Privacy
Privacy policy
Draft — pending legal review
The facts on this page are generated from the same code that runs the site. The wording has not yet been reviewed by a lawyer, and sections marked “to be completed by counsel” are gaps, not omissions. Not yet reviewed.
What Vekuva stores about you, where it is kept, which companies handle it, how long it is kept, and how to get a copy or have it deleted. Each list below is generated from the code that does the storing.
Who is responsible
- Operator
- not yet published
- Registered address
- not yet published
- Registration number
- not yet published
- Grievance officer
- see the grievance section
If you have an account
Your sign-in (email address, name and sessions) is held by Clerk. The rows below are held in our database, keyed to your account id, and exist only if you used the feature:
saved_articles— articles you savedWhy: to show you the articles you saved, on any device you sign in from. On what basis: the use you voluntarily made of the feature (DPDP s.7(a)) — to be confirmed by counsel.article_likes— articles you likedWhy: to show you what you liked and to count likes on an article. On what basis: the use you voluntarily made of the feature (DPDP s.7(a)) — to be confirmed by counsel.summary_feedback— your ratings of AI summaries, the reason you picked, and any comment you typed in free textWhy: to measure whether AI summaries are any good, and to fix the ones that are not. On what basis: the use you voluntarily made of the feature (DPDP s.7(a)) — to be confirmed by counsel.reader_prefs— the constituency and label language you choose while signed in — copied from your device automatically, so it follows you to other devicesWhy: to carry your constituency and label language to your other devices. On what basis: the use you voluntarily made of the feature (DPDP s.7(a)) — to be confirmed by counsel.reader_reads— which articles you opened while signed in, the day, and whether you finished themWhy: to build your own information diet on /me, and to resume where you left off. On what basis: the use you voluntarily made of the feature (DPDP s.7(a)) — to be confirmed by counsel.story_follows— the developing stories you followWhy: to tell you when a story you follow develops. On what basis: the use you voluntarily made of the feature (DPDP s.7(a)) — to be confirmed by counsel.alert_preferences— your alert settings: timezone, quiet hours, frequency caps and any digest pauseWhy: to send alerts at the times you asked for and no more often than you asked. On what basis: the use you voluntarily made of the feature (DPDP s.7(a)) — to be confirmed by counsel.consent_events— which version of the cookie notice you answered, what you chose, and whether you affirmed you are 18 or older — carrying your account id only if you were signed in when you answered, and no identifier at all if you were notWhy: to be able to show what you were told and what you chose, if anyone asks us to prove it. On what basis: an obligation under law — to be confirmed by counsel.rights_requests— a request you made about your own data — what you asked for, the address you gave us to reply to, any nominee you named, and how it was resolvedWhy: to handle the request you made about your own data, and to show it was handled on time. On what basis: an obligation under law — to be confirmed by counsel.brief_subscriptions— the weekly constituency briefs you asked to receive by email, and which place each one coversWhy: to send you the weekly brief for the constituency you subscribed to, until you unsubscribe. On what basis: your consent, which you can withdraw.
Staff and analyst accounts additionally have access-grant rows (entity_grants, place_grants, beat_grants).
If you do not have an account
Reading this site signed out creates no account rows. These tables hold a visitor key rather than an account row: a salted hash built from your account id or from your IP address and browser user agent, depending on the table (the one exception is noted in its row). A salted hash is pseudonymous rather than anonymous: we cannot read your address back out of it, but the same visitor produces the same hash.
article_views— one row per article per visitor per day, to count views without double-countingWhy: to count how many people read an article without counting the same person twice in a day. On what basis: the use you voluntarily made of the feature (DPDP s.7(a)) — to be confirmed by counsel.rate_limit_hits— request counters used to slow down automated traffic, kept for a short window — keyed by your account id itself when you are signed in, otherwise by a salted hashWhy: to slow down automated traffic and keep the site up for everyone else. On what basis: the use you voluntarily made of the feature (DPDP s.7(a)) — to be confirmed by counsel.search_queries— the text of searches typed into the site, with a hashed visitor keyWhy: to learn what readers are looking for and cannot find — the questions the archive could not answer. On what basis: not yet determined by counsel.citizen_inputs— the text of a reader submission, the place and category you picked, and a hashed submitter keyWhy: to read what you told us about your area, moderate it, and count it in the needs index for your constituency. On what basis: your consent, which you can withdraw.ad_events— impressions and clicks on sponsored placements, with a hashed visitor keyWhy: to count impressions and clicks on sponsored placements, so an advertiser can be billed correctly. On what basis: the use you voluntarily made of the feature (DPDP s.7(a)) — to be confirmed by counsel.
Reader submissions (citizen_inputs) are read by a moderator first. Once approved, the text alone is sent to the Google Gemini API to extract the need it describes. Using an approved submission to evaluate and train that model is a SEPARATE choice, made on the submission form itself and off unless the submitter ticked it — submitting does not consent to it. Where it was given, only ids and split labels are ever copied out of the database for that purpose, never the text.
Preferences such as type size and theme stay in your browser. They are listed on the cookies and storage page.
