Privacy Policy

Last updated: May 23, 2026

Our Commitment to Privacy

Swaranga is built on the principle of anonymity. We believe you should be able to speak freely without surrendering your identity. This Privacy Policy explains what data we collect, why we collect it, how we protect it, and what rights you have over it.

We collect only what is strictly necessary to operate the Platform. We do not require your real name, email address, or phone number — ever. By using Swaranga, you consent to the practices described in this policy.

Information We Collect

The data we collect depends on how you use the Platform:

  • Anonymous users: A randomly generated session identifier, stored locally in your browser. No account creation, no server-side profile.
  • Registered users: A chosen username and a securely hashed password. No email address, phone number, or real name required.
  • User content: Posts, comments, likes, bookmarks, and reports you create on the Platform.
  • Technical logs: IP addresses and browser user-agent strings are logged temporarily for security monitoring and abuse prevention. These are not linked to user profiles and are not retained beyond what is necessary.

How We Use Your Information

We use the data we collect exclusively to:

  • Operate, maintain, and improve the Platform
  • Authenticate registered users and maintain sessions
  • Detect and prevent abuse, spam, and security threats
  • Comply with legal obligations and enforce our Terms of Service

We do not use your data for advertising, behavioral profiling, or any commercial purpose beyond operating the Platform.

AI Content Processing

Posts submitted to Swaranga may be processed by third-party AI services for content moderation and sentiment analysis. Only the text content of posts is transmitted — no usernames, account details, session identifiers, or personally identifying information are shared with these services.

These AI providers operate under their own privacy policies and data processing agreements. By posting on Swaranga, you acknowledge that your post content may be processed by these services for the purpose of safety and moderation.

Local Storage & Anonymity by Design

We use browser localStorage — not cookies — to store your session identifier, chosen username, and authentication token. We do not use third-party tracking cookies, advertising pixels, analytics SDKs, or fingerprinting techniques.

Anonymous sessions exist entirely in your browser. Clearing your browser storage will remove your anonymous identity. Registered accounts use only your chosen username — we make no attempt to associate your account with your real identity, location, or device beyond what is required to prevent abuse.

Data Sharing & Security

We do not sell, rent, trade, or otherwise transfer your personal data to third parties. We do not share your data with advertisers or data brokers. Anonymous post content is publicly visible on the Platform by design.

We may disclose information only when required by applicable law, court order, or to prevent imminent harm to users or others.

All passwords are hashed using bcrypt. Authentication uses signed JWT tokens with expiration. Data in transit is encrypted using HTTPS/TLS. We implement rate limiting, access controls, and input sanitization. Despite these measures, no system is completely immune to security risks, and we cannot guarantee absolute security.

Your Rights & Data Retention

You can delete your own posts and comments at any time from within the Platform. Registered users can permanently delete their account and all associated data — posts, comments, likes, and bookmarks — directly from the Security tab in their dashboard. No request needed; deletion is immediate and irreversible. Anonymous session data is local to your browser and can be cleared by you at any time by clearing your browser storage.

Depending on your jurisdiction, you may have rights to access, rectify, or erase your personal data, or to object to or restrict its processing. If you are located in the European Economic Area (EEA) or the UK, these rights are granted under the GDPR or UK GDPR. If you are a California resident, you may have rights under the CCPA. We honor all valid requests within 30 days.

Data we hold is retained only as long as necessary to provide the service or comply with legal obligations. Technical security logs are deleted on a rolling basis.

Children, International Users & Changes

Swaranga is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that a user under 13 has registered, we will promptly delete their account and associated data.

Swaranga may be accessed from anywhere in the world. If you access the Platform from outside the jurisdiction where we operate, your data may be transferred to and processed on servers in that jurisdiction. By using the Platform, you consent to such transfer and processing in accordance with this policy.

We may update this Privacy Policy at any time. The “Last Updated” date at the top of this page reflects the most recent revision. Continued use of the Platform after changes constitutes your acceptance of the updated policy. For material changes, we will make reasonable efforts to notify registered users.

Contact

For privacy-related inquiries, data access or deletion requests, or to raise a concern about how your data is handled, please use the report feature on any post or contact us through the Platform. We will respond to all formal requests within 30 days.