Privacy Policy: coming soon.
Darpan is in a private, invite-only pilot; no public sign-up, no payments.
Questions: [email protected].
Privacy Policy — pilot draft for review
This draft is not yet effective. Interim pilot statements and remaining launch decisions are described below. The private-pilot notice above remains the publication status.
Effective date: not yet effective; to be set when these policies are published as final.
1. Operator and scope
VG, an individual, operates Darpan's website and hosted account service for the private, invite-only pilot. The operator's full legal name and postal address will be published before public launch; for now, contact the operator at [email protected]. This policy covers that service and explains how the host client connects your machine to a browser. A machine owner or administrator controls the local desktop, its applications and its users; their handling of information may be separate from ours.
The current pilot has no payments. No advertising, sale of personal data or third-party marketing analytics was identified in the reviewed application and site code; optional provider analytics settings have not been verified. The operator must confirm the enabled services and settings before public launch. Operational health reports and security logs still exist; absence of marketing analytics does not mean absence of technical data.
2. Information used to provide the service
- Accounts: email address, password hash, email-verification status, creation time, plan/access status and any account-disable status. Passwords are processed to authenticate you and stored as Argon2 hashes, not plaintext account passwords.
- Sign-in and security: session-token hashes, anti-forgery values, creation, expiry and last-use times; verification/reset-token records; temporary pairing and single-sign-on codes and host-access leases. Pairing temporarily holds a newly issued host token until the connector retrieves it. Your browser and connector hold their own authentication credentials.
- Hosts and invitations: host identifiers, chosen names and public subdomain labels, owner account, client version, gateway port, last contact time and Cloudflare tunnel/DNS identifiers. Invitations associate an email address with a host, local Unix username, role and acceptance state. Host owners can see and manage their hosts and memberships.
- Health information: the connector sends its version, whether the local gateway responds and machine uptime. The latest report is stored. The cloud API also accepts bounded session usernames, viewer counts and agent labels; the current bundled connector sends empty session and agent lists.
- Security and operational records: account actions, timestamps, account/host identifiers and contextual details. Some audit entries include the originating IP address, and administration entries can identify the administrator. Server, proxy, tunnel and mail logs may contain connection details, errors, addresses and message-delivery metadata. Rate limiting also uses IP addresses and email-derived identifiers in memory.
- Correspondence: your email address, message contents, attachments and details you choose to provide when contacting support or reporting abuse. Do not send secrets or desktop content unless needed to explain the problem.
We use these categories to create and secure accounts, verify addresses, pair and authorise hosts, manage invitations, establish connections, diagnose failures, answer requests and respond to abuse or lawful demands. Necessary account and connection data cannot be omitted while using the corresponding feature. We do not describe these operational uses as advertising tracking.
3. Desktop content and host-side features
Your authorised host captures desktop video and, when enabled, desktop audio, and sends it to your browser over WebRTC. Keyboard, pointer and gamepad actions go back to the host. Enabled clipboard sharing and file transfer exchange the clipboard or files between browser and host over the connection. Browser microphone sharing, if enabled by host policy and allowed in your browser, sends microphone audio to the host. Content can contain information about you or other people.
The hosted account database is not a repository of desktop video, clipboard contents or transferred files. That does not mean content leaves no copies: files can persist on hosts and receiving devices, applications can retain clipboard history, and host administrators control local storage. Optional host recording writes video files locally; authorised agent/dashboard features can expose screenshots and maintain local task or activity information. Recording is off by default in the supplied NixOS configuration, but an administrator can enable it. A visible recording indicator is not a guarantee against other software recording the screen.
Actual pilot settings for recording, microphone access, clipboard sharing, file transfer, administrator viewing and agents, and local retention periods, have not been verified. Supplied defaults are not a guarantee of a host's settings. Check with the machine administrator before use; host logs, metrics and optional diagnostic traces are separate from cloud-account records.
4. Network and service providers
The hosted app runs on one Contabo VPS in the European Union, using NixOS and Docker, with its SQLite database on that VPS.
