Privacy Policy
Last updated: September 2026
1. Who we are
Policara (“we,” “us,” or “our”) operates the website at policara.com. This Privacy Policy explains what personal data we collect, why we collect it, and how we handle it.
Policara is operated by Divyam Makar, an individual (sole proprietor), based in Ghaziabad, Uttar Pradesh, India. Divyam Makar is the data controller for the personal data described in this policy and decides why and how it is processed. There is no separate company entity and we have not appointed a Data Protection Officer, and we have not appointed a representative in the European Union or the United Kingdom under Article 27 — we are a one-person business and process personal data only as far as running this service requires. If you are in the EEA or the UK you can raise anything in this policy with the controller directly, in English, at the address below. You can reach the controller at hello@policara.com.
2. Information we collect
We collect the following categories of personal data:
- Email address — provided when you create an account to generate a document. We use it to sign you in (via a one-time link) and to send you copies of your documents.
- Intake wizard answers — the information you provide about your product (platform type, services used, data practices) so we can generate your legal document. Most of this describes your product rather than you, but it can include the contact email and business address you choose to publish in the document you generate.
- Account identifier — a unique account ID that associates your generated documents with your email-verified account.
- Billing and subscription data — if you buy a paid plan, Paddle acts as merchant of record and handles the payment. Paddle gives us back a customer ID, a subscription ID, the subscription status and the plan you are on, and we store those on your account record. Card numbers never reach us.
- Usage records — each document generation writes a row recording your account ID, the document produced, and the AI model used. We use these to enforce plan limits and abuse caps. Alongside each row we store a salted SHA-256 hash of the IP address the request came from — used only for per-IP rate limiting, and not the address itself.
- Anonymous usage analytics — we use Plausible Analytics, a privacy-friendly, cookieless analytics service. Plausible does not collect personal data or use cookies. Aggregate page-view and referrer data is collected without identifying individual visitors.
We do not collect payment card details, precise location, health data, biometric data, or any special category data.
3. How we use your information
- To generate your legal documents based on the intake answers you provide.
- To send you a copy of your document by email (if you provide your email).
- To keep you signed in and to associate your documents with your account.
- To bill you and manage your subscription, if you are on a paid plan.
- To enforce plan limits and prevent abuse of the generation service.
- To improve the service based on aggregate, anonymized usage patterns.
- To comply with legal obligations.
We do not sell or share your personal data with third parties for their own commercial purposes or for cross-context behavioural advertising.
Legal bases (EEA and UK). If you are in the European Economic Area or the United Kingdom, we owe you the Article 6 basis each of those purposes rests on:
- Generating your documents, emailing you a copy, keeping you signed in, and billing and managing a paid subscription — performance of a contract with you, Article 6(1)(b). This is the service you asked us for.
- Enforcing plan limits, rate limiting by hashed IP address, and otherwise preventing abuse of the generation service — legitimate interests, Article 6(1)(f).
- Improving the service from aggregate, anonymized usage patterns — legitimate interests, Article 6(1)(f).
- Complying with legal obligations that apply to us — legal obligation, Article 6(1)(c).
The legitimate interests we are actually pursuing are narrow: stopping one person from draining the free tier or running automated abuse against a paid AI service, and understanding in aggregate which parts of the product work so we can improve them. Where we rely on legitimate interests you can object to that processing at any time — email us and we will stop unless we have a compelling reason not to. We do not rely on your consent as the basis for any of the processing described in this policy.
Do you have to give us your email address? Not by statute, but yes in order to use the service. Generating a document requires an account, the only way to create one is the one-time sign-in link we email you, and the generation endpoint refuses a request that carries no account. Your email is therefore a requirement of entering into the contract: without it we cannot create an account, and you cannot generate a document, save a draft or come back to one. The intake answers are different — they describe your product, and how much detail you give is your choice, though a thinner answer produces a thinner document.
Automated decision-making. We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you, and we do not profile you, so Article 22 does not apply. Parts of the service are of course automatic: an AI model writes your document from the answers you give it, and a scoring pass grades that document against the laws we detected for it. Both judge the document, not you. The plan-limit and rate-limit checks are automatic too, but all they do is count generations against the allowance of the plan you chose and stop the run when it is used up; they evaluate nothing about you as a person.
4. Third-party services
We use the following third-party services to operate Policara:
- Vercel — website hosting (processes server logs including IP addresses).
- Supabase — authentication and database (stores your account, email address, intake drafts and generated documents).
- Plausible Analytics — privacy-friendly, cookieless website analytics (no personal data collected).
- Resend — transactional email delivery (processes your email address when we send you sign-in links and document copies).
- Paddle — merchant of record and payment processing for paid plans (processes billing details and tax information; we never store card numbers).
- Google Cloud Vertex AI — AI language model API (your intake answers are sent as prompt context to generate the document).
This list is complete: we run no advertising, attribution or behavioural-tracking services, and no analytics beyond Plausible. Each provider processes data in accordance with their own privacy policies.
5. Where your intake answers are stored
The intake wizard keeps your answers in two places, and it is worth being precise about both:
- In your browser — your progress is written to your browser's local storage under the key
policara.wizard.v1, so that closing the tab or following a sign-in link does not lose your answers. This copy is not cleared when you close the tab: it expires 24 hours after it was written, and is deleted when the document is generated and when you sign out. You can also clear it yourself from your browser's site data. - On our servers — if you are signed in, the same answers are also mirrored to a draft row on your account, so a run started on one device can be continued on another. Deleting the draft from your dashboard deletes that row.
