This Privacy Policy explains how Simplability Private Limited ("we", "us", "our") collects, uses, and protects information when you use TerraOS. TerraOS is an internal field-operations platform for agricultural organizations, provided as two apps:
- the TerraOS mobile application (the "Mobile App"), and
- the TerraOS web application (the "Web App"),
together referred to as the "Services". Access to either app requires an account provisioned by your organization.
By using the Services, you agree to the practices described in this policy. Where a practice applies to only one app, this is called out explicitly; otherwise it applies to both.
1. Who this policy applies to
TerraOS is a business-to-business workforce platform. Accounts are issued by your employer or the organization that engaged us ("your Organization"). The data you enter and generate in the Services belongs to your Organization.
Our role depends on the purpose. For operating the Services for your Organization — the day-to-day functionality covered by most of this policy — your Organization is the data controller for the data you enter and generate, and we act as a data processor on your Organization's instructions. Separately, for developing and improving our own agricultural-intelligence, traceability, and standards-compliance models, we use de-identified and aggregated data and act as an independent data controller for that limited purpose. That second use is described in Section 4b and is subject to the safeguards stated there.
The two apps are intended for different users within your Organization:
- Mobile App — on-ground field staff. Field supervisors and farmers who perform and record agricultural activities in the field (e.g. recording a task with photo and location evidence).
- Web App — office and management users. Administrators, field managers, and cultivation planners/agronomists who plan work, manage master data (farms, plots, crops), assign tasks, oversee activities, and administer user accounts from a desktop browser.
A single person may use both apps if their role requires it.
2. Information we collect
We collect only the information needed to operate the Services and, in de-identified form, to develop the models described in Section 4b. We do not use third-party advertising, analytics, or crash-reporting services, and we do not sell your personal data.
a. Account & authentication data Both apps
- Your login identifier (e.g. email or username) and authentication tokens.
- Your assigned role and organization, used to control which features you can access.
b. Operational content you create Both apps
- Tasks and activity records you view, create, or update.
- On the Web App, the master and planning data you manage — farms, plots, crops, crop plans, cultivations, task assignments, and (for administrators) user accounts.
- Notes, remarks, and other text you enter.
c. Camera and media Both, in context
- Photos and videos you capture as evidence of field work. On the Mobile App these are captured via the device camera; on the Web App they are captured via your browser's camera, or selected from your device.
- For video recordings only, the audio track recorded together with the video. Audio is never recorded in photo-only mode.
d. Precise location Both, in context
- Your device's GPS/location is used in two ways: (1) at the moment you record a field activity, your location is captured and attached to the record — it is sent to our servers together with the photo or video as evidence of where the work occurred; and (2) while you are actively using the app, your location may be used to show you local weather updates and alerts and contextual tasks relevant to where you are.
- Location is accessed only while the app is in active use (in the foreground). The Services do not track your location in the background, and location access stops when the app is no longer in the foreground.
e. Device & connectivity information Mainly Mobile App
- Basic network connectivity state, used to enable offline functionality and synchronize data when a connection is available. Offline operation is a feature of the Mobile App; the Web App operates while connected to the internet.
3. Permissions we request and why
The Services request only the permissions needed to record field activities. How a permission is requested differs by app: the Mobile App requests operating-system permissions, while the Web App requests the equivalent permissions through your web browser (which prompts you per site).
| Permission | Why we request it |
|---|---|
| Camera | To capture photo and video evidence of field activities. |
| Microphone | Only when you choose Video mode, to record the audio track of the video. Not used in photo mode. |
| Precise location (GPS) | To tag the location where a field activity is recorded (sent to our servers with the photo or video), and, while you are actively using the app, to show local weather updates and alerts and contextual tasks relevant to where you are. |
| Network / Internet | To sync your data with our servers and load your tasks. |
You can decline or revoke any permission in your device or browser settings. Please note:
- Camera and precise location are required to record field activities. Because every field activity record must include photo evidence and a location tag to be valid, you will be prompted for these permissions when recording, and recording cannot complete until both are granted. On the Mobile App, if you have permanently declined them, you will be directed to your device settings to enable them; on the Web App, you can re-enable them in your browser's site permission settings.
- Microphone is optional and requested only in context. It is requested only when you choose Video mode while recording an activity. Declining it does not block the Services; photo capture and all other features continue to work.
- Web App browsing requires no special permissions. Viewing and managing data (tasks, farms, plots, crops, users) in the Web App needs only a logged-in session; camera and location are requested solely if and when you record an activity from the browser.
4. How we use your information
We use your information for two distinct purposes, described below: (4a) operating the Services for your Organization, and (4b) developing our own models from de-identified data.
4a. Operating the Services
To operate the Services for your Organization, we use the information described above only to:
- Authenticate you and enforce your role-based access.
- Display, create, and synchronize your tasks, activity records, and (on the Web App) the operational and master data you manage.
- Attach photo, video, and location evidence to field activities.
- While you are actively using the app, use your location to show local weather updates and alerts and contextual tasks relevant to where you are.
- Record which farmer completed which task or activity, using your identity to attribute work so your Organization can see who performed it.
- Provide offline functionality (Mobile App) and reconcile changes when connectivity returns.
- Administer user accounts and access on behalf of your Organization (Web App, administrators only).
