Sanatan Labs

Gita Shlok Path · गीता श्लोक पथ

Privacy Policy · गोपनीयता नीति

App: Gita Shlok Path (गीता श्लोक पथ)
Package ID: com.gitashlokpath.app
Developer: Sanatan Labs (India)
Contact: sanatanlabs01@gmail.com
Last updated: 8 September 2026

1. Overview

Gita Shlok Path is an offline devotional app that presents all 700 verses of the Shrimad Bhagavad Gita with audio recitation, meanings and word-by-word explanations.

The short version: You can read and listen to the entire app without an account. The app never asks for your name, phone number or location, contains no advertising, and contains no analytics or tracking of any kind. There is one exception, and only in the Indus Appstore version: unlocking the full Gita there asks you to sign in with Google, so that your unlock can be restored on a new phone. Even then we keep only the account identifier Google gives us — not your email address, not your name. All verse content and audio is bundled inside the app and works fully offline. Your bookmarks, listening progress and settings never leave your device.

This policy explains, plainly and completely, what the app does and does not do with information. It applies to the Gita Shlok Path Android application, however you obtained it — through the Google Play Store or the Indus Appstore. The two versions handle payment differently, so sections 4 and 4a describe each one separately.

2. Information we do NOT collect

We want to be specific rather than vague, because "we respect your privacy" means nothing on its own. The app does not collect, request, transmit or store any of the following:

There is no account and no login for using the app. Reading, listening, bookmarking and searching all work without identifying yourself in any way. The only place an identity is involved at all is the optional purchase in the Indus Appstore version, described in section 4a.

The app declares four Android permissions, and no others:

PermissionWhat it is for
INTERNETOnly for the optional purchase and its verification. Reading and listening to verses requires no internet connection at all
POST_NOTIFICATIONSTo show the playback notification with play, pause and skip controls while audio is running
FOREGROUND_SERVICETo keep audio playing when the screen is off or you switch to another app
FOREGROUND_SERVICE_MEDIA_PLAYBACKThe media-playback category required by Android for the above

None of these permissions gives the app access to your personal data, and the app requests no location, contacts, storage, camera or microphone permission of any kind.

3. Information stored on your device

The app saves a small amount of data locally so that it can remember your preferences between sessions. This data lives only in the app's private storage on your phone. It is never uploaded to us, and is never shared with anyone.

What is storedWhy
Bookmarked versesSo your saved verses are there next time you open the app
Last verse played and playback positionSo you can resume where you left off
Settings — language, theme, font size, default sleep timerSo you don't have to set them again
Unlock status of the full-Gita purchaseSo the app knows which chapters to make available
The sign-in token from your last purchase or restore (Indus Appstore version only)So the app can silently re-check your unlock when it starts, without asking you to sign in again. It stays in the app's private storage
The 700 verses and their encrypted audio filesBundled with the app so it works fully offline
A crash report, if the app has crashedShown to you on the next launch so you can report the problem if you wish. It is stored only on your device and is never sent anywhere automatically

Uninstalling the app removes all of this data from your device.

4. Purchases — Google Play Store version

Chapters 1 and 2 are permanently free. The remaining chapters can be unlocked with a single optional one-time in-app purchase. In the Play Store version this is handled entirely by Google Play Billing, using the payment methods already on your Google account. There is no separate sign-in and we ask you for nothing.

4a. Purchases — Indus Appstore version

The version of the app distributed through the Indus Appstore does not use Google Play Billing. Payment there is handled by Razorpay, a licensed Indian payment gateway, and your unlock is tied to a Google account so that it can be restored later.

Signing in with Google. When you choose to buy the full Gita, or when you tap Restore previous purchase, the app asks you to pick a Google account. This is the only moment sign-in ever appears — it never happens when you open the app, and you are never made to sign in to read or listen.

What we keep on our server. Once a payment succeeds, a single small record is written, stored against your account identifier:

FieldWhy it is kept
Account identifier (Google sub)To know whose unlock this is when you restore
Unlocked: yesThe answer the app is asking for
Razorpay order ID and payment IDTo trace a payment if something goes wrong, and to process a refund
Amount paid and the dateAccounting, and to confirm the correct amount was charged

That is the whole record. There is no name, no email address, no phone number, no address and no device information in it.

Razorpay's part. Razorpay processes the payment itself and handles your card, UPI or banking details under Razorpay's Privacy Policy. We never see or store those details. Razorpay's own checkout screen may ask you for contact details for its receipt — anything you enter there goes to Razorpay, not to us, and the app does not fill it in for you or read it back. So that a payment can later be matched to the right unlock, a shortened form of the account identifier is sent to Razorpay as the order reference; it is not your email address and cannot be used to contact you.

