PRIVACY POLICY
Effective Date: 20-07-2026 Last Updated: 20-07-2026
Table of Contents
- Introduction
- Who We Are and How to Reach Us
- Scope of This Policy
- Definitions and Interpretation
- Summary of Key Points
- Information We Collect
- Information We Do Not Collect
- How We Use Information
- Legal Bases for Processing
- Location Information
- User-Generated Content and Public Visibility
- Community Interactions
- Anonymous Posts
- How We Share and Disclose Information
- Third-Party Services We Use
- Cookies, Local Storage, and Similar Technologies
- Device Permissions
- Your Rights and Choices
- Account Deletion
- Data Retention
- Data Security
- Community Content Disclaimer
- Verification Policy
- Moderation and Enforcement
- Children's Privacy
- International Users and Data Transfers
- Legal Frameworks and Regional Rights
- Advertising, Tracking, and Sale of Information
- Third-Party Links and External Content
- Changes to This Policy
- Contact Us and Grievance Redressal
1. Introduction
Vivaram ("Vivaram," "we," "us," or "our") is a community-driven hyperlocal information platform that helps people discover, share, and access important local information. Through the Vivaram mobile application and related websites and services (collectively, the "Services"), users can read and contribute community reports ("Naatile Samsaram"), ask and answer questions, view government notices, browse local events, and access public-interest information such as weather updates, electricity outage information, market prices, lottery results, train timings, and bus timings.
Vivaram's purpose is to improve access to reliable local information while encouraging responsible community participation. Because the Services involve personal accounts, community submissions, and location-relevant content, we want you to understand clearly what information we collect, why we collect it, how long we keep it, who we share it with, and what control you have over it.
That is what this Privacy Policy explains. We have written it to be read by ordinary people, not only lawyers. Where the law requires precise language, we use it; everywhere else, we have tried to be plain and direct.
Please read this policy together with our Terms of Service and Community Guidelines, which govern your use of the Services and the content you contribute.
2. Who We Are and How to Reach Us
Vivaram is independently developed and operated by Muhammed Rijas, together with contributors and volunteers collectively referred to as the "Vivaram Team." Vivaram is not currently operated by a registered company or incorporated entity.
For the purposes of applicable data protection laws, the person responsible for the processing of personal information described in this policy is:
Owner / Data Fiduciary: Muhammed Rijas Email: [email protected] Website: https://getvivaram.com Country: India
Members of the Vivaram Team — including developers, moderators, and volunteers — may access personal information only to the extent needed to perform their specific functions, and are bound by confidentiality and security obligations appropriate to their role.
3. Scope of This Policy
This Privacy Policy applies to:
- the Vivaram mobile application on Android, iOS, and any other supported platform;
- the Vivaram website and any web pages that link to this policy;
- account registration, guest browsing, content submission, and all community features;
- all personal information collected or processed in connection with the Services.
This policy does not apply to:
- third-party websites, services, or applications that we do not operate, even if you reach them through the Services (see Section 29);
- the practices of Google, Apple, Firebase, Cloudflare, MapTiler, or other providers, which are governed by their own privacy policies (see Section 15);
- information you voluntarily make public through Community Content, which may be seen and used by others (see Section 11).
4. Definitions and Interpretation
4.1 Definitions. In this policy:
- "Account" means a registered user profile used to access account-based features of the Services.
- "Anonymous Post" means Community Content displayed to other users without revealing the author's identity, while Vivaram retains the internal account association described in Section 13.
- "Community Content" means any content created, posted, submitted, or transmitted by users through the Services, including reports, questions, answers, notices, events, comments, replies, and correction requests.
- "Guest User" means a person who accesses publicly available parts of the Services without registering an Account.
- "Personal Information" (also "personal data") means any information that identifies, relates to, or could reasonably be linked with an identified or identifiable individual.
- "Processing" means any operation performed on Personal Information, including collection, storage, use, disclosure, and deletion.
- "Verified Badge" means an indicator applied to certain content following review by an authorized moderator or administrator, as described in Section 23.
- "Vivaram Team" has the meaning given in Section 2.
4.2 Interpretation. Headings are for convenience only and do not affect interpretation. "Including" means "including without limitation." Words in the singular include the plural and vice versa. References to laws include their amendments, re-enactments, and successor provisions. If any provision of this policy conflicts with a mandatory right you have under applicable law, the mandatory right prevails to the extent of the conflict.
