Privacy Policyগোপনীয়তা নীতি
Prohori is built around data minimization. The app does not monitor, collect, store, or transmit your child's web browsing history, the pages they visit, their searches, messages, or any private content. There is no advertising, no analytics, and no sale of data. প্রহরী তথ্য-সংক্ষিপ্তকরণের নীতিতে তৈরি। অ্যাপটি আপনার সন্তানের ওয়েব ব্রাউজিং ইতিহাস, ভিজিট করা পেজ, সার্চ, বার্তা বা কোনো ব্যক্তিগত বিষয়বস্তু পর্যবেক্ষণ, সংগ্রহ, সংরক্ষণ বা প্রেরণ করে না। কোনো বিজ্ঞাপন নেই, বিশ্লেষণ নেই, তথ্য বিক্রি নেই।
1. Introduction১. ভূমিকা
Prohori ("we", "our", "us") is a parental-control app that helps parents block harmful websites — such as adult and gambling sites — on a child's Android device. Prohori is currently offered free of charge. This policy explains, in plain language, exactly what the app does and does not do with data. প্রহরী ("আমরা") একটি অভিভাবক-নিয়ন্ত্রণ অ্যাপ যা অভিভাবকদের সন্তানের অ্যান্ড্রয়েড ডিভাইসে ক্ষতিকর ওয়েবসাইট — যেমন প্রাপ্তবয়স্ক ও জুয়ার সাইট — ব্লক করতে সাহায্য করে। প্রহরী বর্তমানে বিনামূল্যে দেওয়া হয়। এই নীতি সহজ ভাষায় ব্যাখ্যা করে অ্যাপটি তথ্য নিয়ে ঠিক কী করে এবং কী করে না।
2. Who this is for২. এটি কার জন্য
Prohori is a tool for parents and guardians. It is intended to be installed and configured on a child's device by a consenting parent or guardian. During setup the parent (not the child) authorizes the app's sensitive permissions (see §5). প্রহরী অভিভাবক ও অভিভাবকদের জন্য একটি টুল। এটি একজন সম্মতিপ্রাপ্ত অভিভাবক কর্তৃক সন্তানের ডিভাইসে ইনস্টল ও কনফিগার করার উদ্দেশ্যে তৈরি। সেটআপের সময় অভিভাবক (সন্তান নয়) অ্যাপের সংবেদনশীল অনুমতিগুলো অনুমোদন করেন (§৫ দেখুন)।
3. What we collect — and what we don't৩. আমরা যা সংগ্রহ করি — এবং যা করি না
To pair a parent with a child device and keep the block list in sync, we process a small amount of technical data: একজন অভিভাবককে সন্তানের ডিভাইসের সাথে যুক্ত করতে এবং ব্লক তালিকা সিঙ্ক রাখতে, আমরা অল্প পরিমাণ কারিগরি তথ্য প্রক্রিয়া করি:
- Device account identifiers. On first launch the child device generates a random account ID and a random secret key (both random UUIDs, not tied to your name, email, or phone number), stored on the device and on our backend purely to authenticate the device to the API.ডিভাইস অ্যাকাউন্ট শনাক্তকারী। প্রথম চালুতে সন্তানের ডিভাইস একটি এলোমেলো অ্যাকাউন্ট আইডি ও একটি এলোমেলো সিক্রেট কী তৈরি করে (দুটোই এলোমেলো UUID, আপনার নাম, ইমেইল বা ফোন নম্বরের সাথে যুক্ত নয়), যা শুধু ডিভাইসটিকে API-তে প্রমাণীকরণ করতে ডিভাইসে ও আমাদের ব্যাকএন্ডে সংরক্ষিত হয়।
- Block-list configuration. The domains (and optional labels) a parent chooses to block, and which built-in categories are enabled — stored so a parent can manage it remotely and the device can sync it. This is parent-chosen configuration, not a record of sites the child visited.ব্লক-তালিকা কনফিগারেশন। অভিভাবক যে ডোমেইন (ও ঐচ্ছিক লেবেল) ব্লক করতে বেছে নেন এবং কোন বিল্ট-ইন ক্যাটাগরি চালু আছে — যাতে অভিভাবক দূর থেকে পরিচালনা করতে ও ডিভাইস সিঙ্ক করতে পারে। এটি অভিভাবক-নির্বাচিত কনফিগারেশন, সন্তান কোন সাইটে গেছে তার রেকর্ড নয়।
