This Privacy Policy explains how DialPay handles information about you. DialPay is a pre-launch, Bharat-focused convenience app that helps you use India's *99# (NUUP/USSD) service so you can send money, scan and pay, and check your balance without internet or mobile data. The *99# service itself is operated by NPCI and your mobile carrier and bank; DialPay is an independent tool that automates only the non-sensitive parts of it, with your consent. DialPay is not authorised, licensed or endorsed by NPCI, the Reserve Bank of India (RBI), any bank or any carrier, and is not a UPI member, PSP, TPAP or payment aggregator. Please read this Policy together with our Terms of Service. By joining our waitlist today, and later by using the app, you confirm that you have read and understood this Policy. If you do not agree, please do not use the website or the app.
1. Who We Are & Scope
"DialPay", "we", "us" and "our" refer to DialPay, an unincorporated, founder-operated, pre-launch venture based in Ahmedabad, Gujarat, India. DialPay is not yet a registered company. Where a natural person must be identified, the responsible person is the founder-operator of DialPay. You can reach us about anything in this Policy at hello@dialpay.in.
This Policy covers two things: (a) our website at https://www.dialpay.in, which today collects only a waitlist email; and (b) the DialPay Android app, which has not yet launched. Because the app is not live, the sections describing the app explain in advance how it is designed to behave. We will update this Policy before the app begins to collect or process any data, so you can review the final terms before you use it.
DialPay is Android only (there is no iOS app) and works only on SIMs that support *99# — currently Airtel, Vi and BSNL. It does not work on Jio, which does not offer the *99# USSD service.
2. Plain-Language Summary
Here is the short, honest version. The detail follows in later sections, and the detail governs.
- You enter your UPI PIN yourself, in your mobile carrier's own *99# screen. You type your PIN directly into the carrier's secure prompt, exactly as if you had dialled *99# by hand. DialPay's assistance service is designed and built to step back while the carrier's PIN screen is shown, so that it does not receive your PIN; there is no PIN field anywhere in the DialPay app and no code path that handles a PIN. We do not, and cannot in our systems, see it because we never receive or transmit it. (See Section 5 for the one residual limit: the safeguard relies on your carrier showing the PIN as a standard secure field, and the service is built to disengage if it is ever unsure.)
- DialPay only fills in the non-sensitive parts. With your explicit in-app consent, it auto-fills the *99# fields you already entered (payee UPI ID/VPA, amount, remark) and confirms the non-credential menu steps, then steps back so you type your PIN in the carrier's secure dialog. Afterwards it reads only the carrier's final result message (success/failure/reference) to show you the outcome.
- The *99# channel is an unencrypted carrier channel DialPay does not control. *99# runs over a plain cellular (USSD) channel operated by your carrier, your bank and NPCI — not by DialPay. Like any cellular channel it carries inherent telecom risks (such as SIM-swap fraud, base-station/IMSI-catcher spoofing and interception) that are outside our control. Always verify the payee before you authorise.
- Your history stays on your phone. Your transaction history is stored only on your device, in a database encrypted at rest. You can delete any entry or clear everything at any time, instantly. No UPI PIN is ever stored.
- Almost nothing leaves your device. The only data the app sends to our servers is two anonymous running totals — a count of transactions and a total value — on a single shared document stored in India. We do not send anything about you, the recipient, any single amount, time, or device. (The network request itself necessarily carries your IP address and may carry a Firebase app-instance identifier; see Section 8.)
- DialPay never touches your money. Funds move directly bank-to-bank over the NPCI/UPI rails. DialPay never holds, pools, routes or settles money.
- DialPay is independent. It is not a UPI member, PSP, TPAP or payment aggregator, does not use NPCI's Common Library, and is not authorised or endorsed by NPCI, RBI, any bank or any carrier. Using it to automate the non-sensitive parts of *99# is your choice.
3. What We Collect Today (Website Waitlist)
Right now, the only thing we collect is what you give us to join the waitlist on our website. When you submit the waitlist form, we collect:
- your email address;
- the date and time you submitted it (a timestamp);
- a fixed source label ("website-waitlist") that simply records where the sign-up came from; and
- your browser's user-agent string (basic technical information your browser sends automatically, such as browser and device type), used for security and to prevent abuse.
