Privacy Policy

How Sumitra collects, uses, and protects the data in your employer-issued account.

Last updated 09 September 2026

Applies to the Sumitra mobile app (Android package: com.tilicho.sumitra) and the Sumitra web application.

1. Who we are

Sumitra is published by Tilicho Labs LLP ("we", "us"). Sumitra is an internal workforce application. Accounts are created and issued by an employer; the app cannot be used without an employer-issued account. Your employer is the controller of the employee data in the app, and we process that data on their behalf.

Contact: it-admin@tilicho.in

2. Data we collect

We collect only what the app needs to function:

  • Account and identity data — name, work email address, employee ID, job title, department, reporting manager, and the profile photo you choose to upload.
  • Employment and HR data entered by you or your employer — time entries, attendance, leave requests, timesheets, performance records, assets assigned to you, helpdesk tickets, and onboarding/exit records.
  • Payroll and statutory data, where your employer uses those features — salary components, PAN, provident fund details, tax regime selection, and investment declarations you submit.
  • Documents and files you upload through the app.
  • Device and diagnostic data — app version, device model, operating system version, crash reports, error logs, and in-app usage events (for example, which screens are opened). This is used to keep the app stable and is not used to build advertising profiles.

We do not collect your precise or approximate location. We do not collect contacts, SMS, call logs, microphone audio, or health data. We do not sell personal data, and we do not use it for advertising.

3. Device permissions

  • Camera — only when you choose to take a profile photo.
  • Photos / media — only when you choose to pick a profile photo or upload a file.
  • Storage / documents — only when you choose to attach or download a document.

Permissions are requested at the moment you use the feature, and you can deny or revoke them in your device settings. Denying them only disables that specific feature.

4. How we use the data

  • To authenticate you and keep your session secure.
  • To provide the app's features: time tracking, attendance, leave, payroll, and the other HR functions your employer has enabled.
  • To make your data available to your employer's authorised administrators and your reporting line, according to their access rules.
  • To detect and fix crashes, errors, and performance problems.
  • To comply with legal, tax, and statutory obligations that apply to your employer.

5. Sharing

We share data only with:

  • Your employer and its authorised administrators.
  • Microsoft (Azure Active Directory) — for sign-in and identity verification.
  • Google (Firebase Analytics) — for anonymous app usage and stability metrics.
  • Sentry — for crash and error reports.
  • Our cloud hosting and database providers, which store the data on our behalf under contract.

These providers process data only to deliver their service to us. We do not sell or rent personal data to anyone, and we do not share it with data brokers or advertisers. We may disclose data where required by law.

6. Security

All traffic between the app and our servers is encrypted in transit using HTTPS/TLS. Authentication tokens are stored on your device in the operating system's secure storage (Android Keystore / iOS Keychain). Access to production data is restricted to authorised personnel. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information.

7. Retention

We retain employee data for as long as your employer maintains your account, and afterwards only for as long as required by applicable employment, tax, and statutory record-keeping laws. Crash and analytics data is retained for a limited period and then deleted.

8. Your rights and data deletion

You may request access to, correction of, or deletion of your personal data. Because your employer controls this data, start with your HR administrator, or write to it-admin@tilicho.in and we will act on your employer's instruction.

Uninstalling the app removes locally stored data from your device but does not delete your account.

To request account and data deletion, email it-admin@tilicho.in from your work email address with the subject "Data Deletion Request". We will respond within 30 days. Some records may be retained where law requires it.

9. Children

Sumitra is not directed at children. It is only for employed adults with an employer-issued account. We do not knowingly collect data from anyone under 18.

10. Changes to this policy

We may update this policy. The "Last updated" date at the top will change, and material changes will be communicated through the app or by your employer. Continued use after an update means you accept the revised policy.

11. Contact

Tilicho Labs LLP
Email: it-admin@tilicho.in