- Device name (optional). A label a parent may give a child device (e.g. "Rahim's phone") so alerts and the app can tell multiple devices apart.ডিভাইসের নাম (ঐচ্ছিক)। অভিভাবক সন্তানের ডিভাইসকে একটি নাম দিতে পারেন (যেমন "রহিমের ফোন") যাতে সতর্কতা ও অ্যাপে একাধিক ডিভাইস আলাদা করা যায়।
- Pairing data. A temporary 8-digit pairing code (expires ~15 minutes) and, once a parent links their phone, a management token stored only as a SHA-256 hash — never in plain text.পেয়ারিং তথ্য। একটি অস্থায়ী ৮-সংখ্যার পেয়ারিং কোড (~১৫ মিনিটে মেয়াদ শেষ) এবং, অভিভাবক ফোন যুক্ত করলে, একটি ম্যানেজমেন্ট টোকেন যা শুধু SHA-256 হ্যাশ হিসেবে সংরক্ষিত হয় — কখনো প্লেইন টেক্সটে নয়।
- Trial / subscription state. We store a trial start date and, if you subscribe in the future, your subscription status, to manage access to features. We do not store payment-card or bank details (see §4).ট্রায়াল / সাবস্ক্রিপশন অবস্থা। আমরা একটি ট্রায়াল শুরুর তারিখ এবং, ভবিষ্যতে সাবস্ক্রাইব করলে, আপনার সাবস্ক্রিপশন অবস্থা সংরক্ষণ করি, ফিচারে অ্যাক্সেস পরিচালনা করতে। আমরা পেমেন্ট-কার্ড বা ব্যাংক বিবরণ সংরক্ষণ করি না (§৪ দেখুন)।
- Tamper events. If protection is turned off on the child device, we record the account ID, the event type, and a timestamp so the paired parent can be alerted. These contain no browsing data and are automatically deleted after 30 days.হস্তক্ষেপ ইভেন্ট। সন্তানের ডিভাইসে সুরক্ষা বন্ধ করা হলে, আমরা অ্যাকাউন্ট আইডি, ইভেন্টের ধরন ও একটি টাইমস্ট্যাম্প রেকর্ড করি যাতে যুক্ত অভিভাবককে সতর্ক করা যায়। এতে কোনো ব্রাউজিং তথ্য থাকে না এবং ৩০ দিন পর স্বয়ংক্রিয়ভাবে মুছে যায়।
- Parent notification token. When a parent links their phone, we store that device's push-notification token (from Firebase Cloud Messaging) so we can send tamper alerts — even when the app is closed. It is used only for these alerts and is removed when it becomes invalid.অভিভাবক বিজ্ঞপ্তি টোকেন। অভিভাবক ফোন যুক্ত করলে, আমরা সেই ডিভাইসের পুশ-বিজ্ঞপ্তি টোকেন (Firebase Cloud Messaging থেকে) সংরক্ষণ করি যাতে হস্তক্ষেপ সতর্কতা পাঠানো যায় — অ্যাপ বন্ধ থাকলেও। এটি শুধু এই সতর্কতা পাঠাতে ব্যবহৃত হয় এবং অকার্যকর হলে সরিয়ে ফেলা হয়।
- Feedback you send. If you use the in-app "Send feedback" feature, we store your message and any contact detail you choose to include, so we can respond and improve the app.আপনার পাঠানো মতামত। আপনি অ্যাপের "মতামত পাঠান" ফিচার ব্যবহার করলে, আমরা আপনার বার্তা ও আপনি যে যোগাযোগের তথ্য দিতে চান তা সংরক্ষণ করি, যাতে উত্তর দিতে ও অ্যাপ উন্নত করতে পারি।
