BlueNautics India Private Limited

Privacy Policy

Mustr - Marine Inspection ApplicationEffective 18 July 2026Version 1.1

BlueNautics India Private Limited ("BlueNautics", "we", "us", or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use the Mustr mobile application ("App") and associated services ("Services").

This Privacy Policy has been prepared in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"). As the DPDP Act's substantive provisions are being phased in through May 2027, we commit to maintaining compliance with both the existing IT Act framework and the incoming DPDP regime.

Layered Format

This Privacy Policy is provided in a layered format. You can navigate to the specific section most relevant to you using the headings below. This policy supplements any specific consent notices presented to you within the App and is not intended to override them.

1. Who We Are

BlueNautics India Private Limited is a company incorporated under the Companies Act, 2013, with its registered office at:

529, Near Shiv Mandir, Khizarpur Ahir, Ganaur City, Ganaur, Sonipat - 131101, Haryana, India

BlueNautics is the Data Fiduciary (as defined under the DPDP Act, 2023) responsible for determining the purposes and means of processing your personal data in connection with the Mustr application.

2. Personal Data We Collect

Personal data means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act, 2023. We collect only the data that is necessary for providing the Services.

2.1 Data You Provide Directly

When you register and use Mustr, you provide us with:

  • Identity data: Full name, professional title, certifications (e.g. SIRE 2.0, CDI, RISQ), profile photograph (optional)
  • Contact data: Email address, phone number (optional, only if you enable SMS-based multi-factor authentication)
  • Account credentials: Password (stored as a one-way Argon2id hash; we never store your plaintext password), and identity-link metadata for enabled Google or Microsoft authentication
  • Professional data: Company or organisation name, years of experience, professional biography (optional)
  • Payment data: Subscription identifiers, transaction status, entitlement periods, and billing events verified through Apple, Google Play, or Razorpay. We do not store your full card number.
  • Inspection content: Vessel inspection records, observations, photographs taken during inspections, worklist entries, forum posts, messages, and any documents you upload to the App (including OCIMF pre-inspection packs)
  • User preferences: Language settings, notification preferences, dark mode preference, and other App configuration choices

2.2 Data We Collect Automatically

When you use the App, we may automatically collect:

  • Device data: Device type, operating system version, unique device identifiers (used for session management and push notifications)
  • Usage data: Features accessed, inspection workflow steps completed, time spent on specific screens (aggregated and anonymised for product improvement)
  • Crash and error data: Technical logs generated when the App experiences errors, to enable us to diagnose and fix issues
  • Sync data: Timestamps and metadata relating to data synchronisation between your device and our servers

2.3 Data We Do Not Collect

We do not collect:

  • Biometric data (Face ID / Touch ID authentication is processed entirely on your device by the operating system; we receive only a pass/fail signal)
  • Location data (we do not request or access GPS coordinates)
  • Contents of your device contacts, calendar, or other apps
  • Personal data of third parties mentioned in your inspection observations (vessel crew names, officer details) except where you explicitly enter them as responsible persons in the worklist

3. How We Use Your Personal Data

We process your personal data only for the purposes for which it was collected and on a lawful basis as set out below. Under the DPDP Act, 2023, we rely on consent and legitimate use as our lawful bases for processing.

3.1 To Provide and Operate the Services

  • Creating and managing your account
  • Processing subscription payments and managing billing
  • Storing and synchronising your inspection data between devices
  • Enabling AI features to respond to your queries and process user-selected attachments (content is processed through Google Gemini; see Section 5)
  • Enabling multi-factor authentication
  • Providing customer support

3.2 To Improve the Services

  • Analysing aggregated and anonymised usage patterns to understand how features are used
  • Diagnosing and resolving technical errors using crash reports
  • Conducting product research and development

3.3 To Communicate With You

  • Sending transactional communications (account verification emails, password reset codes, payment receipts, subscription renewal reminders)
  • Sending service-related notifications (e.g. new features, planned maintenance, policy updates)
  • Responding to your support requests

3.4 To Ensure Security and Prevent Fraud

  • Monitoring for suspicious account activity
  • Verifying your identity
  • Enforcing our Terms of Use
  • Complying with legal obligations

We will not use your personal data for purposes incompatible with those stated above without obtaining your separate consent or unless required by law.

