Privacy Policy

Effective date: 8 September 2026
Last updated: 8 September 2026
Version: 1.0


1. Who we are

1.1 This Privacy Policy explains how Utsav Mangla, an individual carrying on business as a sole proprietor with a place of business in Delhi, India ("we", "us", "our", "Provider"), collects, uses, shares and protects personal data in connection with the mobile and desktop application published by us that acts as a client for Google's Blogger platform ("the App").

1.2 The App is distributed under storefront-specific names, including "Blogging for Blogspot Blog" on the Apple App Store in the United States (Apple App ID 6504722976), and under equivalent names on other storefronts and on Google Play. This Policy covers all of them.

1.3 We are the data controller (GDPR/UK GDPR), the business (CCPA/CPRA) and the Data Fiduciary (India's Digital Personal Data Protection Act, 2023) for the personal data described in this Policy, except where stated otherwise in Section 4.

1.4 Contact: support@umango.in
Grievance Officer / privacy contact: Utsav Mangla, support@umango.in, Delhi, India.

1.5 We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. We have not appointed an EU or UK Article 27 representative; if you are in the EEA or UK you may contact us directly at the address above.


2. The most important thing to understand first

2.1 The App is an unofficial, third-party client for Google's Blogger/Blogspot service. We are not affiliated with, endorsed by or connected to Google.

2.2 Your blog and its contents live on Google's systems, not ours. When you write, edit, publish or delete a post through the App, that content is transmitted directly from your device to Google's official Blogger API, under an authorisation you granted through Google's own consent screen. Google's collection and use of that data is governed by the Google Privacy Policy (https://policies.google.com/privacy) and the Blogger Terms of Service — not by this Policy.

2.3 We hold far less about you than Google does. What we hold, and why, is set out below in full.


The table below is the authoritative description of our processing. "Legal basis" columns refer to the GDPR/UK GDPR; where you are in India, the corresponding basis under the DPDP Act, 2023 is consent or certain legitimate uses as noted.

3.1 Account and authorisation data

DataSourcePurposeLegal basis
Google Account email address, display name, profile photo URLGoogle Sign-In, at your electionCreate and operate your account; identify you in the App; associate your blogs with youContract (Art. 6(1)(b))
Firebase Authentication user ID (UID) — a pseudonymous identifier we generateGenerated on first sign-inPrimary key for everything we store about you; authenticate your API requestsContract
Google OAuth authorisation for the scope https://www.googleapis.com/auth/bloggerGranted by you on Google's consent screenRead and manage your own Blogger blogs at your instructionConsent given to Google; Contract with us
List of Blogger blogs you own or administer (blog ID, title, URL, role)Blogger APIShow your blogs; determine what you may edit; verify authorship for Feed publicationContract

About the OAuth token. The access token issued by Google is held by the Google Sign-In SDK on your device. We do not store your Google password, refresh token, or long-term credentials on our servers. In a small number of server-assisted operations (for example, retrieving blog page-view statistics that the Blogger API exposes only to the blog owner), a short-lived access token may be transmitted to our backend for the duration of that single request and is not persisted. You can revoke our authorisation at any time at https://myaccount.google.com/permissions.

3.2 Content data

DataSourcePurposeLegal basis
Post title, body (HTML), labels, images, publication status, drafts and schedulingYou, in the AppTransmit to the Blogger API at your instruction; render in the AppContract
Publicly published post content, title, excerpt, images, labels, blog theme, publication dateRetrieved from your blog's public page/RSS feed after you publishInclude in the App's discovery Feed, search index, recommendations and notificationsContract (for your own content) and legitimate interests (Art. 6(1)(f)) in operating a discovery service
Automated analysis output: detected language/locale, topical category, and moderation signals (spam, sexual content, child-safety concerns, illegal activity, violent extremism) with confidence scoresGenerated by Google Gemini from public post contentRoute posts to the right language/country feed; categorise; keep unlawful and harmful content out of the FeedLegitimate interests and legal obligation (Art. 6(1)(c) / 6(1)(f)); DPDP "legitimate use"
Images selected from your photo library or cameraYou, with your OS-level permissionUpload to your Blogger post; compressed on device before uploadContract

Important: only content that is already publicly readable at its Blogger/Blogspot URL enters the Feed or is analysed. Private blogs and unpublished drafts are not sent to the Feed pipeline or to Gemini.

