Publyq Privacy Policy

Effective date: 2 October 2026 · Last updated: 4 October 2026

1. About this Policy

This Privacy Policy explains how Sushilkumar S, trading as Publyq ("Publyq", "we", "us" or "our"), collects, uses, shares and protects personal information in connection with publyq.in, app.publyq.in and related features, APIs and services (the "Service"). We decide why and how this information is processed.

It covers two groups of people: people who use the Service or contact us, and people whose information appears in the public civic sources we use, such as complainants, other people mentioned in complaints, and public officials.

2. In short

  • We build civic insights from publicly available grievance information and government responses.
  • We do not publish complainants' names, phone numbers, email addresses, postal addresses, social media handles or photographs.
  • We remove personal details from complaint text where we can, and we remove records on request.
  • We do not sell personal information and we do not show advertising.
  • You can contact us with questions or grievances at any time.

3. Information we collect

3.1 Information you give us

  • Collaboration and contact forms: name, email address, phone number, what you do, and your message.
  • Correction, removal and grievance requests: your contact details, the record concerned, and any information you provide to support your request.
  • Accounts, where offered: name, email address and login details.
  • Text you type into search boxes.

3.2 Information collected automatically

  • Technical information such as IP address, browser and device type, pages viewed, time of access, referring page and error logs.
  • Information needed for security and fair use, such as request rates and blocked requests.
  • Preferences stored on your device, such as language, theme and filters (see section 15).

3.3 Publicly available civic and social media information

We collect information from public sources, including:

  • complaint references that government bodies publish on their public social media accounts;
  • the corresponding records on public government grievance portals, such as complaint number, date, category, department, location description, complaint text, status, and official responses and their dates;
  • public social media posts through which residents raise grievances; and
  • public information about public officials and elected representatives, such as name, role, area served, party and links to public profiles.

These sources can contain personal information, such as a complainant's name, contact details, address, social media handle or photographs, or personal details written into the complaint text. Information being publicly available does not mean it raises no privacy concerns, so we apply the safeguards described below.

3.4 What we do not keep or publish

We remove complainants' names, phone numbers, email addresses, postal addresses, social media handles and photographs when we collect a record, and we do not publish them. We keep a limited technical record of each collection, such as the complaint reference, the source link, the time of collection and a digital fingerprint of the source page, so that we can show where information came from.

3.5 Information we generate

From the information above we create derived information, including ward, zone and constituency mapping, standard categories, translations, groupings of similar complaints, labels such as category, severity or urgency, statistics, trends, and views of complaints by area and by the officials and representatives responsible for that area.

4. How we clean, classify, enrich and analyse data

  • Collect: we retrieve records only through public pages and public references.
  • Minimise: we remove direct identifiers and redact personal details such as phone numbers, email addresses, house numbers and personal names from complaint text, using automated tools and review. No method is perfect, so we also act on removal requests.
  • Standardise: we clean formatting and map categories and departments to standard labels.
  • Locate: where a record does not state its ward, we infer it from the location description using official boundaries.
  • Translate and group: we translate Tamil text into English and group similar complaints.
  • Analyse: we produce labels, statistics and trends, mostly at the level of wards, zones, departments and constituencies.

Information we infer is marked where practical. Status reflects what the source showed on the date of collection.

5. AI and automated analysis

  • We use an AI model to translate complaint text, and rule-based and statistical methods (keyword rules and text similarity) to classify, group and label records.
  • We do not use these tools to make decisions about individuals, to profile complainants, or to assess individual public officials. Officials are shown by the area they serve.
  • We translate complaint text with IndicTrans2, an open source model from AI4Bharat that we run on our own systems. Complaint text is not sent to an outside AI service.
  • AI generated output can be wrong. We label it as machine generated.

6. How we use information

  • To operate, maintain and secure the Service.
  • To publish civic insights in the public interest.
  • To respond to your messages, collaboration enquiries, grievances, and correction or removal requests.
  • To prevent abuse, enforce our Terms of Service and apply usage limits.
  • To improve the accuracy and usefulness of the Service.
  • To comply with law and legal process, and to establish, exercise or defend legal claims.

We do not sell personal information, use it for advertising, or build marketing profiles of individuals.

7. Legal basis and Indian privacy law

  • We handle personal information in line with the Information Technology Act, 2000 and the rules made under it, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, where they apply. We do not intend to collect sensitive personal data or information as defined in those rules.
  • The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 are being brought into force in phases. Several provisions, including those on notice, consent, individual rights and exemptions, take effect on dates notified by the Government of India. We are designing our practices with this framework in mind and will update this Policy as its provisions take effect.
  • Information you give us: we process it with your consent, for the purpose for which you gave it. You may withdraw consent at any time. Withdrawal does not affect processing that took place before it.
  • Publicly available civic information: we process it for civic transparency, research, statistical and public interest purposes. Indian law treats some publicly available personal data, and some research and statistical processing, differently from other processing. Whether and how those provisions apply depends on the source and nature of the information and on when the provisions take effect. In every case we apply the minimisation, redaction and removal practices in this Policy.
  • Legal obligations: we may process information where the law, a court order or a lawful direction requires it.