- Request IP address (transient). To prevent abuse, our backend briefly processes the IP address of incoming requests for rate-limiting. It is not used to build a profile and is not retained beyond the short rate-limit window.অনুরোধের IP ঠিকানা (অস্থায়ী)। অপব্যবহার রোধে আমাদের ব্যাকএন্ড রেট-লিমিটিংয়ের জন্য আগত অনুরোধের IP ঠিকানা সংক্ষিপ্তভাবে প্রক্রিয়া করে। এটি প্রোফাইল তৈরিতে ব্যবহৃত হয় না এবং সংক্ষিপ্ত রেট-লিমিট উইন্ডোর পরে রাখা হয় না।
We do NOT collect:আমরা সংগ্রহ করি না:
- Browsing history, visited URLs, or the pages your child viewsব্রাউজিং ইতিহাস, ভিজিট করা URL, বা সন্তানের দেখা পেজ
- Search queries or keystrokesসার্চ বা কীস্ট্রোক
- Location / GPS dataঅবস্থান / জিপিএস তথ্য
- Contacts, photos, or messagesপরিচিতি, ছবি বা বার্তা
- Advertising identifiers, analytics, or crash/telemetry dataবিজ্ঞাপন শনাক্তকারী, বিশ্লেষণ, বা ক্র্যাশ/টেলিমেট্রি তথ্য
- Your payment-card or bank detailsআপনার পেমেন্ট-কার্ড বা ব্যাংক বিবরণ
Your Parental PIN is chosen on the child device and stored only on that device. It is never sent to or stored on our servers.আপনার অভিভাবক পিন সন্তানের ডিভাইসে নির্বাচিত হয় এবং শুধু সেই ডিভাইসেই সংরক্ষিত থাকে। এটি কখনো আমাদের সার্ভারে পাঠানো বা সংরক্ষণ করা হয় না।
4. Payments৪. পেমেন্ট
Prohori is currently free; this version does not process any payments and contains no in-app purchases. If a paid subscription is introduced in the future, payments will be handled by a licensed Bangladeshi payment provider (supporting methods such as bKash, Nagad, and cards). In that case we would receive only your subscription status — never your card or bank details — and this policy will be updated before any such feature goes live. প্রহরী বর্তমানে বিনামূল্যে; এই সংস্করণ কোনো পেমেন্ট প্রক্রিয়া করে না এবং কোনো ইন-অ্যাপ ক্রয় নেই। ভবিষ্যতে সাবস্ক্রিপশন চালু হলে, পেমেন্ট একটি লাইসেন্সপ্রাপ্ত বাংলাদেশি পেমেন্ট প্রোভাইডার দ্বারা পরিচালিত হবে (বিকাশ, নগদ ও কার্ডের মতো পদ্ধতিসহ)। সেক্ষেত্রে আমরা শুধু আপনার সাবস্ক্রিপশন অবস্থা পাব — কখনো আপনার কার্ড বা ব্যাংক বিবরণ নয় — এবং এমন কোনো ফিচার চালুর আগে এই নীতি হালনাগাদ করা হবে।
5. Permissions and sensitive APIs৫. অনুমতি ও সংবেদনশীল API
We use two sensitive Android APIs, strictly for the app's core parental-control function, and only after the parent authorizes them during setup.আমরা দুটি সংবেদনশীল Android API ব্যবহার করি, শুধুমাত্র অ্যাপের মূল অভিভাবক-নিয়ন্ত্রণ কাজের জন্য, এবং শুধু সেটআপের সময় অভিভাবক অনুমোদন করার পরেই।
A. VpnService (local DNS filter)ক. VpnService (স্থানীয় DNS ফিল্টার)
Prohori uses Android's VpnService to run a local, on-device DNS filter. It is not a remote VPN and does not tunnel your internet traffic through our servers.প্রহরী Android-এর VpnService ব্যবহার করে একটি স্থানীয়, ডিভাইসেই-চলা DNS ফিল্টার চালাতে। এটি রিমোট ভিপিএন নয় এবং আপনার ইন্টারনেট ট্রাফিক আমাদের সার্ভারের মধ্য দিয়ে টানেল করে না।
