Legal · Privacy
Privacy Policy
Last updated 27 August 2026
What we collect
Account information. When you register, we store your handle, display name, and your password only as a salted one-way hash (we currently use Argon2id, a modern, industry-standard algorithm built to resist password-cracking); we never store, log, or can recover your actual password. Vaak is pseudonymous by default: your handle does not have to be your legal name.
What you post. A vāk's subject, its content, an optional location (ward or map coordinates, if you choose to attach one), and any photo, video, or voice recording you upload as evidence.
Photo evidence (JPEG/PNG). When you upload a photo, we split it into three parts. What gets published, and what everyone sees, is a freshly regenerated copy with embedded metadata (GPS location, capture time, camera make/model, and similar EXIF fields your device may have recorded) removed, so a photo's metadata is never part of the public record. The exact bytes you uploaded, metadata included, are encrypted and retained separately as a sealed original, together with a private record of the metadata we removed and a coarse signal about the network the upload came from (for example, "known VPN/Tor exit," never your raw IP address). Neither the sealed original nor this private record is exposed through any public page or API; a platform moderator can access them only through an internal, logged process, tied to a stated reason, when investigating a specific dispute over whether a piece of evidence is genuine. We also compute a similarity fingerprint of the image (to help moderators recognize the same or a near-identical photo reused across multiple posts) and check whether the file carries a C2PA content-credentials marker (industry-standard metadata some cameras and editing tools attach); both are internal signals for that same moderation purpose, never a public verdict on whether a photo is authentic.
Other evidence (video, audio, PDF). We do not yet have the ability to regenerate these file types the way we do photos, so they are stored and served exactly as uploaded, metadata and all; if you attach one to a public vāk, any metadata it carries becomes part of the public record along with it. Remove location or other metadata from a file like this yourself before you upload it, if you do not want it public. We will update this section once these file types get the same regeneration treatment photos already have.
Direct messages. Messages you send to another person or a group are not end-to-end encrypted. Message content is stored on our servers and handled the same way as the rest of your account data (see "Security measures" below), the way most messaging features work unless a product is specifically built around end-to-end encryption. Authorized Vaak personnel can access message content as part of operating and moderating the service, and, like any stored data, it would be exposed in the event of a serious security breach. If you need a stronger confidentiality guarantee than that, keep it out of Vaak's messaging. Media you send in a message is stored the same way as other uploads.
Civic identity verification. Originating a vāk (a report, testimony, proposal, question, or similar, anything except responding to one already published), marking yourself affected by an issue, signing a petition, responding to a consultation, and verifying an issue's completion all require your civic identity to be verified first; reading, following, and responding never do. The intended path is DigiLocker: a redirect to a government-run consent screen that verifies a government-issued document automatically, with no human review and no document image ever stored or seen by us. It is not yet connected to a real government record, we are still completing the DigiLocker Partner API onboarding, so it does not verify your identity today; that connection is in place before the app itself opens, and we will update this section, and remove this notice, once it does. Until then, and afterward as a fallback for anyone who cannot use DigiLocker, you can verify manually: submit a document type and number for a moderator to review. The document number is combined with a server-side salt and stored only as a one-way hash; the raw number itself is never persisted, only used once to compute that hash. Once a moderator has reviewed the image or scan you uploaded as evidence, it is unlinked from the review queue so moderators can no longer find it there. We have not yet built the step that deletes the underlying file itself, so today it can remain in storage after review; we treat this as a gap we are closing, not a design choice, and will update this section once that deletion step ships. Contact us (below) if you want a specific file deleted sooner. Only the salted hash stays linked to your account, in a separate store that is never exposed through the API.
The waitlist. Joining the waitlist on the front page asks you two things: to confirm you are a citizen of India, and where you stand. We store exactly three things: your email address, the place you gave us, and the time, in a database with no other purpose. The place is either a rough location your browser shared with your explicit consent, rounded to about a kilometre before it ever leaves your device (we round it again on arrival and never hold anything finer), or, if you decline the browser prompt, the PIN code you type instead. Where people are waiting decides where Vaak opens first; that is the only use. No IP address or device information is attached to any of it. We confirm the address before it counts: we send one mail with a confirmation link, and an address that never confirms is deleted within seven days and was never on the list. Every mail we send carries a one-click link that removes your address immediately, no account and no reply required; writing to us (below) does the same. If a mail to your address bounces or is marked as spam, we delete it for the same reason: there is nothing left to do with an address we cannot reach or that does not want to hear from us. We use the address to write to you about Vaak opening and for nothing else, and we never share it.
Standard technical logs. Like any web service, our servers log IP addresses and request metadata for security and abuse prevention. We do not use this for advertising.
