The app is deliberately minimal. It collects only what is needed to do the officer's job:
| Data | Why | Where it goes |
|---|---|---|
| Username & password | To sign in to the department's own server | Sent to the department's server only. The password is never stored on the phone. |
| Session token | To stay signed in | Stored encrypted on the phone. Removed on sign-out. |
| Photographs of seized property | To attach evidence photos to the property record | Uploaded to the department's server, then deleted from the phone. Never saved to the phone gallery. |
| App installation identifier | So a lost or stolen phone can be blocked by the administrator | A randomly generated value created by the app. It is not the device's hardware ID, IMEI, advertising ID or phone number, and cannot identify the handset. |
| Property record details — read | Shown on screen after scanning a label | Fetched from the department's server for display. Not stored on the phone. |
| Property record details — entered by the officer | To add a new item to the register, correct an existing record, or record a movement, release or disposal | What the officer types is sent to the department's own server and stored in that department's register. This can include the description of the item, the case number, and the names of persons connected with the case — for example the person a released item is handed to, or a witness. This information belongs to the department, not to MMG Infotech. If the phone has no network, the entry is held in the app's own private storage and sent as soon as connectivity returns. |
The QR / barcode reader runs entirely on the device. Camera images used for scanning are processed on the phone and are never transmitted or stored.
The app connects to exactly two kinds of address, and to nothing else:
malkhana.mmginfotech.com) — used only to
tell the app which department server to connect to, and whether the app version is still
supported. This service receives the username being signed in and the app's random
installation identifier. It never receives any property, case, evidence, photograph
or personal record.All connections use HTTPS with certificate pinning. Plain, unencrypted connections are blocked by the app itself.
All evidence and case data entered through the app belongs to the police department that licenses the software. MMG Infotech acts only as a technology provider (a data processor). We do not sell, rent, share or use department data for any purpose of our own, and we do not transfer it to advertisers or data brokers.
Department data is held on the department's own server, under that department's control and retention rules.
On the phone: signing out removes the stored session. Uninstalling the app removes everything the app kept on the device.
On the server: case and evidence records are official police records. Requests to access, correct or erase them must be made to the concerned police department, which is the owner of that data. MMG cannot delete a department's records on its own.
Evidence photographs are never permanently destroyed by a user action; a removed photograph is hidden from listings but retained in the record with the reason and the identity of the officer who removed it.
Processing is carried out for law-enforcement purposes on behalf of the licensing police department. Under Section 17(2) of the Digital Personal Data Protection Act, 2023, certain data-principal rights may be restricted where processing is necessary for the prevention, detection, investigation or prosecution of offences.
See also our main Privacy Policy and Cookie Policy.
This is a workplace application issued to serving police personnel. It is not directed at children and is not made available to the general public.
MMG Infotech Private Limited
CIN: U72200UP2021PTC142703
Email: info@mmginfotech.com
Website: mmginfotech.com
For questions about data held by a particular police department, please contact that department directly; they are the owner of that data.