Privacy Policy

Last updated: August 31, 2026

Application Ownership and Data Governance Framework

This Privacy Policy is formulated specifically for the mobile software titled BerryFlow (designated as the "App"), which is made available to users exclusively via the Google Play distribution channel.

The App is owned, operated, and continuously supported by Sitl-Sonali Information Technology Ltd (identified within this policy as the "Developer", "we", "our", or "us"). It is hereby clarified that Sitl-Sonali Information Technology Ltd constitutes the sole and responsible party for all data-handling activities and operational decisions pertaining to BerryFlow.

Should you choose to download and utilize BerryFlow from Google Play, this Privacy Policy will comprehensively govern the modalities by which your information is gathered, processed, preserved, and shared, as well as the conditions under which such information may be disclosed to third parties during the normal course of using the application.

Summary of Processing Activities

The end-to-end functional logic of the service encompasses the following sequential stages:

  1. The process initiates when the user supplies image files and designates a template of their choosing for the ensuing transformation.
  2. A personalized replica of the underlying diffusion model is subsequently trained against the supplied visual data, thereby calibrating the system to reflect the user's distinct characteristics.
  3. Upon the successful calibration of the model, the application proceeds to render a final avatar output that is uniquely associated with the individual.
  4. Immediately after the avatar has been delivered, both the source images and the ephemeral model replica are expunged from our storage systems without any residual backup. Users are hereby reminded that the avatar feature must not be misused---generating inappropriate content, including but not limited to explicit nudity or depictions of other individuals without proper consent, constitutes a violation of our acceptable use policy.
  5. It is expressly affirmed that personal information furnished during this process will never be utilized for the advancement of our foundational AI systems, nor will it be redirected toward the construction of any independent or supplementary software products.

User-Directed Cloud Execution Framework

The application offers a suite of advanced AI-driven capabilities---covering editing, enhancement, and rendering workflows---all of which are facilitated through secure remote server processing. This processing mode is exclusively engaged when the user intentionally opts for a function that requires off-device computation to deliver the intended outcome.

The uploading of photographs, videos, or any associated media to our protected servers occurs strictly subsequent to the user's affirmative selection of a cloud-dependent feature and the explicit commencement of the corresponding operation. BerryFlow does not, at any point, initiate automatic, unsolicited, or latent transfers of personal media content. It is further established that the App distinctly signals to the user, prior to the upload phase, that the requested service will involve cloud-based data handling, thereby ensuring informed consent throughout the interaction.

Storage Duration and Data Disposition Framework

Any media assets uploaded to our platform are preserved solely for the operational window necessary to complete the specific processing task requested by the user. Following the conclusion of the processing cycle, all original uploads and their corresponding generated derivatives are permanently expunged from our systems within a maximum timeframe of 72 hours. It is hereby affirmed that Sitl-Sonali Information Technology Ltd neither retains redundant copies of user-provided media nor employs such data for promotional purposes, machine learning model development, behavioral analytics, or any purpose unrelated to the immediate service delivery.

Infrastructure Security Standards

The integrity of all inbound and outbound data transfers is maintained through the application of TLS encryption, which adheres to recognized industry benchmarks. Authorization to access uploaded content is meticulously restricted, being confined exclusively to automated operational processes and the essential technical systems that are directly necessary for the provision of the requested functionality.

User Feedback and Content Oversight

We are committed to configuring the AI model with careful attention to appropriateness and user expectations. Nevertheless, it is possible that certain generated outputs may not align with your personal standards of suitability. In the event that you encounter material of an offensive or objectionable nature, we kindly request that you forward your observations to us at sitlbd5@gmail.com. We undertake to respond with due diligence to all such reports, and we also recognize that your input serves as a valuable resource for the continuous improvement of our algorithmic systems over the longer term.

