Recallio
Privacy Policy
Last updated: September 17, 2026 · Android com.calecutech.recallio
This policy describes how Recallio, a mobile application published by Calecute Technologies LLC, handles personal data. It applies to the Android application com.calecutech.recallio and its iOS equivalent, and to the Recallio service they connect to.
Recallio teaches a PSC syllabus as small fact cards and schedules them with spaced repetition, so each fact comes back just before you would have forgotten it. A day takes about five minutes, and the plan is counted back from your exam date.
Who it is for: Candidates preparing for Kerala Public Service Commission examinations. Anyone can create an account with a Google account.
What we collect, and why
Personal identifiers
- Name
- Email address
- Profile picture
Creating your account and recognising you when you sign in on another phone. All three come from Google Sign-In; we never see your Google password.
App activity
- Which course you are preparing for, your exam date and when your plan started
- Which cards you have been shown, whether you answered each correctly, how many times, and when each is next due
- Mock test attempts: the option you chose for each question, and the resulting score
- Your daily reminder time and whether you chose English or Malayalam
This is the study record itself. The schedule is computed from it, and it is what makes a streak, a progress bar and a weak-module figure possible. It is also what would be lost if it were not backed up, which is why it is stored to your account and not only on the phone.
Purchasesoptional
- Whether a subscription for a course is active
- Which payment route was used
Unlocking the course you paid for, and restoring it after a reinstall. The payment itself is handled entirely by Google Play or by Razorpay — we never see your card, UPI or netbanking details.
Device identifiersoptional
- Push notification token
Delivering announcements that only a server can know about — a corrected card, new material for your course, a payment that completed while the app was closed. Your daily study reminder does NOT use this: that one is scheduled by your own phone and needs no token. Sign out and the token is deleted.
Permissions the app requests
- Notifications
- Two separate things share this permission. Your daily study reminder is scheduled by your own phone at the time you chose, needs no token and arrives with no signal. Announcements — corrected cards, new material — are sent from our server and do use a push token, which you can stop by turning notifications off.
- Internet
- Signing in, downloading course content, and backing up your study record. The app is built to work without it: once content has been downloaded, a full day's study works with no signal.
Who we share it with
We do not sell personal data, and we do not use it for advertising or share it with data brokers.
How long we keep it
Your study record is kept while your account exists, because its value is that it remembers years of revision. Delete the account and it is removed within 30 days. Content you never touched — the cards themselves — is ours and is not personal data.
Security
Data is transmitted over TLS and stored on access-controlled servers. Passwords are stored only as salted hashes, never in a readable form. Every table is protected by a database policy that ties a row to the account that owns it, so one signed-in user cannot read another's study record even if the app on their phone is tampered with. Sign-in tokens are held in the Android keystore or iOS keychain, never in ordinary app storage.
What we do not collect
- We do not collect your contacts, calendar, call logs or SMS.
- We do not track you across other apps or websites, and there is no analytics or advertising SDK in the app.
- We do not use advertising identifiers and show no advertising.
- The app never asks for camera, microphone, location or file access, because it does not use them.
- We never receive your Google password, and never your card, UPI or netbanking details — those are entered on Google Play's or Razorpay's own screen.
Services that process data for us
We use the following providers. They act on our instructions and may not use your data for their own purposes.
Google Sign-In
Authenticates you and tells us your name, email address and profile picture. We never see your Google password.
Their privacy policySupabase Inc.
Hosts the database and the sign-in service. Your study record is stored there so a new phone can pick up where the old one left off. Supabase stores it on our behalf and does not use it for its own purposes.
Their privacy policyGoogle Play Billing (Google LLC)
Takes the payment for a subscription and tells the app whether you have one. The payment screen is Google's own — your card, UPI or netbanking details are entered there and never reach us. We receive only the fact that a subscription is active.
Their privacy policyRazorpay Software Private Limited
Takes payment when you choose to pay by UPI or card. The payment screen is Razorpay's own; your UPI id, card or netbanking details are entered there and never reach us. We are told only that a payment succeeded, and for how much.
Their privacy policyFirebase Cloud Messaging (Google LLC)
Delivers push notifications to your device. It receives the notification text and your device's push token. It is not used to sign you in and holds none of your app data.
Their privacy policyWhere your data is held
Data is stored on servers operated by our hosting providers. Some of those servers are outside India, and the providers named above may process data in other countries under their own contractual safeguards. By using the app you consent to that transfer.
Why we are allowed to hold it
We process your data to provide the service you asked for — an account, a study plan, and a record of what you have revised. You give consent when you create an account, and you may withdraw it at any time by deleting the account.
Your rights
You may ask us what personal data we hold about you, ask us to correct it, or ask us to delete it. Write to info@calecutech.com, or follow the account deletion instructions. Under India’s Digital Personal Data Protection Act, 2023 you may also raise a grievance with us at the same address; we respond within 30 days.
Raising a grievance
If you are unhappy with how we have handled your data, write to The Grievance Officer at info@calecutech.com, Calecute Technologies LLC, Kozhikode (Calicut), Kerala, India. We acknowledge within 7 days and respond within 30. If you remain dissatisfied you may complain to the Data Protection Board of India.
Children
The app is not directed at children and we do not knowingly collect data from anyone under 18.
Changes
If we change what we collect, we will update this page and the date above before the change takes effect.
Contact
Calecute Technologies LLC
Operations office: Kozhikode (Calicut), Kerala, India
info@calecutech.com