BHOMU Logo

BHOMU

AI-Powered Model Generator

Loading your workspace...

Back to Login

Privacy Policy

Last Updated: March 24, 2026

A product by Kalariq Studios

1. Introduction

Bhomu ("we", "our", or "us") is an AI-powered clothing catalog image generation platform operated by Kalariq Studios(“Company”). This Privacy Policy describes how we collect, use, store, share, and protect your personal data when you access or use our platform at app.bhomu.com (the "Service").

This Policy is compliant with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. By using the Service, you consent to the practices described herein.

2. Data Fiduciary — Who We Are

For the purposes of the DPDPA 2023, Kalariq Studios is the Data Fiduciary — the entity that determines the purpose and means of processing your personal data. Our designated Grievance Officer details are listed in Section 15 of this Policy.

3. Information We Collect

The following data points are explicitly collected by the Service based on observed code and system behaviour:

3.1 Information You Provide Directly

  • Identity: Full name and display name
  • Contact: Email address and phone number (stored in +91XXXXXXXXXX format)
  • Business details: Business name, city
  • Profile media: Logo image (URL) or logo text
  • Authentication credentials: Password (managed and hashed by Firebase Authentication; we never store plaintext passwords) or Google OAuth token
  • Clothing images: For sarees — whole-garment, pallu, and blouse images; for lehengas — design and dupatta images; for dresses — top and bottom images
  • Product information: Catalogue item name and retail rate (pricing) submitted during image generation
  • Preferences: Theme (light/dark/system) and notification preferences stored as account settings

3.2 Information Collected Automatically

  • IP address: Captured in server-side audit logs at login, logout, and administrative actions (via x-forwarded-for / x-real-ip headers)
  • Timestamps: Account creation date, last login time, and daily wallet activity timestamps
  • Wallet and transaction data: INR wallet balance, daily recharge amount, and full transaction ledger (type, amount, description, metadata)
  • Upload lifecycle data: Status of each generation request (pending, processing, completed, error), INR spent per generation, clothing type, and image URLs
  • Audit log data: Actor ID, role, action type, entity type, IP address, and timestamp for all privileged operations
  • Generation failure logs: Error details for failed AI generation requests, stored for admin review

3.3 Analytics Data (via Firebase Analytics / Google Analytics)

We use Firebase Analytics (a Google service) which automatically collects:

  • Firebase User ID (UID) linked to your account
  • Login and sign-up method (email/password or Google)
  • Page views and navigation patterns
  • Feature usage events (image generation, gallery downloads, wallet recharges)
  • Clothing type and cost associated with generation events
  • Error event types and messages
  • Search terms used within the platform
  • Device information, browser type, and OS (collected by Google per their Privacy Policy)

4. How We Use Your Information

We use your personal data only for the following purposes:

  • Service delivery: to authenticate your account, process clothing image uploads, invoke the AI generation model, and deliver generated catalogue images
  • Wallet management: to track INR balance, deduct credits per successful generation, enforce daily recharge limits, and maintain a transaction ledger
  • In-app notifications: to inform you of generation status, profile completion prompts, and account-related updates
  • Security and fraud prevention: to log IP addresses for suspicious activity detection, enforce role-based access controls, and maintain audit trails for privileged operations
  • Platform improvement: to analyse aggregated usage patterns via Firebase Analytics and improve service quality
  • Legal compliance: to retain financial records as required by applicable Indian law
  • Customer support: to respond to queries, complaints, and grievances submitted via contact channels

5. Legal Basis for Processing Under DPDPA 2023

5.1 Consent: By registering for an account and using the Service, you provide your explicit, informed, and freely given consent to process your personal data for the purposes described in Section 4.

5.2 Contractual necessity: Processing of your account data, wallet transactions, and uploaded images is necessary to perform the contract for the Service you have requested.

5.3 Legitimate interests: IP address logging and audit trail maintenance are carried out for fraud prevention and platform security as legitimate interests of Kalariq Studios.

5.4 Legal obligation: Retention of financial transaction records may be required under Indian tax and accounting laws.

6. Third-Party Service Providers

We share your data only with the following sub-processors necessary to operate the Service. We do not sell your personal data to third parties.

Firebase / Google (Authentication & Database):Your email, name, hashed password, and Firestore documents (profile, uploads, gallery, transactions, notifications) are stored in Google Firebase infrastructure. Google's servers may be located outside India. Governed by Firebase Privacy Policy.

Google Gemini AI (Image Generation): Your uploaded clothing images and product information are transmitted to Google Gemini's API for AI processing. Google embeds a SynthID watermarkin all generated images as per Google's responsible AI policy. Governed by Google Privacy Policy.

Amazon Web Services — S3 & CloudFront (Image Storage & CDN): All uploaded and generated images are stored on AWS S3 using INTELLIGENT_TIERING storage class and served via AWS CloudFront CDN. Image paths are scoped per user ID and upload ID. Governed by AWS Privacy Policy.

Google Analytics / Firebase Analytics (Usage Analytics): Behavioural analytics data (events, page views, user properties) are collected and processed by Google. Governed by Google Privacy Policy.