Under the DPDP Act, 2023, we process your personal data on the following bases:

BasisProcessing ActivityExamples
ConsentProcessing personal data for specific purposes you have agreed toMarketing communications; optional profile enrichment; AI assistant conversations
Contract PerformanceProcessing necessary to deliver the Services you have subscribed toAccount creation; inspection data storage; payment processing; customer support
Legitimate Use (DPDP Act)Processing necessary for purposes recognised under the DPDP Act without separate consentFraud prevention; security monitoring; legal compliance; emergency safety communications
Legal ObligationProcessing required by applicable Indian lawResponding to lawful court orders; tax compliance; mandatory data breach reporting

5. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data to third parties. We share your personal data only in the following circumstances and only to the extent necessary:

5.1 Service Providers (Data Processors)

We engage carefully selected third-party service providers who process personal data on our behalf under written agreements that require them to protect your data to the same standard as we do. These include:

ProviderPurposeData Shared
Google GeminiAI assistant, rewriting, transcription, attachment analysis, and AI analyticsThe prompts, observation text, and user-selected attachments required for the AI feature you invoke, together with technical usage metadata.
Apple, Google Play, and RazorpaySubscription purchase and entitlement verificationAccount-linked purchase identifiers, transaction status, billing period, currency, and amount. Card details are handled by the selected provider.
Google (USA)SSO authenticationBasic profile data (name, email) returned by Google OAuth, with your consent
MicrosoftAccount authenticationBasic profile data (name, email) returned by Microsoft authentication, with your consent
Cloud infrastructure providerServer hosting & data storageEncrypted inspection data synced from your device (only when you use online sync)
Email delivery providerTransactional emailsEmail address and message content for verification and support communications

5.2 Legal Requirements

We may disclose your personal data to governmental authorities, law enforcement agencies, or courts when we are required to do so by applicable Indian law, court order, or other legal process. We will, where legally permissible, notify you of such a requirement before disclosing your data.

5.3 Business Transfers

If BlueNautics India Private Limited undergoes a merger, acquisition, restructuring, or sale of all or substantially all of its assets, your personal data may be transferred to the acquiring entity. We will notify you of any such transfer and ensure that the acquiring entity is bound by privacy obligations at least as protective as those in this Policy.

5.4 With Your Consent

We may share your personal data for other purposes not described in this Policy where we have obtained your prior, express, free, specific, informed, unconditional, and unambiguous consent.

6. Cross-Border Data Transfers

As described in Section 5.1, some of our service providers are located outside India, including in the United States. When we transfer your personal data to these providers, we rely on appropriate safeguards including contractual clauses requiring the recipient to maintain privacy standards consistent with Indian law. As the DPDP Act's cross-border data transfer framework is implemented by the Government of India, we will update our transfer mechanisms to comply with any regulations issued thereunder.

The Mustr App maintains an encrypted local working cache to support offline inspections. When connectivity is available, supported records are synchronised to our servers, which hold the authoritative cloud record. AI, billing verification, and other online-only features require a server connection.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are:

Data CategoryRetention Period
Account informationDuration of account + 30 days after deletion request, then permanently deleted
Inspection data (synced)Duration of account + 30 days after account deletion. You may delete individual inspections at any time.
Inspection data (device-only)Stored on your device. Deleted when you uninstall the App or delete specific records. We have no control over device-stored data.
Payment records7 years from the date of transaction (required under Indian tax and accounting law)
Crash and error logs90 days, then automatically deleted
Forum posts and messagesDuration of account. You may delete your posts at any time. Deleted posts are removed from public view immediately.
AI conversations and usage recordsRetained for the duration of your account unless you explicitly delete a conversation, and then removed or anonymised through the applicable deletion workflow. Auditable usage records may be retained where required for security, billing integrity, or law.

8. Your Rights as a Data Principal

Under the DPDP Act, 2023 and applicable Indian law, you have the following rights regarding your personal data. We commit to responding to your requests within 30 days of receipt (or such shorter period as required by law):

8.1 Right to Access

You have the right to request a summary of the personal data we hold about you and how it is being processed. You can access much of this data directly within the App at Settings > Profile.

8.2 Right to Correction

You have the right to request correction of any personal data that is inaccurate or incomplete. You may update most of your personal data directly within the App at Settings > Edit Profile. For data you cannot self-correct, contact us at support@mustr.in.

8.3 Right to Erasure

You have the right to request deletion of your personal data. You may delete your account within the App at Settings > Account > Delete Account. Upon receiving a deletion request, we will erase your personal data in accordance with the retention periods set out in Section 7. We will confirm deletion within 30 days.

8.4 Right to Withdraw Consent

Where we process your data on the basis of your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing conducted before withdrawal. Withdrawal of consent may limit your ability to use certain features of the App. You can manage your consent preferences at Settings > Privacy & Data.

8.5 Right to Grievance Redressal

You have the right to raise a grievance regarding our processing of your personal data. Please contact our Grievance Officer in the first instance (Section 10). If your grievance is not resolved to your satisfaction, you have the right to approach the Data Protection Board of India once it is fully constituted.

