Policy Effective 6 September 2026

Data policy for the private synthetic demo

Karz Setu uses a private anonymous browser account to keep one synthetic CHG-1 preparation case separate from every other user. It does not submit anything to MCA.

What we store

For seven days, we store the anonymous Firebase user identifier, synthetic case metadata, document SHA-256 hashes, selected evidence excerpts, extracted candidate values, conflict decisions and reasons, audit events, and the generated PDF and JSON review artifacts.

What we do not store

Original uploaded PDF bytes are processed transiently and are not retained. We do not collect a name, email address, phone number, government identifier, password, OTP, payment information, digital-signature material, or real MCA credentials. Application logs do not contain document bodies, filenames, evidence excerpts, human reasons, authentication tokens, or user identifiers.

Synthetic documents only

Phase 2 accepts only the supplied synthetic evidence pack. Do not upload personal or company documents. Unsupported files are rejected and not retained.

Purpose and processors

Data is used only to demonstrate evidence-backed CHG-1 preparation and private review-pack generation. Vercel operates the web application. Firebase and Google Cloud provide anonymous authentication, Firestore metadata storage, and private artifact storage in an India region. A short synthetic company-event description may be sent to an external research provider to check allowlisted official sources and propose a filing explanation. Documents, evidence excerpts, decisions and case records are never sent to the model. If live research is unavailable, the app uses its labelled Bedrock and deterministic recovery path.

Access and sharing

Every case request must present the anonymous account token for the owning browser. The server derives the storage path from that verified identity. Firestore and Storage reject direct browser access, artifacts have no public URL, and a different anonymous user cannot read or download the case.

Retention and deletion

Case metadata and artifacts are scheduled for deletion seven days after their latest update. Firebase may retain the anonymous account identifier for its separate anonymous-account cleanup period; it is not linked to a name or email. Reset demo immediately deletes the saved case and artifacts before creating a fresh synthetic case. Expiry remains a fallback if a reset request is interrupted.

External boundaries

The event router may make the limited external research call described above and otherwise uses a labelled recovery path. There is no live MCA, mailbox, professional-sharing, payment, DSC, bank, or government integration. Later certification, signature, payment and filing screens remain clearly labelled simulations.

Security limits

This is an independent competition prototype, not a production filing service or legal opinion. It uses authentication, owner-scoped server access, App Check, strict validation, private storage and audit records, but it must still receive professional and security review before real company data is accepted.

Return to the private case