DPDPA 2023
Digital Personal Data Protection
IT Rules 2021
Intermediary Guidelines
TCS Rules 2025
Telecom Cybersecurity
GDPR
EU/UK Data Protection
CCPA / CPRA
California Privacy

Who We Are

Data Fiduciary: RR AI Labs Pvt. Ltd., India
Platform: B Anon — available on iOS, Android, and banon.app

Under the DPDPA 2023, RR AI Labs Pvt. Ltd. is the Data Fiduciary — the entity that determines the purpose and means of processing your personal data. You are the Data Principal — the individual whose data is processed.

B Anon is also an Intermediary under Section 2(w) of the Information Technology Act, 2000 and is bound by the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended to October 2025.

This policy applies to all users of B Anon worldwide. Sections 1–21 detail our Indian law obligations (DPDPA 2023, IT Rules 2021). Section 22 covers additional GDPR rights for EEA/UK users. Section 23 covers CCPA/CPRA rights for California residents. Questions: privacy@banon.app

How B Anon Works

B Anon is an anonymous one-to-one chat application built with privacy and data minimisation as core architectural principles, intended exclusively for users aged 18 and above.

Anonymous Identity

No real name, phone number, or email required. Appear as an emoji or wear an AR masquerade mask.

Nearby Discovery

Smart Match Engine connects you based on shared interest tags — not follower counts or identity data.

End-to-End Encrypted

Messages are encrypted on your device. Only the recipient's device can decrypt them. We cannot read content.

No Permanent Storage

Messages are deleted from our servers the moment delivery is confirmed. We hold no chat history.

Personal Data We Collect

We collect only what is strictly necessary to operate, secure, and maintain B Anon. Each category has one specific, stated, lawful purpose — satisfying DPDPA §5 (purpose limitation) and §4 (data minimisation).

Anonymous Device ID Until uninstall

Randomised ID generated at install. Not linked to identity.

Purpose: Message delivery, service integrity · Legal Basis: Legitimate Use §7
Messages (Temp) Deleted on delivery

Encrypted text/media held until delivery.

Purpose: Reliable message delivery only · Legal Basis: Consent / Contract §6
Log Data Limited period

IP address, OS version, timestamps.

Purpose: Security, abuse prevention · Legal Basis: Legitimate Use §7
Google Token (Optional) Until unlinked

Auth token if user opts in. No email stored.

Purpose: Account recovery only · Legal Basis: Explicit Consent §6
Camera Feed (AR) Never stored

Live feed for mask rendering. Processed on-device only.

Purpose: Real-time masquerade mask · Legal Basis: Explicit Consent §6
Reported Content 30 days post-report

Snapshot of a reported message.

Purpose: Grievance resolution · Legal Basis: Legal Obligation §7
DPDPA §5 — Purpose Limitation. Data collected for one purpose will not be used for any other purpose without fresh consent. No data category above feeds into advertising, user profiling, or any purpose not explicitly stated. We do not cross-reference data categories to build identity profiles.

Face Filters & AR Masks

Instead of a real profile photo, you choose how to appear using one of two privacy-preserving options. Your real face is never required, never captured, and never shared.

Default Emoji Avatar

Pick any emoji. This becomes your anonymous face. No camera access required. Nothing is stored on our servers.

B Anon AR Mask

Activate camera to wear a real-time mask rendered by our AR filter engine. Only the mask is visible to others.

How the AR camera feature works. When you activate an AR mask, the camera feed is processed entirely on your device using machine learning to detect face positions. At no point does any camera frame or biometric data leave your device. What is transmitted to the other person is the final rendered mask image, not your camera feed.

What the AR feature NEVER does:

Optional Google Account Linking

B Anon offers an optional feature to link your Google account as a safeguard — protecting your access if your device is lost. This is purely a recovery tool and is never required.

What B Anon does
  • Receive a basic authentication token used only to associate your anonymous ID with a new device
  • Delete the token immediately when you unlink or delete account
What B Anon does NOT do
  • We do not store your email address
  • We do not access your Gmail, contacts, or photos
  • We do not use linking for ads or profiling

Premium Upgrades

Optional subscriptions unlock features. Purchases are processed by Apple or Google. We never directly handle or store your payment card details.

Data We Never Collect

The following are structurally absent from B Anon. There is nothing to breach or misuse.

We do not collect or store: Real name · Phone number · Aadhaar / Gov ID · Facial images or biometrics · Email address (unless optionally linked) · Permanent chat history · Location history · Contact list · Browsing history · Caste / religion · Health data · Ad profiles · Cookies.

