Privacy Policy

Last updated: August 3, 2026

1. About Us and This Policy

JB Companion is a mobile app that lets you set up, monitor, and control your JB air purifiers. You can control one purifier or several together.

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. We have written it in plain language on purpose.

Who we are: Joyful Being Home Appliances Pvt. Ltd., Ground floor, 1, RK Puram, 1st Street, West Mambalam, Chennai 600033, India.

We are the Data Fiduciary for your personal data under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). You are the Data Principal. In plain terms: we decide what data is collected and why, and you have rights over that data.

What this policy covers: JB Companion, the JB mobile app for Android and iOS, and the services behind it.

What it does not cover: WhatsApp, your mobile network operator, the Apple App Store, Google Play, or any other service you use alongside the app. Those have their own privacy policies.

We ask for your consent separately, and in plain language, before we collect the data described in this policy, for example, when you create your account, and again if you turn on a feature that needs additional data such as location. You can change your mind at any time; see Section 12.

2. What We Collect: At a Glance

What

Examples

Where it comes from

Account

Phone number, Firebase user ID

You, at sign-up

Profile

Name, email address, profile picture

You, if you fill it in

Your purifier

Model, device ID, firmware version, status, filter life, operating mode, sensor readings, error logs

Your purifier

Your settings

Schedules, routines, and device and room names

You

Location

Approximate and precise location

Your phone, with your permission

Network

Wi-Fi network names, Bluetooth scan results, local network device discovery, your Wi-Fi password during setup

Your phone

Camera

QR codes you scan during setup

You

App usage

Events like login, device commands, routine actions, screen views

Automatically

Diagnostics

Crash reports, error logs

Automatically

Notifications

Push notification token

Automatically

Support

What you tell us when you contact us

You

We do not sell your personal data. We do not use your location to trаck your movements. We do not show you advertising.

3. What We Collect, In Detail

3.1 Account and profile

Required to create an account:

  • Mobile phone number: you enter this to receive a one-time code (OTP) by SMS.
  • The OTP: you enter it to verify the number. We use it once, to sign you in. We never log the OTP, and we never send it to our analytics or crash reporting tools. If a sign-in attempt fails, only the type of error (for example, "invalid verification code") is recorded for troubleshooting, never the code itself, and never the verification ID behind it.
  • A Firebase user ID: a unique ID that identifies your account across our systems.

Your phone number and Firebase user ID are held by Google Firebase Authentication.

Optional, if you choose to add them:

  • Your name
  • Your email address
  • A profile picture

Name and email are stored on our own backend. Your profile picture is stored in Amazon S3. Adding your name, email and profile picture are optional. The app works even if you choose not to add these details. All information from you that are mandatory at the time of sign-up are marked with the tag "required" to indicate their mandatory nature.

SMS is delivered by Google Firebase and your mobile operator. Your operator's standard message rates apply.

3.2 Your purifier

Once a purifier is paired to your account, we collect:

  • Air purifier model, device identifier, firmware version
  • Device status: on or off, connected or offline
  • Filter life
  • Operating mode: for example auto, sleep, turbo
  • Sensor readings, such as indoor particulate levels
  • Error logs and fault codes
  • Any schedules, routines, or automations you create
  • Device and room name

We use this to make the app work, to send you alerts like filter reminders, to help you when something goes wrong, and to improve our products.

3.3 Location

We ask for location permission for two reasons:

1. To find Wi-Fi networks during setup. Android and iOS both require location permission before an app can scan for nearby Wi-Fi networks. We use it only to help you pick the right network for your purifier.

2. To complete pairing. Pairing a purifier through Tuya needs a temporary grant of precise location, so your phone and the purifier can be matched to the same network and place while they connect. This is needed during setup only. Once your purifier is paired, you can reduce this back to approximate location.

3. To show you outdoor air quality for your area. We send your approximate location, or a city you search for, to a weather service to get the local Air Quality Index.