5. Our verification server

To stop the paid content from being unlocked fraudulently, and to let you restore a purchase, the app talks to a small server we operate on Cloudflare Workers, with the record described in section 4a held in Cloudflare Workers KV. This is the only server of ours the app ever contacts.

The app contacts it in exactly three situations: when you make a purchase, when you tap restore, and once at startup only if you have already bought the unlock, to re-check that it is still valid. If you have not bought anything, the app makes no network request at all.

As part of any internet request, the hosting infrastructure processes your device's IP address transiently in order to deliver the response and to protect against abuse. We do not log it into any record of ours, do not build profiles, and do not use it for any purpose beyond serving the request. Cloudflare acts as our infrastructure provider under Cloudflare's Privacy Policy.

To do its job, our server in turn contacts Google (for the public keys used to check a sign-in token, and for the Play Developer API in the Play Store flow) and Razorpay (to confirm a payment really was received). It contacts nothing else.

6. Device integrity check

The app contains support for the Google Play Integrity API, an anti-piracy measure that confirms the app is running on a genuine, unmodified Android device. This check is currently switched off and the app collects no device or app identifier through it. If we enable it in a future version, we will update this page before doing so. Were it enabled, it would produce an integrity verdict for that purpose only; it would not be used to identify you as a person and would not be combined with any other data.

7. Audio content

The verse recitations included in the app are produced using AI voice synthesis (Vagdhenu AI) and are bundled with the app in encrypted form. The app never records audio, never requests microphone access, and never sends any audio anywhere.

8. Sharing and selling of data

We do not sell, rent, trade or share your data with anyone. There are no advertising partners, no data brokers and no third-party analytics providers involved in this app.

The only third parties involved at all are:

Each is used strictly for the purpose described above, and only when you choose to make or restore a purchase.

9. Data retention

Data stored on your device remains there until you delete it in the app or uninstall the app.

In the Play Store flow, our server stores nothing at all. In the Indus Appstore flow, the unlock record described in section 4a is kept for as long as your purchase is valid, because deleting it would take away access you have paid for. It is removed if you ask us to delete it (see section 10) or if the payment is refunded. Purchase records are separately retained by Google Play or Razorpay according to their own policies and Indian tax law.

10. Your rights and choices

11. Children's privacy

This app is a general-audience devotional and reference app. It is not directed at children, and it does not knowingly collect any personal information from anyone, including children under the age of 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has made a purchase or provided information to us, please contact us and we will delete the record and assist with a refund.

12. Security

The verse audio is protected by two layers of encryption: the audio files are encrypted before being packaged into the app, and on first launch they are re-encrypted on your device using a key generated in the Android Keystore, which never leaves your device. All network requests made by the app use encrypted HTTPS connections. Payment amounts are decided on our server rather than by the app, and every payment is re-checked directly with Razorpay before an unlock is granted, so a tampered device cannot claim a purchase that did not happen.

No system can be guaranteed perfectly secure, but since the app holds no personal data, the impact of any such event on your privacy is minimal by design.

13. Changes to this policy

If the app's behaviour changes in a way that affects this policy, we will update this page and revise the "Last updated" date at the top. Significant changes will also be noted in the app's release notes on the Google Play Store and the Indus Appstore. Continued use of the app after an update constitutes acceptance of the revised policy.

14. Contact

For any question, concern, correction or complaint regarding this policy or the app — including a request to delete your data — please write to:

Email: sanatanlabs01@gmail.com
Developer: Sanatan Labs, India
Grievance contact: the same address. We acknowledge within 2 working days and aim to resolve within 30 days.

We read every message and will respond as promptly as we are able.

• • •

हिंदी में गोपनीयता नीति

अंतिम संशोधन: 8 सितम्बर 2026

संक्षेप में: पूरा ऐप बिना किसी खाते (account) के पढ़ा और सुना जा सकता है। ऐप आपका नाम, फ़ोन नंबर या स्थान (location) कभी नहीं माँगता, इसमें कोई विज्ञापन नहीं है, और किसी भी प्रकार की ट्रैकिंग या एनालिटिक्स नहीं है। केवल एक अपवाद है, और वह भी सिर्फ़ Indus Appstore वाले संस्करण में — सम्पूर्ण गीता खरीदते समय आपसे Google खाते से साइन-इन करने को कहा जाता है, ताकि नया फ़ोन लेने पर आपका अनलॉक वापस मिल सके। तब भी हम केवल वह पहचान-संख्या रखते हैं जो Google देता है — आपका ईमेल पता नहीं, आपका नाम नहीं। सभी श्लोक और ऑडियो ऐप के भीतर ही मौजूद हैं और पूरी तरह ऑफ़लाइन चलते हैं। आपके प्रिय श्लोक, सुनने की प्रगति और सेटिंग्स आपके फ़ोन से कभी बाहर नहीं जाते।