3.3 Social and activity data

DataSourcePurposeLegal basis
Blogs you follow and unfollow (blog IDs, timestamps), follower and following countsYour actionsOperate follow, feed personalisation and follower-count featuresContract
Notification preferences per followed blogYour actionsSend only the notifications you asked forContract
Firebase Cloud Messaging registration token and topic subscriptions (one topic per followed blog)Firebase SDK on your deviceDeliver push notifications about new posts on blogs you followConsent (device notification permission)
Content reports you submit (blog ID, post ID, violation categories, your UID, timestamp)Your actionsInvestigate and action reports; prevent abuse; maintain an audit trailLegitimate interests; legal obligation
Post read historyYour reading in the AppShow recently-read posts; avoid repeating items in the feedStored only on your device; not transmitted to us

3.4 Device, diagnostic and usage data

Collected through Google Firebase SDKs embedded in the App:

SDKDataPurposeLegal basis
Firebase Analytics (Google Analytics for Firebase)App Instance ID, your Firebase UID set as user_id, screen views and in-app events, session data, app version, device model, OS version, language, coarse country/region derived from IP addressUnderstand which features are used; fix usability problems; measure retentionConsent where required by ePrivacy/local law; otherwise legitimate interests
Firebase CrashlyticsCrash and non-fatal error reports, stack traces, Crashlytics installation UUID, device state at time of crash, OS and app version, breadcrumb logsDiagnose and fix crashesLegitimate interests in a functioning, secure app
Firebase Performance MonitoringNetwork request timings and payload sizes, screen render traces, app start times, device and connection typeDetect and fix performance regressionsLegitimate interests
Firebase Remote ConfigDevice/app attributes used to target configuration values; the config values delivered to your installRoll out features gradually; run configuration experimentsLegitimate interests
Firebase App CheckDevice/app attestation token (Apple App Attest / DeviceCheck; Android Play Integrity)Confirm requests come from a genuine, unmodified install of the App; block abuse of our backendLegitimate interests in security
device_info_plus / package_info_plusDevice model, OS version, app version and build numberSupport, compatibility handling, diagnosticsLegitimate interests
IP addressAutomatically, at the network layerRoute responses; security and abuse prevention; derive approximate countryLegitimate interests

We do not collect precise GPS location. We do not access your contacts, calendar, microphone, health data or SMS.

3.5 Advertising data (free tier only)

DataCollected byPurposeLegal basis
Device advertising identifier — Apple IDFA (only if you grant App Tracking Transparency permission) or Android Advertising IDGoogle AdMob SDKServe, cap and measure adsConsent
IP address, coarse location (country/region), device and OS attributes, ad impressions, clicks, viewabilityGoogle AdMob SDKServe and measure ads; detect ad fraudConsent for personalised ads; legitimate interests for fraud prevention and basic delivery
SKAdNetwork / Privacy-Preserving Attribution postbacks (iOS)ApplePrivacy-preserving install attributionApple platform mechanism; no user-level identifier

Personalised ads and consent. Where required — in the EEA, the UK and Switzerland, and elsewhere where local law requires — the App presents a consent request (via Google's User Messaging Platform / an IAB TCF-compatible consent mechanism) before any personalised advertising is served or any advertising identifier is used for that purpose. If you do not consent, ads are served on a non-personalised basis. On Apple platforms, no IDFA is accessed unless you separately allow tracking through the App Tracking Transparency prompt. You may change your choice at any time in the App's settings, and may reset or limit your advertising identifier in your device settings.

Purchasing an ad-free entitlement, where offered, stops the App from serving ads.

3.6 Purchase and subscription data

DataSourcePurposeLegal basis
Store transaction identifiers, receipts, product IDs, purchase and expiry dates, renewal and cancellation status, trial status, entitlement status, store country, and a "last seen country" signalApple / Google Play, via RevenueCat, Inc.Verify and unlock what you paid for; sync entitlements across devices; determine your country for country-specific feeds; handle support queriesContract; legal obligation (tax and accounting)

We never see, receive or store your payment card number, bank details, CVV or billing address. Payment is processed entirely by Apple or Google. Your RevenueCat "app user ID" is your Firebase UID.

3.7 Support correspondence

If you email us, we process your email address, the content of your message and any attachments, in order to answer you and keep a record of the issue. Legal basis: legitimate interests / contract.


4. Public Blogger content and people who are not our users

4.1 To power search, discovery and recommendations, the App collects and caches information that is already published publicly on the open web by Blogger/Blogspot blogs, including: blog titles, URLs, descriptions, themes and page-view counts; post titles, excerpts, images, labels and dates; public author profile pages and public display names and profile images; and public RSS/Atom feeds. We obtain this through the official Blogger API, ordinary retrieval of publicly served pages and feeds, and publicly available web-crawl datasets.

4.2 Some of that information constitutes personal data of blog authors who are not users of the App. Our legal basis is legitimate interests (Art. 6(1)(f)) in operating a discovery service for publicly published blogs, balanced against the limited privacy impact of surfacing content its author chose to publish publicly.

4.3 If you are a blog author and you do not want your blog surfaced in the App, write to support@umango.in from an address or Google Account associated with the blog, giving the blog URL. We will remove and exclude it, ordinarily within 15 days. You may also object to this processing under Article 21 GDPR by the same route. Removal from the App does not affect your blog's availability elsewhere on the web.