Information Collected Through Our Services

  1. User Activity and Behavioral Data
    We may record information concerning your interaction with our Platforms, encompassing navigation history, selection events, resource downloads, media sharing activities, editing operations performed on video content, and any other data points you voluntarily provide throughout your use of our offerings. This information is instrumental in rendering the Platform's features accessible to you.
  2. Hardware and Connection Log Information
    To uphold operational reliability and security, refine the overall user journey, enable targeted communications and message propagation, and protect your account against unauthorized access, we acquire specific hardware and connectivity details upon your access to the Platforms. These data items include: distinct device identifiers, GAID, handset model, configured system language, geographic territory, advertising ID, operating system release version, originating IP address, application version number, network connection type, observed network performance indicators, and associated service log entries.
  3. Inquiries and Feedback Submissions
    Whenever you initiate contact with us for support purposes or to express your views, we collect the content and ancillary files that you supply, alongside your contact information (such as your phone number and email address). This enables us to appropriately address your questions and provide meaningful assistance.
  4. Biometric Facial Mapping Data
    In the course of utilizing facial manipulation or compositing functionalities, our systems identify and map the position and configuration of your facial features, thereby extracting the requisite analytical inputs for photo transformation. The resulting derived imagery is then furnished to you as the final output. We neither store the source photographs, video sequences, facial signature data, nor the generated renderings; moreover, we do not transfer or make available any of this information to outside entities. This data processing is conducted solely to facilitate the facial recognition feature and to improve the fidelity of your results. If your editing work incorporates the facial likeness of another person, it is your obligation to notify that individual and obtain their prior authorization.
  5. Remote Server Processing
    To enable rapid and accurate handling of image or video assets, we may temporarily transfer your materials or their associated tags to a remote server for effect synthesis. These transfers are performed exclusively for the particular task that you have initiated. We do not preserve the media, tags, or any connected data for any duration longer than is strictly necessary, nor do we apply them to any unrelated purposes or extend access to any third party.

Device Permissions

To provide you with better products, efficient services, and an improved user experience, we may request certain permissions on your device when offering additional features. With your consent and following the principle of collecting only the minimum necessary data, we may access the following permissions and the corresponding information:

  1. Read/Write External Storage Permission -- Used to read from and write to your device's external memory card for video editing purposes.
  2. Camera Permission -- Allows you to take photos and record videos within the app.
  3. Network Access Permission -- Enables various online services, such as accessing and downloading materials.

The personal information accessible through the permissions listed below is classified as sensitive data. If you decide to refuse a particular permission, this will merely restrict your ability to employ the feature that relies on it; your continued use of all other application functionalities will not be compromised in any manner. You are empowered to examine the current permission configuration at any time via the system preference panel on your device. You retain the full freedom to activate or deactivate any or all such permissions according to your own judgment and requirements.

It is important to recognize that when you affirmatively grant a permission, you are explicitly consenting to our collection and utilization of the related personal information, strictly for the purposes of rendering the associated service. Should you later choose to turn off a permission, this action will effectively withdraw or rescind your earlier consent, and we will immediately discontinue any collection or processing of personal information based on that permission going forward. However, please note that disabling a permission will not retroactively affect any data collection or usage that took place while the permission was still in effect.

External SDK Utilization and Provider Arrangements

To support the provision of essential features, the execution of analytic operations, and the facilitation of digital transactions within the application, BerryFlow has integrated the third-party SDKs enumerated herein. These SDKs may acquire and process particular categories of device information and user activity data, as further elaborated in the following sections. Notably, no such processing shall commence unless and until you have provided your valid consent through acceptance of this Privacy Policy.

  1. AppsFlyer (provided by AppsFlyer Ltd.)
    Purpose: Mobile attribution, marketing analytics, and campaign performance tracking.
    Data collected: Device identifiers (Android ID, Google Advertising ID), IP address, app install source (referrer), conversion events, and in-app user actions. This data helps us understand how you discovered our app and improve our promotional activities.
  2. Google Play Billing (provided by Google LLC)
    Purpose: Processing in-app purchases and subscription transactions.
    Data collected: Purchase details, transaction history, and order identifiers. We do not store or have access to your full payment card information; all payment data is handled directly by Google Play.
  3. Google Install Referrer (provided by Google LLC)
    Purpose: Identifying the source (channel) that led to your app installation.
    Data collected: Referrer information (e.g., which campaign or ad led to the install) and installation timestamp. This data is used exclusively for attribution analysis.
  4. Google Ads Identifier & AppSet ID (provided by Google LLC)
    Purpose: Providing anonymized identifiers for analytics and ad performance measurement.
    Data collected: Google Advertising ID (AAID) and AppSet ID. You may reset or limit these identifiers at any time via your device settings.
  5. Google Sign-In (provided by Google LLC)
    Purpose: Enabling Google account-based login and authentication.
    Data collected: Only when you actively choose to sign in, we receive your basic profile information (name and email address) as provided by your Google account. No data is collected passively.
  6. Functional Libraries (No Data Collection)
    The following tools are used solely for technical operations such as networking, image loading, media playback, local storage, and background scheduling. They do not collect, transmit, or process any personal data: Retrofit & OkHttp (networking), Glide (image loading), ExoPlayer (media playback), DataStore (local preferences), WorkManager (background tasks), and Hilt (dependency injection).

