Effective date: 8 September 2026
Last updated: 8 September 2026
Version: 1.0
1. Who we are
1.1 This Privacy Policy explains how Utsav Mangla, an individual carrying on business as a sole proprietor with a place of business in Delhi, India ("we", "us", "our", "Provider"), collects, uses, shares and protects personal data in connection with the mobile and desktop application published by us that acts as a client for Google's Blogger platform ("the App").
1.2 The App is distributed under storefront-specific names, including "Blogging for Blogspot Blog" on the Apple App Store in the United States (Apple App ID 6504722976), and under equivalent names on other storefronts and on Google Play. This Policy covers all of them.
1.3 We are the data controller (GDPR/UK GDPR), the business (CCPA/CPRA) and the Data Fiduciary (India's Digital Personal Data Protection Act, 2023) for the personal data described in this Policy, except where stated otherwise in Section 4.
1.4 Contact: support@umango.in
Grievance Officer / privacy contact: Utsav Mangla, support@umango.in, Delhi, India.
1.5 We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. We have not appointed an EU or UK Article 27 representative; if you are in the EEA or UK you may contact us directly at the address above.
2. The most important thing to understand first
2.1 The App is an unofficial, third-party client for Google's Blogger/Blogspot service. We are not affiliated with, endorsed by or connected to Google.
2.2 Your blog and its contents live on Google's systems, not ours. When you write, edit, publish or delete a post through the App, that content is transmitted directly from your device to Google's official Blogger API, under an authorisation you granted through Google's own consent screen. Google's collection and use of that data is governed by the Google Privacy Policy (https://policies.google.com/privacy) and the Blogger Terms of Service — not by this Policy.
2.3 We hold far less about you than Google does. What we hold, and why, is set out below in full.
3. What we collect, why, and on what legal basis
The table below is the authoritative description of our processing. "Legal basis" columns refer to the GDPR/UK GDPR; where you are in India, the corresponding basis under the DPDP Act, 2023 is consent or certain legitimate uses as noted.
3.1 Account and authorisation data
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Google Account email address, display name, profile photo URL | Google Sign-In, at your election | Create and operate your account; identify you in the App; associate your blogs with you | Contract (Art. 6(1)(b)) |
| Firebase Authentication user ID (UID) — a pseudonymous identifier we generate | Generated on first sign-in | Primary key for everything we store about you; authenticate your API requests | Contract |
Google OAuth authorisation for the scope https://www.googleapis.com/auth/blogger | Granted by you on Google's consent screen | Read and manage your own Blogger blogs at your instruction | Consent given to Google; Contract with us |
| List of Blogger blogs you own or administer (blog ID, title, URL, role) | Blogger API | Show your blogs; determine what you may edit; verify authorship for Feed publication | Contract |
About the OAuth token. The access token issued by Google is held by the Google Sign-In SDK on your device. We do not store your Google password, refresh token, or long-term credentials on our servers. In a small number of server-assisted operations (for example, retrieving blog page-view statistics that the Blogger API exposes only to the blog owner), a short-lived access token may be transmitted to our backend for the duration of that single request and is not persisted. You can revoke our authorisation at any time at https://myaccount.google.com/permissions.
3.2 Content data
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Post title, body (HTML), labels, images, publication status, drafts and scheduling | You, in the App | Transmit to the Blogger API at your instruction; render in the App | Contract |
| Publicly published post content, title, excerpt, images, labels, blog theme, publication date | Retrieved from your blog's public page/RSS feed after you publish | Include in the App's discovery Feed, search index, recommendations and notifications | Contract (for your own content) and legitimate interests (Art. 6(1)(f)) in operating a discovery service |
| Automated analysis output: detected language/locale, topical category, and moderation signals (spam, sexual content, child-safety concerns, illegal activity, violent extremism) with confidence scores | Generated by Google Gemini from public post content | Route posts to the right language/country feed; categorise; keep unlawful and harmful content out of the Feed | Legitimate interests and legal obligation (Art. 6(1)(c) / 6(1)(f)); DPDP "legitimate use" |
| Images selected from your photo library or camera | You, with your OS-level permission | Upload to your Blogger post; compressed on device before upload | Contract |
Important: only content that is already publicly readable at its Blogger/Blogspot URL enters the Feed or is analysed. Private blogs and unpublished drafts are not sent to the Feed pipeline or to Gemini.