8.6 Right to Nominate

Under the DPDP Act, you have the right to nominate another individual to exercise your data rights on your behalf in the event of your incapacity or death. To register a nominee, please contact us at support@mustr.in.

To exercise any of the above rights, please contact us at support@mustr.in with the subject line "Data Rights Request - [your right]". We will verify your identity before processing your request to ensure the security of your data.

9. Security

We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using TLS 1.2 or higher for all communications between the App and our servers
  • Encryption of sensitive data at rest on our servers using AES-256
  • One-way hashing of passwords using Argon2id
  • Multi-factor authentication (MFA) available for all accounts (optional for Basic and Pro, encouraged for all users)
  • Access controls restricting employee access to personal data on a need-to-know basis
  • Regular security assessments of our systems and third-party providers
  • Device-level security: the App prompts you to enable device lock (Face ID / PIN) to protect locally stored inspection data

Your inspection data is stored primarily on your device using a local SQLite database. The security of device-stored data depends on your device security settings. We strongly recommend enabling device-level encryption and access control.

Despite our best efforts, no system is completely secure. In the event of a personal data breach that is likely to result in harm to you, we will notify the Data Protection Board of India and affected users in accordance with our obligations under the DPDP Act and applicable regulations.

10. Grievance Officer

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, BlueNautics India Private Limited has designated a Grievance Officer. You may contact the Grievance Officer with any complaints or concerns relating to the processing of your personal data or the content on the Mustr platform:

  • Grievance Officer - BlueNautics India Private Limited
  • Email: support@mustr.in (Subject: "Grievance - [description]")
  • Address: 529, Near Shiv Mandir, Khizarpur Ahir, Ganaur City, Ganaur, Sonipat - 131101, Haryana, India
  • Response Time: We will acknowledge your grievance within 24 hours and endeavour to resolve it within 30 days.

If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India (once constituted) or seek appropriate judicial relief before competent courts in India.

11. Children's Privacy

The Mustr App is not directed at or intended for use by individuals under 18 years of age. We do not knowingly collect, process, or store personal data of minors. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us immediately at support@mustr.in and we will take prompt steps to delete such data.

12. Cookies and Similar Technologies

The Mustr mobile application does not use browser cookies. The App uses:

  • Local device storage (SQLite) to store inspection data, preferences, and session tokens - this data remains on your device and is not tracking technology
  • Device advertising identifiers (IDFA/GAID) - we do not use these for advertising purposes. These identifiers may be collected by our crash reporting provider to correlate error logs with device types. You may opt out of their use in your device settings.
  • Push notification tokens - used solely to deliver service-related notifications (e.g. sync confirmations, support replies). You may disable push notifications at any time in your device settings.

We do not use cross-site tracking technologies and do not sell data to advertising networks. Mustr is advertising-free.

13. AI and Automated Processing

Mustr includes AI-powered features including a maritime assistant, observation rewriting, transcription, attachment analysis, and AI analytics. Enabled server AI features use Google Gemini. When you use these features:

  • Your text input and any attachment you deliberately select for an AI request are transmitted to the configured Gemini API for processing. Google's applicable service terms and privacy terms govern that provider processing.
  • We separate system instructions from user content, limit the context sent for each feature, and record the prompt version, provider usage, and user-visible input and output for security, support, and credit accounting.
  • AI-generated insights for charts are generated from aggregated statistical data, not from individual identifiable observations.
  • AI features are only available when you have an internet connection. If you are offline, AI features are gracefully disabled. No AI processing occurs offline.
  • We do not use automated decision-making that produces legal or similarly significant effects on you without human involvement. All AI outputs in Mustr are informational and advisory - they support your professional judgment, not replace it.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by displaying a prominent notice within the App at next login and by sending an email to your registered address at least 14 days before the changes take effect. The "Effective Date" at the top of this Policy indicates when it was last revised.

Your continued use of the App after the effective date of an updated Privacy Policy constitutes your acknowledgement of the changes. We will maintain an archive of previous versions of this Policy and make them available on request.

15. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us:

ContactDetails
CompanyBlueNautics India Private Limited
Emailsupport@mustr.in
Address529, Near Shiv Mandir, Khizarpur Ahir, Ganaur City, Ganaur, Sonipat - 131101, Haryana, India
Grievance OfficerContact via support@mustr.in - Subject: "Grievance - [description]"
Data Protection BoardOnce constituted, complaints may be filed with the Data Protection Board of India at www.dataprotectionboard.gov.in

This Privacy Policy is effective as of 18 July 2026.

© 2026 BlueNautics India Private Limited. All rights reserved.

Read the Terms of UseRead the Delete Account