5. Summary of Key Points
This summary is provided for convenience. The full policy below controls.
- Accounts are optional. You can browse much of Vivaram as a Guest User. Accounts are created with email and password (verified by email OTP) or with Google Sign-In. We do not use phone numbers, mobile OTP, or SMS verification.
- We do not track your location. We never access GPS in the background, never collect live location, and never build a movement history. The only locations we store are ones you deliberately select when posting.
- Community Content is public. Reports, questions, notices, events, and comments you post may be visible to other users. Anonymous posts hide your identity from other users, but not from Vivaram.
- We never sell your information. We share information only with the service providers needed to run the platform, when the law requires it, to protect safety, or with your consent.
- You have control. You can access, correct, export, or delete your information, manage notifications, and delete your Account.
- Community content is not guaranteed to be accurate. Vivaram is community-driven. Always verify important information — especially government, emergency, medical, transport, legal, or financial information — against official sources.
- Contact us anytime at [email protected] with privacy questions or requests.
6. Information We Collect
We collect information in three ways: information you give us, information collected automatically, and information we receive from third parties.
6.1 Information You Provide
6.1.1 Account Information. When you create an Account, we collect:
| Data element | Purpose |
|---|---|
| Name | Display identity on the platform |
| Email address | Authentication, verification, password recovery, service communications |
| Password | Stored only as a cryptographic hash; never stored in plain text |
| Profile photo | Optional profile personalization |
| Bio | Optional profile personalization |
| Preferred language | Interface and content localization |
6.1.2 Profile Location Information. You may optionally provide your district, municipality, and pincode. This helps us surface relevant local content. It is self-declared profile information — it is not derived from your device's GPS.
6.1.3 Authentication Data. If you register with email and password, we verify your email address by sending a one-time password (OTP) to that address. If you register with Google Sign-In, we receive authentication confirmation and basic profile information from Google as described in Section 6.3. Password recovery is performed through email verification. We do not offer phone number registration, mobile OTP, or SMS verification.
6.1.4 Community Content You Submit. The content of every submission you make, including:
- Naatile Samsaram reports: title, description, the location you select through location search, your anonymous-posting preference, and the municipality or district scope you choose. Naatile Samsaram does not currently support image or video uploads.
- Questions: question text and your anonymous-posting preference. Media uploads are not currently supported.
- Government Notices: title, description, source information, and related details you supply. Government Notices are not automatically verified (see Section 23).
- Local Events: title, description, category, date, time, venue, source, and scope. If you RSVP to an event, we record that association.
- Interactions: likes, comments, replies, reports, correction requests, and helpful votes.
6.1.5 Communications. If you contact us for support, to report a problem, or to exercise a privacy right, we collect the content of your communication and the contact details you use.
6.2 Information Collected Automatically
When you use the Services, we and our service providers automatically collect limited technical information:
- Device information: device platform (for example, Android or iOS), operating system version, and app version.
- Push token: a Firebase Cloud Messaging token used to deliver notifications you have enabled.
- Anonymous installation identifiers: resettable identifiers used for analytics, crash diagnostics, and abuse prevention. These are not your name, email, or device IMEI.
- Crash diagnostics: technical data about app crashes and errors, such as stack traces and device state at the time of failure, collected through Firebase Crashlytics.
- Analytics events: records of how you interact with the Services — for example, which screens you visit and which features you use — collected through Firebase Analytics.
- Performance metrics: data about app responsiveness, load times, and stability.
- Log data: standard server logs, which may include IP address, access timestamps, requested resources, and error codes. An IP address can indicate a coarse geographic area (such as a city or region); we do not use it to determine your precise location.
6.3 Information from Third Parties
- Google Sign-In: if you choose to sign in with Google, Google confirms your identity and shares basic profile information (typically your name, email address, and profile picture) according to your Google settings and the permissions you grant. We use this solely to create and authenticate your Account.
- Service providers: analytics, crash-reporting, and infrastructure providers may supply us with aggregated or diagnostic information described in Section 15.
6.4 Guest Browsing
You can browse publicly available content without an Account. Guest Users are not required to provide a name or email address. We still collect the automatic technical information described in Section 6.2, which is necessary to deliver content, maintain security, and measure reliability.
