This Privacy Policy explains what information the Jewel Pic mobile app collects, why it collects it, who it is shared with, and the choices you have. It applies to the Jewel Pic app for Android and iOS (package com.asterix.kumuduimage) and to the cloud services that support it.
Jewel Pic is business software licensed to jewellery retailers. It is used by the staff of a licensed shop, on devices managed by that shop, to photograph stock, look up tag details, print or share reports, and place exhibition orders. It is not a consumer social or shopping app, and it contains no advertising.
1. Who we are
Jewel Pic is developed and published by Kumudu Software Solution ("we", "us", "our"). We are the developer named on the Google Play and Apple App Store listings for this app.
You can reach us at any time about privacy at the email address in the Contact section at the end of this policy.
2. Scope, and who controls which data
Jewel Pic sits between two different systems, and it matters which one your data is in:
- Your shop's own server. Each licensed shop runs its own copy of the stock/billing server, on the shop's own computer and network. Stock items, tag numbers, rates, bills, quotations and staff logins live there. That data belongs to the shop: the shop is the data controller and we only provide the software that reads and writes it on the shop's instruction. We do not host it and we do not receive a copy of it.
- Our cloud services. Licence validation, device registration, jewellery image storage and AI image editing run on our cloud services. For that limited set of information we are the data controller.
If you are a member of shop staff and you want to know what your employer holds about you, ask the shop. If you want to know what we hold, write to us.
3. Information the app collects
| Information | Why | Where it goes |
|---|---|---|
| Device identifier — a device ID/UUID provided by the operating system (on iOS, a value we generate once and keep in the device keychain), plus platform name and OS version | To check that this device is covered by a valid licence, to bind the licence to authorised devices, and to meter AI image credits | Our licence and AI service (our cloud). Sent each time the app starts. |
| Device registration details — a device name or staff name typed by the user, sent together with the device identifier | Only when a device is not yet licensed, so our support team can approve it for your shop | Our registration service (our cloud), and our support inbox |
| Photos and images — jewellery photographs taken with the camera or chosen from the device gallery or files, together with cropped, edited and AI-generated versions, and PDF or Excel files the app generates | To attach images to stock items, so any device in the shop can see them; to produce reports the user asks for | Our cloud image storage; the device's own storage; and, if AI editing is used, our AI service and its AI provider (see section 7) |
| Tag and barcode scans — the tag, barcode or RFID number scanned or typed | To look up the stock item that number belongs to | The shop's own server only |
| Stock and business records — item, design, metal, weight, rate, sold status, quotations, exhibition orders | The core function of the app | The shop's own server, plus a local cache on the device |
| Staff credentials — a username and password typed to unlock admin-only screens | To verify the user is authorised, using the shop's own accounts | The shop's own server only. These are never sent to our cloud and we never store them. |
| Local network information — whether the device is on Wi-Fi or mobile data, whether that connection has internet, and the device's local IP range | To find the shop's server on the same Wi-Fi automatically, and to tell the user why a connection failed | Stays on the device. Local addresses are not uploaded to us. |
| App settings and local cache — your app preferences, the last server address used, cached stock, images and exhibition data | So the app remembers your setup and works when the network is slow | Stored only on the device (app storage, local database, and the keychain for the iOS device identifier) |
| Technical error messages | To diagnose faults when you contact support | Written to the device log. The app includes no crash-reporting or analytics SDK, so these are not collected automatically. |
The app has no sign-up form and no consumer accounts. Access is granted by the shop and by us at the shop's request.
4. What we do not collect
To be explicit, Jewel Pic does not collect, use or transmit:
- Advertising identifiers. There is no advertising in this app and no ad network SDK.
- Third-party analytics, attribution or tracking SDKs. We do not track you across other apps or websites.
- Your geographic location. The app has no location-based features and never reads, stores or transmits where you are.
- Contacts, SMS or call logs, calendar entries, health data, or microphone audio.