5. What we do not do


6. Automated decision-making

6.1 We use automated systems to decide whether a publicly published post is admitted to the Feed, what topical category and language it is assigned, and whether it is withheld for suspected policy violation (Section 3.2).

6.2 These decisions affect only the visibility of content within our App. They do not affect your blog, your Google account, your ability to publish, or your legal rights, and they do not produce legal effects concerning you within the meaning of Art. 22(1) GDPR.

6.3 Nevertheless, you may request human review of any such decision by writing to support@umango.in with the blog and post URL. We will re-examine the decision and tell you the outcome.


7. Third parties who process data for us

We use the following processors and services. Each is bound by contract or by its own published terms to process data only as instructed and to apply appropriate safeguards.

ProviderRoleWhat it processesWhereTerms
Google LLC / Google Ireland Ltd — Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Messaging, Analytics, Crashlytics, Performance Monitoring, Remote Config, App CheckProcessor (and controller for some Analytics/Ads purposes)Account data, content and feed data, device and diagnostic data, push tokensGlobal (US, EU, India)policies.google.com/privacy · firebase.google.com/support/privacy
Google Cloud RunHosting of our backend APIAll backend requestsasia-south1 (Mumbai, India) and, for some workloads, us-central1 (United States)cloud.google.com/terms
Google Blogger API v3The service the App is a client forYour blog content and metadata, at your instructionGoogle infrastructurepolicies.google.com/privacy
Google Gemini APIAutomated content moderation, language detection and categorisationPublicly published post textGoogle infrastructureai.google.dev/terms
Google Programmable Search / Custom Search APISupplementary discovery of public blogsSearch queries about public blogsGoogle infrastructurepolicies.google.com/privacy
Google AdMobAdvertising (free tier)Advertising identifier, IP, ad interaction dataGlobalpolicies.google.com/technologies/ads
TypesenseHosted search index over public blog, post and author dataPublic blog/post/author records; your search queriesProvider's hosting regiontypesense.org/privacy
RevenueCat, Inc.Subscription and entitlement infrastructureFirebase UID, store receipts, subscription status, store/last-seen countryUnited Statesrevenuecat.com/privacy
Apple Inc.App distribution and paymentPurchase transactions, SKAdNetwork attributionGlobalapple.com/legal/privacy
Google Play (Google LLC)App distribution and paymentPurchase transactionsGlobalpolicies.google.com/privacy

We may also disclose personal data: (a) to professional advisers under duties of confidentiality; (b) to a successor in connection with a merger, acquisition or asset sale, on notice to you; and (c) as described in Section 8.


We may disclose personal data where we believe in good faith that it is reasonably necessary to: comply with a law, regulation, legal process or enforceable governmental request; enforce our Terms of Service, including investigating potential violations; detect, prevent or address fraud, security or technical issues; or protect against harm to the rights, property or safety of our users, ourselves or the public as required or permitted by law. Material relating to child sexual abuse or exploitation is reported to the appropriate authorities. Where lawful and practicable, we will notify you of a legal demand for your data.


9. Children

9.1 The App is not directed to children. You must be at least 13 years old to use it, and at least 16 in the EEA, the UK and Switzerland (or the local age of digital consent, if lower, with parental consent).

9.2 We do not knowingly collect personal data from a child below those ages. In line with the DPDP Act, 2023, we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

9.3 If you believe a child has provided us with personal data, write to support@umango.in and we will delete it promptly.


10. Your rights

10.1 Everyone

Whatever your location, you can:

How to exercise these rights: email support@umango.in from the email address associated with your account, stating what you want. We may ask for information to verify your identity — we will not ask for more than is necessary. We respond within 30 days, and will tell you if we need a permitted extension. There is no charge unless a request is manifestly unfounded or excessive.

10.2 EEA, UK and Switzerland (GDPR / UK GDPR)

You additionally have the right to restrict processing, to object to processing based on legitimate interests (Art. 21 — including our Feed and discovery processing, and any direct marketing, which you may object to at any time with immediate effect), to data portability, and to lodge a complaint with a supervisory authority in your Member State of residence, place of work or place of the alleged infringement, or with the UK Information Commissioner's Office (ico.org.uk). You may do so without first complaining to us.

International transfers. We are established in India, and some of our processors are in the United States. Transfers of personal data out of the EEA/UK are made under the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), incorporated into our agreements with Google and RevenueCat, together with supplementary technical measures (encryption in transit and at rest, access controls, pseudonymisation by Firebase UID). You may request a copy of the relevant transfer mechanism by writing to support@umango.in.