We use this only to confirm your sign-up, keep you on the waitlist, and tell you when DialPay launches. We do not collect your name, phone number, UPI ID, bank details or any financial information through the website.
To run the waitlist we use these service providers: Firebase Firestore (Google) stores the waitlist entry; Resend (United States) sends a confirmation email to you and a notification to our internal address; and Cloudflare hosts and secures the website. See Sections 12 and 13 for more on these providers and cross-border transfers.
4. What the Android App Will Access When It Launches
When the app launches, it will use Android's Accessibility permission together with your phone's dialer / USSD screens to assist you with *99#. In plain terms, the app reads the on-screen text of the *99# menus and helps you move through them faster. Specifically, with your explicit in-app consent, the assistance service will:
- auto-fill the non-sensitive fields you already entered in the app — the payee UPI ID/VPA, the amount, and an optional remark — into the carrier's *99# menus, and confirm the non-credential menu steps;
- step back so you type your UPI PIN yourself in the carrier's own secure PIN screen (see Section 5); and
- read only the carrier's final result message — the last *99# screen showing success or failure and a reference number — so the app can show you the outcome and save it to your on-device history.
This access is limited to the dialer/USSD screens involved in a *99# transaction. The app does not read your other apps, messages, contacts or general screen activity for this purpose, and it does not read the PIN-entry screen at all. Everything the app does here happens on your device. See Section 9 for the full technical description of the Accessibility service.
Before you grant this permission — what this means
Because the Accessibility permission is powerful, please understand the following at the point you turn it on:
- DialPay is independent and not authorised by NPCI/RBI. It is not a UPI member, PSP, TPAP or payment aggregator, does not use NPCI's Common Library, and is not authorised, licensed or endorsed by NPCI, RBI, any bank or any carrier. Automating the non-sensitive parts of *99# is your choice.
- Itemised consent notice. By turning on the assistance service you consent to it processing, on your device: the *99# menu text; the non-sensitive details you entered (payee VPA/name, amount, optional note); and the carrier's final result text (success/failure/reference) and a timestamp. Purpose: to auto-fill those non-sensitive fields, confirm non-credential menu steps, and read the carrier's final result so the app can show you the outcome and save it to your on-device history. It does not process your UPI PIN, and it does not read the PIN-entry screen.
- Accessibility is a powerful permission. Any app holding it can, in principle, observe on-screen content. Install DialPay only from the official source, keep your device free of malware, and review what the service does (this Section and Section 9). A malicious app abusing accessibility, or a tampered build of DialPay from an unofficial source, could misuse this kind of permission — which is why source and device hygiene matter.
5. Your UPI PIN — You Enter It in Your Carrier's Own Screen; DialPay Never Handles It
This is the most important promise in this Policy, so we explain exactly how it works, why it is true, and the one residual limit honestly.
When it is time to authorise a payment, you type your UPI PIN yourself, directly into your mobile carrier's own *99# on-screen dialog — the carrier's secure prompt — exactly as if you had dialled *99# manually. DialPay's assistance service is designed and built to disengage on the carrier's secure PIN/credential prompt — the masked credential field the carrier shows for authorisation. Concretely:
- the service does not subscribe to keystroke or text-input events, so it does not receive what you type;
- it is built to disengage on the carrier's secure PIN/credential prompt — that is, a masked credential input shown for authorisation — and it does not auto-fill or read that screen (this is narrower than "any editable field", because the non-sensitive *99# menus it does fill are also editable; it steps back specifically on the credential/PIN prompt); and
- there is no PIN field in the DialPay app and no code path that handles a PIN.
Because of this design, DialPay is designed and built so that it does not receive your PIN. It never sees, captures, reads, stores, logs or transmits it, your PIN never reaches our servers, and there is no code path by which it could. The app never autonomously enters your PIN or completes the authentication for you — only you do that, in the carrier's screen.
