Who processes your data
CivilIndia operates https://civilindia.com and the CivilIndia mobile apps. For the purposes of the Digital Personal Data Protection Act, 2023 we are the Data Fiduciary for the personal data described here, and you are the Data Principal.
What we collect, and why
Your account. Your email address, the display name you choose, and a hash of your password. We never store your password itself — it is hashed with argon2id, which is designed so the stored value cannot be turned back into what you typed. We collect this to give you an account, to let you sign in, and to show you the titles you own.
Your age declaration. When you register you confirm you are 18 or over. CivilIndia does not knowingly create accounts for children, because the Act treats anyone under 18 as a child and requires verifiable parental consent that we are not set up to obtain. If you believe a child has registered, tell us and we will delete the account.
Your purchases. The titles you buy, the amount, the invoice, and the payment reference returned by our payment gateway. We need this to give you access to what you bought, to issue invoices, and to keep the accounting records the law requires. We never see or store your card number, UPI PIN or bank credentials — those go directly to the gateway and never reach our servers.
Your devices. Because titles are protected by digital rights management, a licence is bound to the devices you read on. We store an identifier your device derives locally, its platform and model, and when it was last seen. This is deliberately not a hardware serial number: the app sends a one-way hash of an install identifier, which changes if you reinstall. We use it to enforce the device limit and to detect account sharing, and for nothing else.
Your reading. Which title you have open and your position in it, so you can continue where you left off across devices, along with counts of pages read that feed the royalty reports we owe publishers.
Job alerts. If you ask for job alerts we store the email address you gave and the filters you chose. Nothing is sent to that address until you confirm it by opening a link we email you, and every alert carries an unsubscribe link that does not expire.
Technical data. Server logs recording IP address, user agent and the request made, kept to operate the service, investigate abuse, and meet directions issued under the CERT-In rules.
What we do not do
We do not sell your personal data. We do not share it with advertisers, we do not run advertising or third-party tracking pixels on this site, and we do not build profiles of you for anyone else’s benefit.
Who we share it with
Only those who need it to make the service work: our payment gateway, to take payment and issue refunds; our email provider, to send you account, order and alert emails; and our hosting and infrastructure providers, who store the data on our behalf. Publishers receive sales and reading figures for their own titles in aggregate — never your identity. We also disclose data where a law, a court, or a lawful government direction requires it.
Where it is stored, and for how long
Your data is stored on servers in India. We keep your account and its data for as long as the account exists, because your library and your licences depend on it. Invoices and payment records are kept for eight years, which is the retention tax law requires. Server logs are kept for 180 days, per the CERT-In directions. When you delete your account we remove your personal data, other than records we are legally required to keep.
Your rights
Under the Act you may ask us for a summary of the personal data we hold about you and what we do with it; ask us to correct or complete anything inaccurate; ask us to erase data we no longer need; withdraw a consent you gave; and nominate someone to exercise these rights if you die or become incapacitated. You may also complain to the Data Protection Board of India if we do not deal with you properly.
Much of this is self-service: your account page shows your details, your orders and your registered devices, and lets you change your name, your password, and which devices are authorised. For anything else, write to us from the contact page. We will respond within 30 days.
Cookies
We use cookies only to keep you signed in and to keep your cart. There are no advertising or analytics cookies on this site. The sign-in cookie is marked HttpOnly and Secure, so it cannot be read by scripts in your browser and is only sent over HTTPS.
Security
Passwords are hashed with argon2id. Sessions use short-lived tokens that expire in fifteen minutes, refreshed against a token we store only as a hash, so a copy of our database does not hand anyone your live session. Purchased content is encrypted at rest with AES-256-GCM. All traffic is served over HTTPS. No system is perfectly secure, and if a breach affects your personal data we will notify you and the Data Protection Board as the Act requires.
Changes
If we change this policy we will change the date at the top and, where the change is significant, tell you by email. That date is the last time this wording changed — not the day you happen to be reading it.