10.3 California (CCPA/CPRA) and other US state privacy laws

Categories of personal information we have collected in the past 12 months, by CCPA category: identifiers (email, name, UID, device and advertising identifiers, IP address); internet or other electronic network activity (app usage, screens viewed, searches, reading and follow activity); commercial information (subscription and purchase history); geolocation (coarse, country/region level only); audio/visual (images you choose to upload); inferences (content categories associated with your reading and publishing).

Sources, purposes and recipients are set out in Sections 3 and 7. We do not sell personal information and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes requiring a right to limit under the CPRA.

You have the right to know, delete, correct, and to non-discrimination for exercising your rights. Requests: support@umango.in. An authorised agent may submit a request with written authorisation and verification. Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comparable laws have equivalent rights, including a right to appeal a refusal — write to support@umango.in with "Appeal" in the subject line.

10.4 India (Digital Personal Data Protection Act, 2023)

As a Data Principal you have the right to access a summary of your personal data and our processing, to correction, completion, updating and erasure, to grievance redressal, and to nominate another individual to exercise your rights in the event of death or incapacity. You may withdraw consent at any time, with the same ease with which it was given; withdrawal does not affect the lawfulness of processing before withdrawal, and may prevent the App from functioning.

Grievance Officer: Utsav Mangla — support@umango.in — Delhi, India. We acknowledge complaints within 24 hours and aim to resolve them within 15 days. If unsatisfied, you may approach the Data Protection Board of India.

10.5 Other jurisdictions

Residents of Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), South Africa (POPIA), Japan (APPI), South Korea (PIPA) and comparable regimes may exercise the equivalent rights available under their local law by writing to support@umango.in.


11. Retention

DataRetention
Account data (UID, email, name, photo URL, blog list)While your account exists; deleted or anonymised within 30 days of account deletion
Follows, notification preferences, following/follower recordsWhile your account exists; deleted within 30 days of account deletion
Feed entries derived from your published postsUntil you delete or unpublish the post, you request removal, or the entry is aged out of the Feed; caches purged within 30 days thereafter
Cached public blog/author/post records (including non-users)Refreshed periodically; removed on request under Section 4.3, or when the source becomes unavailable
Moderation signals and content reports24 months, or longer where needed to resolve an ongoing dispute or to meet a legal obligation
Crash, performance and analytics dataPer Firebase's own retention settings — Crashlytics 90 days; Analytics event data 14 months
Push token / topic subscriptionsUntil you unfollow, disable notifications, sign out or delete the App
Purchase and subscription recordsRetained for the life of the entitlement and thereafter for 8 years to meet Indian tax and accounting obligations
Support correspondence3 years from last contact
Data held solely on your device (read history, preferences, caches)Until you clear the App's data, sign out or uninstall it

Backups are overwritten on a rolling cycle and any residual copy is deleted within 90 days.


12. Security

12.1 We apply measures appropriate to the risk, including: TLS encryption in transit; encryption at rest for data held in Google Cloud; authentication of every backend request by verified Firebase ID token; Firebase App Check device attestation to reject requests from unauthorised clients; least-privilege service accounts and OIDC-authenticated service-to-service calls; a search-only (non-administrative) key for the search index; secrets held in environment configuration rather than in the application binary; and the principle of storing as little as possible — we hold no passwords and no payment instruments.

12.2 No system is perfectly secure. We cannot guarantee absolute security, and you share information at your own risk.

12.3 Breach notification. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where GDPR applies, notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act, and notify you without undue delay where the risk is high.


13. Cookies and similar technologies

13.1 The App is a native application and does not use browser cookies for its own interface. It does use local device storage (SharedPreferences/UserDefaults, a local SQLite cache, and an image/file cache) to store your preferences, session state, read history and cached content on your device. You can clear this by signing out or uninstalling the App.

13.2 Where the App displays web content in an embedded browser or web view (for example, opening a blog, a help page or an advertiser's landing page), that web page may set its own cookies and use its own trackers, governed by that site's policies, not ours.

13.3 The Firebase and AdMob SDKs use device identifiers and similar technologies as described in Sections 3.4 and 3.5.


14. App store privacy labels

The disclosures we make in Apple's App Privacy labels and Google Play's Data safety form are derived from this Policy and are intended to be consistent with it. If you identify an inconsistency, please tell us at support@umango.in and we will correct it.


15. Changes to this Policy

We may update this Policy. The current version is always available at https://umango.in/blog-manager/privacy-policy and within the App. For changes that materially affect your rights or expand our use of your data, we will give at least 30 days' notice by in-App notice, email or a prominent notice on the policy page, and where the change requires your consent under applicable law, we will obtain it before the change applies to you. The "Last updated" date at the top always reflects the current version.


16. How to contact us

Email: support@umango.in
Grievance Officer / privacy contact: Utsav Mangla, Delhi, India (full postal address supplied on written request)
Policy page: https://umango.in/blog-manager/privacy-policy


End of Privacy Policy.