7. Information We Do Not Collect
We think it is as important to state what we do not collect as what we do. Vivaram does not:
- collect phone numbers or perform SMS or mobile OTP verification;
- access GPS or location services in the background, or at any time without a deliberate, feature-level action by you;
- collect live or real-time location;
- build, store, or analyze any history of your movements;
- access your contacts, call logs, SMS messages, or other apps' data;
- collect biometric identifiers, health data, or precise sensor data;
- use advertising identifiers to show you third-party ads (see Section 28).
If a future feature ever requires a new category of information, we will update this policy before enabling that collection and, where the law requires, obtain your consent first.
8. How We Use Information
We use the information described above for the following purposes, and only for these purposes:
8.1 Operating the Services. Creating and maintaining Accounts; authenticating sign-ins; verifying email addresses; enabling password recovery; displaying and organizing Community Content; delivering local information relevant to your selected district, municipality, or scope; operating the notification center; and providing the explore-nearby experience based on the locations attached to content.
8.2 Personalization. Presenting content in your preferred language and prioritizing local information connected to your self-declared profile location or to content scopes you interact with.
8.3 Communications. Sending verification codes, password reset links, responses to support requests, safety and policy notices, and — where you have enabled them — push notifications about relevant local activity.
8.4 Safety, Security, and Integrity. Detecting and preventing spam, fraud, scams, impersonation, and abuse; enforcing our Terms of Service and Community Guidelines; investigating reports; protecting the rights and safety of users and the public.
8.5 Improvement and Reliability. Diagnosing crashes, measuring performance, understanding aggregate feature usage, fixing defects, and developing new features. This analysis is performed on aggregated or de-identified data wherever practicable.
8.6 Legal Compliance and Protection of Rights. Complying with applicable laws, lawful requests from authorities, court orders, and legal processes; establishing, exercising, or defending legal claims; and enforcing our agreements.
We do not use your Personal Information for automated decision-making that produces legal or similarly significant effects on you. Moderation-related automated filtering is described in Section 24.
9. Legal Bases for Processing
Where applicable law requires us to state a legal basis, we rely on the following:
- Consent: for optional processing such as push notifications, profile photo upload, and analytics where required. You can withdraw consent at any time (Section 18).
- Performance of a contract: to provide the account and platform features you request.
- Legitimate interests: to secure the Services, prevent abuse, and improve reliability, balanced against your rights and expectations.
- Legal obligation: to comply with binding legal requirements, including preservation and disclosure duties.
- Protection of vital interests and public interest: in limited cases, to protect life, safety, or the integrity of public information.
Under the Digital Personal Data Protection Act, 2023 (India), the corresponding grounds are consent and the "legitimate uses" recognized by that Act, such as the voluntary provision of data for a specified purpose and compliance with law.
10. Location Information
This section exists because location privacy matters, and we want our position to be unambiguous.
10.1 What we do not do. Vivaram does not continuously track you, does not access GPS in the background, does not collect live location, and does not build any movement or location history. There is no feature in Vivaram that passively records where you are.
10.2 Voluntary location selection only. For certain community features — for example, when you file a Naatile Samsaram report — you may deliberately choose a location using the in-app location search powered by MapTiler. That search returns place names and coordinates; the place you select is then attached to that specific report so other users in that municipality or district can see it.
10.3 What we store. We store only the location you intentionally selected for that piece of content. It is associated with the content, not with your device, and it does not update as you move. Selecting a location for one post does not set a location for anything else.
10.4 Profile location. The district, municipality, and pincode in your profile (Section 6.1.2) are self-declared. They help us show you relevant local content. You can change or remove them at any time in your profile settings.
10.5 Coarse IP-derived location. Server logs may contain your IP address, from which a coarse region can sometimes be inferred. We use this only for security, abuse prevention, and aggregate analytics. We do not convert it into precise location or store it as a location history.
11. User-Generated Content and Public Visibility
11.1 Community-driven platform. Most of what you see on Vivaram is created by users. When you submit Community Content, you should assume it may be visible to other users, including Guest Users, according to the scope you select (for example, a municipality or district).
11.2 Current content types and media limitations. At present, Naatile Samsaram, Questions, Government Notices, and Local Events are text-based; image and video uploads are not supported. Future versions may introduce media support. If that happens, we will update this policy to explain what is collected, how media is stored (including any use of Cloudflare R2), and what controls you will have, before the feature launches.