The one residual limit, stated honestly
The safeguard above is best-effort screen classification: the service relies on your carrier showing the PIN screen as a standard secure / masked credential field so it can recognise and step back from it. On a carrier or OEM dialer that renders the PIN entry in a non-standard or unlabelled way, on a custom ROM, or where the Android accessibility information is unusual, this classification could in principle be defeated. We therefore do not claim a perfect, unconditional guarantee. Instead, the service is built to fail safe: where it is uncertain whether a screen is a credential prompt, it disengages rather than acting. The strong, unconditional facts remain true regardless: there is no PIN field and no PIN-handling code path in the app, and your PIN is never transmitted and never reaches our servers.
This is a statement about how DialPay is built, not a guarantee about your whole phone. You must still keep your device secure (see Section 15): on a device infected by malware, on a rooted or otherwise compromised device, or if you install a tampered build of the app from an unofficial source, your PIN and other data could be exposed by those other factors, which are outside our control. Always verify the payee before you authorise, because a UPI ID or QR code can be altered or spoofed.
6. We Do Not Handle Your Money
DialPay is non-custodial as to funds. We never hold, pool, route, custody or settle your money. When you make a payment, the funds move directly bank-to-bank over the NPCI/UPI rails operated by NPCI, your bank and the receiving bank. DialPay only helps you complete the non-sensitive steps of the *99# menu; it is never a party to the movement of money and never has access to your funds. We never ask for your bank account number, debit card details or full banking credentials.
7. Your On-Device Transaction History
To help you keep track of what you have done, the app keeps a transaction history only on your device. For each transaction it may store: the payee VPA (UPI ID), the payee name if known, the amount, your optional note, the carrier's result text (success/failure/reference), and a timestamp. No UPI PIN is ever stored, because the app never receives it.
How it is protected
This history is stored in a local database that is encrypted at rest using SQLCipher. The encryption key is protected by your device's hardware-backed keystore. The history does not leave your device as part of normal operation. Please note: this on-device encryption protects your history at rest, but it cannot protect data on a rooted or otherwise compromised device, where the keystore and other protections can be undermined by the compromise itself (see Sections 15 and 20).
Your control
You can delete any single entry or clear your entire history at any time, instantly, from within the app. Where the app offers an export feature, any export you create is generated on your device and goes only where you choose to send it. We keep history only for a limited retention period (see Section 16).
8. Aggregate, Non-Personal Statistics
The only data the app sends from your device to our servers is two anonymous running totals on a single shared document: a count of transactions and a total value. These totals are simply added to, across all users combined.
The counter increments only when the app reads the carrier's final result frame — the last *99# screen reporting a completed or attempted transaction. It is never tied to PIN entry and the app does not observe the authorisation step. The payload we send contains nothing that could identify you or anyone else: not your identity, not the recipient, not any individual amount, not the time of any transaction, and not any device information — only the additions to the two combined totals.
To be fully transparent about the network request itself (as opposed to its payload): like any internet request, it necessarily exposes your IP address to the receiving infrastructure, and our backend (Google Firebase) may attach a Firebase app-instance identifier to the request. An IP address can, in some circumstances, be treated as personal data under the DPDP Act, 2023, even though the payload we store is just an anonymous count and value. We do not use the IP or any such identifier to profile you, and the two totals themselves are stored in India and cannot be traced back to you.
9. The Accessibility Service — What It Reads and Why
This section is the prominent disclosure for DialPay's use of Android's Accessibility permission. Please read it carefully, because the Accessibility permission is powerful and we want you to understand exactly how we use it.
What the service reads
The DialPay assistance service reads the visible text of the dialer / USSD windows shown during a *99# session — that is, the *99# menu text, the non-sensitive details you entered (payee UPI ID/VPA, amount, remark), and the carrier's final result message (success/failure/reference) — and it never reads the carrier's PIN-entry screen, on which it disengages (see Section 5). That is all it reads for this purpose.
What the service does
- It auto-fills the non-sensitive fields you already entered into the *99# menus and confirms the non-credential menu steps. You initiate the *99# session; the service populates the fields you already entered and confirms standard, non-credential menu choices — it does not enter or read credentials.
- It reads only the carrier's final result frame to detect success or failure and to show and save the outcome, and to increment the two anonymous totals (Section 8).
