BackLibrio

Privacy Policy

Last updated: 2 October 2026

This policy explains what personal data Librio collects, why we collect it, who else sees it, and what you can ask us to do about it. It covers both the library owner who uses Librio and the students whose details an owner records.

1. Who we are

Librio is software for study library owners, operated from India. For the personal data of a library owner’s account, we are the data fiduciary. For the personal data of that library’s students, the owner is the data fiduciary and we act as a data processor on their instructions.

Our contact details are on our home page. Write to us there for any privacy question or to exercise a right described in Section 10.

2. Our role and yours

This distinction decides who answers a student’s complaint. If a student asks us to delete their phone number from your library’s records, we route that to you, because you hold that record. We will help you respond, and we will enforce the access separation that stops one library seeing another’s data.

3. What we collect

Data about the owner, which you give us directly:

  • name, email address and the library’s name, phone number and location;
  • a hashed password. We never store your password, so we cannot recover it for you;
  • your last sign-in time, and the status of your account.

Data about students, which the owner enters on their behalf:

  • Identity and contact: name, 10-digit phone number, and an email address if the owner chooses to record one;
  • Membership: plan, shift, seat, monthly fee, expiry date, join date and, if the student leaves, the date they left;
  • Payments: amount in rupees, mode (cash, UPI or other), the period the payment covers, the date paid, and any note;
  • Photograph: optional, up to 2 MB, stored with our file storage provider rather than in our database;
  • Custom fields: whatever additional admission details the library defines, for example a course or an institution;
  • Email consent: whether a student agreed to receive automatic fee reminders.

Data we generate while you use the service:

  • an EmailLog for every mail we attempt, whether it was sent, failed or skipped: recipient, subject, status, and the time;
  • the Google OAuth tokens for a mailbox you connect, encrypted at rest;
  • a card token for each student you print a library card for, used only to resolve that card’s public page.

We do not collect payment card numbers. Card details, where a payment is taken, are handled by a payment provider and never reach us.

4. Why we use it

  • to authenticate you and keep your account secure;
  • to run the features you asked for: showing who has paid, when a seat expires, and recording a payment;
  • to send a fee reminder, a receipt or a note, and to keep the log of mails that were attempted;
  • to send the automatic expiry reminder, but only where the library has switched the feature on and the individual student has consented;
  • to keep one library’s records separate from another’s, every single time;
  • to support you when something is wrong, and to meet our legal, tax and accounting obligations.

We do not use student data to build advertising profiles, and we do not share it for anyone else’s marketing.

6. Who we share it with

We share personal data only with the following, and only as much as each needs:

  • Google, if you connect a mailbox, for authentication and for sending mail from it. Google acts as an independent controller for that processing under its own terms.
  • Our hosting and database provider, which stores the database on our behalf, and our file storage provider, which stores student photographs.
  • Professional advisers such as our accountants and lawyers, andlaw enforcement or regulators where we are legally required to disclose.
  • A successor or buyer, but only in a genuine corporate transaction and only under the same confidentiality obligations.

We do not sell personal data, and we do not disclose one library’s records to another library, to that library’s students, or to their parents.

7. The Gmail connection

This is the part owners ask about most, so it is worth being precise.

  • We request two Google permissions. The first is the ability to send mail. The second is your email address, so we can show which mailbox is connected. We do not request permission to read, draft, delete or open your mail, and we never call any endpoint that would return your messages.
  • Google hands us an access token and a refresh token. Both are stored encrypted with AES-256-GCM and are never stored in readable form, not even in our own database.
  • Access tokens last one hour. We refresh them automatically in the background. If a refresh fails, we mark the connection as needing a reconnect and stop. We never log in as you to read your mail.
  • Mail is sent one at a time, not in a parallel burst, because a burst trips Gmail’s per-mailbox rate limit and can lock the mailbox. A single bulk action is capped at 50 recipients.
  • You can disconnect at any time from Settings. Disconnecting deletes the stored tokens immediately.

The public library card page. A card’s QR code resolves to a public page showing the library name, a masked student name, status, expiry, plan, shift, seat and fee. It never shows a phone number, an email address or a full name, it is not indexed by search engines, and it shows nothing at all for a student who has left.

8. How long we keep it

  • Student records stay in your account while it is active. When a student leaves, the record is kept, not deleted, so payment history survives. It goes when you delete the student or close the account, subject to the export window.
  • Payment records are kept for as long as the account exists, and then for the period Indian tax and accounting law requires, which is generally 8 years.
  • Email logs are kept for 24 months, so you can see what was sent and what failed.
  • Google OAuth tokens are deleted the moment you disconnect, or when the account is closed.
  • Photographs are deleted with the student record or on account closure.

After account closure you have 30 days to export. After that we delete, except for an encrypted backup kept for security and legal reasons and deleted on our ordinary backup cycle.

9. How we protect it

  • Passwords are hashed with bcrypt and are never stored or emailed in plain text.
  • Google tokens are encrypted at rest with AES-256-GCM under a key kept outside the code.
  • Every database query is scoped to your library. A record belonging to another library is reported as not found, never as forbidden, so our own app cannot confirm it exists.
  • Owner routes check the session and re-verify that the account and library are active on every call, not just at sign-in.
  • The Google sign-in handshake is protected by a single-use, short-lived state value, which blocks a forged callback from binding an attacker’s mailbox to your account.
  • Data in transit is encrypted with TLS. Public card pages are marked noindex, nofollow.

No system is perfectly secure. If a breach affects your data we will notify you and the relevant authority as the law requires.

10. Your rights

Owners can exercise most of these directly in the app, without asking us: export students and payments as CSV, edit any record, correct any field, clear a student’s email and consent together, and delete a student.

Where you cannot, write to us and we will act within the time the law allows, generally 30 days. Depending on who the data belongs to, a request may come to us from you as the library owner or from the student, and we may need your confirmation before acting.

  • Access — a copy of the personal data we hold about you or your students.
  • Correction and erasure — fix inaccurate data, or delete it where there is no overriding legal reason to keep it.
  • Withdraw consent — switch a student out of automatic reminders.
  • Grievance redressal — a named contact who will acknowledge your complaint and respond to it.
  • Nominate someone — you can ask us to deal with a request through an authorised representative.

We do not charge for a request unless it is manifestly unfounded or excessive. We may verify who you are before we act, to make sure we do not disclose one library’s data to another.

11. Children's data

Librio is a business tool for study libraries, and many of its users are students. We do not knowingly collect data from anyone under 18, and we do not run a service directed at children. A student’s record exists because a library, not Librio, created it, and the library is the data fiduciary for it.

If you believe a child’s information has been entered without a lawful basis, tell us and the library concerned, and we will act on it.

12. Where data is stored

The database and file storage are hosted in India, which keeps personal data of Indian residents within the country as the Digital Personal Data Protection Act, 2023 contemplates. Mail you send is delivered by Google from the mailbox you connected.

A provider who needs to process data outside India does so only where the transfer is lawful, and we keep the data minimised to what that processing needs.

13. Changes to this policy

If we change this policy in a way that affects your rights, we will notify you in writing, by email or in the app, before the change takes effect, and update the date at the top of this page. Continuing to use the service means you accept the revised policy.

14. Contact and complaints

For a privacy question, a data request or a complaint, write to the email address on our home page. Our terms of service explain how to reach us formally, and we aim to respond within 3 working days.

If you are not satisfied with our response, you are free to complain to the Data Protection Board of India, as the Digital Personal Data Protection Act, 2023 provides. We would rather fix the problem first, and we will cooperate with any enquiry.