Privacy
What is recorded about a person, what is deliberately not recorded, and what happens when somebody asks to be erased.
Last updated 29 September 2026
1. Who is responsible
[to be filled: registered name] operates Pravesh ID. For questions about this policy, write to support@myind.ai.
A mandal decides what it collects at its own event. We provide the software and store the data on its behalf.
2. What is recorded
If you run or help run a mandal
- Your name, email address and phone number.
- Which mandals and events you are on, and what you are allowed to do on each.
- What you did: passes you scanned, payments you confirmed, identity checks you made, people you added or removed, permissions you changed.
If you buy or hold a pass
- The name and phone number given at purchase.
- The name of each person the pass covers.
- Which event, which tier, and whether the pass has been used.
- Each time the pass was scanned, at which gate, and the result.
- If the mandal asks for it at the desk, a photograph of your face, so the guard at the gate can see the pass belongs to you. It is kept in private storage, shown to that event’s guards through links that expire within hours, and never used for anything else.
If you use the Pravesh ID phone app
The app asks for each permission only when you use the feature that needs it.
- Camera — to scan a pass QR at the gate, and to take a guest’s face photo at the desk. Identity documents are never photographed.
- NFC — to read a guest’s wristband at the gate and to write one at the counter. Only the band’s own identifier is read.
- Location — only when you tap “Near me” or “Use my location”. It is not tracked or kept; only a venue pin you choose to save is sent.
- Photos — only when you pick a guest’s face photo from the gallery.
- Face ID / fingerprint — to unlock the app on your own phone. The check happens on the phone; nothing about your face or fingerprint reaches us.
- Passes you add are kept in the phone’s secure storage so they open with no network. Deleting the app removes them.
- Crash reports. If the app crashes, a report (phone model, system version, app version and the error) goes to Google Firebase Crashlytics so it can be fixed. It does not carry your name, email or phone number.
3. What is deliberately NOT recorded
This section matters more than the one above it.
- No identity document number, ever. When a committee member checks an Aadhaar card, a driving licence, a voter ID, a PAN or a passport, the app records only the kind of document, the name and date of birth as shown on it, and who looked at it. There is no field for a number.
- No photograph or scan of a document. There is no camera and no upload on that screen. A photograph of an Aadhaar card contains the number, so a photograph would be the same problem with extra steps.
- No payment card or bank details. A buyer pays a committee member’s UPI account directly. We never see the transaction.
The reason for the first two is legal as well as ethical: holding an Aadhaar number without an AUA/KUA licence is an offence under the Aadhaar Act. The app is built so that it cannot happen by accident.
4. Why each thing is kept
- To issue and check a pass. A gate has to be able to say whether this person may come in.
- To let a committee answer for its own night. Who confirmed this payment? Who checked this identity? Who overrode this refusal? A mandal where several volunteers share one phone cannot answer those questions without a record.
- To stop one pass being used by ten people. Repeat scans are recorded and shown.
5. Who can see it
- The committee of the mandal running the event, according to what each role is allowed.
- A platform operator, for support and moderation.
- The services that run it for us: Supabase (database, sign-in and file storage) and, for the phone app’s crash reports only, Google Firebase. They process data on our behalf and may not use it for anything else.
- Nobody else. Data is not sold, rented, or shared for advertising.
Access is enforced in the database itself — every table has row-level security — not only in the screens. A volunteer cannot reach another mandal’s data by changing a URL.
6. Erasing yourself
In the phone app, open Profile and tap “Delete my account”. On the web, sign in, open your account and use “Erase my account”. Both run immediately (step by step: delete your account). Your name becomes “Erased”, your email is replaced with an unusable value, your phone number is removed, and your memberships are deleted.
Two things it does not do, stated plainly:
- Entry records, payment confirmations and identity attestations are kept — without your identity attached. They are append-only, because a record a committee can quietly edit afterwards is not worth keeping.
- If you own a mandal you must hand it over first. Erasing an owner would strand the committee and everyone holding a pass for its events.
7. How long things are kept
Event records are kept while the mandal needs them for its own accounts, and a mandal can archive an old event. There is no automatic deletion today. If you want a mandal’s data removed entirely, write to support@myind.ai from the owner’s address.
8. Where it is stored
On managed Postgres infrastructure. Passes and gate lists are also held on the gate device’s own storage so it keeps working without a network; that copy is signed, and a device holds only the event it is working.
9. Cookies
A session cookie keeps a committee member signed in. There is no advertising cookie, no analytics tag, and no third-party tracker on the website or in the phone app. The only outside service the app reports to is the crash reporting described in section 2.
10. Your rights
You can ask what is held about you, ask for it to be corrected, and erase your account as described above. Write to support@myind.ai. If you are not satisfied, the contact page names a grievance officer.
11. Changes
The date at the top changes when this policy does.