- It is a deterministic, rule-based service: it follows fixed rules for the standard *99# flow. It does not act autonomously beyond filling those non-sensitive fields, confirming non-credential steps, and reading the result.
What the service never does
- It never reads the PIN-entry screen. It disengages on the carrier's secure PIN/credential prompt (a masked credential field) and does not subscribe to keystroke events (see Section 5).
- It never enters your PIN or completes authentication on your behalf.
- It never sends the carrier's screen text to our servers. The result is used only on your device.
How the service is technically scoped
We want to be precise rather than over-reassuring about what "limited to the dialer" means. Android accessibility services receive UI events at the operating-system level and, by their nature, could technically observe other apps. DialPay constrains this by configuration, not by an impossibility: the service is configured to act only on the relevant carrier / dialer / USSD packages (via the accessibility service's package filtering and content-retrieval settings), so that in normal operation it engages only during a *99# session and does not act on your other apps, messages, contacts or general phone activity. This is a configured limit on a powerful permission — which is another reason to install DialPay only from the official source. While the service is enabled it remains registered with Android, but it is built to engage only for the *99# dialer/USSD flow as described, and to disengage on the credential prompt.
You turn this service on yourself, and you can turn it off at any time in Android's Accessibility settings or by withdrawing consent in the app (see Section 11). If the service is off, the app cannot assist you and you would dial *99# manually.
10. Purpose & Lawful Basis
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, we process personal data only for specific, lawful purposes and, where required, on the basis of your consent, which is free, specific, informed, unambiguous and given by a clear affirmative action, and which you can withdraw at any time. At or before the moment of collection, we present an itemised notice of the data and purposes (the in-app Accessibility consent notice is set out in Section 4).
- Waitlist email and related data — purpose: to confirm your sign-up and notify you about the launch. Lawful basis: your consent when you submit the waitlist form.
- The Accessibility assistance and reading the result frame — data: *99# menu text, the non-sensitive details you entered (payee VPA/name, amount, optional note), and the carrier's final result text and timestamp; purpose: to auto-fill the non-sensitive *99# fields, confirm non-credential menu steps, and read only the carrier's final result so the app can show and save your outcome. Lawful basis: your separate, explicit in-app consent, given before the assistance is used. You are asked to consent specifically to this assistance, and you can decline or withdraw it.
- On-device transaction history — purpose: to let you review your own past transactions. This data stays on your device under your control.
- Two anonymous aggregate totals — purpose: to understand overall usage volume. The payload is anonymous; note the network-request disclosure (IP / Firebase instance identifier) in Section 8.
We do not use your data for any purpose that is incompatible with the purpose for which you gave it, and we do not ask for more data than we need.
11. Withdrawing Consent & Unsubscribing
You can withdraw your consent at any time, as easily as you gave it. Withdrawing consent does not affect anything we lawfully did before you withdrew it.
Unsubscribing from waitlist emails
Every email we send offers all three of these options:
- click the one-click unsubscribe link in the email;
- reply "unsubscribe" to the email; or
- email us at hello@dialpay.in and ask to be removed.
When you unsubscribe, we stop sending you waitlist emails and remove or deactivate your waitlist entry.
Withdrawing app consent
In the app you can withdraw consent for the Accessibility assistance and turn the service off (also available in Android's Accessibility settings). You can also delete your on-device history at any time, instantly (Section 7). To exercise any data right or ask a question, contact hello@dialpay.in.
12. Sharing & Service Providers
We do not sell your personal data and we do not share it for anyone else's marketing. We share data only with the service providers (data processors) we need to run the service, and only for the purposes described here, under appropriate terms.
- Firebase Firestore (Google) — stores the website waitlist entry and receives the two anonymous aggregate totals.
- Resend (United States) — sends the confirmation email to you and a notification email to our internal address (dialpay.socials@gmail.com, a Gmail/Google address).
- Cloudflare — hosts and secures the website.
For the app, your transaction history is not shared with anyone — it stays on your device. The only thing the app sends to our own servers is the two anonymous aggregate totals (Section 8). We may also disclose data if the law requires it, such as a valid order from a court or authority.
