CivilOS™ Open the app →
Privacy Policy

Privacy Policy

Last updated: 20 July 2026

This policy explains what personal data CivilOS™ (thecivil.site) collects, why it is collected, how long it is kept and what rights you have. It is written to align with India's Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Who we are

CivilOS is an independently developed civil-engineering platform operated from Jaipur, Rajasthan, India by Abhimanyu Tiwari, who acts as the Data Fiduciary for the purposes of the DPDP Act.

Contact for privacy questions: abhimanyutiwari94@gmail.com · +91 8005983291

2. What we collect, and why

2.1 If you do not create an account

You can use most of CivilOS without signing in. In that case your drawings, plans, BOQs and models are stored only in your own browser (localStorage / IndexedDB) — they are never uploaded to us.

DataWhy
A random visitor ID (stored in your browser)To count visitors and distinguish new from returning, without identifying you
Page views, time spent per section, time zoneTo understand which tools are actually useful
Approximate city/country, derived from your IP addressBasic audience geography. Your IP address is not stored — only the resulting city/country label is retained

2.2 If you create an account (Team Workspace)

DataWhy
Name and email addressTo identify your account and let teammates recognise you
PasswordStored only as a salted scrypt hash — we cannot read or recover your password
Session cookieTo keep you signed in. Strictly necessary; no advertising or tracking cookies are used
Team name, role, membership, activity logTo operate teams, roles and permissions
Project data you choose to save to the cloudOnly when you press "Save my work" or "Save to team"

2.3 Live Site Audits

DataWhy
Site photographs you captureInspection evidence attached to your audit record
GPS coordinates and accuracyTo stamp where an inspection took place. Location is requested with your device's permission and can be refused — audits still work without it
Auditor name, designation, company; contractor nameTo make the audit record meaningful and attributable
Please do not photograph people's faces, identity documents or other personal information unless you have their consent. Audit photos are visible to your team members.

2.4 Task management

If you assign a task to someone, you may enter their name, email and WhatsApp number. You are responsible for having a lawful basis to share their details with us. This information is used only to label the assignment and to let you send them their task list; we do not message them ourselves — WhatsApp and email are opened on your own device for you to send.

2.5 AI features

When you use the AI Engineer, quantity takeoff or drawing-reading features, the text and any file you attach are sent to Anthropic PBC (our AI provider) for processing, and the answer is returned to you. Do not paste confidential or personal data you are not permitted to share. See Anthropic's privacy terms at anthropic.com/legal/privacy.

3. What we never do

4. Where your data is stored

Account and project data is stored on servers operated by Render Services, Inc. in the United States, on an encrypted persistent disk with automatic daily backups retained for 7 days. Because of this, your data is transferred outside India. Sub-processors we rely on:

5. How long we keep it

DataRetention
Account, teams, cloud projects, audits, tasksUntil you delete them or ask us to delete your account
Login sessions30 days, then automatically expire
Password reset codes30 minutes
7-day cloud vault (passcode-protected temporary storage)7 days, then automatically deleted
Locally saved projects in your browser180 days from last opening (on your device only)
Aggregate visitor statisticsRetained as anonymous totals; not linked to any identified person

6. Your rights under the DPDP Act

You have the right to:

To exercise any of these, email abhimanyutiwari94@gmail.com with the subject "DPDP request". We aim to respond within 30 days.

7. Children

CivilOS is a professional engineering tool intended for users aged 18 and above. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

8. Security

We use HTTPS everywhere, hashed passwords, HttpOnly session cookies, rate limiting, a strict Content Security Policy, and AES-256-GCM encryption for the passcode vault. No system is perfectly secure; if we become aware of a personal data breach we will notify affected users and the Data Protection Board as required by law.

9. Changes to this policy

We may update this policy as CivilOS develops. The "last updated" date at the top always reflects the current version, and material changes will be announced in the app's Training Corner.

Note: CivilOS is an independently operated product in early commercial stage. This policy describes our actual practices honestly. If you are using CivilOS for a project with specific regulatory or contractual data requirements, please review this policy with your own legal adviser.