Privacy Policy

Last updated: 31 May 2026

Unified Business Web Solution ("Company", "we", "us", or "our"), operating through its website at www.ubwebs.com, operates the Rymind mobile application and the Rymind Web companion application at rymind.in (collectively, the "Service").

This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information when you use the Service. By using the Service, you consent to the practices described in this Privacy Policy.

1. Information We Collect

1.1 Information You Provide Directly

When you create an account and use Rymind, we collect the following information:

Data TypePurposeWhen Collected
Full nameDisplay in your profile; personalise notificationsAccount registration
Email addressAccount login; email verification; deliver email remindersAccount registration
Phone number (with country code)Phone verification; deliver SMS and WhatsApp remindersAccount registration
PasswordAccount authentication (stored as a bcrypt hash — we never store your plaintext password)Account registration
Reminder contentTitles, messages, scheduled times, timezone, delivery channels, repeat settingsWhen you create or edit reminders
ContactsNames, phone numbers, and/or email addresses of people you save for quick reminder assignmentWhen you add contacts in the app

1.2 Information Collected Automatically

We collect metadata and technical logs to ensure reliable delivery of messages:

Data TypePurposeHow Collected
Expo Push TokenDeliver push notifications to your specific deviceGenerated by your device when you grant notification permission
Device informationIdentify device type for push notification compatibilityExpo Device API
Web session metadataBrowser type (user-agent string), approximate IP address for web session managementWhen you link a web session via QR code scan
Reminder delivery logsTrack which reminder notifications were sent and through which channelsAutomatically when a reminder fires

1.3 Information We Do NOT Collect

  • We do not collect your precise GPS location.
  • We do not access your device's contact book or address book. The "Contacts" feature in Rymind uses only contacts you manually create within the app.
  • We do not collect photos, files, or media from your device. Camera access is used solely for scanning QR codes to link Rymind Web sessions.
  • We do not use cookies for tracking on the mobile app. For Rymind Web, see Section 8.
  • We do not collect any biometric data.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide the Service: Create and manage your account, store and schedule your reminders, deliver notifications through your chosen channels.
  • Deliver reminders: Send push notifications, WhatsApp messages, SMS, and emails at your scheduled times.
  • Send reminders to others: When you create a reminder for another person, we use the contact information you provide (name, phone, email) to attempt delivery. If the recipient is a registered Rymind user (matched by phone number), we deliver a push notification directly to their device.
  • Verify your identity: Send verification codes via SMS and email during account registration.
  • Manage web sessions: Enable and manage QR-based login for the Rymind Web companion app.
  • Improve the Service: Analyse usage patterns (in aggregate) to improve reliability, fix bugs, and develop new features.
  • Communicate with you: Send important service announcements, security alerts, or respond to your support requests.

We do not use your information for advertising, and we do not sell your data to any third party.

3. Third-Party Services

To deliver the Service, we rely on the following trusted third-party providers. Your data is shared with them only to the extent necessary to perform their specific function:

Service ProviderData SharedPurpose
MongoDB AtlasAll account data, reminders, contacts, logs (encrypted at rest)Cloud database hosting and storage
TwilioPhone number, reminder contentDeliver SMS and WhatsApp messages
ResendEmail address, reminder contentDeliver email notifications and verification codes
Expo (Expo Application Services)Expo Push Token, notification payload (title, message)Deliver push notifications to mobile devices
RailwayServer hosting (your data passes through their infrastructure)Backend server hosting

Each of these providers maintains their own privacy policy and security practices. We recommend reviewing their policies:

We do not share your data with any third-party advertisers, data brokers, or analytics platforms.

4. Data Storage and Security

  • Location: Your data is stored on MongoDB Atlas cloud servers. Server hosting is provided by Railway.
  • Encryption: Passwords are hashed using bcrypt with salted rounds before storage. We never store your password in plaintext. Data in transit is encrypted using TLS/HTTPS.
  • Access control: API endpoints are protected by JWT (JSON Web Token) authentication. Only authenticated requests can access your data.
  • Verification codes: One-time verification codes (for phone and email) automatically expire after 10 minutes and are deleted from the database after successful verification.
  • Web session tokens: Web session JWTs expire after 30 days. You can revoke any linked web session at any time from the mobile app.

While we implement commercially reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.

