Privacy policy.
iamaware is a small team publishing a daily current-affairs digest for exam aspirants. We collect as little as we can get away with, we say plainly what we do with it, and you can delete all of it yourself.
Who we are
iamaware.in is run by two founders as a side project. We are the people who decide what is collected and why — in the language of India’s Digital Personal Data Protection Act, 2023, we are the Data Fiduciary and you are the Data Principal.
You can read the site’s bulletin, Explained articles and map behaviour in the appendix, and the sources we publish from in the bibliography. Our rules of use are in the terms.
What we collect, and why
- Your account — Your name, your email address, and — if you sign up with a password — that password stored only as a one-way hash. We never see or store the password itself. We need this to create your account, to sign you in, and to send you account email.
- Signing in with Google — If you choose Google, Google tells us the basics on your Google profile: your name, your email address, whether Google has verified that address, your profile picture, and a Google account identifier we store so we can recognise you next time. We never receive your Google password, your contacts, or anything else in your Google account.
- Security logs — Sign-ins, sign-outs, failed sign-in attempts, password changes, email verification and account deletion are recorded with the event type, the time, your IP address and your browser’s user-agent string. This is what lets us lock an account that is being attacked, rate-limit abuse, and answer “was that me?” if you ask.
- Session cookies — Three strictly necessary cookies keep you signed in:
iaw_at(a short-lived access token, 30 minutes),iaw_rt(a refresh token, 30 days from last use) andiaw_sess(a marker that simply says a session exists). They are HttpOnly, first-party, and cannot be read by scripts. They carry no advertising or tracking value, so they are not part of the consent choice below. - Your cookie choice — One first-party cookie,
iaw_consent, remembers whether you accepted or declined analytics. It lasts 12 months. - Analytics — only if you accept — We use Google Analytics 4 to see which pages are read and where the site is slow. It is loaded only after you press Accept on the consent banner: Google Consent Mode starts with
analytics_storageset to denied, and if you decline, the analytics script is never loaded and no analytics cookies are set. When you have accepted and are signed in, we pass GA4 a random account identifier and your plan tier — never your name or email address.
What we do not collect: payment details (there is no paid plan yet), your location, your contacts, or anything from other sites. We do not sell your data, and we do not share it for advertising.
Cookies and changing your mind
On your first visit, a small bar asks whether analytics may be switched on. Accept or Decline — both are one click, and declining costs you nothing on the site.
You can change that choice at any time from the Cookie choices link in the footer of every page. Withdrawing consent stops analytics from that moment; clearing your browser’s cookies for iamaware.in also resets the choice and asks you again. The three session cookies stay either way, because without them we cannot keep you signed in.
Who else touches your data
We use a short list of service providers. They process data on our instructions only, for the purposes below, and nothing else. Some of them run infrastructure outside India.
- Google — Sign in with Google (only if you use it) and, after your consent, Google Analytics 4.
- Resend — Sends our account email — verification, password reset, and security notices — from noreply@iamaware.in. Resend receives your email address and the contents of those messages.
- Vercel, Render and Microsoft Azure — Host the website, the API and the database respectively. They hold the data described above in order to run the service.
How long we keep it
- Account details — Until you delete your account. Then they are erased as described below.
- Security logs — 180 days. A few security-relevant events — lockouts, password changes, deletions — are kept for twice that, then deleted automatically.
- Sessions — A signed-in session expires 30 days after you last use it, and signing out ends it immediately.
- Analytics — Held by Google under GA4’s own retention window, and only if you consented.
- Your cookie choice — 12 months, then we ask again.
Deleting your account
You can delete your account yourself from the account page. Because it cannot be undone, we ask for your password again first — or, for Google-only accounts, a fresh Google sign-in.
When you confirm, straight away:
- Your identity is removed — Your email address is replaced with an unusable placeholder, your name and profile picture are erased, your Google link is deleted, and your password hash is removed.
- Every session is ended — All your sessions on all devices are revoked, and any access token still in flight stops working within a minute.
- Security logs are stripped — The email address, IP address and user agent on your past security-log entries are erased. Only the event type and the timestamp remain, so our records of “an account was deleted” stay intact — and those entries are purged on the retention schedule above.
- The empty record stays — A stub row without any personal detail is kept so that the rest of the database stays consistent. It no longer identifies you and cannot be used to sign in.
Your rights under the DPDP Act, 2023
Indian law gives you these rights, and we honour them for everyone, wherever you are.
- Know what we hold — Ask us for a summary of your data and who we have shared it with.
- Correct or complete it — Fix your name or email yourself on the account page, or ask us.
- Erase it — Delete your account, which erases your data as set out above, or ask us to do it.
- Withdraw consent — Turn analytics off from the footer link at any time. Consent given at sign-up for running your account can be withdrawn by deleting the account.
- Nominate someone — Ask us to record a person who may exercise these rights on your behalf if you die or are incapacitated.
- Raise a grievance — Write to us first; we answer within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.
You also owe us something in return, as the Act says: please give accurate details and do not file frivolous complaints or impersonate someone else.
iamaware is meant for people aged 18 and over. We do not knowingly create accounts for children. If you believe a child has signed up, tell us and we will remove the account.
How we protect it
Traffic runs over HTTPS. Passwords are stored only as salted one-way hashes. Sign-in tokens are short-lived and rotate on every use, repeated failed attempts slow down and then lock the account, and a lockout emails you. Only the two of us can reach the production database.
No system is perfect. If a breach ever affects your data, we will tell you and the Data Protection Board of India as the Act requires.
Changes to this policy
When this policy changes we update the date at the top of the page. If a change is significant — a new processor, a new purpose — we will say so on the site and, where the law requires it, ask for your consent again.
Contact us
For anything on this page — a request, a correction, a grievance — write to either founder. A real person replies.
Our contact page has the same addresses, and the feedback form reaches us too.