11.3 Government Notices. Any user may create a Government Notice. Notices are not automatically verified at submission. A notice may later receive a Verified Badge after review by an authorized moderator or administrator (Section 23). Regardless of any badge, you should confirm official government information through official government channels before acting on it.
11.4 Your responsibility. You are responsible for the content you submit and for ensuring you have the right to share it. Do not post other people's personal information, confidential information, or content that violates law or our Community Guidelines.
11.5 Persistence. Public content may be cached, indexed, copied, or retained by others even after you delete it or delete your Account. Vivaram cannot control copies made by other users or third parties.
12. Community Interactions
Users can engage with content through likes, comments, replies, reports, correction requests, and helpful votes. These interactions are stored and may be displayed publicly — for example, a comment appears under your display name (unless the underlying feature is anonymous), and counts of likes or helpful votes are shown on content.
Reports and correction requests are treated as moderation signals: they are visible to moderators and administrators, not to the general public, and we do not disclose a reporter's identity to the reported user except where the law requires.
The Services do not currently include a share function for redistributing content to external platforms or users. If sharing is introduced later, this policy will be updated to describe any associated data processing.
13. Anonymous Posts
Certain features, including Naatile Samsaram and Questions, allow you to post anonymously.
- What anonymity means: your name, profile photo, and profile link are hidden from other users. The content appears without attribution to you.
- What anonymity does not mean: Vivaram internally retains the association between the post and your Account. Anonymous posting is a display preference, not a deletion of authorship records.
We retain this association because anonymity cannot be a shield for abuse. The internal association may be used for abuse prevention, platform security, fraud investigation, community moderation, and compliance with law — for example, responding to a lawful request concerning illegal content posted anonymously. We do not reveal the author of an anonymous post to other users, and we resist disclosure except where legally compelled or necessary to protect safety and rights.
If you post anonymously, remember that the content itself can still identify you — names, places, and details you include may make you recognizable to people who know the context.
14. How We Share and Disclose Information
We do not sell your Personal Information. We do not rent it, trade it, or disclose it to third parties for their own marketing. We disclose Personal Information only in the following limited circumstances:
14.1 Service providers. We share information with vendors that perform services for us — hosting, storage, analytics, crash reporting, notifications, authentication, and location search — strictly as needed to deliver those services and under contractual or platform terms that restrict their use of the information. Section 15 identifies these providers.
14.2 Other users, through your actions. Community Content and public interactions you choose to make are visible to other users as described in Sections 11 and 12. This is disclosure caused by your own publishing choices.
14.3 Legal requirements. We may disclose information if we reasonably believe it is required by applicable law, regulation, legal process, or an enforceable governmental request — for example, a court order or a lawful request from law enforcement. Where permitted, we will attempt to notify affected users before complying.
14.4 Safety and protection of rights. We may disclose information when we believe in good faith that it is necessary to protect the safety of any person, prevent fraud or abuse, protect the integrity of the Services, or defend our legal rights.
14.5 Business transfers. If the operation of Vivaram is ever transferred to another person or entity — for example, through incorporation of the project, an acquisition, or a merger — user information may be transferred as part of that transaction. Any successor will be required to honor this policy unless you are notified of changes and given the choices required by law.
14.6 Aggregated and de-identified information. We may share aggregated or de-identified information that cannot reasonably be used to identify you — for example, total reports filed in a district or aggregate app-usage statistics — for research, transparency, or public-interest purposes.
15. Third-Party Services We Use
The Services rely on the following providers. Each processes limited information on our behalf or under its own terms; we encourage you to read their privacy policies.
| Provider | Purpose | Typical data involved |
|---|---|---|
| Firebase Analytics (Google) | Usage analytics | Anonymous installation identifiers, app interaction events |
| Firebase Crashlytics (Google) | Crash reporting | Crash logs, device and OS state, installation identifiers |
| Firebase Cloud Messaging (Google) | Push notifications | Push token, notification delivery metadata |
| Firebase Remote Config (Google) | Feature management | Installation identifiers, app version, configuration requests |
| Google Sign-In (Google) | Authentication | Name, email, profile picture (per your Google permissions) |
| Cloudflare R2 | File storage | Stored content and files associated with the Services |
| MapTiler | Location search and geocoding | Search queries you type, selected place results |
Notes on the above:
- Firebase services operate under Google's data processing terms for Firebase. Analytics and crash data are used to operate and improve the Services, not to build advertising profiles.
