Effective 10 Sep 2026Version 1.0Governing law DPDP Act, 2023 (India)
Janaḥ is a platform for reporting civic grievances and engaging with your local community. This policy explains what we collect, why, and the rights you hold over your data under India's Digital Personal Data Protection Act, 2023.
1Information we collect
Account information
Name, username, email address, phone number, and date of birth, collected when you register.
Your password, stored only as a salted cryptographic hash — we never store or can see it in plain text.
If you sign in with Google or Apple, we receive your name, email address, and profile photo from that provider. We never receive your Google or Apple password.
Optional profile details you add, such as a bio or avatar photo.
Location and reports
The precise location (latitude/longitude) and address details (locality, city, state, postal code) attached to any grievance or post you file, so it can be routed and shown to your community.
Photos or media you attach to a report, comment, or post.
The text of your reports, comments, polls, and messages.
Usage and verification
Votes, follows, community memberships, bookmarks, and other interactions within the App.
Direct messages you send to other users within the App.
One-time passcodes (OTPs) sent to your email or phone to verify your identity — we store only a hash of the code, and it expires shortly after issue.
Basic device and diagnostic information (app version, OS version) needed to keep the service running.
2How we use your information
Purpose
What we use
Route your grievance to the right local authority and category
Report text, photos, location, category
Show reports and discussions to your community
Report content, locality, username, avatar
Verify you're a real person and secure your account
Email/phone OTP, password hash
Sign you in via Google or Apple
OAuth profile (name, email, photo)
Auto-categorise or summarise a report, and flag likely duplicate or fake images, where this AI-assisted feature is enabled
Report text and photos, processed by our AI service provider solely for this purpose
Prevent abuse and fraud
Account activity, report history
Respond to your data-rights requests
Account information
3How we share your information
We never sell your personal data.
Individual grievance reports are visible to your local community and, where relevant, shared with the concerned local authority — this is the core purpose of the App.
Only aggregated, anonymised locality-level insights (for example, "120 pothole reports in this ward this month") are shared with third parties such as researchers or local governance bodies. These cannot be traced back to you.
Where AI-assisted categorisation is enabled, report text and photos are sent to our AI service provider for processing only, under a data-processing agreement — never for the provider's own model training or advertising.
We may disclose information where required by Indian law, a valid court order, or to protect the safety of our users.
4Data retention
We retain your account data for as long as your account is active. If you delete your account, we anonymise your personal identifiers (name, email, phone, photo) immediately. Public grievance reports you filed may be retained after account deletion in anonymised form, as a public-interest civic record — they can no longer be linked back to you.
5Your rights under the DPDP Act, 2023
You have the right to:
Access and export a copy of your personal data, available directly from the App's settings.
Erase your account at any time from the App's settings — this anonymises your personal identifiers as described above.
Withdraw consent for optional processing at any time.
Raise a grievance with our Grievance Officer if you believe your data has been mishandled. We will respond within the timeframe required by the DPDP Act.
6Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS/TLS) between the App and our servers, salted password hashing, and access-controlled secret management for our infrastructure credentials. No system is 100% secure, but we work to continually improve our safeguards.
7Children's privacy
The App is not directed at children under 18. We do not knowingly collect personal data from children under 18. If you believe a child has provided us personal data, contact us below and we will delete it.
8Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you in the App and update the effective date above. Continued use of the App after a change means you accept the updated policy.