- How it works: while protection is on, the app inspects the device's DNS lookups on the device. A lookup for a blocked domain is stopped locally (the answer is synthesized on the device and never sent anywhere). A lookup for an allowed domain is forwarded to a family DNS resolver to be resolved (see §6).যেভাবে কাজ করে: সুরক্ষা চালু থাকা অবস্থায় অ্যাপটি ডিভাইসের DNS লুকআপগুলো ডিভাইসেই পরীক্ষা করে। একটি ব্লক করা ডোমেইনের লুকআপ স্থানীয়ভাবে থামানো হয় (উত্তরটি ডিভাইসেই তৈরি হয় এবং কোথাও পাঠানো হয় না)। একটি অনুমোদিত ডোমেইনের লুকআপ সমাধানের জন্য একটি ফ্যামিলি DNS রিজলভারে পাঠানো হয় (§৬ দেখুন)।
- What we do NOT do: we do not route, log, store, or transmit your web traffic or browsing history to our servers or to advertisers.যা আমরা করি না: আমরা আপনার ওয়েব ট্রাফিক বা ব্রাউজিং ইতিহাস আমাদের সার্ভার বা বিজ্ঞাপনদাতাদের কাছে রাউট, লগ, সংরক্ষণ বা প্রেরণ করি না।
B. Device Administrator (BIND_DEVICE_ADMIN)খ. ডিভাইস অ্যাডমিনিস্ট্রেটর (BIND_DEVICE_ADMIN)
Prohori can be set as a Device Administrator, which the parent enables through an explicit in-app consent step (behind the Parental PIN) followed by Android's own confirmation screen.প্রহরীকে একটি ডিভাইস অ্যাডমিনিস্ট্রেটর হিসেবে সেট করা যায়, যা অভিভাবক একটি স্পষ্ট ইন-অ্যাপ সম্মতি ধাপ (অভিভাবক পিনের পিছনে) এবং তারপর Android-এর নিজস্ব নিশ্চিতকরণ স্ক্রিনের মাধ্যমে চালু করেন।
- Why: solely to prevent a child from uninstalling or disabling Prohori. The app stays protected until a parent turns off device administration in Android Settings.কেন: শুধুমাত্র সন্তানকে প্রহরী আনইনস্টল বা নিষ্ক্রিয় করা থেকে বিরত রাখতে। একজন অভিভাবক Android সেটিংসে ডিভাইস অ্যাডমিনিস্ট্রেশন বন্ধ না করা পর্যন্ত অ্যাপটি সুরক্ষিত থাকে।
- What we do NOT do: we declare no device-admin policies. We do not lock the screen, wipe data, change passwords, access the camera, or monitor any activity. It is used only for uninstall protection.যা আমরা করি না: আমরা কোনো ডিভাইস-অ্যাডমিন নীতি ঘোষণা করি না। আমরা স্ক্রিন লক করি না, তথ্য মুছি না, পাসওয়ার্ড পরিবর্তন করি না, ক্যামেরা অ্যাক্সেস করি না বা কোনো কার্যকলাপ পর্যবেক্ষণ করি না। এটি শুধু আনইনস্টল সুরক্ষার জন্য ব্যবহৃত হয়।
6. Third parties (sub-processors)৬. তৃতীয় পক্ষ (সাব-প্রসেসর)
We do not sell, rent, or trade user data, and we do not share it for advertising. The app relies on the following service providers to function:আমরা ব্যবহারকারীর তথ্য বিক্রি, ভাড়া বা বিনিময় করি না এবং বিজ্ঞাপনের জন্য শেয়ার করি না। অ্যাপটি কাজ করতে নিচের সেবা প্রদানকারীদের উপর নির্ভর করে:
- Firebase Cloud Messaging (push notifications). Google's messaging service delivers tamper alerts to a parent's device. We send Firebase the parent device's notification token and the alert text (which names the event type and, if set, the device name — with no browsing data), under Google's Privacy Policy.Firebase Cloud Messaging (পুশ বিজ্ঞপ্তি)। Google-এর মেসেজিং সেবা অভিভাবকের ডিভাইসে হস্তক্ষেপ সতর্কতা পৌঁছে দেয়। আমরা Firebase-কে অভিভাবক ডিভাইসের বিজ্ঞপ্তি টোকেন ও সতর্কতার টেক্সট পাঠাই (যাতে ইভেন্টের ধরন এবং, সেট করা থাকলে, ডিভাইসের নাম থাকে — কোনো ব্রাউজিং তথ্য নয়), Google-এর গোপনীয়তা নীতির অধীনে।
