RailStaff — Last updated: 15 September 2026
This policy explains how RailStaff handles personal data when you use the website or installed web app. RailStaff is operated by an independent individual in India. For privacy questions, corrections, grievances or deletion requests, email support@railstaff.in.
You can browse the public home page and standard tools without signing in. Depending on what you choose to use, RailStaff may handle:
RailStaff does not request access to your contacts, SMS or call logs, does not use third-party advertising, and does not sell personal data.
For offline use, app data and preferences may be stored in your browser using local storage, session storage, IndexedDB and the service-worker cache. Signed-in data is also processed using Google Firebase, including Firebase Authentication, Cloud Firestore, Hosting and Cloud Functions. Google acts as a service provider for this infrastructure and may process data in locations where its services operate.
If you confirm Charge Memo Scan, the selected compressed image is sent by a Firebase Function to Google Gemini solely to return suggested field values. RailStaff does not add the photo itself to your journal or cloud record; only values you review and choose to apply become app content. Google’s processing of that request is also subject to its applicable service terms and safeguards. Do not scan material you are not authorised to send, and crop or redact anything unnecessary.
Your private journal and account data is restricted to your account and authorised administration/support access. Mutual transfer request details needed for matching are shared within the matching service, but the submitted mobile number is kept in a separate protected record. The server releases a partner’s number only to a signed-in user after it verifies a reciprocal 2-way or 3-way match. Do not post confidential information, independently verify a match, and remove your request when it is no longer required. Data may also be disclosed where required by law, to protect users or the service, or during a lawful transfer of the service.
Account and app data is generally retained while your account remains active or until you delete it. A mutual transfer request remains until you remove it or the account is deleted. Support, security and legal records may be retained only as long as reasonably necessary for those purposes. RailStaff does not intentionally retain the Charge Memo photo after the extraction response, although the service provider may process request data under its applicable terms. Local copies can remain on a device until you clear the app's data or browser storage, or use Log out & clear this device for that signed-in account.
You may review and correct editable profile or app information within RailStaff. You can remove individual content, remove a mutual request, or delete your account. To delete the account, sign in, open Menu → Account → Delete Account, and follow the confirmation steps. Account deletion is permanent and cannot be undone.
Your saved data is deleted only when you delete it. Apart from content you remove yourself, your workings and other saved cloud data are erased only when you delete your account. RailStaff does not provide a bulk cloud “clear all data” action, and it never deletes your saved workings on its own — not during cloud sync, not when you sign in on another device, and not if you clear your browser data. A working you delete is kept in Recently Deleted for 5 days so it can be restored. On a shared device, Log out & clear this device removes only that account’s local copy and sign-in cache; it does not delete its cloud data or another account’s local namespace.
If you cannot access the in-app option, follow the instructions on the Account & Data Deletion page or email the address above from your registered Google email. We may verify identity before acting. Valid requests are normally completed within 7 days, subject to information that must be retained by law or for resolving security, fraud or dispute issues.
RailStaff uses HTTPS, Firebase Authentication, database security rules, restricted administrative access and other reasonable safeguards. TM Chat uses device-key encryption so Firebase normally stores ciphertext rather than message text, but this is not an absolute guarantee against a compromised device, malicious service-delivered code or key substitution. The app records a peer-key fingerprint locally and warns when it changes; verify that warning with the peer before sharing sensitive details. No online system is completely secure, so keep your own backup and protect your Google account and device. If a personal-data incident requires user action, affected users will be notified through available contact or in-app channels as appropriate.
RailStaff is intended for working adults aged 18 or older. It is not directed to children, and a child should not create an account or submit personal data.
This policy may be updated when the service or legal requirements change. The updated version and effective date will be posted here. Material changes may also be shown inside the app.
For access, correction, deletion, consent or privacy complaints, email support@railstaff.in with the subject RailStaff Privacy Request. Include the Google email used for the account and enough detail to identify the issue. We aim to acknowledge complaints within 48 hours and resolve valid requests promptly.
Use of RailStaff is also governed by the Terms of Use, including the independent-app disclaimer, calculator limitations and prohibition on uploading confidential or restricted official material.