Platform

Permission

Used for

Android

Approximate location (Coarse)

Outdoor AQI

Android

Precise location (Fine)

Wi-Fi scanning and device pairing

iOS

While Using the App

Outdoor AQI, Wi-Fi scanning, device pairing

 

We only need location while you are using the app. We do not use location in the background. We do not build a location history, and we do not use location for advertising.

Your phone may also offer you an "Always Allow" option. The app does not need it and does not use location in the background. "While Using the App" is enough for everything above.

If you turn location off, outdoor AQI will not work and you may have to type in your Wi-Fi details by hand.

3.4 Network and connectivity

To connect your purifier, the app uses:

  • Wi-Fi information: network names and scan results, so you can pick the right network. On Android the app also uses standard Wi-Fi state permissions to scan and switch networks during setup. These do not produce a separate permission prompt.
  • Your Wi-Fi password: you enter it once during setup so the purifier can join your network. It is passed through the secure device provisioning process run by Tuya, our IoT platform. We do not store your Wi-Fi password, and we do not share it beyond what setup requires.
  • Bluetooth: to find and pair nearby purifiers. On Android this uses Bluetooth Scan and Bluetooth Connect. On iOS the app uses Bluetooth through the standard system permission. On Android 13 and above, the app also uses the Nearby Wi-Fi Devices permission for the same purpose. We use Bluetooth scan results only to find your purifier, not to work out where you are, and not to identify anyone else's devices.
  • Local network (iOS): the app finds JB and Tuya devices on your home network using Bonjour, and talks to them directly. This is what lets the app work as a remote control on your own network. This discovery stays on your network.

Pairing and device control are handled by the Tuya ThingSmart SDK, which is built into the app. See Section 7.1.

3.5 Camera and photos

  • Camera: used only to scan QR codes during setup. Decoding happens on your phone. No photos or video from the scanner are stored or uploaded.
  • Photo library (iOS): used only when you pick a profile picture. We access only the image you choose, and we upload only that image. We do not browse or index your photo library.

3.6 Files on your phone (Android)

On Android, the app uses storage permissions to save files into an app-specific Resources folder on your phone. What we keep there is your product user manual and warranty PDF, so you can open them from the app, along with the app's own resource files.

Depending on your Android version this uses Read/Write External Storage, or Manage External Storage on Android 11 (API 30) and above. We do not read, scan, or upload any other file on your phone.

3.7 How you use the app

We use Google Firebase Analytics to understand how the app is used so we can improve it. It records:

  • Events: sign-in, sign-out, device commands, routine actions, screen views
  • A user ID, set when you log in and cleared when you log out
  • Whether the app is a development, test, or production build
  • Standard details like app version, device model, operating system version and session timing

We also use Firebase Core, which creates an app installation ID that the other Firebase services rely on.

3.8 Crashes and errors

We use Google Firebase Crashlytics to find and fix problems. When the app crashes, it records the error and stack trace, the app version, your device model and OS version, and your user ID so we can link the crash to the affected account.

3.9 Notifications

We use Firebase Cloud Messaging to send push notifications. It registers a push token for your installation. We use it to send device status alerts, AQI updates and filter replacement reminders. The app also creates some notifications directly on your phone. The full list of notifications from the app is as follows:

  • Routine reminder notifications
  • Routine commencement notifications
  • Routine completion notifications
  • Device onboarding success notifications
  • AQI alert notifications

We may update this list from time to time as we evolve the features of the app. Please check back on the Privacy Policy from time to time to apprise yourself of any additional or amended notifications.

You can turn notifications off in your phone settings at any time. The rest of the app will keep working, but you will stop getting device alerts.

3.10 Support

If you contact us, we collect whatever you tell us, namely your account details and a description of the problem.

The app has a support button that opens a chat with us in WhatsApp. Tapping it hands you over to the WhatsApp app. JB Companion does not collect or send the contents of that conversation. Once you are in WhatsApp, WhatsApp's own terms and privacy policy apply.