- CleanBrowsing (DNS resolution). DNS lookups for allowed domains are forwarded to CleanBrowsing's public "Family" DNS resolver (185.228.168.168 / 185.228.169.168), which resolves them and applies its own adult/malware filtering. This means CleanBrowsing receives the domain names your device looks up for allowed sites (the same information any DNS resolver would receive), under CleanBrowsing's privacy policy.CleanBrowsing (DNS সমাধান)। অনুমোদিত ডোমেইনের DNS লুকআপ CleanBrowsing-এর পাবলিক "Family" DNS রিজলভারে (185.228.168.168 / 185.228.169.168) পাঠানো হয়, যা সেগুলো সমাধান করে এবং নিজস্ব প্রাপ্তবয়স্ক/ম্যালওয়্যার ফিল্টারিং প্রয়োগ করে। এর মানে CleanBrowsing আপনার ডিভাইস অনুমোদিত সাইটের জন্য যে ডোমেইন নামগুলো খোঁজে তা পায় (যে কোনো DNS রিজলভার যা পেত), CleanBrowsing-এর গোপনীয়তা নীতির অধীনে।
- Cloud hosting. Our account/block-list API and its database are hosted on Railway, with servers located in Singapore. If we later change provider or region, we will update this policy.ক্লাউড হোস্টিং। আমাদের অ্যাকাউন্ট/ব্লক-তালিকা API ও এর ডেটাবেস Railway-তে হোস্ট করা, সার্ভার সিঙ্গাপুরে অবস্থিত। ভবিষ্যতে প্রোভাইডার বা অঞ্চল পরিবর্তন করলে এই নীতি হালনাগাদ করা হবে।
7. Data storage, location, and retention৭. তথ্য সংরক্ষণ, অবস্থান ও ধারণ
- Location. Our backend and database are hosted in Singapore (Railway). If you use Prohori from Bangladesh or elsewhere, the technical data in §3 is transferred to and processed in Singapore.অবস্থান। আমাদের ব্যাকএন্ড ও ডেটাবেস সিঙ্গাপুরে (Railway) হোস্ট করা। আপনি বাংলাদেশ বা অন্য কোথাও থেকে প্রহরী ব্যবহার করলে, §৩-এর কারিগরি তথ্য সিঙ্গাপুরে স্থানান্তরিত ও প্রক্রিয়া করা হয়।
- Retention. The device account and block-list configuration are retained until they are deleted (see §8). Pairing codes expire automatically (~15 minutes). Management tokens are retained until you unpair or delete the account. Tamper events are deleted after 30 days. Rate-limiting IP data is transient.ধারণ। ডিভাইস অ্যাকাউন্ট ও ব্লক-তালিকা কনফিগারেশন মুছে ফেলা পর্যন্ত রাখা হয় (§৮ দেখুন)। পেয়ারিং কোড স্বয়ংক্রিয়ভাবে মেয়াদ শেষ হয় (~১৫ মিনিট)। ম্যানেজমেন্ট টোকেন আপনি আনপেয়ার বা অ্যাকাউন্ট মুছে ফেলা পর্যন্ত রাখা হয়। হস্তক্ষেপ ইভেন্ট ৩০ দিন পর মুছে যায়। রেট-লিমিটিং IP তথ্য অস্থায়ী।
8. Deleting your data / your choices৮. আপনার তথ্য মুছে ফেলা / আপনার পছন্দ
- On the device: turning off protection stops all filtering. To fully remove locally stored data, a parent disables device administration in Android Settings, then uninstalls the app and/or clears its storage.ডিভাইসে: সুরক্ষা বন্ধ করলে সব ফিল্টারিং থামে। স্থানীয়ভাবে সংরক্ষিত তথ্য সম্পূর্ণ সরাতে, একজন অভিভাবক Android সেটিংসে ডিভাইস অ্যাডমিনিস্ট্রেশন বন্ধ করে, তারপর অ্যাপ আনইনস্টল করেন এবং/অথবা এর স্টোরেজ পরিষ্কার করেন।
