Pramaan — Privacy Policy
Pramaan is a sign-in companion app: it lets you approve sign-ins to your organisation's applications with a tap, generates authenticator codes, and stores passkeys in your device's secure hardware. It is built so that the most sensitive material — private keys and authenticator secrets — never leaves your device. This policy explains what little data the service does process, and why.
Data we process, and why
| Data | Purpose | Where it lives |
|---|---|---|
| Account identifiers (name, username, email) from your organisation's identity provider | Signing you in and showing which account is in use | Your identity provider; cached on your device |
| Device enrolment record (device model, a hardware-backed public key, a push-notification token) | Delivering sign-in requests to your device and verifying your approvals | The Pramaan ID Broker operated by your organisation |
| Sign-in security metadata (IP address, approximate location derived from it, time, application name) | Shown to you on each approval so you can reject sign-ins that are not yours; risk checks against unusual locations; security audit log | The Pramaan ID Broker, in the audit trail |
| Device integrity verdict (Google Play Integrity) | Detecting compromised or counterfeit devices at enrolment | Verified server-side; the verdict is not retained beyond evaluation and logging |
Data that never leaves your device
- Private keys — approval and passkey keys are generated in your device's secure hardware (StrongBox/TEE) and are non-exportable.
- Authenticator (TOTP) secrets — stored only on your device. If you explicitly enable cross-device sync, they are end-to-end encrypted with a passphrase only you know before upload; the server stores ciphertext it cannot read.
- Biometrics — fingerprint/face data is handled entirely by Android; Pramaan only receives a yes/no from the operating system.
What we don't do
- No advertising, no trackers, no analytics SDKs.
- No sale or sharing of personal data with third parties. The only third-party processor is Google (Firebase Cloud Messaging for push delivery, Play Integrity for device attestation).
Retention
Enrolment records are kept while the device is enrolled and are deleted when you (or your administrator) revoke the device — revocation is available in the app under "Where you're signed in". Sign-in audit events are retained per your organisation's security policy and then purged.
Your choices and rights
- Revoke any enrolled device at any time from the app; this immediately stops push delivery and invalidates its approval key.
- Uninstalling the app destroys its on-device keys.
- To exercise data access or deletion rights, contact your organisation's administrator or the address below.
Contact
Frontier Labs Private Limited
contact@pramaanid.cloud