3.11 What we do not collect

  • We use no analytics or crash tools other than Google Firebase. There is no Mixpanel, Amplitude, Sentry, AppsFlyer or anything similar in this app.
  • We do not collect your contacts, calendar, call logs, SMS contents, microphone audio, or health data.
  • We do not collect payment card details in the app.
  • We do not sell your data, and we do not share it with advertisers or data brokers.

4. App Permissions

Permission

Platform

Why we ask

If you say no

Precise location (Fine)

Android

Wi-Fi scanning, device pairing

Setup may fail; enter Wi-Fi details manually

Approximate location (Coarse)

Android

Outdoor AQI

AQI will not show

Location: While Using the App

iOS

AQI, Wi-Fi scanning, pairing

Setup and AQI may not work

Bluetooth Scan and Bluetooth Connect

Android

Find and pair purifiers

Bluetooth pairing unavailable

Bluetooth

iOS

Find and pair purifiers

Bluetooth pairing unavailable

Nearby Wi-Fi Devices

Android 13+

Find purifiers, alongside Bluetooth

Device discovery may fail

Wi-Fi state / change network state

Android

Scan and switch networks during setup. Standard permission: no prompt is shown.

Local network (Bonjour)

iOS

Find and control your JB and Tuya devices on your home network

Local control unavailable; app uses cloud instead

Camera

Both

Scan setup QR codes

Pair without QR scanning

Photo library

iOS

Choose a profile picture

No profile picture

Read/Write External Storage

Older Android

Save user manual and warranty PDF

Those documents may not open

Manage External Storage

Android 11+

Save user manual and warranty PDF

Those documents may not open

Notifications

Both

Device alerts, AQI updates, filter reminders

No alerts

You can change any of these in your phone settings at any time.

We do not request or use background location on iOS or Android. If your phone offers you an "Always Allow" location option, the app does not need it.

5. Why We Use Your Data

Purpose

What we use

Our basis

Create your account and sign you in

Phone number, OTP, Firebase user ID

Consent

Set up and pair your purifier

Location, Bluetooth, Wi-Fi details, camera

Consent

Let you monitor and control your purifier

Device data, account ID, local network

Consent

Sync your settings across your phones

Device settings, schedules, routines

Consent

Run your schedules and routines

Device data, schedule settings

Consent

Show outdoor air quality

Approximate location or city name

Consent

Send device alerts and filter reminders

Push token, device status

Consent

Fix crashes and technical problems

Crash reports, error logs, user ID

Consent

Improve the app

Usage events, screen views

Consent

Help you when you contact support

Account and support details

Consent

Keep accounts secure and prevent misuse

Account and device records, security logs

Legitimate use under Section 7, DPDP Act

Meet legal obligations

Whatever the law requires

Legal obligation

 

A note on how consent works here. Under the DPDP Act our processing runs on your consent, plus the narrow "legitimate uses" the Act allows. We do not rely on "legitimate interests." This is a European concept and it does not exist in Indian law.

You can withdraw consent at any time. See Section 12.

We do not make automated decisions about you. Nothing in the app decides anything about you by algorithm that has a legal or similarly significant effect. We do not profile you for advertising.

6. Messages We Send You

We send you:

  • SMS containing your sign-in code
  • Push and in-app notifications about your purifier, specifically status changes, connectivity problems, faults, filter reminders and AQI updates
  • Service messages about your account, security, or changes to this policy

We do not send marketing or promotional messages through the app. If this changes, we will ask for your consent separately first, and you will be able to opt out at any time without losing any app features.

7. Who We Share Data With

We share data only with the parties below. We do not sell your data.

Our processors at a glance. These companies process personal data on our instructions, under contract, and remain our responsibility under Section 8(1) of the DPDP Act:

Processor

Role

Data location

Tuya Global Inc.

IoT platform: pairing, control, telemetry

India

Google (Firebase)

Sign-in, analytics, crash reporting, notifications

Includes servers outside India

Amazon Web Services

Hosting for our backend and profile pictures

India

Open-Meteo

Outdoor air quality lookup only

Europe / North America

If we add or change a processor in a way that materially affects you, we will update this policy and tell you as described in Section 18.