1. हम क्या एकत्र नहीं करते

ऐप का उपयोग करने के लिए कोई खाता या लॉगिन नहीं चाहिए। पढ़ना, सुनना, प्रिय करना और खोजना — सब बिना अपनी पहचान बताए चलता है। पहचान केवल एक जगह आती है: Indus Appstore वाले संस्करण की वैकल्पिक ख़रीद (देखें भाग 3a)।

ऐप केवल चार Android अनुमतियाँ लेता है, इसके अतिरिक्त कोई नहीं:

इनमें से कोई भी अनुमति ऐप को आपकी व्यक्तिगत जानकारी तक पहुँच नहीं देती। स्थान, संपर्क, स्टोरेज, कैमरा या माइक्रोफ़ोन की अनुमति ऐप कभी नहीं माँगता।

2. आपके फ़ोन पर क्या सहेजा जाता है

ऐप कुछ जानकारी केवल आपके फ़ोन की निजी स्टोरेज में सहेजता है, ताकि आपकी पसंद याद रहे। यह हमें कभी अपलोड नहीं होती और किसी के साथ साझा नहीं की जाती:

ऐप को अनइंस्टॉल करने पर यह सारा डेटा आपके फ़ोन से हट जाता है।

3. ख़रीद — Google Play Store संस्करण

अध्याय 1 और 2 सदैव नि:शुल्क हैं। शेष अध्याय एक बार की वैकल्पिक इन-ऐप ख़रीद से खुलते हैं, जिसे Play संस्करण में पूरी तरह Google Play Billing संभालता है — कोई अलग साइन-इन नहीं, और हम आपसे कुछ नहीं माँगते। आपका कार्ड नंबर, बैंक विवरण या UPI ID हम कभी नहीं देखते और न ही सहेजते हैं; भुगतान Google द्वारा संसाधित होता है। ऐप को केवल एक purchase token मिलता है, जो आपके नाम या संपर्क से जुड़ा नहीं होता। वह टोकन हमारे सत्यापन सर्वर पर भेजा जाता है, जो Google से पूछकर हाँ या ना का उत्तर पाता है — इस प्रक्रिया में हमारे सर्वर पर कुछ भी सहेजा नहीं जाता। रिफ़ंड और भुगतान इतिहास Google Play के माध्यम से प्रबंधित होते हैं।

3a. ख़रीद — Indus Appstore संस्करण

Indus Appstore वाले संस्करण में भुगतान Razorpay द्वारा होता है, और आपका अनलॉक एक Google खाते से जुड़ा होता है ताकि बाद में वापस मिल सके।

Google से साइन-इन। जब आप सम्पूर्ण गीता खरीदना चुनते हैं, या पिछली ख़रीद वापस पाएँ दबाते हैं, तभी ऐप आपसे Google खाता चुनने को कहता है। साइन-इन केवल इसी क्षण आता है — ऐप खोलते समय कभी नहीं, और पढ़ने-सुनने के लिए कभी नहीं।

हमारे सर्वर पर क्या रहता है। भुगतान सफल होने पर आपके खाता पहचानकर्ता के साथ एक छोटा-सा रिकॉर्ड लिखा जाता है: पहचानकर्ता, "अनलॉक: हाँ", Razorpay का order ID और payment ID, चुकाई गई राशि और तिथि। बस इतना ही। उसमें कोई नाम, ईमेल, फ़ोन नंबर, पता या डिवाइस-जानकारी नहीं होती।

Razorpay का हिस्सा। आपके कार्ड/UPI/बैंक विवरण Razorpay संभालता है — हम उन्हें कभी नहीं देखते। Razorpay की अपनी checkout स्क्रीन रसीद के लिए आपसे संपर्क विवरण माँग सकती है; वहाँ जो भी आप भरते हैं वह Razorpay के पास जाता है, हमारे पास नहीं, और ऐप उसे न तो स्वयं भरता है न पढ़ता है। भुगतान को सही अनलॉक से मिलाने के लिए खाता पहचानकर्ता का एक छोटा हिस्सा order reference के रूप में Razorpay को भेजा जाता है — वह आपका ईमेल नहीं है और उससे आपसे संपर्क नहीं किया जा सकता।

4. सत्यापन सर्वर

ख़रीद असली है या नहीं यह जाँचने के लिए, और आपको अनलॉक वापस देने के लिए, ऐप Cloudflare Workers पर बने हमारे एक छोटे सर्वर से एन्क्रिप्टेड HTTPS द्वारा संपर्क करता है; भाग 3a वाला रिकॉर्ड Cloudflare Workers KV में रहता है। हमारा यही एकमात्र सर्वर है जिससे ऐप कभी संपर्क करता है।

