# Sachet Nagarik Privacy Policy Effective date: 15 June 2026 Sachet Nagarik is a civic reporting and community coordination app. This Privacy Policy explains what information the app collects, why it is used, who may see it, and what choices users have. ## 1. Scope This Privacy Policy applies to the Sachet Nagarik mobile app, related backend services, admin portal features, support features, and public legal/support pages. Sachet Nagarik is not an emergency service. If there is an immediate danger to life, health, safety, or property, contact the relevant emergency service directly. ## 2. Information we collect Depending on how you use the app, Sachet Nagarik may collect or process the following information: - Account information, such as name, email address, profile address details, selected Palika, district, province, ward, and account role. - Email OTP verification metadata, such as verification status, OTP creation time, and login/session records. - Report information, such as category, description, location, coordinates, Palika routing information, selected ministry or department, public/private status, images, and report status. - Community post information, such as text, optional image, optional location, selected ministry routing, votes, comments, and moderation information. - Comments, replies, authority updates, internal notes, external notes, and status-change history. - Photos or images submitted with reports, posts, or admin updates. - Location data selected on the map or provided by the device while using the app. - Directory usage data needed to display public contact information for Palikas, ministries, emergency contacts, government offices, and other public resources. - Support requests sent through the in-app support form, including the description you provide and technical context needed to investigate the issue. - Safety and moderation data, such as reports of abusive content, blocked users, moderation decisions, and audit logs. - Basic technical data, such as IP address, device/platform information, app version, request timestamps, error logs, and backend diagnostic logs. For the first public release, citizen sign-in and verification use email OTP only. SMS OTP is planned for a later release and is not active unless explicitly enabled on the server. ## 3. Information you choose to submit You control the text, photos, locations, comments, and other report/post content you submit. Please avoid submitting unnecessary personal information about yourself or others. Do not submit OTP codes, passwords, private documents, medical details, financial details, or sensitive information unless it is strictly necessary for the civic issue being reported. ## 4. How we use information Sachet Nagarik uses information to: - Authenticate users using email OTP. - Create, display, route, and track civic reports. - Route reports or posts to the relevant Palika, ministry, authority, or admin account. - Show public issue feeds and community posts. - Allow users and authority users to comment, update status, and coordinate responses. - Send email notifications about reports, shared reports, shared posts, and account verification. - Maintain admin workflows, audit logs, moderation records, and safety controls. - Provide support and troubleshoot app/backend issues. - Prevent spam, abuse, fraud, harassment, false reports, duplicate submissions, and unauthorized access. - Improve reliability, performance, and user experience. - Comply with applicable law, platform policies, and legitimate operational requirements. ## 5. Public visibility Some content may be visible to other app users, including public reports, public posts, comments, report status, category, general location, photos, and public authority updates. If you choose the option to avoid public posting for a report, the report may be hidden from the public feed, but it can still be sent to the relevant authority or department with your contact details for follow-up. ## 6. Authority and admin visibility Relevant Palika, ministry, department, or authority admins may see reports or posts routed to them. They may see contact details needed to follow up, such as your verified email and profile name, unless a workflow specifically limits visibility. Authority users may also add public updates, external comments, internal notes, photos, status changes, and audit-log entries. Internal notes are intended for authority/admin users and may not be visible to citizen users. ## 7. Email notifications and recipients Sachet Nagarik may send emails for OTP login, contact verification, report alerts, shared reports, shared posts, support requests, and administrative workflows. Report emails may include report category, location, coordinates, description, location information, selected recipients, reporter details, and links to submitted images when available. Email delivery depends on configured email providers and recipient mail systems. Once an email is sent, Sachet Nagarik cannot fully control retention, forwarding, or deletion inside external inboxes. ## 8. Photos and files Photos submitted through the app may be stored in app-managed storage or object storage, such as Cloudflare R2, depending on backend configuration. The database may store image URLs, object keys, or related metadata. Images may be displayed in the app, linked in emails, shown to authority users, used for issue verification, or retained as part of the report/post record. ## 9. Location data Sachet Nagarik uses location data to place reports and posts on the map and route them to the correct Palika or relevant authority. The app may use your current location when you allow location permission, or you may manually select a location on the map. The app is designed to use location while the app is in use. It is not intended to track users continuously in the background. ## 10. Service providers Sachet Nagarik may use third-party service providers to operate the app. These may include: - Hosting and backend infrastructure providers. - PostgreSQL database hosting providers. - Object storage providers for images. - Email delivery providers. - Map tile, geocoding, and location search providers. - App distribution platforms such as Apple App Store and Google Play. - Analytics, logging, or debugging tools if added later. Service providers process data only as needed to provide their service, subject to their own policies and security practices. ## 11. Data sharing Sachet Nagarik does not sell personal information for advertising. Data may be shared: - With the public, when content is posted publicly. - With relevant Palika, ministry, authority, or department users for report handling. - With service providers needed to operate the app. - With support or moderation administrators. - When required by law, safety needs, fraud prevention, abuse investigation, or platform policy compliance. - With your consent or at your direction, such as when you share a report/post. ## 12. Data retention Account and profile data are retained while your account is active. Reports, posts, comments, photos, audit logs, moderation records, and authority workflow records may be retained as long as needed for public issue history, operational continuity, safety, abuse prevention, legal compliance, or administrative follow-up. When you delete your account, personal account details are removed from the active account record, community posts may be deleted, and civic reports may be retained as anonymized operational records. ## 13. Account deletion Citizen users can request account deletion inside the app from Settings. Account deletion removes sign-in access and personal profile contact data. Civic issue reports may remain in anonymized form where needed for public interest, issue tracking, or authority workflows. More details are available in the Account Deletion document: https://raw.githubusercontent.com/wrr094/SachetNagarik-Docs/refs/heads/main/Account%20Deletion.md ## 14. Security Sachet Nagarik uses reasonable technical and organizational safeguards to protect data, such as server-side authentication, access controls, HTTPS, provider security controls, and limited admin workflows. No internet service can be guaranteed to be completely secure. You are responsible for keeping your email account secure and for not sharing OTP codes. ## 15. Children Sachet Nagarik is intended for general civic use and is not directed specifically to children. Users should not submit personal information about children unless it is necessary for a legitimate public-interest report and is shared responsibly. ## 16. International processing Your information may be processed or stored using cloud infrastructure outside Nepal, depending on the providers used by the app. By using the app, you understand that data may be processed in locations where service providers operate. ## 17. Your choices You may: - Choose whether to create an account. - Choose whether to grant location, camera, or photo permissions. - Manually select a map location instead of using live location. - Avoid adding unnecessary personal information to reports or posts. - Use account deletion from inside the app. - Contact support for help with access, deletion, privacy, or safety issues. ## 18. Changes to this policy This Privacy Policy may be updated as the app, backend, legal requirements, or store policies change. The latest version will be published through the public policy link. ## 19. Contact For privacy questions, support, or account deletion help: - Email: wrr094@gmail.com