Usage Analytics and Performance Insights

We engage in the collection and evaluation of service-related metrics for the ongoing betterment of our platform and the optimization of user interactions. The data in question is processed in aggregate format, thereby affording us the ability to discern broader usage trends and to direct our refinement efforts accordingly. The resultant aggregated intelligence may be shared with our affiliated entities, service representatives, and business associates, for application in areas such as academic research, feature development, and commercial forecasting. We confirm unequivocally that such information is fully anonymized and contains no personally identifiable elements pertaining to either you or the users of your applications.

Use of Personal Information

Consistent with the principles set forth in this Privacy Policy, we may process the data you provide in order to render our services or to maintain contact with you. The principal purposes for which your information may be used are detailed as follows:

  1. Enhancement of Service Quality and Features
    Your information is instrumental in our ongoing efforts to design, build, run, distribute, and advance our products. For instance, by examining user engagement with the platform, we are able to verify that the experience remains accessible, efficient, and straightforward.
  2. Protection of Systems and User Accounts
    Your information is utilized to preserve the security of both user accounts and our network infrastructure, ensuring that our services remain protected for every individual user. Such usage may include proactive screening or examination of uploaded files to detect potentially illegal content. Furthermore, your data may be applied to fraud prevention, user security support, and associated protective protocols.
  3. Dissemination of Important Service Announcements
    We make use of your information to distribute significant administrative messages, including notifications concerning your account status and revisions to our governing terms, conditions, or policies.
  4. Adherence to Applicable Legal Standards
    We preserve and govern your information as required to satisfy our statutory obligations. Such processing may encompass the recording, auditing, analyzing, or handling of your data in compliance with legislative requirements, including under urgent or exceptional circumstances.

Your Choices

You may limit data collection by:

User Entitlement to Data Erasure

Throughout your use of our application, you maintain full discretion over the information you have provided, and you are empowered to delete stored records at any time and for any reason. We are dedicated to upholding your privacy rights and to ensuring that the process of data removal is both transparent and operationally feasible. Your historical activity logs and other accumulated data can be expunged via the preferences menu located within the app's settings. Additionally, should you choose to uninstall the application, any data cached locally on your device will be automatically and permanently purged. It is important to note that deleted data is irretrievable and cannot be restored once removed. If you have any questions or concerns regarding the exercise of your deletion rights, please do not hesitate to reach out to our support team for guidance.

Usage of Cookies and Associated Tracking Technologies

Consistent with prevailing practices among online platforms, we utilize cookies, web beacons, and related technologies. Cookies are minor data records that reside on your hard disk or in the memory of your device, preserving information about your activity while using our offerings. These assist in performing essential operations such as verifying user identity, recalling your selected preferences and personal configurations, analyzing visitor traffic and usage behaviors, assessing the performance of promotional campaigns, and facilitating social functionality. Web beacons, which are miniature software components embedded in web content or email messages, enable us to monitor your interactions with the material in question.

The default configuration of most browsers is to permit the storage of cookies. You retain the ability to adjust your browser settings to block or remove cookies should you wish to do so. We caution, however, that such adjustments may restrict the accessibility and impair the operational capacity of our services.

We make use of external analytics providers to evaluate traffic levels and consumption patterns for our services. These providers collect information transmitted by your device or generated through our platform, which may encompass the pages viewed, the extensions utilized, and additional metrics that support our improvement efforts. The data gathered in this context is combined with aggregated data from other users, and is processed in such a way that it does not reasonably disclose the identity of any individual.

We maintain arrangements with third-party advertising agencies for the placement of advertisements across internet properties and other outlets. To measure the effectiveness of such advertising and to compute the compensation owed to these agencies, we embed third-party components into our applications. Moreover, we may integrate such components to further our understanding of the manner in which users engage with our services.

Retention Schedule and Information Disclosure

Your personal data is maintained in our systems for a period of 48 months. We reserve the right to retain and process your information for as long as may be necessary to satisfy our statutory and regulatory obligations (for example, adherence to applicable legal provisions), to settle any disputes that may arise, and to enforce our terms of service and internal governance policies.

In addition, we retain Usage Data for internal analytical assessments. This category of data is ordinarily kept for a more limited timeframe, subject to exceptions where such retention is essential for security reinforcement, product enhancement, or where we are compelled by law to preserve it for an extended duration.

