1.The short version
CivicLens is a free site that publishes daily news summaries for Indian districts. We would rather hold none of your data than hold some of it, so this policy is mostly a list of things we do not do.
- No advertising cookies, no tracking cookies, no ad network, no Google Analytics, no social pixels, no session recording.
- We count page views in a way that cannot be traced back to you, and you can switch that off.
- We never sell, rent or share your information for marketing. There is nobody to sell it to and we would not do it anyway.
- If you subscribe to the daily digest, we keep your email address and the places you picked. That is it — no name, no phone number, no address.
Everything below is the detail behind those four lines.
2.What we collect
If you just read the site
Each page view is recorded as one row containing: the page path, the type of page and the district or state slug, the hostname of the site that linked you here (the hostname only — never the full referring URL or anything in its query string), any campaign tags in the link you followed, an approximate country and region, your device type, browser and operating system, and a per-day visitor hash described in the next section.
Your IP address is not stored. It is used for a fraction of a second to compute the hash and to look up an approximate country, and then it is gone.
If you subscribe to the email digest
We store your email address and the settings you chose:
- the states you selected, and up to five specific districts
- whether you want the dark or light version of the email
- a random token that identifies your preferences page and your unsubscribe link
- whether you have unsubscribed, and the date you signed up
We do not ask for your name, phone number, postal address, age or anything else, and there is no field to enter them.
If you flag a summary
Every summary has a “Flag this summary” button. If you use it, we store the reason you picked, anything you typed, the page it came from, a one-way hash of your IP address so that one person cannot bury us in thousands of reports, and your email address only if you chose to give one so we can reply.
Keeping the site standing up
Public endpoints — subscribing, changing preferences, the admin login — are rate limited. To do that we build a key out of your IP address and the name of the endpoint, hash it with SHA-256, and store only the hash alongside a counter and a timestamp. The hash cannot be turned back into an IP address, and the counter resets once the time window passes.
3.How our analytics work
Our analytics are first-party and cookieless. We wrote them, they write to our own database, and nothing is sent to a third party. There is no analytics vendor involved at all.
The only thing that connects two page views to each other is a value we call the visitor hash. It is the SHA-256 hash of your IP address, your browser’s user-agent string, and a secret salt that changes every day. It is computed on our server at the moment of the request and stored on its own; the IP address that went into it is never written down.
The practical effect: within a single day, your visits produce the same hash, so we can say “about 400 people read Pune today” rather than only “900 pages were opened”. The next day the salt changes, the same person produces a completely different hash, and there is no way — including for us — to link the two. It is not a persistent identifier, it cannot be reversed, and it follows you nowhere.
We do not fingerprint devices beyond that, do not track you across other websites, and do not record your screen, mouse movements or scrolling.
Opting out
Choose Opt out of analytics in the notice at the bottom of the page. That writes a flag called civiclens-analytics-optout into your browser’s local storage, and while it is there the site sends nothing to our analytics endpoint. The flag lives in your browser, so it applies to that browser only, and clearing your site data clears it too.
5.If you subscribe to the digest
Subscribing gets you one email a day, at 2:00 PM IST, covering the states and districts you chose. There is a welcome email when you sign up. There is nothing else — no marketing, no “partner offers”, no re-engagement campaigns.
Your address is passed to Brevo, the service that actually delivers the mail, because it cannot be delivered otherwise. Brevo handles it as our processor and does not get to use it for anything of their own.
Every email carries an unsubscribe link and a link to your preferences page, both keyed to your private token. You can change your states and districts, or stop the emails, at any time without contacting us.
Unsubscribing marks your record as unsubscribed and we stop sending. If you would rather the record was deleted outright, email hello@theciviclens.tech and we will delete it.
6.Who else is involved
This is the complete list of outside services CivicLens uses. There are no others.
- Supabase — hosts our database. Everything described in this policy is stored there.
- Vercel — hosts and serves the website. Like any web host, their edge network sees your IP address and your request in order to send you the page.
- Brevo — sends the welcome email and the daily digest. Receives your email address, and only if you subscribed.
- Google News — we fetch public RSS headline feeds to build the summaries. That request is made by our server on a schedule; nothing about you is part of it.
- open-meteo.com — district pages show local weather. Your browser calls open-meteo directly using a fixed coordinate for the district page you are on. It is not your device’s location: we never ask for location permission and could not use it if you gave it. As with any request your browser makes, open-meteo sees your IP address as the caller.
- Google Fonts — the site’s typefaces load from fonts.googleapis.com and fonts.gstatic.com, so your browser contacts Google to fetch them and Google sees your IP address.
No advertising networks, no analytics SDKs, no embedded social widgets, no comment platforms, no chat widgets, no tag managers.
7.Why we are allowed to hold this
Under India’s Digital Personal Data Protection Act, 2023, we process your email address on the basis of your consent, which you give by subscribing and can withdraw at any time by unsubscribing. We ask for nothing else, so there is nothing else that needs a basis.
Page-view records are designed not to identify anyone. Where the law treats them as personal data anyway, we rely on legitimate interests: a one-person project needs to know which districts people actually read so it can spend its limited time on the right things. The same applies to the hashed rate-limit and flag records, which exist to stop a free public site being spammed off the internet.
If you are reading from the EU or the UK, the equivalent bases are Article 6(1)(a) consent for the email digest and Article 6(1)(f) legitimate interests for analytics and abuse prevention.
8.How long we keep things
- Page views — 180 days. A scheduled job deletes anything older, automatically. Nobody has to remember to do it.
- Rate-limit records — a hashed key and a counter that resets as each time window passes. There is nothing in them to identify.
- Subscribers — until you unsubscribe or ask us to delete the record.
- Flag reports — kept while we look into the flagged summary, and afterwards as a record of what we changed and why. There is no automatic deletion schedule for these; email us and we will remove yours.
9.Your rights, and how to actually use them
You can ask what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Email hello@theciviclens.tech and say which you want. We will reply as soon as we can — realistically a few days — and in any event within 30 days.
The honest answer for most people is that there is nothing to look up. If you have only read the site, the analytics records cannot be matched to you, so we could not find “your” rows even if we wanted to. If you subscribed, the whole of what we hold is your email address and your chosen places, and you can see and change it yourself on your preferences page using the link in any digest.
If you think we have handled something badly and we have not fixed it, you can complain to the Data Protection Board of India, or to your national supervisory authority if you are in the EU or the UK.
10.Children
CivicLens is not directed at children and we do not knowingly collect any data from anyone under 18. Indian law requires verifiable parental consent before processing a child’s personal data, and we are not set up to obtain it — so please do not subscribe to the email digest if you are under 18.
Reading the site is fine at any age; nothing on the public pages asks for personal information. If you believe a child has subscribed, email us and we will delete the record.
11.Where your data is processed
Supabase, Vercel and Brevo all operate internationally, so data may be stored or processed on servers outside India, including in the European Union and the United States. We use each of them on their standard terms as a customer, and we do not have the leverage of a large company to negotiate anything different. If that matters to you, the simplest protection is to read the site without subscribing: then there is nothing of yours to move anywhere.
12.Changes to this policy
If what we collect changes, this page changes with it and the “last updated” date at the top moves. We do not keep an archive of previous versions. If a change means we start collecting something new about you, we will say so plainly here rather than burying it in a rewrite.
Questions about this page?
Email hello@theciviclens.tech. CivicLens is run by one person, so a reply usually takes a few days.