3.3 Social and activity data
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Blogs you follow and unfollow (blog IDs, timestamps), follower and following counts | Your actions | Operate follow, feed personalisation and follower-count features | Contract |
| Notification preferences per followed blog | Your actions | Send only the notifications you asked for | Contract |
| Firebase Cloud Messaging registration token and topic subscriptions (one topic per followed blog) | Firebase SDK on your device | Deliver push notifications about new posts on blogs you follow | Consent (device notification permission) |
| Content reports you submit (blog ID, post ID, violation categories, your UID, timestamp) | Your actions | Investigate and action reports; prevent abuse; maintain an audit trail | Legitimate interests; legal obligation |
| Post read history | Your reading in the App | Show recently-read posts; avoid repeating items in the feed | Stored only on your device; not transmitted to us |
3.4 Device, diagnostic and usage data
Collected through Google Firebase SDKs embedded in the App:
| SDK | Data | Purpose | Legal basis |
|---|---|---|---|
| Firebase Analytics (Google Analytics for Firebase) | App Instance ID, your Firebase UID set as user_id, screen views and in-app events, session data, app version, device model, OS version, language, coarse country/region derived from IP address | Understand which features are used; fix usability problems; measure retention | Consent where required by ePrivacy/local law; otherwise legitimate interests |
| Firebase Crashlytics | Crash and non-fatal error reports, stack traces, Crashlytics installation UUID, device state at time of crash, OS and app version, breadcrumb logs | Diagnose and fix crashes | Legitimate interests in a functioning, secure app |
| Firebase Performance Monitoring | Network request timings and payload sizes, screen render traces, app start times, device and connection type | Detect and fix performance regressions | Legitimate interests |
| Firebase Remote Config | Device/app attributes used to target configuration values; the config values delivered to your install | Roll out features gradually; run configuration experiments | Legitimate interests |
| Firebase App Check | Device/app attestation token (Apple App Attest / DeviceCheck; Android Play Integrity) | Confirm requests come from a genuine, unmodified install of the App; block abuse of our backend | Legitimate interests in security |
device_info_plus / package_info_plus | Device model, OS version, app version and build number | Support, compatibility handling, diagnostics | Legitimate interests |
| IP address | Automatically, at the network layer | Route responses; security and abuse prevention; derive approximate country | Legitimate interests |
We do not collect precise GPS location. We do not access your contacts, calendar, microphone, health data or SMS.
3.5 Advertising data (free tier only)
| Data | Collected by | Purpose | Legal basis |
|---|---|---|---|
| Device advertising identifier — Apple IDFA (only if you grant App Tracking Transparency permission) or Android Advertising ID | Google AdMob SDK | Serve, cap and measure ads | Consent |
| IP address, coarse location (country/region), device and OS attributes, ad impressions, clicks, viewability | Google AdMob SDK | Serve and measure ads; detect ad fraud | Consent for personalised ads; legitimate interests for fraud prevention and basic delivery |
| SKAdNetwork / Privacy-Preserving Attribution postbacks (iOS) | Apple | Privacy-preserving install attribution | Apple platform mechanism; no user-level identifier |
Personalised ads and consent. Where required — in the EEA, the UK and Switzerland, and elsewhere where local law requires — the App presents a consent request (via Google's User Messaging Platform / an IAB TCF-compatible consent mechanism) before any personalised advertising is served or any advertising identifier is used for that purpose. If you do not consent, ads are served on a non-personalised basis. On Apple platforms, no IDFA is accessed unless you separately allow tracking through the App Tracking Transparency prompt. You may change your choice at any time in the App's settings, and may reset or limit your advertising identifier in your device settings.
Purchasing an ad-free entitlement, where offered, stops the App from serving ads.
