Security & Data Protection

Protecting Your Family Jewellery Records

Last updated: August 23, 2026

Ghar Ka Sona is designed to help families organise valuable jewellery records while limiting access to authorised members. This page explains our approach to account protection, workspace access, document handling, artificial intelligence, operational safeguards and responsible use.

Important note: No online service can remove every risk. Our goal is to reduce unnecessary exposure, limit access and help users make informed choices about what they store.

Signed-in access

Production records are shown after account sessions are checked.

Family workspaces

Records are organised around workspaces and membership.

Private documents

Bills and photos are not published as open public files.

Draft AI results

AI extraction assists data entry and requires review.

Security designed around private family records

Ghar Ka Sona may hold jewellery descriptions, bills, receipts, photographs, values, weights, ownership notes, beneficiaries, possession details, storage-location labels and family-member information. That information deserves careful handling.

The service uses layered safeguards focused on authenticated access, workspace separation, role-aware permissions, private file handling, server-side validation, temporary file-access links, review of AI-assisted drafts and limited operational access.

Our security principles

Access is limited

Records are shown only after identity and family workspace access are checked.

Family separation

Each family workspace is treated as a separate record area.

Least necessary access

People should receive only the access needed for their role or task.

Private by default

Bills and photos are handled as private workspace content.

Server-side enforcement

Sensitive actions are checked by trusted application logic, not only hidden in the interface.

Review before reliance

AI-assisted information remains a draft until reviewed by the user.

Account and session protection

Users authenticate before production records are shown. Password handling, email confirmation, recovery emails and authentication sessions are provided through our authentication service. Ghar Ka Sona does not need to display or recover your existing password.

Users can create an account, sign in, verify email, request a password reset and sign out through the public account screens. Protecting the email account connected to Ghar Ka Sona is important because email may be used for confirmation and recovery.

Family workspace access

Jewellery records belong to a family workspace. Users see records associated with workspaces they are permitted to access, and choosing a workspace does not grant access by itself. Joining one family workspace does not automatically expose another family workspace.

Anyone invited to a family workspace may be able to view information permitted by their role. Invite only trusted people and remove access when it is no longer needed.

Roles and permissions

The service supports owner, administrator, editor and viewer style workspace roles. Owners may control broader workspace settings. Administrators may manage selected workspace functions. Editors and viewers have more limited abilities.

Major sensitive actions reviewed by us apply workspace and role checks. Permission availability may vary by feature, and we continue reviewing permission coverage as the service develops.

Jewellery bills and photo protection

Bills and jewellery photos are treated as private workspace content. They are delivered through controlled access rather than public directory listings, and access is checked before a preview or download is issued.

Users remain responsible for deciding what private information to upload. Before uploading, consider redacting unnecessary bank details, signatures, identity documents or unrelated personal information.

Secure file handling

We apply file validation and duplicate checks before accepting supported uploads. These checks reduce risk but do not guarantee that every harmful file can be detected.

Unsupported or unsafe-looking uploads may be rejected. Users must not upload harmful, unlawful or unrelated content.

Artificial intelligence and bill extraction

AI-assisted bill extraction is used when the feature is configured and a user chooses to scan a bill. Relevant bill content and technical file information may be sent to the configured AI provider through server-side integration.

Generated results are drafts. AI may misread names, amounts, dates, weights, purity, bill numbers, owners, beneficiaries or storage clues. Users must review and correct generated values before relying on them.

Ghar Ka Sona should not be used as the sole source for insurance, legal, tax, inheritance or valuation decisions. Manual entry remains available according to current plan rules. See the Privacy Policy for more detail about provider processing.

Data separation

Application records are organised by authenticated account and family workspace. Access checks are applied before relevant data is returned, and workspace membership does not grant global access.

Document links and plan status should not bypass authorization or grant access to another family's workspace.

Data transmission and storage

Connections to the production website use HTTPS when accessed through the official domain. Our infrastructure providers may apply encryption to stored information according to their infrastructure and configuration.

Ghar Ka Sona does not currently offer end-to-end encryption, zero-knowledge encryption or user-managed encryption keys.

Operational security

Production credentials for database, storage and AI providers are intended to remain server-side and are not exposed to the browser. The codebase includes automated checks, type checking, build validation and security-focused migration tests to reduce regressions.

We aim to keep development and production access separate and to limit production access to legitimate operational needs. These operational practices should continue to be reviewed as the service grows.

Logging and sensitive-data handling

Limited technical logs may be created for reliability, troubleshooting, abuse prevention and security investigation. Logs may include timestamps, request context, error details and limited identifiers.

Jewellery-document content should not intentionally be written into normal logs. Sensitive fields may be redacted in selected logging paths, but logging coverage is not yet uniform across every code path. Logs are not a complete record of every view or action.

Service providers

Ghar Ka Sona uses service providers to operate the application. Providers may process information according to their own terms, settings and infrastructure.

PurposeHow it is used
Authentication and data servicesUsed for sign-in, account sessions, records and private file storage.
Application hostingUsed to serve the web application and run server-side application code.
AI-assisted bill processingUsed when a user chooses bill extraction and the feature is configured.
Email deliveryUsed for account messages, invitations and product communications.
Payment processingUsed for hosted checkout, payment verification, receipts, refunds and billing reconciliation where payment features are available.
Indicative market dataUsed for limited market information shown inside the app.

Payment security

Where paid checkout is available, payment collection is handled through a hosted Razorpay checkout flow. Ghar Ka Sona records order identifiers, payment status, receipt details, promo-code usage and provider references needed for verification, reconciliation, refunds and support.

Ghar Ka Sona should not receive complete card, UPI or banking credentials when hosted checkout is used. Users should complete payment only through the official application and should report suspicious payment requests.