13. Cross-Border Transfers
Some of our service providers operate outside India. In particular, Resend processes the email-sending in the United States, and Google (Firebase) and Cloudflare may process data on infrastructure located in or outside India. Where your personal data is transferred outside India, we do so in line with applicable Indian law, including the DPDP Act, 2023, and only to the extent needed to provide the service. Our two anonymous aggregate totals are stored in India, and your on-device transaction history is not transferred anywhere by us. As noted in Section 8, the network request that carries the two totals necessarily exposes your IP address to the receiving infrastructure and may carry a Firebase app-instance identifier.
14. Cookies & On-Device Storage
Our website uses only what is necessary to operate securely and to take your waitlist sign-up; we use Cloudflare for hosting and security. We do not use cookies to build advertising profiles of you. In the app, "storage" means the local, encrypted on-device database that holds your transaction history (Section 7) and your app settings; this stays on your device and is not a tracking cookie.
15. Security
We take reasonable security measures appropriate to the data we handle, and we have designed the app to minimise what it ever holds.
What we do
- The app stores your transaction history encrypted at rest with SQLCipher, with the key protected by your device's hardware-backed keystore. This protects history at rest but cannot protect a rooted or compromised device.
- The app is built so it does not receive your UPI PIN and has no code path that handles one; the PIN is never transmitted and never reaches our servers (Section 5).
- Only two anonymous totals ever leave your device; no personal or transaction-level data is sent to us (see Section 8 for the network-request disclosure).
- The website is served and protected through Cloudflare, and waitlist data is held with Google (Firestore).
What is outside our control
- The *99# channel itself is an unencrypted cellular (USSD) channel operated by your carrier, your bank and NPCI — not by DialPay. We do not claim it is encrypted. Like any cellular channel, it can be exposed to risks such as SIM-swap fraud, base-station/IMSI-catcher spoofing, interception, and network outages.
- The PIN-screen safeguard is best-effort screen classification and depends on your carrier rendering the PIN screen as a standard secure/credential field; a non-standard carrier dialer or custom ROM could in principle defeat it. The service is built to fail safe and disengage when uncertain (Section 5).
- Your device security is your responsibility. Malware, a rooted or otherwise compromised device, an insecure clipboard, or a tampered build of the app installed from an unofficial source can expose data regardless of how we build the app. Accessibility is a powerful permission; install only from the official source and review the service's behaviour (Sections 4 and 9).
- Always verify the payee before authorising. A UPI ID or QR code can be altered, spoofed or malicious; only you can confirm you are paying the right person.
No method of transmission or storage is perfectly secure. If something does go wrong, see Section 20.
16. Retention & Deletion
- Waitlist data is kept until you unsubscribe or until it is no longer needed for the waitlist, after which we delete or anonymise it. You can ask us to delete it sooner at hello@dialpay.in.
- On-device transaction history is kept only for a limited retention period, after which it is removed, and you can delete any entry or clear all history yourself at any time, instantly (Section 7). Because this data lives on your device, you control it directly.
- The two anonymous aggregate totals are retained as ongoing usage figures; the stored payload is anonymous and cannot be traced back to you (see Section 8 on the network request).
17. Your Rights as a Data Principal
Under the DPDP Act, 2023, in relation to the personal data we hold about you, you have the right to:
- access a summary of the personal data we process about you and how we process it;
- correct, complete or update inaccurate or incomplete data;
- erase your personal data where it is no longer needed for the purpose it was collected;
- grievance redressal — raise a complaint with us about how we handle your data (Section 19); and
- nominate another person to exercise your rights in the event of your death or incapacity.
How you exercise erasure
You can exercise your right of erasure in two ways:
- On-device history — self-service and immediate. Deleting an entry or clearing all history from within the app is itself a direct exercise of your erasure right. It happens instantly, on your device, under your sole control, without contacting us and without any waiting period (Section 7).
- Server-side waitlist data — by request. For the personal data we hold on our servers (your waitlist email and related data), you can exercise erasure by writing to hello@dialpay.in, and we will delete or anonymise it within the timelines required by law.
To exercise any other right above, contact hello@dialpay.in. We may need to verify your identity before acting on a request, and we will respond within the timelines required by law.