7.1 Tuya: Our IoT platform provider (Data Processor / sub-processor)

Sub-processor clause. JB Companion has the Tuya ThingSmart SDK built into it. Tuya Global Inc. and its affiliates ("Tuya") act as our Data Processor, a sub-processor engaged by us, for everything to do with connecting and controlling your purifier. Tuya processes your personal data only on our instructions and only for the purposes set out below, under a contract with us as required by Section 8(2) of the DPDP Act.

We remain accountable to you for what Tuya does with your data. Under Section 8(1) of the DPDP Act, we stay responsible for compliance even where processing is carried out by a processor on our behalf. If you have a complaint about how your device data is handled, raise it with us using the contact details in Section 17. You do not need to approach Tuya.

Who

Tuya Global Inc. and its affiliates

Role

Data Processor (sub-processor), acting on our instructions

What we share

Device identifiers, device status and telemetry, sensor readings, pairing and provisioning data, your Wi-Fi credentials during setup only, account identifiers

Why

Device pairing and provisioning, remote control, device synchronisation, secure device authentication, status updates, automations

Where

India. Our Tuya account runs on Tuya's India data centre (openapi.tuyain.com). Your device data is stored in India.

Retention

While the device is linked to your account. Removed on unpairing or account deletion.

Erasure

When you delete your account or withdraw consent, we instruct Tuya to delete the data it holds for us, as required by Section 8(7) of the DPDP Act. Section 13 describes what this covers.

Onward transfer

Tuya may rely on the work of sub-processors to store and process the data with our prior, explicit authorization.

 

Tuya also applies its own data handling practices and security standards to device telemetry and provisioning data. Those practices sit alongside, and do not replace, our obligations to you under this policy.

7.2 Google Firebase

What we share

Authentication: phone number, Firebase user ID. Analytics: events, screen views, user ID, installation ID, app and device details. Crashlytics: crash reports, stack traces, device and OS details, user ID. Cloud Messaging: push token.

Why

Sign-in, understanding app usage, fixing crashes, delivering notifications

Where

Google's infrastructure, which includes servers outside India

Retention

Analytics: up to 14 months. Crashlytics: up to 90 days. Auth records: until you delete your account.

Agreement

Google processes this as our processor under its own terms

We do not send your OTP, your Wi-Fi password, or your profile picture to Analytics or Crashlytics.

7.3 Amazon Web Services (our backend)

What we share

Your name and email address, profile picture, device records, schedules and routines

Why

This is our own backend. It stores your profile, keeps your device records, and runs your schedules.

Where

AWS RDS (database) and AWS S3 (profile pictures), hosted in India

Retention

While your account is active; deleted when you delete your account

Agreement

AWS is our hosting provider. It stores data for us and does not use it for its own purposes.

7.4 Open-Meteo (outdoor air quality)

What we share

Approximate coordinates, or the name of a city you search for. No account identifier, device identifier or other personal data is included in the request.

Why

To look up a city and fetch the outdoor Air Quality Index for that place

Where

Open-Meteo's servers are in Europe and North America. This is a transfer outside India, which the DPDP Act permits.

Retention

Open-Meteo keeps web server logs that may include geographical coordinates, does not share them with third parties, and deletes them after 90 days.

Notes

Open-Meteo runs no advertising, no trаcking and no cookies.

7.5 WhatsApp

We share nothing with WhatsApp. The app only opens a link to it if you tap support. Anything you send after that is between you and WhatsApp.

7.6 Others

  • Service providers who help us run the app: Only what they need, and under confidentiality obligations.
  • Authorities, where the law requires it, or where we need to establish or defend a legal claim.
  • A buyer or successor, if our business is sold or merged. We will tell you, and this policy keeps applying until it is replaced.

8. Where Your Data Is Stored

Data

Where

Device data, pairing, control, telemetry

India (Tuya India data centre)

Your profile, device records, schedules

India (AWS)

Profile pictures

India (AWS S3)

Phone number, Firebase user ID

Google infrastructure, includes servers outside India

Analytics, crash reports, push tokens

Google infrastructure, includes servers outside India

Location sent for AQI lookup

Europe or North America (Open-Meteo)

The DPDP Act allows personal data to be transferred outside India, except to countries the Central Government restricts. We do not transfer personal data to any restricted country, and we watch for changes to that list.

