← Back to twocents.co.in

Privacy Policy

Effective: 24 July 2026 · twoCents Labs, Inc. [replace with legal entity + registered address]

The short version: cases are anonymous, we collect the minimum we need, we never sell or share your personal data for advertising, and you can see, correct, export or delete everything. The long version follows.

1. What we collect

Account: email address (for sign-in and recovery), hashed password or SSO token, country (for legal compliance). Content: the dilemmas you file (after automatic de-identification) and your votes — stored decoupled from your identity via pseudonymous IDs. Technical: device type, app version, crash logs, IP address (transient, for security and abuse prevention). Newsletter: email and consent record, if you sign up. We do not collect real names, contacts, precise location, or advertising identifiers.

2. Why, and on what legal basis

Running the service (contract, GDPR Art. 6(1)(b)); safety, moderation and abuse prevention (legitimate interests, Art. 6(1)(f)); analytics and the newsletter (consent, Art. 6(1)(a) — opt-in only, withdrawable anytime); legal obligations (Art. 6(1)(c)). Under India's DPDP Act 2023, we process personal data only for the purposes you consented to, with notice in English and, on request, the languages of the Eighth Schedule.

3. Cookies

Essential (always on): session security, load balancing, and remembering your cookie choice itself. Analytics (off until you opt in): anonymous, aggregated usage measurement. There are no advertising or cross-site tracking cookies on this site. Change your choice anytime via “Cookie preferences” in the footer. Consent records are kept as required by GDPR Art. 7(1).

4. Sharing

We do not sell personal data, and we do not "share" it for cross-context behavioral advertising as defined by the CCPA/CPRA. We use a small set of processors (hosting, email delivery, crash reporting) bound by data-processing agreements; the current list is available from privacy@twocents.co.in. International transfers from the EU/UK rely on Standard Contractual Clauses; transfers from India comply with DPDP §16.

5. Retention

Account data: while your account exists, then deleted within 30 days. Published cases: already de-identified; on account deletion they are removed too. Votes: aggregated permanently, individual records deleted with the account. Server logs: 90 days. Consent records: 5 years (legal requirement).

6. Your rights

Everyone: access, correction, deletion, and export of your data — in-app (Profile → Your data) or via privacy@twocents.co.in; we respond within 30 days. EU/UK (GDPR): additionally restriction, objection, portability, withdrawal of consent, and complaint to your supervisory authority (our EU representative: [name, address — appoint under Art. 27]). California (CCPA/CPRA): right to know, delete, correct, and opt out of sale/sharing — we don't sell or share, but you may still record a preference at privacy@twocents.co.in or via the footer link; we honor Global Privacy Control signals and never discriminate for exercising rights. India (DPDP): access, correction, erasure, grievance redressal, and nomination of another person to exercise your rights.

7. Contacts & officers

Data Protection Officer (GDPR): [name], dpo@twocents.co.in. Grievance Officer (India, DPDP / IT Rules): [name], grievance@twocents.co.in, [Indian address] — acknowledges within 24 hours, resolves within 15 days. General: privacy@twocents.co.in.

8. Children

twoCents is for ages 13 and up. We do not knowingly collect data from anyone under 13, in line with COPPA; suspected under-13 accounts are removed and their data deleted. Where local law sets a higher digital-consent age — GDPR Art. 8 lets EU/UK member states set it between 13 and 16, and India's DPDP Act treats everyone under 18 as a child — users below that age need verifiable consent from a parent or guardian, which we obtain before the account can be used, and we do not track, profile, or serve targeted advertising to minors.

9. Security & changes

Encryption in transit and at rest, access controls, and breach notification to regulators and affected users as required (GDPR Art. 33/34, DPDP §8(6), CA Civ. Code §1798.82). Material changes to this policy are announced in-app and by email 30 days in advance.

This is a design draft, not legal advice. Have counsel review before publishing. Bracketed items must be replaced with real entity details.