3.6 Purchase and subscription data
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Store transaction identifiers, receipts, product IDs, purchase and expiry dates, renewal and cancellation status, trial status, entitlement status, store country, and a "last seen country" signal | Apple / Google Play, via RevenueCat, Inc. | Verify and unlock what you paid for; sync entitlements across devices; determine your country for country-specific feeds; handle support queries | Contract; legal obligation (tax and accounting) |
We never see, receive or store your payment card number, bank details, CVV or billing address. Payment is processed entirely by Apple or Google. Your RevenueCat "app user ID" is your Firebase UID.
3.7 Support correspondence
If you email us, we process your email address, the content of your message and any attachments, in order to answer you and keep a record of the issue. Legal basis: legitimate interests / contract.
4. Public Blogger content and people who are not our users
4.1 To power search, discovery and recommendations, the App collects and caches information that is already published publicly on the open web by Blogger/Blogspot blogs, including: blog titles, URLs, descriptions, themes and page-view counts; post titles, excerpts, images, labels and dates; public author profile pages and public display names and profile images; and public RSS/Atom feeds. We obtain this through the official Blogger API, ordinary retrieval of publicly served pages and feeds, and publicly available web-crawl datasets.
4.2 Some of that information constitutes personal data of blog authors who are not users of the App. Our legal basis is legitimate interests (Art. 6(1)(f)) in operating a discovery service for publicly published blogs, balanced against the limited privacy impact of surfacing content its author chose to publish publicly.
4.3 If you are a blog author and you do not want your blog surfaced in the App, write to support@umango.in from an address or Google Account associated with the blog, giving the blog URL. We will remove and exclude it, ordinarily within 15 days. You may also object to this processing under Article 21 GDPR by the same route. Removal from the App does not affect your blog's availability elsewhere on the web.
5. What we do not do
- We do not sell personal data, and we do not share it for cross-context behavioural advertising within the meaning of the CCPA/CPRA. (If this ever changes, we will update this Policy and provide a "Do Not Sell or Share My Personal Information" mechanism before doing so.)
- We do not use your private posts, drafts or private blogs for the Feed, for recommendations, or for any analysis.
- We do not use your content to train our own machine-learning models. Content sent to Google Gemini for moderation and categorisation is sent through the paid Gemini API, which, under Google's published terms for paid services, is not used by Google to train its models.
- We do not knowingly collect data from children (Section 9).
- We do not collect precise location, biometric data, or special-category data as defined by Art. 9 GDPR. If such data appears inside content you choose to publish, it is your publication decision and is processed by Google as your blog host.
6. Automated decision-making
6.1 We use automated systems to decide whether a publicly published post is admitted to the Feed, what topical category and language it is assigned, and whether it is withheld for suspected policy violation (Section 3.2).
6.2 These decisions affect only the visibility of content within our App. They do not affect your blog, your Google account, your ability to publish, or your legal rights, and they do not produce legal effects concerning you within the meaning of Art. 22(1) GDPR.
6.3 Nevertheless, you may request human review of any such decision by writing to support@umango.in with the blog and post URL. We will re-examine the decision and tell you the outcome.
7. Third parties who process data for us
We use the following processors and services. Each is bound by contract or by its own published terms to process data only as instructed and to apply appropriate safeguards.
| Provider | Role | What it processes | Where | Terms |
|---|---|---|---|---|
| Google LLC / Google Ireland Ltd — Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Messaging, Analytics, Crashlytics, Performance Monitoring, Remote Config, App Check | Processor (and controller for some Analytics/Ads purposes) | Account data, content and feed data, device and diagnostic data, push tokens | Global (US, EU, India) | policies.google.com/privacy · firebase.google.com/support/privacy |
| Google Cloud Run | Hosting of our backend API | All backend requests | asia-south1 (Mumbai, India) and, for some workloads, us-central1 (United States) | cloud.google.com/terms |
| Google Blogger API v3 | The service the App is a client for | Your blog content and metadata, at your instruction | Google infrastructure | policies.google.com/privacy |
| Google Gemini API | Automated content moderation, language detection and categorisation | Publicly published post text | Google infrastructure | ai.google.dev/terms |
| Google Programmable Search / Custom Search API | Supplementary discovery of public blogs | Search queries about public blogs | Google infrastructure | policies.google.com/privacy |
| Google AdMob | Advertising (free tier) | Advertising identifier, IP, ad interaction data | Global | policies.google.com/technologies/ads |
| Typesense | Hosted search index over public blog, post and author data | Public blog/post/author records; your search queries | Provider's hosting region | typesense.org/privacy |
| RevenueCat, Inc. | Subscription and entitlement infrastructure | Firebase UID, store receipts, subscription status, store/last-seen country | United States | revenuecat.com/privacy |
| Apple Inc. | App distribution and payment | Purchase transactions, SKAdNetwork attribution | Global | apple.com/legal/privacy |
| Google Play (Google LLC) | App distribution and payment | Purchase transactions | Global | policies.google.com/privacy |
We may also disclose personal data: (a) to professional advisers under duties of confidentiality; (b) to a successor in connection with a merger, acquisition or asset sale, on notice to you; and (c) as described in Section 8.