9. Data Stored on Your Phone

  • Sign-in and session tokens are stored securely: in the iOS Keychain on iPhone, and in Keystore-backed encrypted storage on Android. They are not kept in plain text.
  • Your user manual and warranty PDF are saved as described in Section 3.6.
  • The app locally caches session, auth tokens, preferences, and the user manual and warranty as PDF documents.

Upon logging out, the push notification tokens, secure storage session records, analytics user ID, and preferences are cleared out. Local data is cleared when you delete your account or uninstall the app. Uninstalling the app on its own does not delete data held on our servers. To do that, delete your account. See Section 13.

10. How Long We Keep Your Data

We keep your data only as long as we need it. When the purpose is finished, we delete it.

Data

How long

Why

Account and profile: name, email, phone, picture

While your account is active, then deleted immediately upon deletion. Encrypted server backups may retain the data for up to 7 days before they are automatically overwritten.

You need an account to use the app

Device pairing and configuration

While the device is linked to your account

Needed to control your purifier

Schedules and routines

While your account is active

Needed to run your automations

Device telemetry and sensor history

While the device is linked to your account, and no more than 3 months after

Diagnostics, filter life trаcking, product improvement

App usage analytics

Up to 14 months

Firebase Analytics maximum retention

Crash reports

Up to 90 days

Firebase Crashlytics retention

Push notification token

Until you turn off notifications, log out, or uninstall

Needed to deliver alerts

Support messages

Up to 12 months after the issue is closed

Service quality and repeat issues

Security and access logs

12 months

The DPDP Rules require a one-year log retention period

Records the law requires us to keep

As long as the law requires

Legal obligation

 

These are maximum periods. We often delete sooner.

We delete your data as soon as the purpose it was collected for is finished: including when you withdraw consent or delete your account. When we delete your data, we also require our processors, including Tuya, Google and AWS, to delete what they hold for us.

11. How We Protect Your Data

On your phone

  • Sign-in and session tokens are kept in the iOS Keychain or Android Keystore-backed encrypted storage
  • Your OTP is never written to logs, analytics or crash reports
  • QR scanner images are never saved or uploaded

In transit

  • All traffic between the app, our backend, Tuya and Google uses HTTPS/TLS.
  • Device authentication with your purifier is secured through Tuya's provisioning process

On our systems

  • Your data sits on AWS infrastructure in India
  • Access controls, access logging, encryption at rest, and patching practices are implemented in AWS and apply toward the protection of your data.

Being straight with you: no system is completely secure. We cannot promise that nothing will ever go wrong. What we can promise is that we take it seriously and that we will tell you if something does. See Section 15.

Your part: keep your phone and your phone number secure. Anyone who can receive your sign-in SMS can get into your account. Tell us immediately at support@jbair.com if you change or give up your number, or if you think someone else has access.

12. Your Rights

Under the DPDP Act you have these rights. All of them are free to use, and using them will never get you worse service.

1. Right to know what we have (DPDP Act, s.11) Ask us for a summary of the personal data we hold about you and what we do with it. → Email us at privacy@jbair.com, subject "Data Access Request". We take no longer than 90 days to respond.

2. Right to correct or complete your data (DPDP Act, s.12) Fix anything wrong or out of date. → Most of it you can change yourself: Settings → Edit Profile. For anything else, email us. We take no longer than 90 days to respond

3. Right to erase your data (DPDP Act, s.12) Have your data deleted. → Delete your account in the app. See Section 13 of this policy or email us. We take no longer than 90 days to respond. We erase all your data apart from anything the law requires us to keep, which we will tell you about.