- Cloudflare: its global network provides DNS, web proxy/CDN, the Cloudflare Pages marketing site, Cloudflare Access and tunnels to the VPS and authorised hosts. Access uses email one-time PINs and processes login email addresses, IP addresses and authentication information. The web proxy handles HTTP traffic and connection metadata, including account requests and WebRTC signaling; enabled host HTTP features such as dashboard screenshots also pass through the proxy.
- Cloudflare STUN: connection setup uses stun.cloudflare.com. STUN receives your public IP address and connection requests. The host and browser peers can learn each other's network addresses. STUN establishes connectivity; it is not storage for the desktop stream.
- Email: outgoing service mail is sent by self-hosted Postfix on the VPS, DKIM-signed, from [email protected] or [email protected]. Incoming mail to @darpan.space uses Cloudflare Email Routing and is forwarded to the operator's Gmail inbox, so Cloudflare and Google process support mail. Your own mail provider also processes messages.
The pilot uses direct peer-to-peer WebRTC where connectivity permits. This description does not announce a paid relay, payment processor or external AI service. We will update the policy before introducing materially different processing.
Contabo, Cloudflare and Google process information for the service as described above. Providers may process data outside India and have their own retention and legal obligations. We do not promise that all data remains in India or that deleting your account instantly removes provider logs or support mail. Beyond the primary VPS's European Union location and Cloudflare's global network, provider processing locations, contracts and any required international-transfer safeguards have not been verified. These must be assessed against the countries of admitted users before public launch or expansion of the pilot; we do not claim that a particular transfer agreement is in place.
5. Cookies and browser storage
The Darpan app uses an authentication cookie, marked Secure and HttpOnly in production, with SameSite protection. An ordinary account session has a maximum 30-day lifetime and expires after seven days without activity; administrator sessions have shorter limits. Expiry invalidates access and is not a promise that every stored session record is erased at that moment. Cloudflare Access has its own login cookies and session rules.
The desktop browser client keeps preferences such as toolbar position, scaling, resolution/output selection, frame rate, bitrate and game mode in local storage. A session-storage flag prevents repeated connection retries. These values can remain on your device until you clear site data; clearing them does not delete server records. Blocking necessary cookies or storage can prevent sign-in or affect the desktop controls.
6. Security and visibility
HTTPS protects web traffic in transit to Cloudflare, where web TLS terminates; Cloudflare Tunnel carries traffic onward to the origin. This is different from WebRTC media and data-channel encryption between the browser and host. Cloudflare can process HTTP requests and signaling; encryption of the desktop connection does not hide IP addresses, timing or traffic volume, or prevent an authorised endpoint from viewing or recording content.
The app uses password hashing, hashed authentication tokens, access checks and anti-forgery protections. Authorised operators can administer the app database and operational systems. We do not claim that SQLite is encrypted at rest, that nobody can access account information, or that these measures prevent every incident. For a breach, applicable law determines the required regulator and affected-person notifications.
7. Retention and deletion
Account and host records remain while the account or host exists. In account settings you can request deletion by confirming your email and password. The app first attempts any applicable provider cleanup and host removal, then deletes the account and related session, email-token, membership, single-sign-on and host-lease rows through database relationships. A failed cleanup can leave the account present; check the response and contact support. Deleting a host also removes its linked pairing records and memberships. If Cloudflare integration is unavailable, external tunnel/DNS cleanup can require operator action.
Account deletion does not automatically delete the separate audit table, operational/provider logs, support correspondence, another person's copies or files and local accounts on a host. It also does not by itself remove a separately managed Cloudflare Access allow-list entry. Database-row deletion is not a guarantee of immediate forensic erasure from SQLite files or storage media.
Pending invitations on someone else's host can also retain an invited email address when they are not linked to the deleted account by user ID. Contact us or that host's owner to address a remaining invitation.
Temporary codes have expiry times, but expiry and physical deletion differ: pairing records are cleaned during later pairing activity, and some session and lease records are cleaned when used or replaced. There is no general timed purge of all expired tokens or audit records. Specific retention periods for audit records, expired credentials, support mail and local host data, and a failed-deletion follow-up process, remain to be settled before public launch. During the pilot, you can request deletion at [email protected]; we will review the request within a reasonable time and explain if deletion cannot be completed, including any applicable legal retention requirement. We do not promise a fixed deletion deadline or automatic deletion of all residual records.