8. Disclosure for legal reasons
We may disclose personal data where we believe in good faith that it is reasonably necessary to: comply with a law, regulation, legal process or enforceable governmental request; enforce our Terms of Service, including investigating potential violations; detect, prevent or address fraud, security or technical issues; or protect against harm to the rights, property or safety of our users, ourselves or the public as required or permitted by law. Material relating to child sexual abuse or exploitation is reported to the appropriate authorities. Where lawful and practicable, we will notify you of a legal demand for your data.
9. Children
9.1 The App is not directed to children. You must be at least 13 years old to use it, and at least 16 in the EEA, the UK and Switzerland (or the local age of digital consent, if lower, with parental consent).
9.2 We do not knowingly collect personal data from a child below those ages. In line with the DPDP Act, 2023, we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
9.3 If you believe a child has provided us with personal data, write to support@umango.in and we will delete it promptly.
10. Your rights
10.1 Everyone
Whatever your location, you can:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Delete your account and associated data — through the in-App account deletion flow, or by writing to support@umango.in;
- Obtain a copy of your data in a portable format;
- Withdraw consent at any time, including by revoking the App's Google authorisation at https://myaccount.google.com/permissions, turning off notifications in your device settings, or changing your ads consent in the App;
- Complain to us at support@umango.in.
How to exercise these rights: email support@umango.in from the email address associated with your account, stating what you want. We may ask for information to verify your identity — we will not ask for more than is necessary. We respond within 30 days, and will tell you if we need a permitted extension. There is no charge unless a request is manifestly unfounded or excessive.
10.2 EEA, UK and Switzerland (GDPR / UK GDPR)
You additionally have the right to restrict processing, to object to processing based on legitimate interests (Art. 21 — including our Feed and discovery processing, and any direct marketing, which you may object to at any time with immediate effect), to data portability, and to lodge a complaint with a supervisory authority in your Member State of residence, place of work or place of the alleged infringement, or with the UK Information Commissioner's Office (ico.org.uk). You may do so without first complaining to us.
International transfers. We are established in India, and some of our processors are in the United States. Transfers of personal data out of the EEA/UK are made under the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), incorporated into our agreements with Google and RevenueCat, together with supplementary technical measures (encryption in transit and at rest, access controls, pseudonymisation by Firebase UID). You may request a copy of the relevant transfer mechanism by writing to support@umango.in.
10.3 California (CCPA/CPRA) and other US state privacy laws
Categories of personal information we have collected in the past 12 months, by CCPA category: identifiers (email, name, UID, device and advertising identifiers, IP address); internet or other electronic network activity (app usage, screens viewed, searches, reading and follow activity); commercial information (subscription and purchase history); geolocation (coarse, country/region level only); audio/visual (images you choose to upload); inferences (content categories associated with your reading and publishing).
Sources, purposes and recipients are set out in Sections 3 and 7. We do not sell personal information and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes requiring a right to limit under the CPRA.
You have the right to know, delete, correct, and to non-discrimination for exercising your rights. Requests: support@umango.in. An authorised agent may submit a request with written authorisation and verification. Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comparable laws have equivalent rights, including a right to appeal a refusal — write to support@umango.in with "Appeal" in the subject line.