- MapTiler receives the text of your location search queries in order to return matching places. If you never use location search, MapTiler receives nothing from you.
- Cloudflare R2 stores content we host. Today that is limited, as uploads are not supported; if media features launch, uploaded files will be stored there.
- These providers may process data in data centers outside your country. See Section 26 for how international transfers are safeguarded.
We may add or replace providers as the platform evolves. Material changes will be reflected in an updated version of this policy.
16. Cookies, Local Storage, and Similar Technologies
16.1 Local storage in the app. The Vivaram app stores certain information on your device to make the Services fast and convenient, including:
- authentication state (so you stay signed in);
- user preferences such as language and theme;
- cached content (so recently viewed information loads quickly);
- notification settings.
This information remains on your device unless the app communicates it to our servers for its normal function (for example, applying your notification settings). Clearing app data or uninstalling the app removes it, though you will need to sign in again and reset preferences.
16.2 Website cookies. If Vivaram is accessed through a web browser, we and our service providers may use cookies and similar technologies to keep you signed in, remember preferences, secure sessions, and understand aggregate site usage. You can control cookies through your browser settings; disabling them may affect sign-in persistence and other features.
16.3 Mobile equivalents. The mobile app does not use browser cookies. Instead it uses functionally equivalent technologies — secure authentication tokens and local storage — to maintain sessions and preferences. These technologies serve the same purposes described above and are subject to the same limitations.
16.4 What we do not use. We do not use cookies or similar technologies for third-party advertising, cross-app tracking, or behavioral profiling for ads (see Section 28).
17. Device Permissions
Vivaram requests only the permissions a feature genuinely needs, at the time you use that feature:
- Internet (required). The Services are online; internet access is necessary to retrieve and submit content.
- Notifications (optional). Used to deliver push notifications you choose to receive — for example, local updates, replies, or announcements. You can disable notifications in your device settings or in the app at any time; the rest of the app continues to work.
- Camera (not currently used). Would be requested only if a future media feature allows taking photos within the app, and only when you invoke that feature.
- Photos / media library (not currently used). Would be requested only if you choose to upload existing media in a future feature. We will never scan or access your library for any other purpose.
Vivaram does not request, and the Services do not need, access to your location, contacts, microphone, call logs, SMS, or calendar. If a future version ever requires a new permission, we will request it transparently at the point of use and update this policy.
18. Your Rights and Choices
Subject to applicable law, you have the following rights and controls:
18.1 Access. You may request confirmation of the Personal Information we hold about you and a copy of it.
18.2 Correction. You may correct inaccurate or incomplete information. Much of this — name, bio, profile photo, preferred language, district, municipality, pincode — can be edited directly in your profile settings.
18.3 Email change. You may change the email address associated with your Account; the new address will be verified by email OTP.
18.4 Notification preferences. You may opt in or out of push notifications at any time.
18.5 Withdrawal of consent. Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing already carried out. Withdrawal may disable the related feature (for example, disabling notifications stops push delivery).
18.6 Deletion and erasure. You may delete your Account as described in Section 19, and you may request erasure of specific Personal Information where the law provides that right.
18.7 Data portability. Where required by applicable law, you may request your Personal Information in a structured, commonly used, machine-readable format.
18.8 Objection and restriction. Where applicable law provides, you may object to certain processing or request its restriction, for example processing based on legitimate interests.
18.9 Grievance and complaints. You may raise privacy grievances with us directly (Section 31). You may also have the right to complain to a data protection authority in your jurisdiction.
18.10 How to exercise your rights. Contact us at [email protected] with your request. To protect your Account, we may need to verify your identity — typically by confirming control of your registered email address. We aim to acknowledge requests promptly and to substantively respond within 30 days, or within the period required by applicable law. We do not discriminate against you for exercising privacy rights.
18.11 Limits. Rights are not absolute. We may decline or limit a request where the law permits — for example, where fulfilling it would compromise another person's privacy, where we must retain information for legal compliance, or where a request is manifestly unfounded or repetitive. If we decline, we will explain why, where the law allows us to do so.
19. Account Deletion
19.1 How to delete. You may permanently delete your Account from within the app's account settings or by contacting us at [email protected]. In-app deletion is the fastest method.
