Privacy notice

What we collect, why, and what you can do about it.

In plain language. Aligned with the Digital Personal Data Protection Act, 2023 (DPDP) and India-region defaults.

Last updated · 23 May 2026

One-line version. We use your data only to build and update your government-scheme roadmap. We never sell it. It stays in India. You can export or delete it any time.

Who is the data fiduciary

NirmanKit is the Data Fiduciary under the DPDP Act 2023. You — the user — are the Data Principal. You can reach our Data Protection Officer (DPO) at any time via the contact page.

What we collect

Always (required to operate)

Optional (only with your explicit consent)

We do not collect full Aadhaar numbers, biometric data, salary, religion, or political views. When DigiLocker sign-in ships (see above), Aadhaar will be used only via DigiLocker's verified-identity API; we will store the verified flag and the last 4 digits, no more.

Why we collect it

Solely to operate the roadmap product — match you against schemes, sequence them correctly, remember your progress, and let you come back. We do not use your data for advertising, training external models, or any purpose outside what you signed up for.

Where it lives

Your data is stored in Mumbai. Specifically: Supabase Postgres (Mumbai region), Supabase Storage (Mumbai), audit-log WORM mirror on S3 Mumbai. Authentication (Supabase Auth) and job orchestration (Trigger.dev) self-hosted in Mumbai. Observability (PostHog, Sentry) India region only. Google Analytics 4 processes aggregate traffic metrics on Google's infrastructure (cross-border; no PII transmitted).

The single cross-border surface is the AI-assisted DPIIT drafter (Phase 2, opt-in). When you choose to use it, your inputs (problem, solution, technology) are sent to Anthropic's API outside India. No other PII flows in the prompt; you can decline this feature at any time. Full posture in where your data is stored and where AI fits in this product.

Your rights under DPDP

Under §§ 11–13 of the DPDP Act 2023 you have the following rights, all of which we implement as live flows (not buried policy text):

How long we keep it

Security

TLS 1.3 in transit, AES-256 at rest. Database access via Row-Level Security (you can only see your own rows) plus application-layer authorisation (defence in depth — see how we check who can change what). Audit log is tamper-evident with a SHA-256 hash chain and WORM mirror (see how we make changes traceable).

Breach notification

If there's a personal data breach, we notify the Data Protection Board of India within 72 hours and you, the affected Data Principals, without undue delay. Technical incident reporting to CERT-In within 6 hours per the 28 April 2022 directive.

Cookies + tracking

Essential cookies only: an HttpOnly session cookie (after sign-in) and aNEXT_LOCALE cookie remembering your language. No third-party tracking cookies. No advertising IDs. Self-hosted analytics (PostHog) only runs if you've consented under the Analytics purpose.

Changes to this notice

Material changes will be announced in-product 14 days before they take effect. This notice is reviewed quarterly; the "Updated" date at the top of this page reflects the last review.

Contact