4. Right to withdraw consent Change your mind at any time. Withdrawing is as easy as giving consent was. → Turn off a permission in your phone settings, turn off the feature in the app, or delete your account. We then stop that processing and delete the related data, unless the law says otherwise. Some features will stop working and that is the only consequence. We take no longer than 90 days to respond

5. Right to nominate someone (DPDP Act, s.14) Nominate another person to exercise your rights for you if you die or become unable to act. → Email us at privacy@jbair.com with their name and contact details. We take no longer than 90 days to respond

6. Right to raise a grievance (DPDP Act, s.13) Complain to us about how we handle your data. See Section 17 of this policy. We take no longer than 90 days to respond

How to make a request: email us at privacy@jbair.com from your registered email address, or write to us at the address in Section 18. We may ask you to confirm your identity first, usually your registered phone number is enough. There is no charge.

13. How to Delete Your Account

JB Companion app users can delete their account directly from the app by going to Account Settings > Delete Account. If a user no longer has access to the app, the user may request app account deletion by emailing walkietalkie@jbair.com with the subject "JB Companion account deletion request" and including the phone number linked to the user's JB app account. If an email address is linked to the account, the request should be sent from that email address. When an app account is deleted, JB deletes personal data associated with that app account, except where JB is required or permitted to retain limited information for legal, security, fraud-prevention, warranty, tax, accounting, dispute-resolution, or compliance reasons.

In the app:

Settings → Edit Profile → Delete Profile → confirm

When you confirm, we delete:

Confirmed by our development team:

  • Your device records from our database
  • Your Firebase Authentication account, including your phone number
  • Your Tuya user account

Upon the deletion of your account, each of the following is deleted too:

  • Your profile: name, email address, profile picture
  • Your profile picture from Amazon S3
  • Your schedules and routines
  • Your push notification token
  • Session data stored on your phone

This is permanent. It cannot be undone.

We may keep a limited amount of data where the law requires it, or where we need it to resolve a dispute. Anything left in routine backups is overwritten within 7 days. Data that has been anonymised, and can no longer identify you, may be kept. If you only want to stop using one purifier, unpair it instead: you do not need to delete your account. You can also request deletion by emailing us at privacy@jbair.com from your registered contact details.

14. Children

You must be 18 or older to have a JB account.

Under the DPDP Act, a child is anyone under 18. We do not knowingly collect a child's personal data. We do not process a child's data without verifiable consent from a parent or guardian. We never trаck, monitor the behaviour of, or direct advertising at children.

An adult can of course run the app in a home with children in it. The account, and responsibility for it, stays with the adult.

If you think a child has given us personal data, contact us and we will delete it.

15. If There Is a Data Breach

If a personal data breach happens, we will tell the Data Protection Board of India and we will tell affected users at the earliest, without any delay. We will also inform the Data Protection Board of such a breach with a detailed report within 72 hours of awareness of such breach.

Our notice will include, in plain language: what happened, what data was involved, what you can do to protect yourself, what we are doing about it, and who to contact with questions.

16. If You Are Outside India

This policy is written around Indian law. If you use the app from outside India, your local law may give you additional rights, for example, in the EU or UK, rights to data portability and to object to certain processing. Contact us and we will help you exercise them.

17. Contact Us and Grievance Redressal

General questions and support JB Support Email: walkietalkie@jbair.com Website: www.jbair.com. We aim to reply within 15 days.

Privacy and data protection questions This is the contact for anything about how we handle your personal data, and for exercising the rights in Section 12. For any questions around privacy and data protection, or to access your rights, please email our Data Protection Officer Arnav Gulati at privacy@jbair.com.

If you make a complaint, we will investigate and reply within 30 days, and in no case later than 90 days.

If you are not satisfied with our response, or we do not respond in time, you can escalate to the Data Protection Board of India. You may also appeal a Board decision to the Telecom Disputes Settlement and Appellate Tribunal within 60 days.

18. Changes to This Policy

We may update this policy. When we do, we will post the new version in the app and change the "Last Updated" date. If the change matters, for example a new type of data, or a new company we share it with, we will tell you in the app or by notification before it takes effect, and where the law requires it, we will ask for your consent again.

Air quality data provided by Open-Meteo.com, licensed under CC BY 4.0.