19.2 What deletion does. When your Account is deleted:
- your profile information (name, email, hashed password, profile photo, bio, preferred language, district, municipality, pincode) is removed from active systems or anonymized;
- your authentication credentials and push tokens are deactivated;
- your profile stops appearing on the Services, and you can no longer sign in.
19.3 What may remain. Deletion is subject to limited retention exceptions. We may retain certain information, for limited periods, where necessary for:
- legal obligations — records we must keep under applicable law;
- fraud prevention and platform security — for example, records needed to stop a banned user from re-registering;
- dispute resolution — information relevant to an ongoing complaint, investigation, or legal claim;
- backup restoration — residual copies in encrypted backups, addressed in Section 19.5.
19.4 Community Content after deletion. Content you posted may remain visible after Account deletion, either anonymized (author shown as a deleted or anonymous user) or, where you request and the law permits, removed. Anonymous posts already display no identity. We may retain and display content that has become part of the community record (for example, a thread others have replied to), subject to applicable law.
19.5 Backups. Copies of deleted data may persist in backups for the duration of our backup cycle (Section 20). Backups are access-restricted and used only for disaster recovery; they are not used to restore deleted Accounts or for any other purpose. Deleted data is purged from backups in the ordinary course as backup sets expire.
19.6 Irreversibility. Account deletion is permanent. It cannot be undone, and a deleted Account cannot be recovered. Deactivation, where offered, is the reversible alternative.
20. Data Retention
We keep Personal Information only as long as needed for the purposes in this policy, after which it is deleted or anonymized. Retention periods depend on the type of information and the reasons we hold it:
| Category | Typical retention |
|---|---|
| Active Account data | For the life of the Account |
| Deleted Account data | Purged or anonymized from active systems within approximately 30–90 days of deletion, except retained exceptions (Section 19.3) |
| Inactive Accounts | Reviewed after an extended period of inactivity (for example, 24 months); we may notify you and, absent response, delete or deactivate the Account |
| Community Content | While the Account exists and thereafter as described in Section 19.4, subject to moderation removal and legal holds |
| Server logs | Generally 30–180 days, longer only where a security investigation or law requires |
| Security and audit records | Generally up to 24 months, or longer where an incident or legal obligation requires |
| Analytics (identifiable) | Limited periods consistent with the provider's configuration; we favor the shortest useful retention |
| Crash diagnostics | Per Crashlytics retention defaults, then deletion or aggregation |
| Backups | Rolling cycles, generally weeks to a few months; expired backups are destroyed |
| Aggregated / de-identified data | May be retained indefinitely, as it no longer identifies anyone |
We periodically review retained data and shorten retention where a purpose has lapsed. Legal holds, active disputes, and investigations can extend any period above for the relevant records.
21. Data Security
We protect Personal Information with layered technical and organizational measures appropriate to the scale and sensitivity of the Services, including:
- Encryption in transit: all communication between the app, website, and our servers uses HTTPS/TLS.
- Password hashing: passwords are stored only as strong cryptographic hashes; we cannot read your password and neither can anyone else who accesses the database.
- Access controls and least privilege: access to production systems and Personal Information is limited to the minimum set of people and services that need it, and only for defined purposes.
- Infrastructure monitoring: servers and services are monitored for availability, intrusion indicators, and anomalous activity.
- Server security: hardened configurations, firewalls, network restrictions, and timely patching of operating systems and dependencies.
- Authentication safeguards: email verification, hashed credentials, token-based sessions, and protections against brute-force and credential-stuffing attempts.
- Fraud and abuse detection: automated and manual systems to detect spam, fake accounts, scams, and coordinated abuse.
- Audit logging: records of administrative and security-relevant actions, retained as described in Section 20.
- Regular updates: the app, its libraries, and server software are updated to address vulnerabilities as fixes become available.
No system is perfectly secure. Despite these measures, we cannot guarantee absolute security, and you should not assume any online service is immune to breach. Use a strong, unique password; do not share your credentials; keep your device updated; and be cautious of messages claiming to be from Vivaram that ask for your password or OTP — we will never ask for those outside the official sign-in and verification flows. If we become aware of a breach affecting your Personal Information, we will notify you and any authority where the law requires, and we will describe what happened, what is affected, and what we are doing about it.
