Yogarohan privacy policy
For the Yogarohan Android app. Last updated 5 October 2026.
Yogarohan ("the app") is developed by Deepankar Garg ("we", "us"). It watches your yoga through your phone's camera, tells you what to correct, and lets a yoga teacher set your practice and follow your progress. This policy explains what data the app handles, who can see it, and how to have it deleted.
Summary
- The camera image never leaves your phone. Video and photos are not recorded, stored or uploaded.
- We store your account (name and email), your links with teachers or students, the practice set for you, your practice results, and feedback you send.
- A teacher you have accepted can see your name, email, the practice they set you and your practice results. You can unlink at any time.
- The app never asks for health details. Please don't type them into names, notes or feedback.
- No advertising, no analytics SDKs, and we never sell or share your data for marketing.
- The app is for adults only (18 and older).
The camera
During practice the app uses your phone's camera to find your body's position (shoulders, hips, knees and so on) and compare it with the ideal pose. This all happens on your phone. The camera image and the body positions it finds are not recorded, stored or sent anywhere. Practice works without an internet connection.
You can try the app without an account. Nothing from a try without an account is sent or kept.
Your account
To use more than the try-out, you log in with Google or with a 6-digit code sent to your email. We store:
- your email address, and your name (from your Google account if you log in with Google, or as you type it in the app; you can change it in Settings);
- that you confirmed you are 18 or older and agreed to this policy, with which version and when;
- a region setting, so your data can be kept in the right place.
If you log in with Google, Google tells us your name, email address and a Google account identifier. We do not get your contacts, photos or anything else from your Google account.
Teachers and students
You can invite a teacher or a student, or be invited. For each link we store who the teacher and the student are, whether the invite is waiting, accepted or ended, and when.
- Inviting someone. If you enter their email address, we store it and email them the invite from no-reply@indidev.org, with your name. You can also share the invite link through any app on your phone; the link contains a random code, of which we store only a scrambled form. The name you save them as is seen only by you.
- Being invited. Your inviter can see the email address they invited. Nothing is linked until you tap Accept.
- Once linked, your teacher can see your name, email address, the practice they set you, the results of that practice, and the results of practice you do on your own. Your student can see your name, email address and the practice you set them.
- Teacher notes. A teacher can write notes about a student. Only that teacher sees them; the student does not. Notes are free text: please don't write health details in them.
- Unlinking. Either side can unlink. After that, the teacher can no longer set the student's practice or see their results.
Practice and results
We store the practice a teacher sets (which asanas, in what order, how long to hold each).
When you finish a practice while logged in, we store its result: when it started and ended, which practice it was (if a teacher set it), each asana practised and on which side, how long you held it, how it ended (held, skipped, stopped, or stopped because it hurt), which corrections you fixed and which are still to work on, a few measurements of your pose while you held it (for example the angle of your front knee or how upright your back was: one number per measurement for each asana, so your progress can be compared later), a stick figure of how you held each asana at one moment (the positions of about 17 points such as shoulders, hips and knees, drawn next to the ideal so you can see your progress), the version of each asana's description used, and the app version. A practice in which the camera never saw you in a pose is not stored, unless you stopped because something hurt. The try-out without logging in stores nothing.
Results contain no video, no photos, no frame-by-frame body positions, and no health details. They are saved on your phone first and uploaded when you are online. You see all your own results. The results of practice a teacher set you are seen only by that teacher; the results of practice you do on your own (a short session, an asana from the library, or a plan you made for yourself) are seen by every teacher you are linked with. Results are never sold or shared further.
A later version of the app may also store one photo of you in each pose for each session, so you can see your progress as it really looked. It does not do so today; we will update this policy and ask you to agree before it does.
Feedback
Settings has a box where you can type feedback. When you tap send, we store what you typed with your account and the app version. Nothing is sent unless you tap send. You can also email us directly from Settings; that message goes through your own email account.
Data kept on your phone
The app keeps your login (encrypted with a key held in Android's secure key storage), a copy of your Home screen so it opens offline, your practice results (and those of your students that you have opened, if you are a teacher), whether you last used the teacher or student view, and an invite link waiting for you to log in. When you log out, your login, the copy of Home and every result already uploaded are removed; a result not yet uploaded stays on the phone until you log in again and it is sent. Everything is removed when you uninstall the app or clear its storage in Android Settings.
If you install the app from an invite link, the app reads the invite code from Google Play's install information, so the invite is waiting for you after you log in.
Where your data is kept, and who handles it
Your account and data are stored by Supabase, in its data centre in Mumbai, India. These services handle data on our behalf, only to run the app:
- Supabase: login, database and server functions.
- Cloudflare: forwards the app's connections to Supabase (api.indidev.org) and serves invite pages (app.indidev.org). It sees your IP address to deliver the connection; we do not store it.
- Resend: sends login codes and invite emails.
- Google: "Continue with Google" sign-in, if you use it, and Google Play, which installs the app.
If you live outside India, your data is transferred to and stored in India. Our service providers are bound by data processing terms that protect it.
We use your data only to run the app and improve it. We don't sell it, rent it or use it for advertising.
Deleting your data, and your other rights
You can see, correct, export or delete your data.
- In the app: Settings → Delete account. It deletes your account at once, with everything linked to it: your profile, links, notes you wrote, practice set for you or by you, results and feedback. Invites you sent are deleted too, and the app removes what it kept on your phone. This cannot be undone.
- Without the app: email deepankar.garg@indidev.org from the email address you log in with, with the subject "Delete my Yogarohan account" (or "Export my Yogarohan data"). We delete the same data and reply to confirm within 30 days.
Unlinking from a teacher or student, which you can do yourself in the app, stops further sharing without deleting your account. We keep your data while your account exists, and delete it when you ask us to delete the account.
If you are in the European Union or the United Kingdom, you can also complain to your data protection authority.
Permissions
The app asks for the camera, only for practice, as described above. You can refuse it; practice then can't run, and everything else still works. The app also uses Android's internet permission, granted at install, to reach the services above. It does not use location, microphone, contacts or any other sensitive permission.
Children
The app is for adults only. You must be 18 or older to log in, and we do not knowingly collect data from anyone younger. If you believe a child has an account, email us and we will delete it.
Changes to this policy
If this policy changes, the updated version will be posted at this address with a new "Last updated" date. If a change affects how your data is shared, the app will ask you to agree again.
Contact
Questions about this policy: deepankar.garg@indidev.org.