Effective: 24 July 2026 · twoCents Labs, Inc. [replace with legal entity + registered address]
The short version: cases are anonymous, we collect the minimum we need, we never sell or share your personal data for advertising, and you can see, correct, export or delete everything. The long version follows.
Account: email address (for sign-in and recovery), hashed password or SSO token, country (for legal compliance). Content: the dilemmas you file (after automatic de-identification) and your votes — stored decoupled from your identity via pseudonymous IDs. Technical: device type, app version, crash logs, IP address (transient, for security and abuse prevention). Newsletter: email and consent record, if you sign up. We do not collect real names, contacts, precise location, or advertising identifiers.
Running the service (contract, GDPR Art. 6(1)(b)); safety, moderation and abuse prevention (legitimate interests, Art. 6(1)(f)); analytics and the newsletter (consent, Art. 6(1)(a) — opt-in only, withdrawable anytime); legal obligations (Art. 6(1)(c)). Under India's DPDP Act 2023, we process personal data only for the purposes you consented to, with notice in English and, on request, the languages of the Eighth Schedule.
We do not sell personal data, and we do not "share" it for cross-context behavioral advertising as defined by the CCPA/CPRA. We use a small set of processors (hosting, email delivery, crash reporting) bound by data-processing agreements; the current list is available from privacy@twocents.co.in. International transfers from the EU/UK rely on Standard Contractual Clauses; transfers from India comply with DPDP §16.
Account data: while your account exists, then deleted within 30 days. Published cases: already de-identified; on account deletion they are removed too. Votes: aggregated permanently, individual records deleted with the account. Server logs: 90 days. Consent records: 5 years (legal requirement).
Everyone: access, correction, deletion, and export of your data — in-app (Profile → Your data) or via privacy@twocents.co.in; we respond within 30 days. EU/UK (GDPR): additionally restriction, objection, portability, withdrawal of consent, and complaint to your supervisory authority (our EU representative: [name, address — appoint under Art. 27]). California (CCPA/CPRA): right to know, delete, correct, and opt out of sale/sharing — we don't sell or share, but you may still record a preference at privacy@twocents.co.in or via the footer link; we honor Global Privacy Control signals and never discriminate for exercising rights. India (DPDP): access, correction, erasure, grievance redressal, and nomination of another person to exercise your rights.
Data Protection Officer (GDPR): [name], dpo@twocents.co.in. Grievance Officer (India, DPDP / IT Rules): [name], grievance@twocents.co.in, [Indian address] — acknowledges within 24 hours, resolves within 15 days. General: privacy@twocents.co.in.
twoCents is for ages 13 and up. We do not knowingly collect data from anyone under 13, in line with COPPA; suspected under-13 accounts are removed and their data deleted. Where local law sets a higher digital-consent age — GDPR Art. 8 lets EU/UK member states set it between 13 and 16, and India's DPDP Act treats everyone under 18 as a child — users below that age need verifiable consent from a parent or guardian, which we obtain before the account can be used, and we do not track, profile, or serve targeted advertising to minors.
Encryption in transit and at rest, access controls, and breach notification to regulators and affected users as required (GDPR Art. 33/34, DPDP §8(6), CA Civ. Code §1798.82). Material changes to this policy are announced in-app and by email 30 days in advance.
This is a design draft, not legal advice. Have counsel review before publishing. Bracketed items must be replaced with real entity details.