ऐप उससे केवल तीन स्थितियों में बात करता है: ख़रीद के समय, restore दबाने पर, और शुरू होते समय तभी जब आप पहले से ख़रीद चुके हों। यदि आपने कुछ नहीं खरीदा, तो ऐप कोई नेटवर्क अनुरोध करता ही नहीं।

किसी भी इंटरनेट अनुरोध की तरह, इस दौरान आपके डिवाइस का IP पता अस्थायी रूप से संसाधित होता है। हम उसे अपने किसी रिकॉर्ड में नहीं रखते और ख़रीद-सत्यापन के अतिरिक्त उसका कोई उपयोग नहीं करते। अपना काम करने के लिए हमारा सर्वर आगे केवल Google (सार्वजनिक कुंजियाँ और Play Developer API) तथा Razorpay (भुगतान की पुष्टि) से संपर्क करता है।

5. डिवाइस अखंडता जाँच

ऐप में Google Play Integrity API की व्यवस्था मौजूद है, किंतु यह जाँच फ़िलहाल बंद है और इसके ज़रिए कोई डिवाइस पहचानकर्ता एकत्र नहीं होता। भविष्य में इसे चालू करने से पहले हम यह पृष्ठ अद्यतन करेंगे। चालू होने पर भी इसका उपयोग आपकी व्यक्तिगत पहचान के लिए नहीं होगा।

6. ऑडियो

ऐप में सम्मिलित श्लोक-पाठ वाग्धेनु AI द्वारा निर्मित हैं और एन्क्रिप्टेड रूप में ऐप के भीतर ही हैं। ऐप कभी ऑडियो रिकॉर्ड नहीं करता और माइक्रोफ़ोन की अनुमति नहीं माँगता।

7. डेटा साझा करना या बेचना

हम आपका डेटा किसी को नहीं बेचते, न किराए पर देते हैं, न साझा करते हैं। इस ऐप में कोई विज्ञापन साझेदार, डेटा ब्रोकर या तृतीय-पक्ष एनालिटिक्स नहीं है। केवल चार तृतीय पक्ष शामिल हैं, और वे भी तभी जब आप ख़रीद या restore चुनते हैं: Google Play Billing (Play संस्करण में भुगतान), Google Sign-In (Indus संस्करण में पहचान), Razorpay (Indus संस्करण में भुगतान), और Cloudflare (सत्यापन सर्वर)।

8. डेटा कितने समय रखा जाता है

आपके फ़ोन का डेटा तब तक रहता है जब तक आप उसे हटाएँ या ऐप अनइंस्टॉल करें। Play वाले प्रवाह में हमारे सर्वर पर कुछ भी सहेजा नहीं जाता। Indus वाले प्रवाह में भाग 3a का अनलॉक रिकॉर्ड तब तक रहता है जब तक आपकी ख़रीद वैध है — उसे हटाना आपकी चुकाई हुई पहुँच छीन लेना होगा। वह तभी हटता है जब आप कहें (भाग 9) या भुगतान वापस (refund) हो जाए। भुगतान के रिकॉर्ड Google Play या Razorpay अपनी नीतियों और भारतीय कर-नियमों के अनुसार अलग से रखते हैं।

9. आपके अधिकार

10. बच्चों की गोपनीयता

यह ऐप सामान्य दर्शकों के लिए है और बच्चों को लक्षित नहीं करता। यह किसी से भी — बच्चों सहित — जानबूझकर कोई व्यक्तिगत जानकारी एकत्र नहीं करता। यदि आपको लगता है कि किसी बच्चे ने ख़रीद कर ली है, तो हमें लिखिए — हम रिकॉर्ड हटा देंगे और रिफ़ंड में सहायता करेंगे।

11. सुरक्षा

ऑडियो दो स्तरों पर एन्क्रिप्टेड है — पहले ऐप में पैक करने से पूर्व, और फिर पहली बार खोलने पर आपके ही डिवाइस के Android Keystore में बनी कुंजी से, जो कभी डिवाइस से बाहर नहीं जाती। ऐप के सभी नेटवर्क अनुरोध HTTPS पर होते हैं। भुगतान की राशि ऐप नहीं, हमारा सर्वर तय करता है, और हर भुगतान अनलॉक देने से पहले सीधे Razorpay से दोबारा जाँचा जाता है।

12. नीति में परिवर्तन

यदि ऐप का व्यवहार इस नीति को प्रभावित करने वाले ढंग से बदलता है, तो हम यह पृष्ठ अद्यतन करेंगे और ऊपर दी गई तिथि बदल देंगे।

13. संपर्क

ईमेल: sanatanlabs01@gmail.com
डेवलपर: सनातन लैब्स, भारत
शिकायत संपर्क: यही पता। हम 2 कार्यदिवस में उत्तर देते हैं और 30 दिन के भीतर समाधान का प्रयास करते हैं।