Third-Party Data Handling

We do not engage in the sale, rental, or leasing of your personal data to external parties. The third-party SDKs listed in this policy transmit data solely to their corresponding providers for the purposes expressly identified, and we bind such providers through contractual provisions requiring them to handle your information in accordance with applicable data protection laws.

Circumstances for Information Sharing

Sitl-Sonali Information Technology Ltd refrains from selling, renting, or trading your personal information to any external entity. We share personal information only when such sharing is deemed necessary to deliver the services that you have expressly requested, to operate and sustain BerryFlow, to complete transactional processes, to comply with pertinent legal mandates, or to safeguard our legitimate rights and the overall security of our service infrastructure.

External Service Partnerships

To enable the essential features and operational integrity of BerryFlow, we collaborate with rigorously selected third-party service providers. These entities contribute to the delivery of critical support services, encompassing identity verification and access management, commercial transaction handling, usage analytics and reporting, campaign attribution for installations, scalable cloud hosting and storage, risk mitigation through fraud prevention measures, and comprehensive monitoring of application performance metrics.

Depending on the feature you use, these providers may process limited categories of information, including:

Each third-party provider processes personal information solely for the purpose of delivering the services they perform on our behalf and in accordance with their own privacy policies and applicable data protection laws. We do not authorize our service providers to use your personal information for their own independent advertising or marketing purposes.

Processing of User Content via Artificial Intelligence

Upon your voluntary submission of images, video recordings, or other media files for processing through our AI capabilities, such content is utilized strictly to produce the outputs that you have explicitly requested.

Your uploaded materials are neither sold, sublicensed, nor transmitted to external entities for promotional purposes, user analytics, or the development of broad-scope AI models. All media files are handled solely to execute the specific operation you have initiated, and will be automatically expunged in line with the data retention provisions detailed within this Privacy Policy.

Legal Disclosure

We may disclose your personal information only when we believe such disclosure is necessary to:

Corporate Reorganization and Data Succession

Should BerryFlow or Sitl-Sonali Information Technology Ltd participate in a merger, takeover, organizational restructuring, capital financing, divestiture of assets, or other analogous commercial transaction, your personal data may be conveyed to the successor party as an element of that transaction.

In such instances, the receiving organization will be bound to maintain the confidentiality and security of your personal information under privacy standards that are substantially comparable to the protections set forth herein, and to administer such information in strict accordance with prevailing data privacy laws.

Information Security and Safeguarding Protocols

We place significant emphasis on the protection and integrity of your personal data. In order to counter the risks of unauthorized intrusion, improper disclosure, or other potential threats, we have deployed appropriate physical, technical, and administrative safeguards across all data collected in connection with your use of our Platform. We are dedicated to exercising the highest degree of diligence in preserving the confidentiality of your information.

Our security framework is continually assessed and refined to remain aligned with operational growth, technological evolution, and applicable regulatory standards. These measures include, without limitation, organizational security policies, permissions-based access restrictions, and periodic staff education on data protection responsibilities.

Although we are deeply committed to securing your information, it must be recognized that no existing mode of data transmission via the internet or electronic data storage is entirely immune to compromise. We endeavor to protect your personal information using practices that are consistent with recognized industry norms; however, we are unable to provide an unconditional assurance of absolute security.

Should we determine that a security breach has occurred that affects your personal information, we will issue a notice to you in compliance with statutory notification requirements. Your continued use of the Platform constitutes your agreement to accept such notifications in electronic form.

Data Subject Rights and Request Handling

If you seek to better understand your statutory rights under relevant privacy legislation, or if you wish to invoke any of those rights, we kindly encourage you to reach out to us via the contact information set out in the "How to Contact Us" section of this document. In accordance with the legal framework governing your region, you may have the right to request that we:

  1. Grant you access to, or furnish you with a copy of, specific personal data we currently process on your behalf.
  2. Discontinue processing your information for direct marketing communications, including any such activities derived from behavioral or preference-based profiling.
  3. Update or correct any personal details we hold that are inaccurate or no longer current.
  4. Delete or permanently remove particular information we retain about you.
  5. Impose restrictions on the processing or disclosure of certain information relating to you.
  6. Facilitate the portability of your information to another service provider.
  7. Revoke any consent you have previously provided in relation to our data processing activities.