When a generation succeeds, we also save the company-stable answers (business name, URL, contact email, address, business type, description, region, target markets and platform details) as a company profile on your account, so that a second document does not have to ask you for them again. Deleting a draft does not delete that profile; email us to have it removed.
6. Data retention
- Browser copy of your intake answers — expires 24 hours after it was written, or sooner (see section 5).
- Server drafts and company profile — kept until you delete the draft, or until you ask us to delete your account.
- Generated documents — stored in our database until you delete them from your dashboard or request deletion.
- Email addresses — retained until you unsubscribe or request deletion.
- Billing and usage records — kept for as long as your account exists, because they are what enforces your plan limits and records what you were charged for. We have not set a fixed deletion schedule for them beyond account deletion.
Deleting your account deletes the rows tied to it — profile, documents, drafts, company profile and usage records. Email us to request it.
7. Cookies and local storage
Policara sets no advertising or analytics cookies, and no third-party cookies of its own. Plausible Analytics is entirely cookieless, and we do not run Google Analytics, tag managers or any other tracker. There is one third party to be honest about: opening a checkout loads Paddle's script from cdn.paddle.com, and Paddle then sets its own cookies and browser storage to run that checkout. It loads only when you click to upgrade, never on the rest of the site, and it is necessary to take your payment — what Paddle stores is governed by Paddle's own privacy policy, not ours. Because nothing we load is used for advertising or analytics, the site shows no cookie banner.
We do use the following browser storage:
- Authentication cookie — when you sign in, Supabase sets a first-party session cookie so that both your browser and our server know you are signed in. It is strictly necessary for the service to work and is cleared when you sign out.
- Local storage — the intake wizard stores your in-progress answers under
policara.wizard.v1(see section 5). - Session storage — when your browser comes back from a Paddle checkout we write a timestamp under
policara.upgrade_pending_at, so that refreshing the dashboard keeps showing “confirming your payment” instead of offering to sell you the plan you just bought. It is cleared the moment the plan is confirmed and expires 30 minutes after it was written.
8. International data transfers
We operate Policara from India, and the providers listed in section 4 operate internationally. If you are in the European Economic Area or the United Kingdom, your personal data is therefore transferred outside the EEA and the UK — including to India, where the controller is located, and to whichever regions our providers use. Our AI requests go to Google Cloud Vertex AI's global endpoint rather than a region we have pinned, so they may be processed in any region Google serves it from.
India is not covered by a European Commission adequacy decision. Where our providers offer standard contractual clauses or equivalent safeguards as part of their own data processing terms, those terms govern the transfer to that provider; we have not entered into a separate transfer agreement of our own. You can ask us which safeguards a named provider relies on and we will point you to the provider's published terms, which is where those safeguards live. If this matters for your use of the service, please contact us before submitting personal data.
9. Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your personal data.
- Portability — receive your data in a structured, machine-readable format.
- Restriction — ask us to restrict processing while a dispute about accuracy or our legitimate interests is resolved.
- Objection — object to processing we base on legitimate interests, described in section 3. We will stop unless we can show compelling grounds that override your interests.
- Opt-out of sale — we do not sell personal data, but you may exercise this right under CCPA.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email us at hello@policara.com. We will respond within 30 days.
Complaints. If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with a data protection supervisory authority — the authority in the EEA country where you live, work, or where you believe the issue occurred, or the Information Commissioner's Office in the UK. You do not have to contact us first, though we would rather have the chance to put things right.
10. If you are in India: the DPDP Act
The controller is based in Ghaziabad, Uttar Pradesh, India, which makes Divyam Makar a Data Fiduciary under India's Digital Personal Data Protection Act, 2023. If you are in India you are a Data Principal, and alongside the rights in section 9 the Act gives you:
- Access (Section 11) — a summary of the personal data we process about you and what we do with it, plus the identities of the other fiduciaries and processors we have shared it with. Section 4 lists every one of them.
- Correction and erasure (Section 12) — correction, completion or updating of your personal data, and erasure of data we no longer need for the purpose you gave it for.
- Grievance redressal (Section 13) — the right to have a complaint about how we handled your data answered, through the route below.
- Nomination (Section 14) — the right to nominate someone to exercise these rights on your behalf if you die or become incapacitated. The Rules setting out how a nomination is made have not been notified yet; email us and we will act on one as far as the Act as it stands allows.
Grievance contact. There is no department to route you to — Divyam Makar handles grievances personally, at hello@policara.com. Put “DPDP grievance” in the subject line so it is not read as a support ticket, and we will respond within 30 days. The DPDP Rules have not yet prescribed a statutory response time; if they set a shorter one, the shorter one applies.
Escalating. Section 13(2) asks you to exhaust our grievance route first. If we do not resolve it, you may complain to the Data Protection Board of India. The Board had not been constituted when this policy was last updated, so there is no filing address we can honestly print here; once it is operating, complaints go to it and we will update this section with its details.
11. Data breaches
If personal data we hold is breached and the breach is likely to put your rights and freedoms at risk, we will report it to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it — that 72-hour deadline is the one GDPR Article 33 sets for notifying the authority, not for notifying you. Where a breach is likely to be a high risk to you, Article 34 also requires us to tell you directly and without undue delay, and we will do that by email to the address on your account.
We owe the same duty as an Indian Data Fiduciary: Section 8(6) of the DPDP Act requires us to inform both the Data Protection Board of India and every affected Data Principal. The DPDP Rules have not yet prescribed the form or the timing of that notice, so we will follow them once they are notified — and we will not wait for them before telling you.
12. Children's privacy
Policara is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
13. Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last updated” date. If we make material changes, we will notify users by email where possible.
14. Contact us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at hello@policara.com.