- Financial account or card details. The app takes no payments from users.
- Biometric data.
We do not sell personal information, and we do not share it for advertising or cross-context behavioural profiling.
5. Device permissions we request
| Permission | Why the app asks | If you decline |
|---|---|---|
| Camera | To photograph jewellery and to scan barcode or QR tags | You can still choose photos already on the device; scanning and new photos will not work |
| Photos, media and files (read; write only on Android 10 and older) | To pick existing images to upload, and to save generated PDF, Excel and edited image files so they can be shared | Uploading existing photos and saving report files will not work |
| Internet and network state | To reach the shop's server and our cloud services, and to tell whether you are on Wi-Fi, mobile data, or a Wi-Fi network with no internet, so the app can explain a failed connection | Granted at install on Android; the app cannot function without network access |
| Nearby devices (Android 12 and newer) | To find and connect to a Bluetooth thermal printer so bills and labels can be printed. The app looks only for printers, and uses this permission for nothing else. | Bluetooth printing will not work. Everything else in the app is unaffected. |
| Bluetooth (Android 11 and older) | The same purpose on older Android versions, which name this permission "Bluetooth" instead of "Nearby devices" — pairing with and printing to a Bluetooth thermal printer | Bluetooth printing will not work. Everything else in the app is unaffected. |
| Local Network (iOS) | To find the shop's server on the same Wi-Fi network | The app cannot discover the shop server automatically |
You can review or withdraw any of these permissions at any time in your device settings, without uninstalling the app.
6. How we use information
We use the information described above only for these purposes:
- App functionality — showing stock, attaching and displaying images, generating reports, printing and sharing.
- Licence validation and fraud prevention — confirming that a device belongs to a paying, licensed shop, and detecting unlicensed use.
- AI image editing and credit metering — producing the edited image the user asked for and recording the credits it used.
- Support and troubleshooting — diagnosing a fault a user has reported to us.
- Legal and accounting obligations — keeping the records the law requires us to keep.
We do not use your information for advertising, for profiling, or for any automated decision that has a legal effect on you.
7. Photos, cloud image storage and AI image editing
Image storage
Jewellery photographs uploaded from the app are stored in our cloud object storage, hosted on Microsoft Azure in the Central India region, under the licensed shop's own area. They are stored so that every authorised device in that shop can see the same image for the same stock item. Images are business photographs of merchandise; they are not intended to contain personal information, and users should not upload photographs of people, identity documents or other personal records.
AI image editing
If your shop uses the optional AI image features, the photograph you select and the instruction or template you choose are sent to our AI service, which forwards them to a third-party generative-AI provider (currently Google's generative image API) solely to produce the edited or generated image and return it to your device.
- The provider acts on our instruction as a processor. Under the paid API terms we use, content submitted through the API is not used to train the provider's models.
- We retain the submitted image and the generated result only as long as needed to deliver the result and, where the shop has asked for it, to store the finished image against the stock item.
- The credit record we keep for billing contains the device identifier, the shop identifier, the quality tier used, a timestamp and the credits consumed. It does not contain the image or the instruction text.
AI features are optional. A shop that does not enable them never sends any image to the AI service.
8. Where your data is stored
- On your device — settings, cached stock and images, the local database, and the keychain entry holding the iOS device identifier. Removed when the app is uninstalled.
- On your shop's own server — stock, tags, bills, quotations and staff accounts, on hardware the shop controls, on the shop's own premises or network.
- In our cloud services on Microsoft Azure — image storage in Central India; the licence, registration, credits and AI service in the Southeast Asia (Singapore) region.
9. How long we keep information
- Uploaded images — kept while the shop wants them. Deleting an image from the app's image manager deletes it from our cloud storage. All of a shop's images are deleted on written request from the shop, and after the licence ends.
- Licence, device registration and credit records — kept while the licence is active, and afterwards only for as long as we need them for accounting, tax, audit or legal purposes.