10.4 India (Digital Personal Data Protection Act, 2023)
As a Data Principal you have the right to access a summary of your personal data and our processing, to correction, completion, updating and erasure, to grievance redressal, and to nominate another individual to exercise your rights in the event of death or incapacity. You may withdraw consent at any time, with the same ease with which it was given; withdrawal does not affect the lawfulness of processing before withdrawal, and may prevent the App from functioning.
Grievance Officer: Utsav Mangla — support@umango.in — Delhi, India. We acknowledge complaints within 24 hours and aim to resolve them within 15 days. If unsatisfied, you may approach the Data Protection Board of India.
10.5 Other jurisdictions
Residents of Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), South Africa (POPIA), Japan (APPI), South Korea (PIPA) and comparable regimes may exercise the equivalent rights available under their local law by writing to support@umango.in.
11. Retention
| Data | Retention |
|---|---|
| Account data (UID, email, name, photo URL, blog list) | While your account exists; deleted or anonymised within 30 days of account deletion |
| Follows, notification preferences, following/follower records | While your account exists; deleted within 30 days of account deletion |
| Feed entries derived from your published posts | Until you delete or unpublish the post, you request removal, or the entry is aged out of the Feed; caches purged within 30 days thereafter |
| Cached public blog/author/post records (including non-users) | Refreshed periodically; removed on request under Section 4.3, or when the source becomes unavailable |
| Moderation signals and content reports | 24 months, or longer where needed to resolve an ongoing dispute or to meet a legal obligation |
| Crash, performance and analytics data | Per Firebase's own retention settings — Crashlytics 90 days; Analytics event data 14 months |
| Push token / topic subscriptions | Until you unfollow, disable notifications, sign out or delete the App |
| Purchase and subscription records | Retained for the life of the entitlement and thereafter for 8 years to meet Indian tax and accounting obligations |
| Support correspondence | 3 years from last contact |
| Data held solely on your device (read history, preferences, caches) | Until you clear the App's data, sign out or uninstall it |
Backups are overwritten on a rolling cycle and any residual copy is deleted within 90 days.
12. Security
12.1 We apply measures appropriate to the risk, including: TLS encryption in transit; encryption at rest for data held in Google Cloud; authentication of every backend request by verified Firebase ID token; Firebase App Check device attestation to reject requests from unauthorised clients; least-privilege service accounts and OIDC-authenticated service-to-service calls; a search-only (non-administrative) key for the search index; secrets held in environment configuration rather than in the application binary; and the principle of storing as little as possible — we hold no passwords and no payment instruments.
12.2 No system is perfectly secure. We cannot guarantee absolute security, and you share information at your own risk.
12.3 Breach notification. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where GDPR applies, notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act, and notify you without undue delay where the risk is high.
13. Cookies and similar technologies
13.1 The App is a native application and does not use browser cookies for its own interface. It does use local device storage (SharedPreferences/UserDefaults, a local SQLite cache, and an image/file cache) to store your preferences, session state, read history and cached content on your device. You can clear this by signing out or uninstalling the App.
13.2 Where the App displays web content in an embedded browser or web view (for example, opening a blog, a help page or an advertiser's landing page), that web page may set its own cookies and use its own trackers, governed by that site's policies, not ours.
13.3 The Firebase and AdMob SDKs use device identifiers and similar technologies as described in Sections 3.4 and 3.5.
14. App store privacy labels
The disclosures we make in Apple's App Privacy labels and Google Play's Data safety form are derived from this Policy and are intended to be consistent with it. If you identify an inconsistency, please tell us at support@umango.in and we will correct it.
15. Changes to this Policy
We may update this Policy. The current version is always available at https://umango.in/blog-manager/privacy-policy and within the App. For changes that materially affect your rights or expand our use of your data, we will give at least 30 days' notice by in-App notice, email or a prominent notice on the policy page, and where the change requires your consent under applicable law, we will obtain it before the change applies to you. The "Last updated" date at the top always reflects the current version.
16. How to contact us
Email: support@umango.in
Grievance Officer / privacy contact: Utsav Mangla, Delhi, India (full postal address supplied on written request)
Policy page: https://umango.in/blog-manager/privacy-policy
End of Privacy Policy.