Cookies and local storage
Vaak does not use tracking cookies or any third-party cookie. We use your browser's local storage, not a cookie, to keep you signed in between visits and to remember your light or dark theme preference; this stays on your device and is not itself transmitted to any third party. Clearing your browser's stored data for Vaak, or signing out, removes it. Your sign-in session expires automatically after a period of time and is refreshed while you are actively using Vaak; signing out on a device ends it there immediately.
What we don't do
- We do not run advertising and do not sell or rent your data to anyone.
- We do not use third-party analytics or advertising trackers of any kind.
- We do not use your civic-verification document number for anything beyond the one-time hash check described above.
Third parties we work with
We keep this list short on purpose, and update it whenever it changes.
- CARTO (map tiles). Once you are signed in, screens that show a map (the home map, the institution console) load background map imagery from CARTO's servers. Each map tile request sends your IP address and basic browser information to CARTO, the same as loading an image from any outside site would; it does not send your Vaak identity, account details, or any vāk content. This only happens on map-bearing screens, and only once you are signed in, never before you have an account.
- No email or SMS provider. Vaak does not send you email or text messages today; every notification happens inside the app, so there is no outside delivery provider with visibility into your account activity.
- No third-party file storage. Photos, video, and other uploads are stored on servers we operate directly, not handed to a third-party storage provider. If that changes as Vaak grows, we will name the provider here and treat them as a processor bound to protect your data, not a party free to use it themselves.
How your content works
Vaak is built as an append-only public record: once a vāk is published, it is visible to anyone with no account required, and the platform's whole purpose is that institutions and neighbours can find and respond to it. You can withdraw or supersede your own vāk, which marks it withdrawn or corrected and removes it from the public feed. Because the underlying system keeps a durable history of every action (the same mechanism that lets institutions prove they responded, and lets you prove they didn't), the original stays reachable at its own link, now labelled accordingly, rather than being erased from the record's history.
Photos, video, and audio you attach are not automatically deleted when the vāk they belong to is withdrawn or superseded: as long as the vāk stays public, the file stays reachable at its own address. We cannot currently delete a single attached file on its own while leaving the rest of a vāk untouched, the smallest unit we can act on is the vāk itself.
If you need something removed for a reason beyond a normal correction, for example a safety concern, contact us (below) and we will handle it directly.
Security measures
Traffic to and from Vaak is encrypted in transit (HTTPS). Passwords and civic-verification document numbers are salted and hashed before they are ever written to our database, in neither case is the original value stored or logged. Uploaded files are served with response headers that stop a disguised file (for example a script masquerading as an image) from running in your browser just because you opened its link. No system is perfectly secure; if you believe you've found a vulnerability, tell us at privacy@upturnbrands.com before disclosing it publicly, so we can fix it first.
Who can see what
Signed-in readers see the full card for a vāk or issue: its content, ward, author handle, support and affected counts, and any evidence attached. A public share link (used when a vāk is shared outside the app, no account required to view it) shows the same fields, minus your avatar image, which is stripped specifically because avatar images are themselves reachable at a public, unauthenticated address. Vaak's separate bulk-data programme for approved partners (see the Terms of Service) strips further fields, like exact author identity and restricted status, that an ordinary public link still shows. If a vāk is restricted by a moderator following a report, it is never silently hidden: a notice explains why, and the decision can be appealed.
Your rights, and where we are on the DPDP Act
India's Digital Personal Data Protection Act, 2023 (DPDP Act) is being brought into force in phases, with full operative compliance obligations (including breach notification and erasure workflows) applying from 14 May 2027. We intend to meet the Act's requirements on that timeline. Today, a self-service "export my data" or "delete my account" tool does not exist yet. Until it does, contact our Grievance Officer at grievance@upturnbrands.com with any request about your data, including access, correction, or deletion, and we will handle it by hand, as promptly as we can.
Retention
We currently retain account and content data for as long as your account exists, since Vaak's design depends on records staying available for the institutions and citizens who follow them; withdrawing or superseding a vāk changes how it is labelled and displayed, not whether the underlying record persists (see "How your content works" above). We have not yet set a fixed, automatic schedule for how long infrastructure-level technical logs (IP addresses, request metadata) are kept. We are developing a formal, per-data-type retention schedule covering both content and logs; this section will be updated once it ships.
International data transfer
Vaak's servers may be located outside the country you are accessing it from. By using Vaak, you understand your information will be processed on servers we operate or contract with, wherever they are located, under the protections in this policy regardless of where that is.
Children
Vaak is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has created an account, contact us and we will act on it.
Changes to this policy
If we materially change what we collect or how we use it, we will update this page and change the date at the top. We do not backdate changes.
Contact
For any question about this policy, or to make a data request (access, correction, deletion, or a complaint about how your data has been handled), write to our Grievance Officer under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, at grievance@upturnbrands.com.