18. Children & 18+
DialPay is intended only for individuals aged 18 years or older. It is not directed at children. We do not knowingly collect personal data of children. If you believe a child has provided us personal data, contact hello@dialpay.in and we will take appropriate steps to delete it.
19. Grievance, Data Protection Function & the Data Protection Board
If you have a complaint or question about how DialPay handles your personal data, please contact us first so we can resolve it. The grievance function is handled by the founder-operator of DialPay, reachable at hello@dialpay.in. We will acknowledge and address your grievance within the timelines required under the DPDP Act, 2023 and the DPDP Rules.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India, as provided under the DPDP Act, 2023.
20. Data Breaches & Device Compromise
If a personal data breach affecting data we hold occurs, we will handle it in accordance with the DPDP Act, 2023 and the DPDP Rules, including notifying the Data Protection Board of India and affected individuals as and where required, and taking reasonable steps to contain and remedy it.
Please remember that much of what the app touches stays on your device. If your device is lost, stolen, or compromised (for example by malware or rooting), the data on it — including your local history — could be at risk from that compromise, which is outside our control; on a rooted device, on-device encryption and the hardware-backed keystore can be undermined by the compromise itself. We recommend you keep your device locked and secure, install the app only from the official source, and clear your history from a device you no longer control where possible.
21. We Do Not Sell or Profile
We do not sell your personal data. We do not use your data to build advertising or behavioural profiles of you, and we do not make automated decisions about you that produce legal or similarly significant effects. The only data we receive from the app is the two anonymous aggregate totals, whose stored payload cannot identify or profile anyone; we do not use the IP address or any app-instance identifier exposed by the network request (Section 8) to profile you.
22. Independence, Regulatory Status & Trademarks
We want to be completely honest about what DialPay is and is not.
- DialPay is an independent tool. It is not a UPI member, Payment Service Provider (PSP), Third-Party Application Provider (TPAP), or payment aggregator.
- DialPay is not authorised, licensed, endorsed or sponsored by NPCI, the Reserve Bank of India (RBI), any bank or any mobile carrier.
- DialPay does not use NPCI's Common Library, and it does not capture UPI credentials — your UPI PIN is entered in your carrier's own *99# dialog and is never handled by DialPay (Section 5).
- What DialPay does is automate the non-sensitive parts of the *99# service, which is your choice. Because DialPay touches no funds and never handles your PIN, it does not require fund-handling authorisation under the Payment and Settlement Systems Act, 2007, but it is still an independent, unaffiliated tool, not an official UPI app.
Trademarks
"UPI", "BHIM", "*99#" and "NUUP" are trademarks of NPCI. "Airtel", "Vi" and "BSNL" are trademarks of their respective owners. These names are used only nominatively, to describe the services DialPay works with. Their use does not imply any affiliation, partnership, endorsement or sponsorship. DialPay is independent of NPCI, RBI, all banks and all carriers.
23. Compatibility & Limits
Some practical limits, set by NPCI and your carrier — not by DialPay — apply when you use *99#:
- DialPay is Android only and works only on Airtel, Vi and BSNL SIMs that support *99#. It does not work on Jio, which does not offer *99# USSD.
- The *99# service typically has a per-transaction cap of about Rs.5,000.
- Your carrier may charge a small *99# session fee of about Rs.0.50 per session.
- *99# depends on your cellular network; it may be affected by network availability and outages.
24. Changes
We may update this Policy from time to time, for example as the app moves from pre-launch to live, or as the law changes. Before the app starts to collect or process any data, we will update this Policy to describe the final behaviour. We will post the current version at https://www.dialpay.in and update the effective date. Where required, we will seek fresh consent. Please review this Policy from time to time.
25. Governing Law & Jurisdiction
This Policy and any dispute relating to it or to your use of DialPay are governed by the laws of India. The courts at Ahmedabad, Gujarat shall have exclusive jurisdiction, subject to any rights you have under the DPDP Act, 2023 to approach the Data Protection Board of India.
26. Contact
For any question, request or grievance about this Policy or your personal data, contact the founder-operator of DialPay at hello@dialpay.in. We are based in Ahmedabad, Gujarat, India.