8. Sharing information

  • Publicly on the Service: only Publyq generated insights and redacted records. We never publish complainants' contact details.
  • Service providers: companies that help us run the Service, namely Vercel (website hosting), Neon (database), Supabase (accounts, sign-in and answers to our collaboration form) and Google (Sign in with Google, email through Google Workspace, and web fonts). They receive only what they need to provide their service.
  • Legal requirements: government agencies, courts or others where required by applicable law or valid legal process, or where reasonably necessary to protect the safety or rights of any person.
  • Successor entity: if the Service is transferred to a registered entity or another operator, information may be transferred to it, subject to this Policy.

9. Processing outside India

Some of our service providers may store or process information outside India. We choose providers that maintain reasonable security safeguards, and we will comply with any restrictions on transfers that the Government of India notifies under applicable law.

10. How long we keep information

InformationHow long we keep it
Collaboration and contact form submissions12 months after our last contact with you
Account informationUntil you close your account, then up to 30 days
Grievances and correction or removal requests3 years, keeping only what we need to show how the request was handled
Technical and security logs90 days, or up to 12 months where needed to investigate a security issue
Redacted copies of source pages12 months from collection
Collection records (reference, source link, time, fingerprint)For as long as we hold information derived from that record, and as needed for legal purposes
Published record level data24 months from the complaint date, after which it is kept only in aggregated form
Aggregated statistics with no personal informationWithout a fixed time limit

We may keep information for longer where the law requires it or where it is needed for an ongoing legal matter.

11. Security safeguards

We use reasonable security practices suited to the information we hold, including:

  • encryption of data in transit;
  • access limited to people who need it;
  • separation of collected records from published data;
  • redaction before information is sent to external processors;
  • logging, monitoring and rate limiting; and
  • review of the service providers we use.

No system is completely secure. If a security incident affects your personal information, we will take reasonable steps to limit its impact and will notify you and the relevant authorities, including CERT-In, where required by law.

12. Your rights and choices

Whether or not a specific law requires it, you can ask us to:

  • tell you what personal information you have given us and how we use it;
  • correct or update information you have given us;
  • delete information you have given us, or withdraw your consent;
  • redact or remove a record that contains your personal information or concerns you; and
  • review a concern about how we handle personal information.

Once the relevant provisions of the Digital Personal Data Protection Act, 2023 are in force, you will also have the rights that Act provides. These include the right to nominate a person to exercise your rights in case of death or incapacity, and the right to complain to the Data Protection Board of India after using our grievance process.

Because we remove identifiers from records, we may need the complaint reference or link to find the record that concerns you. We may ask for reasonable information to verify your request, and we will ask only for what we need. If we cannot meet a request, for example because the law requires us to keep certain information, we will explain why.

13. Correction and removal requests

If you are a complainant, a person mentioned in a complaint, or a public official, and you want information corrected, redacted or removed:

  • write to auth@publyq.in, including the link or complaint reference and what you would like us to do;
  • we acknowledge requests within 72 hours;
  • we aim to redact or remove a person's own personal information within 7 days; and
  • we aim to decide other requests within 15 days.

Removal from Publyq does not remove information from the original government portal or social media platform. Please contact them directly to change the original.

14. Children

The Service is not directed at children under 18, and we do not knowingly collect personal information from children through our forms or accounts. If you believe a child has given us personal information, please contact us and we will delete it. If a civic record mentions a child, we treat it as a priority for redaction and remove it on request. We do not track children or target advertising to them.

15. Cookies, local storage and analytics

  • Essential: we use cookies or local storage to remember preferences such as language, theme and filters, to keep you signed in, and for security and fair use.
  • Analytics: We do not use third party analytics.
  • We do not use advertising cookies.
  • You can control cookies and local storage through your browser settings. Blocking essential storage may affect how the Service works.

16. Third party links

The Service links to government portals, social media platforms and other websites. Their own privacy policies apply when you visit them.

17. Changes to this Policy

We may update this Policy as the Service or the law changes, including as provisions of the Digital Personal Data Protection Act, 2023 take effect. We will post the updated Policy on this page with a new "Last updated" date. If a change is significant, we will also give notice on the Service and, if you have an account, by email.

18. Contact and grievances

Email
auth@publyq.in

We acknowledge grievances within 72 hours and aim to resolve them within one month.