- Data on the device — kept until you clear the app's data, use the app's reset option, or uninstall the app.
- Support correspondence — kept for as long as needed to resolve the issue and to show how it was resolved.
11. How we protect information
- Traffic between the app and our cloud services is encrypted in transit using HTTPS/TLS.
- Licences are bound to a device identifier, so a copy of the app on an unregistered device cannot reach a shop's data through us.
- On iOS the device identifier is held in the system keychain.
- Access to our cloud services is limited to authorised personnel who need it to run the service.
One limitation is worth stating plainly: the connection between the app and your shop's own server runs over your shop's own local network, and depending on how that server is set up it may not be encrypted. That traffic does not leave your premises, and securing the shop network and server is the shop's responsibility. We are happy to advise on it.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we do work to protect information against unauthorised access, loss and misuse, and we will notify affected shops and, where required, the relevant authority if a breach affecting personal data occurs.
12. Your rights and choices
Depending on where you live, you may have the right to ask us to:
- confirm what personal information we hold about you, and give you a copy;
- correct information that is inaccurate or incomplete;
- delete information we no longer need;
- restrict or object to a particular use;
- withdraw a consent you previously gave, without affecting anything done before you withdrew it;
- complain to a data protection authority.
To exercise any of these, email us using the address in the Contact section, from or copying the shop's registered contact so we can verify the request. We will respond within 30 days. We may need to keep certain records where the law requires it, and we will tell you if that is the case.
If your request concerns data held on your shop's own server, ask the shop — it controls that data. We will help the shop act on your request.
Users in India have these rights under the Digital Personal Data Protection Act, 2023, and may raise a grievance with our contact below. Users in the EEA or UK may exercise their rights under the GDPR; our legal bases are performance of a contract (providing the licensed app), our legitimate interests (licence validation and preventing unlicensed use), consent (device permissions such as camera and photos), and legal obligation.
13. Deleting your data or de-registering a device
There is no self-service sign-up in Jewel Pic; devices are registered by us at a licensed shop's request. To have data removed:
- Data on the device — uninstall the app, or clear the app's storage in your device settings. Both remove all locally cached stock, images and settings.
- A registered device — email us with the shop name and the device name, and we will de-register the device and delete its device registration and credit records.
- Stored images — email us with the shop name and either the specific stock items or a request for all of them, and we will delete the images from our cloud storage. Images can also be deleted from within the app by an authorised user.
- Everything we hold for a shop — the shop owner or an authorised representative can ask us in writing to delete the shop's licence, device and image records. We verify the request with the shop owner and complete it within 30 days, keeping only what accounting or tax law requires us to keep.
Data held on your shop's own server is deleted by the shop, not by us.
14. Children
Jewel Pic is business software for the employees and authorised representatives of licensed businesses. It is not directed to children, it is not designed to appeal to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it. If you believe a child has used the app, contact us.
15. International transfers
Our cloud services are hosted in India and Singapore, and our AI provider may process a submitted image in another country. Where information is transferred out of the country it was collected in, we rely on the contractual protections in our agreements with those providers, and we transfer only what the service needs.
16. Third-party services
These are the third parties involved in running Jewel Pic. Their own privacy policies apply to what they do:
We do not embed advertising, analytics or social media SDKs from any third party.
17. Changes to this policy
We may update this policy as the app changes or the law requires. The current version always carries a "Last updated" date at the top, and is available inside the app and at the policy address published on our store listings. If a change materially affects how we handle personal information, we will give notice in the app or to the shop's registered contact before it takes effect. Continuing to use the app after a change takes effect means you accept the updated policy.
18. Contact and grievances
For any question, request or complaint about privacy — including data access, correction and deletion requests, and grievances under the Digital Personal Data Protection Act, 2023 — contact:
We aim to acknowledge privacy enquiries within 7 days and to resolve them within 30 days.