Privacy and regulatory safeguards

Security controls support privacy obligations under laws that may apply to users, including the EU GDPR, UK GDPR and India's Digital Personal Data Protection Act, 2023. These controls include access checks, private document handling, limited operational access, data minimisation guidance, request-verification steps and incident assessment.

If an incident involves personal data, notification decisions depend on the facts, affected users, risk level and applicable legal duties. We keep legal and privacy requests routed through legal@gharkasona.com.

Data retention and deletion

Records are kept while the account or workspace remains active unless they are deleted or archived through available app actions. Some deletion actions remove records from normal use while retaining limited records for integrity, support, security or technical reasons.

Document deletion removes the application record and attempts to remove the stored file. Account deletion is available from profile settings where configured, subject to confirmation and shared-workspace ownership limits. The deletion flow removes or anonymises local account data, removes owned private workspaces and associated private document files where possible, and deletes the authentication user.

Removal from operational backup systems or provider systems may not be immediate. Contact us for deletion enquiries.

Data export and portability

Current export features include selected reports such as an insurance inventory PDF, purchase reports, workspace backup data, and authorised activity exports where available to the signed-in user.

Ghar Ka Sona does not currently offer a complete export of every uploaded file, setting and account record in one self-service package.

Backups and service recovery

Infrastructure providers may maintain operational backups according to their service configuration. These backups are designed for service continuity and are not a user-controlled archive or guaranteed individual-record restore service.

Users should keep original bills, photographs and important reports independently instead of treating Ghar Ka Sona as the only copy.

Administrative and support access

Service personnel may require limited system access for support, abuse prevention, reliability or security investigation. Such access should be limited to legitimate operational needs.

Support should not ask for your password or one-time codes. Do not send full bills or sensitive identifiers through ordinary email unless specifically required and protected.

Security testing and maintenance

We use development checks and automated tests to reduce regressions. These checks include formatting, linting, type checking, production build validation, policy leakage tests and selected browser tests.

These checks are not a guarantee that every vulnerability will be identified, and they should not be read as a formal security certification or independent audit.

User responsibilities

  • Use a strong, unique password and secure your email account.
  • Do not share passwords, confirmation links or one-time codes.
  • Log out on shared devices and keep your devices updated.
  • Invite only trusted family members and review access periodically.
  • Upload only necessary information and redact unrelated financial or identity details.
  • Verify AI-generated drafts before saving or relying on records.
  • Keep original bills and photographs independently.
  • Report suspicious activity promptly.

Shared-family-account considerations

Family members may view or change information according to their role. Ghar Ka Sona records do not resolve family disputes, independently verify ownership or create legal ownership.

Removing a member prevents future app access, but it cannot make that person forget information already seen or delete copies already downloaded. Decide carefully who receives access.

Children and dependent family records

Adults may create records involving children or dependants only when authorised. Avoid collecting unnecessary information about minors and do not upload government IDs or highly sensitive child information unless essential and lawful.

The service is not intended for independent use by children. Guardians remain responsible for information they add.

Mobile devices and shared computers

Browsers may retain sessions. Use private devices where possible, log out after using a shared computer and avoid saving passwords in an untrusted browser.

Downloaded bills, reports and photos are outside Ghar Ka Sona's control after they are saved to a device. Clear them from shared devices when finished.

Phishing and suspicious communications

Ghar Ka Sona will not ask for your password or one-time code by email, phone, chat or social media. Verify that you are using the official domain before signing in.

Check payment requests against the official website. Ghar Ka Sona is a record-keeping service and does not provide jewellery investment schemes or ask users to transfer jewellery.

Security incidents

Suspected incidents are assessed based on available information. Steps may include restricting access, resetting sessions, investigating affected systems or contacting relevant users.

Notification timing depends on facts and applicable obligations. Not every technical error is a security incident.

Responsible vulnerability reporting

If you believe you found a vulnerability, email legal@gharkasona.com. Include a clear description, affected page or feature, reproducible steps, date and time, browser or device details, and screenshots with private information removed.

Do not access another user's data, modify or delete records, use denial-of-service techniques, upload malware, social-engineer users or staff, publicly disclose unresolved vulnerabilities or demand payment. We do not currently operate a paid bug bounty program.

Current limitations

  • No online service can provide absolute security or remove every privacy risk.
  • No end-to-end encryption, zero-knowledge architecture or user-managed keys are currently offered.
  • There is no complete audit trail of every view or action.
  • There is no public security certification or paid bug bounty program.
  • Individual-record backup restoration is not currently offered as a self-service feature.
  • Account deletion is available but can be limited by shared-workspace ownership, provider configuration, legal retention needs and backup cycles.
  • Complete account export containing every uploaded file, setting and account record is limited.
  • Provider settings influence retention and processing locations.
  • Security features will evolve over time.

Policy updates

This policy may change as features, providers and safeguards change. We will update the date on this page when meaningful changes are made. Significant changes may be communicated through the application or email where appropriate.

This policy describes the current service and does not replace rights or obligations that may apply under applicable law.

Contact information

Security concerns
legal@gharkasona.com
Privacy matters
legal@gharkasona.com
General support
support@gharkasona.com
Netherlands / EU
Ghar Ka Sona
Registered trade name under KvK / Chamber of Commerce: 42062317
Vosplantsoen 1, 1338 BC Almere, Netherlands
Phone: +31 633988860
India
Ghar Ka Sona
Udyam: UDYAM-TS-02-0360006
Basith Prestige, 17-1-210, Santosh Nagar, 500059, Hyderabad
Phone: +91 8087608968

Identity verification may be required before we act on account, correction, deletion, export or workspace access requests. We do not request government identity documents by default.