1. Scope and responsibility
This policy covers the Optifocus Android application, optifocus.in, and the related Optifocus API. Optical stores use the service to manage operator access, customer consent, assisted optical measurements, and reports.
For store and operator account information, Optifocus generally determines why and how data is processed. For customer information entered by an optical store, the store may also be responsible for giving notice, obtaining valid consent, and responding to the customer.
2. Data we handle
Store operators
- Phone number and Firebase account identifier.
- Name, email address, store or firm name, GST number, role, city, state, PIN code, and country.
- Subscription, payment-reference, and store-membership records where applicable.
Customers and measurement sessions
- Customer name, optional phone number, store, operator, and session identifiers.
- Consent version, purpose, acceptance time, and related audit events.
- Camera image submitted for analysis, capture metadata, capture-validation outcomes, proposed and confirmed measurements, corrections, warnings, and generated reports.
Technical and support information
- Device and app details, request identifiers, IP address, authentication and security events, diagnostic information, and communications sent to us.
- The public website does not currently use advertising trackers or analytics cookies. Firebase Hosting and network providers may process ordinary request and security logs.
3. How we use data
We use personal data to authenticate operators, create and protect store accounts, record consent, perform assisted measurement analysis, support professional review, generate reports, provide support, prevent abuse, maintain security, improve reliability, comply with law, and enforce our terms.
Where consent is the basis for customer image and measurement processing, the operator must present the applicable notice and record consent before capture. Withdrawing consent does not invalidate processing already completed lawfully, but it may prevent a new measurement or report.
Google and Firebase authentication data
Optifocus uses Google Firebase Authentication to verify an operator's phone number and establish an authenticated app session. Authorized dashboard administrators sign in with Google; Google sign-in alone does not grant dashboard access. We handle the verified phone number or administrator Google account identifier, Firebase account identifier, and related authentication and security events. We do not request access to Gmail, Google Drive, Calendar, Contacts, or other Google Account content. Authentication data is not sold or used for advertising.
4. Facial images and optical measurements
Optifocus stores all capture attempts, including rejected images, in private encrypted storage until the scan session is deleted. Authorized Optifocus administrators can review scans across stores. They may request a one-time advisory image assessment using AWS Bedrock Claude Sonnet 5 for the selected accepted capture. The AI assessment does not alter the saved measurement.
We also retain derived measurement values, capture-validation metadata, operator revisions, consent evidence, audit records, and reports as described below. Optifocus does not use customer images for advertising or sell them.
6. Retention and deletion
Capture images remain until their scan session is deleted; no automatic image expiry is configured. Deleting a session removes its capture images, readings, reports and AI assessment, leaving a minimal deletion audit event. Production report files may otherwise expire after the configured retention period, ordinarily up to 365 days. Account, consent, payment, security, and unrelated audit records may be kept as needed to provide the service or meet legal obligations.
Deletion may be delayed or limited where a record must be preserved for legal, fraud-prevention, safety, accounting, or dispute-resolution purposes. Backup copies may remain until the applicable backup cycle completes.
7. Access, correction, withdrawal, and complaints
Subject to applicable law, you may ask to access, correct, update, or delete personal data, withdraw consent, or raise a grievance. Customers may contact the optical store that collected their information or contact Optifocus directly. We may need to verify your identity and store or session relationship before acting.
For account deletion or a privacy request, email hello@optifocus.in with “Privacy request” in the subject. Do not send facial images, identity documents, OTPs, passwords, or authentication tokens by email unless we specifically provide a secure method.
8. Security, children, and changes
We use measures such as encrypted transport, authenticated access, store-scoped authorization, private storage, restricted service permissions, and audit records. No service can guarantee absolute security; report suspected misuse promptly.
Optifocus is intended for professional optical-store use. A person under 18 should be measured only with authorization from a parent or lawful guardian and in accordance with applicable law.
We may update this policy as the service or law changes. Material updates will be posted here with a new effective date and, where appropriate, communicated through the service.
9. Contact and grievance channel
Optifocus Pvt. Ltd.
Email: hello@optifocus.in
Please include enough information to identify the relevant account, store, or session without emailing sensitive images or credentials.