5. Data Retention

  • Account data (name, email, phone, password hash) is retained for as long as your account is active.
  • Reminders and contacts are retained for as long as your account is active, including completed and cancelled reminders (accessible in your history).
  • Reminder delivery logs are retained for service reliability and troubleshooting purposes.
  • Verification codes are automatically deleted after 10 minutes (TTL-based expiry).
  • Web session records are retained until revoked by you or until they expire.

Upon account deletion (see Section 6), all your data — including your user profile, reminders, contacts, delivery logs, web sessions, and verification codes — is immediately and permanently deleted from our database in real time. No data is retained after deletion.

6. Your Rights

You have the following rights regarding your personal information:

6.1 Access and Portability

You can view your personal information (name, email, phone, country code) at any time through the Profile section of the app. Your reminders and contacts are accessible within the app at all times.

6.2 Correction

If your personal information is inaccurate, you may contact us at contact@rymind.in to request corrections.

6.3 Deletion

You can permanently delete your account and all associated data directly from the app by navigating to Profile → Danger Zone → Delete my account. Upon confirmation, all your data — including your profile, reminders, contacts, delivery logs, linked web sessions, and verification codes — is immediately and permanently deleted from our systems. This action is irreversible.

Alternatively, you may request account deletion by contacting us at contact@rymind.in.

6.4 Notification Opt-Out

You can disable push notifications at any time through your device's system settings. You can choose which reminder channels (push, WhatsApp, SMS, email) to use on a per-reminder basis. Not selecting a channel means we will not send notifications through that channel.

6.5 Revoke Web Sessions

You can revoke any linked Rymind Web session at any time from the "Linked Devices" section in the mobile app, immediately signing out that web session.

6.6 Rights Under Indian Law

Under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDPA), you have the right to:

  • Access your personal data held by us.
  • Request correction of inaccurate or incomplete data.
  • Request erasure of your personal data.
  • Nominate another individual to exercise your rights in case of your death or incapacity.
  • Lodge a grievance with the Data Protection Board of India.

If you wish to exercise any of these rights, please contact us at contact@rymind.in.

7. Reminders Sent to Other People

When you create a reminder for another person:

  • You provide their name and optionally their phone number and/or email address.
  • If the person is a registered Rymind user (matched by phone number), they will receive a push notification on their device with the reminder title and message. The recipient will see that a reminder was sent to them but will not have access to your account information beyond your reminder content.
  • If the person is not a Rymind user, you will be prompted within the app to manually send the WhatsApp, SMS, or email notification yourself.
  • You are responsible for ensuring you have the right and consent to send reminders and notifications to other people. Do not use this feature to send unsolicited or harassing messages.

We store the contact information (name, phone, email) you provide for reminder recipients as part of the reminder record and in your saved contacts (if you choose to save them).

8. Cookies and Web Technologies

Rymind Mobile App: We do not use cookies or similar tracking technologies in the mobile application.

Rymind Web (rymind.in): The web companion application may use:

  • Essential cookies or local storage to maintain your login session (JWT token) and remember your authentication state. These are strictly necessary for the web app to function and cannot be disabled.

We do not use any analytics cookies, advertising cookies, or third-party tracking scripts on Rymind Web.

9. International Data Transfers

Our servers may be located outside your country of residence. By using the Service, you consent to the transfer and processing of your data in jurisdictions where our service providers operate (which may include the United States, European Union, or other regions), subject to appropriate safeguards.

10. Children's Privacy

Rymind is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal data from a child under 13, we will take steps to delete that information promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at contact@rymind.in.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Post the updated Privacy Policy within the app and on rymind.in.
  • Update the "Last updated" date at the top of this document.
  • Notify you via push notification or email for significant changes.

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Privacy Policy.

12. Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify affected users via email within 72 hours of becoming aware of the breach.
  • Report the breach to the relevant Indian authorities as required under applicable law.
  • Take immediate steps to mitigate the impact and prevent further unauthorised access.

13. Grievance Officer

In accordance with the Information Technology Act, 2000 and the rules made thereunder, the Grievance Officer for the purpose of this Privacy Policy is:

Unified Business Web Solution
Email: contact@rymind.in
The Grievance Officer shall address your concerns and grievances within 30 days of receiving your complaint.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: contact@rymind.in
Company: Unified Business Web Solution
Website: www.ubwebs.com