4b. Developing our models (de-identified)
Separately from operating the Services, we use field data — primarily the photos and videos captured as activity evidence and the associated location and activity metadata — to develop and improve our own agricultural-intelligence and operational models. Examples include crop and field-condition analysis ("agro-intelligence"), produce traceability and standards-compliance verification, estimating farmer headcount at a site, and workflow verification (confirming that a recorded activity matches the work it represents).
This use is subject to the following safeguards:
- Direct identifiers are excluded from training. We do not use direct identity data — your name, username, account identifiers, or face — as inputs to model development; these are removed or obscured (for example, faces are blurred) before the data is used. Precise location and timestamps are retained, because the geographic and temporal accuracy of where and when field activities occur is essential to agricultural-intelligence and traceability models; this location data is used to analyze fields and sites, not to track a person. Because precise location and time are kept, the model-development data is de-identified but not fully anonymous, and we treat it accordingly (see the safeguards below).
- Not used to identify or evaluate any individual farmer. Headcount features estimate counts, not identities; workflow verification checks the work, not the person. We do not use the model-development data to profile, rank, score, or make decisions about a specific named individual, and we do not attempt to re-identify de-identified data.
- No advertising, no sale, no sharing for others' purposes. This data is used only to build and improve our models; it is never sold or used for advertising.
- Our role. For this development activity we act as an independent controller (see Section 1). For everything involved in operating the Services for your Organization, we remain a processor acting on your Organization's instructions.
If you or your Organization would prefer that your Organization's field data not be used for model development, your Organization can request this — see Section 12.
We do not use your information for advertising, for building profiles of individual farmers, or to sell your personal data.
5. How your information is stored and protected
- In transit: All communication between the Services and our servers is encrypted using HTTPS/TLS.
- On your device — Mobile App: Authentication tokens are stored in the device's encrypted secure storage (Android Keystore-backed). Data cached for offline use is stored in the app's private, sandboxed storage area that other apps cannot access.
- On your device — Web App: Authentication tokens are stored in your browser's local storage for the site so you stay signed in; they are sent only to our servers over HTTPS and are cleared when you sign out. Because browser storage is less isolated than mobile secure storage, sign out when using a shared or public computer.
- On our servers: Data is stored on our managed cloud infrastructure with access restricted to authorized personnel and your Organization.
No method of transmission or storage is completely secure, but we apply industry-standard safeguards appropriate to the sensitivity of the data.
6. Sharing and disclosure
We do not sell your personal data and we do not share it with third parties for their own purposes. We may disclose information only:
- To your Organization, which owns the data you generate in the Services.
- To service providers who host or operate our infrastructure on our behalf, under confidentiality obligations and only to the extent needed to run the service. These include: our cloud hosting provider; a machine-translation service used to translate text fields (such as task titles and descriptions) when you use the Services in a non-English language; map-tile providers that render maps where the Services display them; and a weather-data provider that supplies the local forecasts and alerts shown while you use the app. Each receives only what is needed to perform its function — for example, the text to be translated, the map area being viewed, or the location for which weather is requested — and not your data for their own purposes.
- Where required by law, regulation, or valid legal process.
7. Data retention
We retain your information for as long as your account is active and as needed to provide the service to your Organization, and thereafter as required to comply with our legal obligations or your Organization's instructions. When data is no longer needed, it is deleted or anonymized.
8. Your rights and data deletion
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data.
Because accounts are managed by your Organization, please direct access or correction requests to your Organization's administrator first. You may also contact us directly.
To request deletion of your account and associated personal data, you can use any of the methods below. In every case the request is recorded and forwarded to your Organization's administrator for follow-up; your account is not deleted instantly. We will verify the request with your Organization and process it within 30 days, subject to any legal retention obligations.
- In the Mobile App (recommended for field staff): while signed in, open Settings → Account → Request account deletion and confirm. The app submits the request and identifies your account automatically. This requires an internet connection.
- In the Web App: while signed in, open Settings → Account → Request account deletion and confirm.
- By email: email info@simplability.com with the subject line "Account Deletion Request". Many field users do not have an email address linked to their account — if that applies to you, you do not need one to use the in-app option above. If you email us, include your username so we can identify your account.
Deletion covers your account and the personal data associated with it. Data that has already been de-identified for model development (see Section 4b) can no longer be linked back to you, so it is not retrievable or individually deletable; it is retained only in that de-identified, non-identifying form.
9. Children's privacy
TerraOS is a workforce tool intended for use by adults in a professional capacity. It is not directed at, and we do not knowingly collect information from, anyone under the age of 18.
10. International data transfers
Your information is stored and processed in India. The main exceptions are two third-party services that may operate outside India: the map-tile providers that render maps where the Services display them (which receive your approximate location/IP and the map area being viewed), and the weather-data provider that supplies the local forecasts and alerts shown while you use the app (which receives the location for which weather is requested). Where data is transferred across borders, we take steps to ensure it remains protected in accordance with applicable law, including confidentiality obligations on our service providers.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, notify your Organization. Continued use of the Services after changes take effect constitutes acceptance of the updated policy.
12. Contact us
If you have questions about this Privacy Policy or our data practices, contact:
Simplability Private Limited
49, Krishna Complex, Bedla Road, Udaipur 313011, RJ, India (IN)
Email: info@simplability.com