22. Community Content Disclaimer
Vivaram is community-driven. Community Content is created by users and third parties, and it represents the views of its authors — not the views of Vivaram or the Vivaram Team.
We do not guarantee the accuracy, completeness, timeliness, or reliability of any Community Content. Information on the platform may be wrong, outdated, incomplete, or misleading, whether posted innocently or deliberately.
You should independently verify important information before relying on it, especially information concerning:
- government matters — schemes, notices, deadlines, and official procedures;
- emergencies and public safety — hazards, alerts, and advisories;
- medical and health information;
- transportation — train and bus timings, cancellations, and schedules;
- legal matters;
- financial decisions — including market prices and lottery results;
- public safety generally.
For authoritative information, consult official government sources, licensed professionals, and the relevant service operators. Content on Vivaram is not professional, legal, medical, or financial advice, and reliance on it is at your own risk. If you find content that is inaccurate or dangerous, report it — community reporting is part of how the platform stays trustworthy.
23. Verification Policy
23.1 What verification is. Certain content — most notably Government Notices — may receive a Verified Badge after review by an authorized moderator or administrator. Verification means a reviewer examined the submission, for example against a cited source or known official information, and found it consistent at the time of review.
23.2 Who verifies. Verification is performed only by moderators and administrators designated for that purpose within the Vivaram Team. Ordinary users cannot verify content.
23.3 What verification is not.
- A Verified Badge is not an endorsement of the content's viewpoint.
- It is not a guarantee of accuracy, completeness, or continued validity — verified information can become outdated.
- It is not a substitute for confirming the information with the issuing authority.
- The absence of a badge does not mean content is false; it means it has not been reviewed. Most content on Vivaram is, and will remain, unverified.
23.4 Revocation and errors. Verification may be withdrawn if content is found to be inaccurate or materially changed. If you believe a Verified Badge was applied in error, report the content with your reasons.
24. Moderation and Enforcement
24.1 Why we moderate. Moderation protects the reliability of local information and the safety of the community. Our enforcement covers, at minimum: spam, misinformation likely to cause harm, harassment and abuse, hate content, scams and fraud, impersonation, illegal content, and violations of the Community Guidelines.
24.2 How moderation works. Moderation combines automated systems (for example, spam and abuse detection) with human review by moderators and administrators. Automated systems may flag, rate-limit, or hold content for review; consequential actions are generally confirmed by human reviewers. User reports are a primary input into this system.
24.3 Enforcement actions. Depending on severity and history, enforcement may include content removal, content labeling, reduced distribution, warnings, temporary suspension, or permanent account bans. For illegal content, we may preserve records and report to appropriate authorities where the law requires or permits.
24.4 Appeals. If your content is removed or your Account is suspended or banned and you believe the decision was wrong, you may appeal by contacting [email protected] or the appeals channel identified in the Community Guidelines. Appeals are reviewed by someone other than the original decision-maker where practicable. We aim to respond to appeals within a reasonable period.
24.5 Abuse of reporting. Knowingly false or bad-faith reports, and attempts to manipulate moderation, are themselves violations and may result in enforcement against the reporter.
24.6 Transparency. As the platform matures, we intend to publish periodic transparency information about enforcement volumes, such as the number of reports, removals, suspensions, and appeals.
25. Children's Privacy
The Services are intended for a general audience and are not directed at children. We do not knowingly collect Personal Information from children below the age of digital consent applicable in their jurisdiction — for example, under 18 in India for the purposes of the DPDP Act without verifiable parental consent, under 13 in the United States under COPPA, and under the age of consent specified by EU/EEA member states under the GDPR (13 to 16 depending on the country).
Because Vivaram deals with local civic information, some content may be of interest to families, but account-based features are not designed for children. If we learn that a child below the applicable age has created an Account or provided Personal Information without required consent, we will delete the Account and the associated Personal Information. If you are a parent or guardian and believe your child has provided us Personal Information, contact us at [email protected] and we will act promptly.
26. International Users and Data Transfers
26.1 Where data is processed. The Services run on cloud infrastructure. Information you provide may be transferred to, stored, and processed in countries other than your own — including countries where our service providers (such as Google/Firebase, Cloudflare, and MapTiler) operate data centers. Those countries may have data protection laws different from, and potentially less protective than, yours.