Vercel (Hosting & Serverless Functions): The web application and API routes are hosted on Vercel. Request logs including IP addresses are processed by Vercel. Governed by Vercel Privacy Policy.

7. Data Storage and Cross-Border Transfers

7.1 Firestore: User profile, uploads, gallery, transaction, and notification data are stored in Google Cloud Firestore. The Firestore project is configured for the Mumbai (asia-south1) region where possible; however, Google may replicate data to other regions for reliability.

7.2 AWS S3: Images are stored in an AWS S3 bucket. The specific AWS region is configured via environment variables. [Assumption: Region may vary; confirm with infrastructure configuration.]

7.3 Cross-border transfers: Your data may be processed on servers outside India (primarily by Google and AWS infrastructure). We rely on the standard contractual clauses and data processing agreements established by these sub-processors to safeguard cross-border transfers as permitted under DPDPA 2023.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service.

8.1 Images: Uploaded clothing images and generated model images are stored on AWS S3 for the duration of your account. You may delete individual gallery items at any time. AWS S3 is configured with a 90-day Glacier transition lifecycle policy for archived images.

8.2 Account data: Upon account deletion, we will use reasonable efforts to remove your personal data from Firestore within 30 days, except where retention is required by law (e.g., financial transaction records).

8.3 Audit logs: Audit logs containing IP addresses and action records may be retained for up to 12 months for security and legal compliance purposes.

8.4 Transaction records: INR wallet transaction history may be retained for up to 7 years as required under applicable Indian financial record-keeping laws.

9. Security Measures

We implement the following security measures in accordance with the IT (Reasonable Security Practices) Rules, 2011:

  • HTTPS/TLS encryption for all data in transit
  • Encryption at rest for Firestore and AWS S3 stored data
  • Firebase Authentication with JWT-based server-side token verification for every API request
  • Role-based access control (user / admin / moderator)
  • Atomic Firestore transactions for wallet balance updates to prevent race conditions
  • Server-side audit logging for all privileged administrative actions
  • Image paths scoped per user ID and upload ID to prevent unauthorised access

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

10. Your Rights Under DPDPA 2023

As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights:

10.1 Right to Access: You may access your account data, uploaded images, and transaction history at any time through your profile and gallery pages.

10.2 Right to Correction: You may update your name, phone number, business name, city, and logo via your profile settings at any time.

10.3 Right to Erasure: You may delete individual gallery items directly. To request full account deletion and erasure of personal data, please contact our Grievance Officer listed in Section 15.

10.4 Right to Data Portability: You may request a structured copy of your personal data by contacting our Grievance Officer. We will respond within 30 days.

10.5 Right to Withdraw Consent: You may withdraw your consent to processing at any time by requesting account deletion. Withdrawal of consent will not affect the lawfulness of processing prior to withdrawal.

10.6 Right to Grievance Redressal: You have the right to have your grievances addressed by our Grievance Officer within the timeframe prescribed under DPDPA 2023 and the IT Rules, 2011 (typically 30 days).

10.7 Opt-Out of Non-Essential Communications: [Assumption: No promotional email marketing service is currently integrated in the codebase.] Transactional in-app notifications (generation status, wallet alerts) are integral to the Service and cannot be disabled while your account is active.

11. Cookies and Similar Technologies

We and our third-party service providers use cookies and similar browser storage technologies:

Authentication session (Firebase Auth): Firebase Authentication uses browser IndexedDB and/or localStorage to persist your login session. These are essential for the Service to function and cannot be disabled.

Analytics cookies (Google Analytics / Firebase Analytics): Google sets cookies (e.g., _ga, _gid) to track unique visitors, session duration, and usage events. These are analytics cookies used to improve the Service.

You may configure your browser to refuse cookies or clear stored data. Disabling essential storage will prevent login and use of the Service. Disabling analytics cookies will not impair core functionality.

12. Children's Privacy

The Service is intended for business users and is not directed at individuals under the age of 18 years. We do not knowingly collect personal data from minors. If we become aware that a minor has provided us personal data, we will take prompt steps to delete it. If you believe a minor's data has been collected, please notify our Grievance Officer immediately.

13. Changes to This Policy

We may update this Privacy Policy periodically. For material changes, we will notify you via in-app notification. The "Last Updated" date at the top of this page indicates the most recent revision. Continued use of the Service following notification of changes constitutes your acceptance of the revised Policy.

14. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of India, including the DPDPA 2023, the Information Technology Act, 2000, and applicable rules made thereunder. Any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the competent courts in India.

15. Grievance Officer and Contact Us

In accordance with the Information Technology Act, 2000, the IT Rules, 2011, and the DPDPA 2023, the following Grievance Officer has been designated to address complaints and concerns regarding the processing of personal data:

Organisation: Kalariq Studios

Grievance / Privacy Contact Email: support@kalariq.com

Website: kalariq.com

We will endeavour to acknowledge your complaint within 7 working days and resolve it within 30 days of receipt, as required by applicable law.

By creating an account and using Bhomu, you acknowledge that you have read and understood this Privacy Policy and provide your informed consent to the collection, use, and processing of your personal data as described herein.