly to prevent banned actors from creating new accounts.
  • Appeals: If you believe an account ban was applied in error, you may submit an appeal for administrative review by emailing support@sddev.in with your account details.

8. Cookies & Session Management

We utilize a secure, HTTP-only session cookie (sddev_session) to maintain authentication state. We do not use persistent cross-site tracking cookies. Disabling cookies in your browser settings will prevent you from signing in to the platform.

9. Children's Privacy

SDdev is not directed to children under the age of 13. We do not knowingly collect personal identifiable information from children under 13. If we discover that a child under 13 has provided personal data, we promptly delete it from our systems.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services or legal requirements. Material modifications will be posted to this page with an updated revision date. We encourage users to review this page periodically.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your data, please contact us: