About this app: MFB Case Monitor (display name: Case Monitor) supports emergency response and case monitoring for authorized Mumbai Fire Brigade (MFB) personnel. Features include events, units, maps, messaging, push notifications, contacts, and an operational dashboard.
Introduction
This Privacy Policy explains how MFB Case Monitor collects, uses, stores, and protects personal information on Android and iOS. The App is for authorized MFB personnel only and requires organizational credentials.
1. Information We Collect
1.1 Account Information
Username and password (encrypted before transmission)
OTP for two-factor authentication
Profile details maintained by your organization
Session tokens and encrypted credentials in local device storage
1.2 Location
Foreground only: Location is collected only while you actively use the App (Map/Events). We do not track location in the background.
GPS coordinates for map display and navigation
Event and unit coordinates from the backend (operational data)
Location is not retained beyond the active session
1.3 Contacts
Device contacts (with permission) for emergency lookup
Stored locally in SQLite; not uploaded to servers
1.4 Communication & Operations
Messages via Message Service API
Push notifications via Firebase; history stored locally in SQLite
Events, units, caller info, and case updates from Case Monitor API
Dashboard content loaded in an in-app WebView from authorized backend
1.5 Device & Technical Data
Device ID (Android ID / iOS IDFV) sent at login and device registration
FCM token for push notifications
Platform, app version (1.0.1), and network connectivity status
Theme preference (light/dark) stored locally
1.6 Not Collected
Camera, microphone, call logs, SMS
Background location
Advertising or behavioural tracking
2. How We Use Your Information
Purpose
Data
Required?
Login & authentication
Credentials, OTP, device ID, FCM token
Yes
Case monitoring
Events, units, coordinates
Yes
Messaging
Chat content, user IDs
Yes
Push alerts
FCM token, notification content
Optional
Maps
Foreground location, tile requests
Optional
Contacts
Local device contacts
Optional
Dashboard
Authenticated WebView session
Optional
3. Data Security and Protection
AES encryption for credentials before transmission (PBKDF2 key derivation)
HTTPS/TLS for API communication
OTP-based two-factor authentication
Token-based sessions; logout from Profile screen
Local SQLite for contacts and notifications on-device only
3A. Data Retention Timelines
Category
Period
Account data
While authorized; deleted/anonymized within 90 days of deactivation
Auth/session logs
Up to 180 days
Messages/notifications
Up to 90 days unless legally required
Case/incident records
Up to 5 years or per MFB policy
Foreground location
Active session only
Local device data
Until uninstall or app data cleared
Security logs
Up to 180 days
3B. Consent Recording and Audit Trail
Policy acceptance recorded at first use with timestamp
Access, permissions, and processing logged for minimum 180 days
Permission changes recorded with timestamp and user ID
Purpose: map tiles. Data: tile requests (no personal data). Tiles may be cached locally. Privacy policy
4.3 Backend Services
Case Monitor API and Message Service API — operated under MFB authorization.
5. Data Sharing and Disclosure
We do not sell data, share with advertisers, track background location, upload contacts, or share messages with unauthorized parties.
We may share data when required by law, for emergency response, to prevent fraud/abuse, with your consent, or with service providers (Firebase, map tiles) solely to deliver App functionality.
6. Your Rights and Control
Under the DPDP Act, 2023 you may request access, correction, erasure, portability, consent withdrawal, and grievance redressal.