All requests submitted will be duly reviewed and addressed within the statutory timeline applicable to your jurisdiction. It should be noted, however, that in certain instances, particular information may fall outside the scope of such rights---for example, where continued processing is necessary for the assertion of our legitimate business interests or for the fulfillment of mandatory legal duties. As part of our verification procedures, we may require you to furnish reasonable documentation to ascertain your identity before we can proceed with your request.

Age Restrictions and Compliance with Data Privacy Statutes

Access to and use of our services is restricted to individuals who have attained the age of 18 years or older. We do not intentionally gather or retain personal information from persons under this age threshold. If you are a parent or legal guardian and you become aware that your minor child has provided us with Personal Data, we kindly request that you notify us immediately. Following the discovery that such data has been collected without duly verified parental authorization, we will take all necessary steps to permanently remove it from our records.

We are fully committed to adhering to the privacy obligations imposed by the CCPA (California), VCDPA (Virginia), GDPR (European Union), and LGPD (Brazil). Residents of these regions are afforded various entitlements under applicable law, including the rights to access, amend, delete, or contest the processing of their personal information. To initiate any such request, we kindly ask that you contact our dedicated support team, who will guide you through the process and ensure your rights are duly respected.

Lawful Grounds for Personal Data Processing

We conduct all processing of your personal information in accordance with relevant privacy legislation, notably the General Data Protection Regulation (GDPR). The legal basis upon which we rely varies according to the specific purpose of each processing operation, and may include one or more of the following:

  1. Legitimate Business Interests
    We may process certain non-personally sensitive data to advance our legitimate business objectives, which include:
    • Improving the operational efficiency and overall user experience of our applications.
    • Maintaining the robustness, security, and continued availability of our app ecosystem.
    • Investigating user engagement patterns to derive insights that support informed product planning and iteration.
    In each case where legitimate interests are invoked, we conduct a rigorous assessment to ensure that such interests are not overridden by your privacy rights and reasonable expectations.
  2. Compliance with Statutory Requirements
    We may be obliged to process your data to satisfy legal responsibilities, such as those arising from applicable fiscal, tax, or supervisory regulatory frameworks.
  3. Protection of Critical Interests
    In rare and urgent situations, we may process your data when doing so is essential to safeguard your vital interests or those of another person---for instance, when responding to an app-related security threat that could cause material harm.

Right to Submit a Complaint to Regulatory Authorities

If you are of the view that our processing activities concerning your personal data are in contravention of applicable data protection laws, or that your statutory rights have been adversely affected, you maintain the right to lodge a complaint with an appropriate supervisory body. This entitlement extends, for instance, to EU residents governed by the GDPR, and equally applies to individuals whose rights are protected under other relevant privacy statutes applicable within their respective regions.

Submission Channels for Complaints

Should you determine to proceed with a formal complaint, you may contact the designated data protection supervisory authority in your jurisdiction. Contact information for such authorities is customarily published on their respective official websites. As an alternative, you are invited to contact us directly for further information and procedural assistance.

Recommendation for Preliminary Internal Contact

Before resorting to a formal complaint submission, we strongly encourage you to first communicate with us so that we may make every reasonable attempt to resolve your concerns amicably and efficiently. You may get in touch with our Data Protection Officer (DPO) or send an email to sitlbd5@gmail.com.

Designation of Data Controller

Under the terms of applicable data protection laws, the data controller for all personal information collected and processed via BerryFlow is Sitl-Sonali Information Technology Ltd. As the designated controller, Sitl-Sonali Information Technology Ltd is responsible for establishing the purposes and methodologies of data processing, and for ensuring that all activities are conducted in strict accordance with prevailing privacy regulations. For any inquiries regarding your personal data or this Privacy Policy, please contact us at sitlbd5@gmail.com.

Data Protection Officer

We have appointed a Data Protection Officer to oversee our privacy practices. The DPO can be contacted as follows:

Policy Review and Revision Schedule

This Privacy Policy is subject to periodic review and may be updated as necessary to reflect evolving business practices, technological advancements, or applicable legal frameworks. We recommend that you check this page on a regular basis for the most current version of our privacy commitments. When we introduce modifications, we will publish the revised text on this page, and such changes will become effective immediately upon posting, unless a different effective date is expressly indicated.

How to Reach Us

If you have any inquiries, reservations, or recommendations with respect to our Privacy Policy, please do not hesitate to contact our team via email at sitlbd5@gmail.com. Your feedback is valued, and we will endeavour to respond promptly to all communications.