Container logs rotate according to the deployed release's size and file-count limits. The system journal has infrastructure-managed storage and retention settings. These settings do not establish uniform retention periods or prove 180-day log retention within India. The outgoing mail queue gives up on undelivered messages after 24 hours; that is not a deadline for deleting delivered mail, mail logs or Gmail correspondence. Cloudflare retains its own access/request records under its policies.
The operator is enabling encrypted backups, kept up to 14 days on the server and up to 90 days on offline drives. These are the intended backup retention limits; runtime encryption, retention, offline copies and restore controls have not yet been verified. Deleted data may remain in backup copies until they expire; handling of previously deleted data on restore still needs verification. We cannot promise recovery of lost app data or that the backup controls are already operating as described.
8. Choices, requests and complaints
You can decline to provide information or ask in writing to withdraw consent for processing that depends on consent. Some features may then be unavailable. Withdrawal does not make earlier lawful processing unlawful, and records required by applicable law may need to be retained. A Privacy Policy or service-term acceptance does not itself replace a separate consent required by law.
You can ask us to review your information, correct inaccuracies, explain processing or recipients, or delete information. Use the contact details below and identify your account email and relevant host or record. VG, Grievance Officer, is the contact for requests and complaints at [email protected]. We may ask for proportionate information to verify your identity and authority, never your password. Requests affecting another person's machine or records may require their administrator's involvement. During the pilot, requests are handled manually; we will review them within a reasonable time and explain obstacles. A documented verification, tracking and escalation procedure and published response periods remain to be settled before public launch. Applicable legal deadlines take priority; this interim process does not extend them.
In India, as of 7 October 2026, the DPDP Act's core notice, consent, children's-data and data-principal-rights provisions and the corresponding substantive Rules have not yet commenced. The notified transition provides for them to commence eighteen months after the November 2025 publication. We do not present them as currently enforceable rights under that Act. Existing applicable laws, including the IT Act and sensitive-personal-data rules, continue to matter. Once applicable DPDP rights commence, they include access to processing information, correction/completion/updating and erasure, grievance redressal, and nomination; its complaint route requires first using the available grievance mechanism.
If EU or UK data-protection law applies to your use, rights can include access, correction, erasure, restriction, objection and portability, withdrawal of consent and a complaint to the competent supervisory authority, subject to that law's conditions. Providing requested account/connection services may rely on contract, proportionate security and abuse prevention on legitimate interests, legal compliance on legal obligation, and genuinely optional consent-based processing on consent. These bases are not substitutes for Indian consent requirements. The admitted-country list, purpose-specific lawful bases, required transfer safeguards and any required EU/UK representative or data protection officer remain under review. We do not claim a worldwide admission policy, a representative appointment or a verified exemption. This assessment must be completed before public launch or expansion to affected users. Invite-only access is not, by itself, an exemption from those laws.
Where intermediary rules apply, complaints about the service or content can be sent to the grievance officer below. Statutory resolution deadlines and any right to appeal to a Grievance Appellate Committee are not removed by this policy.
9. Children and policy changes
Account holders must be 18 or older; minors may not hold accounts. Household members under 18 may use a host only under an adult account holder's responsibility, subject to applicable law and any required parental consent. The current account and invitation flows do not verify age, and parental-consent tooling does not exist yet. Do not treat an adult's invitation as proof of parental consent. Contact us if a child has supplied information contrary to this eligibility policy. Adult responsibility is not a substitute for any legally required consent or safeguards; the operator must review these requirements and controls before allowing participation that requires them.
We will publish changes with an updated effective date and notify pilot users of material changes by email or an in-service notice. Where a new purpose requires new consent, we will request it rather than treating a policy update as consent.
10. Contact
Support, privacy requests and abuse reports: [email protected]. Grievance officer: VG, Grievance Officer, at [email protected]. The operator's full legal name and postal address will be published before public launch; use email during the pilot.