- On our servers: to delete the device account and everything stored for it (the block list and any management tokens) from our backend, contact us at support@amarprohori.com and we will delete it within 30 days.আমাদের সার্ভারে: আমাদের ব্যাকএন্ড থেকে ডিভাইস অ্যাকাউন্ট ও এর জন্য সংরক্ষিত সবকিছু (ব্লক তালিকা ও যেকোনো ম্যানেজমেন্ট টোকেন) মুছতে, support@amarprohori.com-এ আমাদের সাথে যোগাযোগ করুন, এবং আমরা ৩০ দিনের মধ্যে তা মুছে ফেলব।
9. Security৯. নিরাপত্তা
Data is transmitted to our backend over encrypted HTTPS. Management tokens are stored only as SHA-256 hashes; device credentials are randomly generated identifiers, and we do not collect passwords or payment details. No method of transmission or storage is 100% secure, but we take reasonable measures to protect the limited data we hold.তথ্য আমাদের ব্যাকএন্ডে এনক্রিপ্টেড HTTPS-এর মাধ্যমে প্রেরণ করা হয়। ম্যানেজমেন্ট টোকেন শুধু SHA-256 হ্যাশ হিসেবে সংরক্ষিত হয়; ডিভাইস ক্রেডেনশিয়াল এলোমেলোভাবে তৈরি শনাক্তকারী, এবং আমরা পাসওয়ার্ড বা পেমেন্ট বিবরণ সংগ্রহ করি না। প্রেরণ বা সংরক্ষণের কোনো পদ্ধতিই ১০০% নিরাপদ নয়, তবে আমরা যে সীমিত তথ্য রাখি তা রক্ষা করতে যুক্তিসঙ্গত ব্যবস্থা নিই।
10. Children's privacy১০. শিশুদের গোপনীয়তা
Prohori is a parental-control tool operated by a parent or guardian; it is not directed to children and does not knowingly collect personal information directly from a child. A parent installs the app, sets the Parental PIN, and authorizes the VpnService and Device Administrator permissions during setup. Where applicable, we aim to comply with children's-privacy laws (such as COPPA and GDPR-K). If you believe a child has provided us personal information, contact us and we will delete it.প্রহরী একজন অভিভাবক দ্বারা পরিচালিত একটি অভিভাবক-নিয়ন্ত্রণ টুল; এটি শিশুদের উদ্দেশ্যে নয় এবং সরাসরি কোনো শিশুর কাছ থেকে জেনেবুঝে ব্যক্তিগত তথ্য সংগ্রহ করে না। একজন অভিভাবক অ্যাপটি ইনস্টল করেন, অভিভাবক পিন সেট করেন, এবং সেটআপের সময় VpnService ও ডিভাইস অ্যাডমিনিস্ট্রেটর অনুমতি অনুমোদন করেন। প্রযোজ্য ক্ষেত্রে, আমরা শিশু-গোপনীয়তা আইন (যেমন COPPA ও GDPR-K) মেনে চলার চেষ্টা করি। কোনো শিশু আমাদের ব্যক্তিগত তথ্য দিয়েছে বলে মনে করলে, আমাদের সাথে যোগাযোগ করুন এবং আমরা তা মুছে ফেলব।
11. Changes to this policy১১. এই নীতির পরিবর্তন
We may update this policy to reflect changes in the app, our infrastructure, or Android/Play requirements. Material changes will be noted in the app and/or by updating the effective date above.আমরা অ্যাপ, আমাদের অবকাঠামো, বা Android/Play-এর প্রয়োজনীয়তার পরিবর্তন প্রতিফলিত করতে এই নীতি হালনাগাদ করতে পারি। গুরুত্বপূর্ণ পরিবর্তন অ্যাপে এবং/অথবা উপরের কার্যকর তারিখ হালনাগাদ করে জানানো হবে।
12. Contact১২. যোগাযোগ
- Developer: O2A AI Research, Innovation & Solutions Pty Ltdডেভেলপার: O2A AI Research, Innovation & Solutions Pty Ltd
- Email: support@amarprohori.comইমেইল: support@amarprohori.com
- Governing law: Australiaপ্রযোজ্য আইন: অস্ট্রেলিয়া