Effective date: 25 July 2026

Privacy Policy

Saurava Pilot Android application

Saurava Drones (“we”, “us”) builds and operates the Saurava Pilot Android application, used by our field pilots to receive drone-spraying job assignments and record job execution. This policy explains what data the app collects, why we collect it, and how we handle it.

This policy applies only to the Saurava Pilot app. Other Saurava products (farmer portal, admin portal, agent app) are covered by separate policies.

Data we collect

We collect the minimum data required to operate the drone-spraying service. All collection is tied to a specific business purpose below.

Account data

  • Phone number — used as the pilot’s unique login identifier.
  • Name — displayed to the assigning coordinator and to farmers.
  • Pilot ID and role — internal identifiers assigned by our operations team.
  • DGCA license number (where applicable) — for regulatory compliance with India’s Directorate General of Civil Aviation drone-operator requirements.

Location data

  • Precise device location — captured during active job execution to prove the pilot was at the assigned farm plot at the assigned time. Location is also used to compute route ETAs between hub and farm.

Location is only recorded during an active job. The app does not track location in the background or when the pilot is off-duty.

Media

  • Photos taken through the in-app camera — used as delivery evidence: vehicle-checkout photos, drone-checkout photos, geotagged farm-arrival photos, post-spray verification photos, return-to-hub photos.
  • Photos are stamped with the timestamp and GPS coordinates of capture.
  • The app does not access photos from the device gallery.

Device and technical data

  • Firebase Cloud Messaging (FCM) token — used to deliver push notifications for new job assignments.
  • Device model, OS version, app version — used for crash reporting and troubleshooting.
  • Bluetooth pairing state (drone) — used solely to read battery telemetry from the paired agricultural drone during a job.

Operational data (created inside the app)

  • Checklist responses — pre-flight, post-flight, and inventory checklists filled by the pilot.
  • Job status updates — timestamps for started, in-progress, and completed events.
  • Flag-an-issue reports — free-text descriptions of anomalies the pilot needs to escalate.

Why we collect it

Every category above serves one or more of these purposes:

  • Pilot authentication and identity (phone, name, pilot ID, DGCA license)
  • Job assignment and dispatch (name, phone, FCM token, location for ETA)
  • Delivery evidence and regulatory compliance (photos, location, checklists)
  • Post-job payment and dispute resolution (job status timestamps, geotagged photos)
  • Safety and audit (drone telemetry, checklist responses, issue reports)
  • App stability and improvement (device model, OS version, app version)

We do not use pilot data for advertising, profiling, or resale.

Third parties we share data with

The Saurava Pilot app transmits data to the following third parties, exclusively to deliver the service:

  • Google Firebase Cloud Messaging (Google LLC) — delivers push notifications to the pilot’s device. Google receives the FCM token and message metadata (job ID, event type). Reference: Firebase privacy and security.
  • Google Maps SDK for Android (Google LLC) — renders maps of assigned farm plots and computes hub-to-farm routes inside the app. Google receives the device’s location while a map is being displayed. Reference: Google Maps Platform terms.
  • Google Maps app / web (external handoff) (Google LLC) — when the pilot taps “Get directions” on a farm card, the app opens the Google Maps app (or Google Maps in a browser if the app isn’t installed) with the farm’s coordinates as the destination. Google receives the destination coordinates and, once the pilot begins navigation, their live location. This is a user-initiated handoff; the Saurava Pilot app does not pass any additional data.
  • Saurava Drones backend (hosted on Amazon Web Services, Mumbai region — ap-south-1) — stores all account, job, location, and photo data required to operate the service. Access is restricted to authenticated Saurava staff.

We do not share personal data with advertisers, data brokers, or analytics vendors. The app does not include any analytics, crash-reporting, or telemetry SDKs (no Firebase Analytics, Crashlytics, Sentry, Google Analytics, etc.).

Where data is stored

  • All backend data (accounts, jobs, checklists, photos) is stored on AWS infrastructure in the Mumbai (ap-south-1) region.
  • Photos are stored in Amazon S3 with server-side encryption.
  • Access is authenticated per pilot; pilots can only see data related to their own jobs.

Retention

  • Account data (phone, name, pilot ID) — retained for the duration of the pilot’s engagement with Saurava, plus 3 years after the pilot’s last active job to satisfy Indian statutory record-keeping requirements.
  • Job execution records (photos, location, timestamps, checklists) — retained for 7 years after the job’s completion date, per DGCA record-keeping guidance for drone operations.
  • FCM tokens — deleted when the pilot signs out or the app is uninstalled.
  • Location data outside active jobs — never stored; the app does not record it.

After retention periods lapse, data is deleted from primary storage. Encrypted backups may persist for up to 90 days after deletion, following standard AWS backup lifecycles.

Security

  • All network traffic between the app and our backend uses HTTPS (TLS 1.2 or higher).
  • Authentication uses short-lived JWTs stored in the device’s OS-provided secure storage (Android Keystore).
  • Login is by phone number and a password issued by the Saurava operations team. Passwords are hashed on our backend using industry-standard algorithms; we never see or store them in plaintext.
  • Backend access is restricted by role-based permissions and audit-logged.
  • Photos are stored with server-side encryption at rest.

No system is perfectly secure. We follow industry-standard practices and disclose any material data incidents to affected users per applicable law.

Your rights

Pilots have the right to:

  • Access — request a copy of your account data. Email info@sauravadrones.com.
  • Correction — request correction of inaccurate account data.
  • Deletion — request deletion of your account. Note: job execution records may be retained for the DGCA-mandated 7-year period even after account deletion.
  • Withdrawal of consent — uninstall the app. This does not delete backend records; email us to request deletion.
  • Complaint — contact us first at info@sauravadrones.com; you may also lodge a complaint with the Data Protection Board of India once operational under the Digital Personal Data Protection Act, 2023.

We aim to respond within 30 days of receiving a request.

Children

The Saurava Pilot app is intended for licensed drone pilots, all of whom are legal adults (18+) under Indian law. The app is not directed at children and we do not knowingly collect data from anyone under 18.

International transfers

Data is stored in India (AWS Mumbai). Firebase FCM and Google Maps may process data on Google infrastructure located outside India, subject to Google’s own privacy commitments linked above.

Changes to this policy

We may update this policy as the app evolves. Material changes will be notified via a prominent in-app notice at least 14 days before taking effect, and the “Effective date” at the top will be updated.

Previous versions of this policy are available on request.