Companies that process it
Clerk
- Why we use them
- so you can create an account, sign in, and stay signed in
- Receives
- your email address, name and sign-in sessions, if you create an account
- Region
- United States
- Runs
- for every visitor who uses the feature
Supabase
- Why we use them
- to store the site itself and the account-linked rows listed below
- Receives
- the account-linked records listed below, keyed by your account id
- Region
- unverified — set by the project dashboard
- Runs
- for every visitor who uses the feature
PostHog
- Why we use them
- to see which pages work and which are never reached, so the site can be improved
- Receives
- page views and clicks under a pseudonymous id — never your email or name — and only after you accept analytics
- Region
- United States
- Runs
- only after you consent
PostHog (error reports)
- Why we use them
- to find out when a scheduled job on our server has failed
- Receives
- nothing about you: when a scheduled background job fails on our server, the error's type, a shortened message with quoted text removed, the job step and a run id
- Region
- United States
- Runs
- for every visitor who uses the feature
Google AdSense
- Why we use them
- to sell the advertising that pays for the site
- Receives
- cookies and device identifiers for ad serving; ads are non-personalised unless you accept ads
- Region
- United States
- Runs
- only after you consent
Google Gemini API
- Why we use them
- to run the analysis this product exists to publish
- Receives
- published news text, and the text of reader submissions you send us, for analysis
- Region
- United States
- Runs
- for every visitor who uses the feature
Fly.io
- Why we use them
- to serve this site to your browser
- Receives
- request logs (IP address, user agent, URL) as the site's host
- Region
- Singapore (sin)
- Runs
- for every visitor who uses the feature
Amazon Web Services
- Why we use them
- to keep the server logs above in India for as long as the law requires
- Receives
- the same request logs, shipped to a bucket in India and retained there
- Region
- India (ap-south-1)
- Runs
- for every visitor who uses the feature
To be completed by counsel · the legal basis for each transfer outside India, and the data-processing terms in place with each company.
How long it is kept
These windows are enforced by a scheduled job, not by hand. The figures are the ones this deployment is configured with.
- 3 months
- per-day view de-duplication rows (hashed viewer)
- 1 day
- rate-limit counters (a hashed viewer key, or your account id while signed in)
- 1 year
- search queries typed into the site
- 30 days
- the hashed submitter key on a moderated reader submission
- 2 years
- your reading history (articles opened while signed in)
- 3 years
- the record of which consent notice you answered and what you chose
Account rows other than reading history are kept until your account is deleted. ad_events and the text of reader submissions have no retention window yet.
To be completed by counsel · whether these windows meet each applicable retention obligation.
Getting a copy, and deleting it
Export. On Settings → Data & privacy, the export button downloads one JSON file with your account rows and the preferences stored in this browser.
Deletion. Deleting your account (from the account menu) erases the account rows listed above: saved_articles, article_likes, summary_feedback, reader_prefs, reader_reads, story_follows, alert_preferences, consent_events, rights_requests, brief_subscriptions. These are kept:
- right-of-reply threads with a newsroom — because they are a published correction to something this product said about an outlet.
- the account id recorded on staff and moderation actions (for example who approved a change) — because they are the audit trail of an editorial decision, not reader data.
This browser. The same settings section clears everything stored on this device.
Anything else, including naming someone to act for you. The rest — a correction, a summary of what we hold, withdrawing a consent that is not a cookie choice, and nominating a person to exercise these rights if you die or become unable to (DPDP s.14) — goes through one form: make a request. We answer within 30 days. What the form can ask for:
- A copy of what you hold about me — A summary of the personal data we hold and what we do with it. The export button already produces the account rows themselves, immediately.
- Correct or complete something — Tell us which record is wrong and what it should say. Corrections to civic reference data — a politician, a school, an office — go through the same review a human commit does.
- Erase my data — Deleting your account already erases the rows listed on the privacy page. Use this if you want something erased that account deletion does not cover, and say what.
- Nominate someone to act for me — Name one person who may exercise these rights on your behalf if you die or become unable to. We store their name and an email address, and nothing else about them.
- Withdraw a consent — Cookie choices can be changed from “Cookie preferences” at the foot of every page, and take effect at once. Use this for a consent that is not a cookie choice — for example, letting a submission of yours be used to test the model.
- Complain about how my data was handled — Goes to the grievance officer. If we do not resolve it, you may complain to the Data Protection Board of India — the route is on the privacy page.
To be completed by counsel · which of these rights apply, from what date, and what response time the law requires — the 30 days above is a commitment this product makes, not a statutory figure.
How you identify yourself to us
When you ask us for something about your own data (Rules r.14(1)(b)), make the request while signed in — the form fills in who you are from your session, and there is no field in which you could name anybody else.
or write from the email address on your account, quoting the account id shown on Settings → Data & privacy.
What we never ask for: we do not ask for a photo ID, an Aadhaar number, a phone number or an address to answer a request about data we hold under an email address.
If we do not resolve it
Take it first to the grievance officer named on the contact page — the grievance officer. If that does not resolve it, you may complain to the Data Protection Board of India.
To be completed by counsel · the Board’s current complaint address. We will not print a URL for it that we have not checked: a wrong address on the one page telling you where to complain is worse than no address.
School results pages
The pages under /results and /school are read by school-age students. They run no analytics, whatever you chose, and any ads on them are non-personalised.
What our clients receive
Organisations that use our intelligence product receive aggregates only. There are no identified readers, no lists of readers’ inferred political leanings, and no view of one reader that could be exported.
Changes and contact
A change to what we ask consent for bumps the consent version, and the site asks you again. Questions and complaints go to the grievance officer.
To be completed by counsel · purposes and lawful basis for each category of data, and governing law.