26.2 Safeguards. When Personal Information is transferred internationally, we rely on appropriate safeguards, which may include:
- the contractual data protection terms of our service providers, including their commitments to recognized transfer mechanisms (such as standard contractual clauses) where applicable;
- transfer only to the extent necessary to provide the Services;
- encryption in transit and at rest across providers;
- the access-control and least-privilege practices described in Section 21.
26.3 Your choice. By using the Services, you understand that your information will be processed as described in this policy, including internationally. Where your local law grants you rights regarding international transfers, we will honor them as required.
27. Legal Frameworks and Regional Rights
Vivaram strives to process Personal Information responsibly and in accordance with applicable law. We do not claim certifications or formal compliance attestations we do not hold; instead, we design our practices around the following frameworks and honor the rights they provide.
27.1 India — Digital Personal Data Protection Act, 2023 (DPDP Act). For users in India: we act as the data fiduciary for Personal Information processed through the Services. We process personal data with consent or for legitimate uses permitted by the Act; we honor rights of access, correction, erasure, and grievance redressal; we apply reasonable security safeguards; and we will notify affected users and the Data Protection Board of a personal data breach as required. Grievance contact: Section 31.
27.2 EU/EEA, UK, and Switzerland — GDPR principles. Where the GDPR or equivalent law applies, you have the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent, and the right to lodge a complaint with a supervisory authority. Our legal bases are set out in Section 9. Given Vivaram's current scale, we have not appointed an EU representative or Data Protection Officer; if the law comes to require either, we will appoint one and update this policy.
27.3 California — CCPA/CPRA principles. For California residents: in the preceding 12 months we have collected the categories of personal information described in Section 6 (identifiers such as name and email; internet or electronic activity information such as analytics events; and coarse geolocation, to the extent an IP address implies region). We collect these for the business purposes in Section 8. We do not sell personal information and we do not share it for cross-context behavioral advertising. California residents may request to know, access, correct, and delete their personal information, and will not be discriminated against for doing so.
27.4 App-store requirements. Vivaram is designed to meet the Google Play User Data Policy and Apple App Store privacy requirements, including accurate privacy disclosures, data-safety declarations, and permission justifications. The declarations we publish on each store listing reflect the practices described in this policy.
27.5 Other jurisdictions. Privacy rights exist in many other jurisdictions. Whatever your location, you may contact us with a privacy request and we will honor it to the extent required by the law that applies to you.
28. Advertising, Tracking, and Sale of Information
- We do not sell Personal Information — to anyone, for any purpose.
- We do not display third-party advertising in the Services, and we do not share your information with advertising networks.
- We do not track you across other companies' apps or websites, and we do not use advertising identifiers.
- Analytics collected through Firebase are used to understand and improve the Services, not to profile you for ads.
If Vivaram ever introduces advertising or any form of paid promotion, we will update this policy before launch, clearly distinguish sponsored content, and provide any choices the law requires.
29. Third-Party Links and External Content
Community Content and notices may reference or link to third-party websites, government portals, or services we do not operate — for example, an official department page cited as the source of a notice. We are not responsible for the content, accuracy, or privacy practices of third-party sites. Their own privacy policies govern your interactions with them, and we encourage you to read those policies before providing them any information.
30. Changes to This Policy
We may update this Privacy Policy as the Services evolve or as law requires. When we make changes:
- we will revise the "Last Updated" date at the top;
- for material changes — for example, collecting a new category of data or changing how we share information — we will provide advance notice through the app, by email to your registered address, or on our website, and where the law requires, we will obtain your consent;
- the previous version will be superseded as of the effective date stated in the notice.
Your continued use of the Services after an update takes effect constitutes acceptance of the revised policy, except where the law requires consent, in which case we will ask for it. If you do not agree with an update, you should stop using the Services and may delete your Account under Section 19. We encourage you to review this page periodically.
31. Contact Us and Grievance Redressal
For privacy questions, requests, complaints, or grievances — including requests to exercise any right in Section 18 — contact:
Owner / Data Fiduciary: Muhammed Rijas (for and on behalf of the Vivaram Team) Email: [email protected] Website: https://getvivaram.com Country India
We aim to acknowledge privacy requests within a reasonable time and to resolve them within 30 days or the period required by applicable law. If your concern is not resolved, you may have the right to escalate to the data protection authority in your jurisdiction.
© 2026 Vivaram. All rights reserved.