In effect from 30 August 2026
What this site collects
Nothing that you type, because on these pages there is nothing to type.
There is no contact form, no newsletter, no comments and no shopping. The
site sets no cookies of its own and runs no analytics, so there is no
profile of you being built here and nothing being shared with
advertisers.
The one exception is the client area, which existing clients sign in to.
It is described in full below. If you never go there, nothing else on
this page changes.
What still gets recorded
Two things happen that are worth naming plainly, because both involve a
third party seeing that you visited.
-
Hosting logs. The site is served by Firebase Hosting,
a Google service. Like any web server, it records requests, including
your IP address, the page requested, the time, and your browser's user
agent string. These logs are operational. They exist so the service can
run and so abuse can be detected. They are held by Google under its own
retention policy, not mine.
-
Fonts. The typefaces on this site are loaded from
Google Fonts. That means your browser makes a request to
fonts.googleapis.com and fonts.gstatic.com, and Google receives your IP
address as part of it. If that matters to you, a content blocker will
stop the request and the site will fall back to the fonts already on
your device.
Signing in to the client area
The client area at saswatlife.com/client is for
people I am already working with. It exists so the documents from an
engagement sit in one place behind your own identity instead of scattered
through an inbox. Nothing else on this site asks you to sign in, and
there is nothing to gain by signing in if you are not a client.
There are two ways in and neither creates a password, so there is no
password of yours for me to hold or to lose.
The first is Google. When you sign in that way, Google passes on your
name, your email address, whether that address is verified, your Google
account identifier, and a link to your profile picture, which this site
does not display. That is the whole of what arrives.
The second is a link sent to your email address. You type the address,
a one time link arrives, and opening it signs you in. The link expires
and stops working once it has been used. If it is opened in a different
browser from the one that asked for it, it asks for the address again
before it will do anything, which is what stops a forwarded link from
being enough on its own. Your address is held in your own browser
between asking and arriving, so the link knows who it is for, and it is
removed once you are in. Nothing but the address is asked for and no
profile comes with it.
Your address, and your name if Google supplied one, are then kept along
with the times the account was created and last used, by Firebase
Authentication, a Google service. The only thing any of it is used for is
deciding which documents to show you. Your email address is the key: it
is matched against the record I filed for you, and if there is no
matching record you see nothing. Your browser keeps the session on your
own device so you are not asked to sign in on every visit. It is not
readable by any other site, and signing out removes it.
The phone number, and why it is asked for
Once you are signed in, the client area asks for a mobile number. It is
a request, not a condition. There is a Not now beside it, your documents
are there either way, and nothing is withheld if you never give one.
What it is for: a second way to reach you when something in your
engagement needs a decision rather than another email in a thread. It is
not used for marketing, it is not shared, and no automated messages are
sent to it.
If you give one, a six digit code is sent to it by SMS and the number is
only kept once you have typed that code back. That is deliberate. A
number typed with a digit wrong would otherwise sit in my records looking
correct. The SMS is sent by Firebase, a Google service, and before it is
sent your browser runs a Google reCAPTCHA check, which exists to stop
somebody using this page to send messages to strangers. Both of those
mean Google sees the number and your IP address at that moment.
The number is kept on the same Firebase Authentication record as your
email address. It is not written into the documents record, and it is
removed when the sign in is, which is described under how long things
are kept. You can ask me to remove it sooner and I will.
What the client area holds, and what it does not
That record lives in Firestore, a Google service, in the Mumbai region.
It holds a title, a short description and a link for each document. The
documents themselves are not stored there, so each file stays where it
already lives, under the sharing you and I already agreed. The client
area lists your documents. It does not hold them.
The client area asks for three things and no more: an address to send a
link to, a number to send a code to, and the code. Nothing you type there
goes into your documents record. No browser signed in or otherwise can
change anything in that record, which is a decision in the design rather
than a gap in it. Records are written by me and read by you. The pages
are also marked so that search engines do not index them, and nothing
there is used for analytics, advertising or tracking. No cookie is set
for advertising and none is set for measurement.
If you email or message
If you write to me, I hold what you send: your name, your address or
number, and whatever you chose to tell me about your business. It is used
to reply and to carry the conversation forward, and for nothing else. It
is not sold, rented, or passed to anyone for marketing.
Email and WhatsApp are run by other companies and are subject to their
own privacy terms. Anything genuinely sensitive is better discussed on a
call than typed into a chat.
Information shared during an engagement
Diagnosing a business means seeing how it actually works, which can
include operational records, supplier and customer information, pricing,
and access to existing systems. That information is treated as
confidential under the Terms. It is used only to do the work agreed, it
is kept no longer than the work and any support period require, and it is
returned or deleted on request once the engagement has ended.
Access is asked for at the narrowest scope the work genuinely needs.
Where a read only account will do, that is what I will ask for.
How long things are kept
Correspondence is kept while a conversation is live and for a reasonable
period afterwards, so that a returning client is not starting from
nothing. Records connected to a paid engagement are kept as long as
Indian tax and accounting law requires. Everything else is deleted when
it stops being useful.
A client area sign in, and the record behind it, are kept while we are
working together and for the support period that follows. After that they
are deleted, and they are deleted sooner if you ask.
Your rights
You can ask what I hold about you, ask for it to be corrected, ask for a
copy, or ask for it to be deleted. Where deletion would conflict with a
legal obligation such as retaining invoices, I will say so and delete
what is left. There is no form for this. An email is enough, and you will
get a reply from a person.
Children
This is a service sold to businesses. It is not directed at children and
no information is knowingly collected from them.
Changes to this page
If what happens to information changes, this page changes with it and the
date at the top moves. The date is the honest signal of when it was last
true.
Contact
Questions about privacy, and any grievance about how information has been
handled, go to
mail@saswatlife.com. The
practice is a single person, so the person who reads it is the person
responsible for it.