⚖ Draft pending legal review — not legal advice. This is a drafting
template for the PolyglotFormFill product. It must be reviewed and approved by qualified legal counsel in
each jurisdiction where the Service is offered (incl. the EU/EEA under the GDPR, India under the DPDP
Act 2023, and the US under the CCPA/CPRA) before publication. Contact/identity fields are completed; a final read by counsel is still recommended before wide public release.
The substance, plainly:We do not see, store, or transmit your documents or
the data you enter, and we do not send them anywhere you did not intend. Everything is processed on
your device. Your content leaves your device only when you take a specific action — submitting a
completed form to the recipient you choose, or a web search you type — and it goes
directly there, never through us.
1.Who we are
This Policy is issued by Subramanya Mysore (sole proprietor), India ("we", "us"), responsible for the PolyglotFormFill application, browser extension, and
website (the "Service"). For the GDPR we act as data controller; under the India DPDP Act 2023 as
the Data Fiduciary; where we process no personal data, no such role arises.
Grievance Officer / Contact:Subramanya Mysore · subumysore@gmail.com.
2.Definitions
Personal Data — information relating to an identifiable natural person.
User Content — the documents, forms, images, and values you enter or store (your "vault"),
including any Personal Data within them.
Device — the computer or device on which you run the Service.
3.Our core privacy principle
The Service is designed so that we do not see, store, or transmit your User Content, and we do not
send it to any location you did not intend. Specifically:
On-device processing. Reading/rendering, OCR, translation, field detection, filling, export,
and signing are performed locally on your Device. We do not receive your User Content to do them.
No collection by us. We do not collect, receive, access, or store your User Content. There is
no account required and no upload of your User Content to us.
User-directed transmission only. User Content leaves your Device only when you initiate a
specific action, and only to the destination you choose:
(a) Submitting a completed form — transmitted directly from your Device
to the recipient you select (e.g. a government or vendor site). We do not proxy, intercept,
receive, retain, or access it.
(b) Web search (optional) — only the search terms you type are sent,
directly to the third-party search provider (DuckDuckGo), to return
results. No User Content, vault data, or identifiers are sent. Enter a URL to avoid this entirely.
These are the only circumstances in which content or search terms leave your Device — each
user-initiated, clearly labelled, and directed to a destination you selected.
4.Limited non-content data we may process
Software distribution & updates. Downloading/updating the Service, or its download of assets
(updates, fonts, models), makes a one-way request to the relevant channel, which may process technical
data (e.g. IP) as an independent controller under its own policy. This is a download to your
Device and provides no path to upload your User Content. [confirm hosts]
Payments & licensing. Paid features are unlocked by an offline signed license verified on
your Device (contacts no server). If you purchase, payment is handled by
not applicable (no paid features yet); we receive only what is needed to issue/support the license
(e.g. name, email, order id) — never your User Content.
Voluntary communications. If you contact support, we process what you provide to respond.
We do not use analytics, advertising identifiers, tracking technologies, or
content-bearing crash reporting.
5.Legal bases (GDPR, where applicable)
For the limited processing in §4: contract (Art. 6(1)(b)) for licensing/support; legitimate interests
(Art. 6(1)(f)) for secure distribution/updates; consent (Art. 6(1)(a)) where required. No legal basis is
required for User Content because we do not process it. [counsel to confirm]
6.Security of your on-device data
Your vault is stored only on your Device and is encrypted at rest (AES-256-GCM).
The key is derived on unlock from your passphrase or a hardware passkey (WebAuthn); it is
never stored and never transmitted.
The extension uses least-privilege permissions and contains no remote code (Manifest V3).
7.Sharing & international transfers
Because we do not receive your User Content, we do not share, sell, or transfer it. For the
limited non-content data in §4, we share only with the providers named there, under contract; any
cross-border transfer follows that provider's safeguards. [transfer mechanisms +
sub-processors]
8.Retention
We do not retain your User Content (we never receive it). Non-content data in §4 is retained only as
long as necessary. [specify periods]
9.Your rights
Subject to applicable law (GDPR Arts. 15–22; India DPDP Ch. III; CCPA/CPRA) you may have rights to
access, correct, delete, port, restrict, or object, to withdraw consent, and to complain to a
supervisory authority / the Data Protection Board. Because your User Content resides solely on your
Device, you access and delete it directly (in the Service or by removing local data). For the
limited non-content data we hold, contact subumysore@gmail.com.
10.Children
The Service is not directed to, and we do not knowingly process Personal Data of, children under
13.
11.Changes
We may update this Policy; material changes update the Effective date and, where required, include
additional notice.