Privacy notice
What we collect, why, and what you can do about it.
In plain language. Aligned with the Digital Personal Data Protection Act, 2023 (DPDP) and India-region defaults.
Last updated · 23 May 2026
One-line version. We use your data only to build and update your government-scheme roadmap. We never sell it. It stays in India. You can export or delete it any time.
Who is the data fiduciary
NirmanKit is the Data Fiduciary under the DPDP Act 2023. You — the user — are the Data Principal. You can reach our Data Protection Officer (DPO) at any time via the contact page.
What we collect
Always (required to operate)
- Your answers to onboarding questions (persona, goal, stage, entity type, state).
- Your saved roadmaps and any steps you mark complete or annotate.
- Authentication identifiers — your Indian mobile number, used to send a one-time SMS code to sign you in. We don't use passwords or email for sign-in. MeriPehchaan / DigiLocker sign-in is planned and will be disclosed here before it ships.
- An append-only audit log of meaningful actions (login, profile edit, roadmap save). PII is excluded from this log.
Optional (only with your explicit consent)
- Personalisation — cross-cutting flags you opt into (woman entrepreneur, SC/ST, disability) to surface targeted schemes.
- Communications — email or WhatsApp for deadline reminders.
- Analytics — anonymised product analytics: pages visited, journey progress, and aggregate app-performance and error counts. Never the contents of any error, and never your answers. We use two complementary tools: self-hosted PostHog (Mumbai infrastructure) and Google Analytics 4 (GA4) for aggregate search and traffic insights. GA4 data is processed by Google under their standard terms; no PII is sent.
We do not collect full Aadhaar numbers, biometric data, salary, religion, or political views. When DigiLocker sign-in ships (see above), Aadhaar will be used only via DigiLocker's verified-identity API; we will store the verified flag and the last 4 digits, no more.
Why we collect it
Solely to operate the roadmap product — match you against schemes, sequence them correctly, remember your progress, and let you come back. We do not use your data for advertising, training external models, or any purpose outside what you signed up for.
Where it lives
Your data is stored in Mumbai. Specifically: Supabase Postgres (Mumbai region), Supabase Storage (Mumbai), audit-log WORM mirror on S3 Mumbai. Authentication (Supabase Auth) and job orchestration (Trigger.dev) self-hosted in Mumbai. Observability (PostHog, Sentry) India region only. Google Analytics 4 processes aggregate traffic metrics on Google's infrastructure (cross-border; no PII transmitted).
The single cross-border surface is the AI-assisted DPIIT drafter (Phase 2, opt-in). When you choose to use it, your inputs (problem, solution, technology) are sent to Anthropic's API outside India. No other PII flows in the prompt; you can decline this feature at any time. Full posture in where your data is stored and where AI fits in this product.
Your rights under DPDP
Under §§ 11–13 of the DPDP Act 2023 you have the following rights, all of which we implement as live flows (not buried policy text):
- Right to information — this notice + the in-product data tools on your profile page.
- Right to access — download a ZIP of your profile, roadmaps, applications, and audit log.
- Right to correction — edit any profile field in place.
- Right to erasure — one-click delete with a 30-day cooling-off window before hard-delete.
- Right to grievance redressal — contact the DPO; we acknowledge within 7 days, resolve within 30.
- Right of nomination — appoint a nominee who can exercise your rights if you are deceased or incapacitated.
- Withdraw consent — at any time, per purpose. Withdrawal is one click and equally accessible as consent.
How long we keep it
- Active account — for as long as you're using the product.
- Inactive 18 months — we notify you in-app and via email if you consented.
- Inactive 24 months — soft-delete (anonymised; analytics retained for 6 more months).
- Inactive 30 months — hard-delete; all rows dropped.
- Audit log + consent artefacts — 7 years (DPDP-aligned retention).
- Application logs — 180 days (CERT-In Directive alignment).
Security
TLS 1.3 in transit, AES-256 at rest. Database access via Row-Level Security (you can only see your own rows) plus application-layer authorisation (defence in depth — see how we check who can change what). Audit log is tamper-evident with a SHA-256 hash chain and WORM mirror (see how we make changes traceable).
Breach notification
If there's a personal data breach, we notify the Data Protection Board of India within 72 hours and you, the affected Data Principals, without undue delay. Technical incident reporting to CERT-In within 6 hours per the 28 April 2022 directive.
Cookies + tracking
Essential cookies only: an HttpOnly session cookie (after sign-in) and aNEXT_LOCALE cookie remembering your language. No third-party tracking cookies. No advertising IDs. Self-hosted analytics (PostHog) only runs if you've consented under the Analytics purpose.
Changes to this notice
Material changes will be announced in-product 14 days before they take effect. This notice is reviewed quarterly; the "Updated" date at the top of this page reflects the last review.
Contact
- DPO — Data Protection Officer channel on the contact page
- General — contact page
- Security disclosure — security channel on the contact page