Consent Framework

All optional features require explicit opt-in (free, specific, informed, unconditional). Examples: AR mask (OS camera prompt), Push Notifications (OS prompt), Interest tags (In-app choice). You can withdraw consent for any of these at any time via settings.

Message Architecture

All messages use end-to-end encryption (E2EE). B Anon cannot read message content at any point.

Zero Permanent Storage. Messages and media are held in encrypted form on our servers only until delivery is confirmed. Once confirmed, content is immediately and permanently deleted. Your conversations exist only on your device.
Screenshot prevention. B Anon enforces OS-level screenshot blocking (FLAG_SECURE on Android, UIScreen on iOS) within the app.

Push Notifications

Push notifications carry only a signal that a message is waiting. They do not contain message text or sender info. Content is decrypted only when you open the app.

Abuse Prevention

We analyze limited metadata for abuse patterns. When you report a user, a snapshot of the reported message is preserved in isolated storage for 30 days for moderation review, then permanently deleted.

Third-Party Services & Sharing

We use providers like Google LLC (Firebase, Auth) and Apple APNs purely as Data Processors bound by strict agreements. We do not use ad networks or data brokers.

Disclosure: We disclose data only under valid legal obligations (IT Act §69, DPDPA §7) such as formal court orders. Because we hold no message content, the maximum data we can produce is connection logs and device IDs.

Telecom Identity & SIM Rules 2025

B Anon is not a TIUE. The DoT Rules for Telecommunication Identifier User Entities (TIUEs) apply to apps using phone numbers. B Anon does not request or verify phone numbers at any point. The SIM-binding obligations do not apply to our architecture.

Data Retention & Account Deletion

Personal data is erased as soon as its purpose is fulfilled. You have the Right to Erasure (account deletion) at any time via Settings → Account → Delete Account.

Children's Data

Strictly for users 18+. If we become aware of an underage user, the account and data are permanently deleted immediately.

Your Rights as a Data Principal

Right to Access

Request data summary.

Right to Erasure

Delete your profile data.

Grievance Redressal

File complaints via Officer.

Right of Nomination

Nominate a successor.

Grievance Officer

  • Name: Grievance Officer, RR AI Labs Pvt. Ltd.
  • Email: grievance@banon.app
  • Response Time: Acknowledged in 24 hrs, resolved within 15 days.

⚖️ IT Rules 2021: If unsatisfied, you may appeal to the Grievance Appellate Committee (GAC) at grievanceappellate.meity.gov.in

European Economic Area (EEA) & UK — GDPR

If you access B Anon from the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional rights and disclosures apply under the General Data Protection Regulation (GDPR) and the UK GDPR.

Legal Basis for Processing

Data Legal Basis (Art. 6)
Device ID (anonymous account creation) Legitimate interest — necessary to provide the service without collecting personal identifiers
Approximate location (nearby matching) Consent — you grant location permission; revocable at any time via device settings
Crash & connection logs Legitimate interest — maintaining app stability and security
Google auth token (optional account recovery) Consent — only processed if you choose to link a Google account; no email address is stored

Your Rights Under GDPR

In addition to the rights listed in Section 19, EEA/UK users have:

International Data Transfers

B Anon's servers are located in India. If you are in the EEA/UK, your data is transferred to India. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Art. 46(2)(c)) to ensure adequate data protection for any cross-border transfer.

Data Protection Officer

For GDPR-related inquiries, contact our Data Protection Officer at privacy@banon.app.

Supervisory Authority

You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

California Residents — CCPA / CPRA

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights regarding your personal information.

Categories of Personal Information Collected

CCPA Category Data Collected Purpose
Unique identifiers Device ID Anonymous account creation
Geolocation (approximate) City-level location Nearby user matching
Internet activity Crash logs, connection metadata App stability
Account identifiers (optional) Google auth token (no email stored) Account recovery only

What We Do NOT Do

Your Rights Under CCPA/CPRA

How to Submit a Request

California residents may submit a verifiable consumer request by emailing privacy@banon.app with the subject line "CCPA Request". We will respond within 45 days. You may also use the in-app account deletion feature for immediate data erasure.

Note: Because B Anon is designed around anonymity, we collect minimal personal information. Many CCPA rights are automatically satisfied by our privacy-first architecture — there is very little data to access, correct, or delete.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:

Minimal breach impact by design. Because B Anon does not store message content, real names, phone numbers, or email addresses, the scope of any potential breach is structurally limited to device IDs, connection logs, and (if linked) Google auth tokens. There is no message history or identity data to expose.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. When we make changes:

B Anon is a private anonymous chat app — learn more about our safety guidelines.