Legal
๐Ÿ”
Privacy Policy

We take your privacy seriously. Here's exactly what we collect and why.

Effective ยท September 2026 ยท Fuse Labs India
๐ŸšซNo data sold
๐Ÿ‘ถDPDP Act 2023 Compliant
๐Ÿ‡ฎ๐Ÿ‡ณIT Rules 2021 Compliant
01Introduction & Regulatory Scope

Fuse ("we", "our", or "us"), operated by Fuse Labs India, functions as an intermediary under Section 2(1)(w) of the Information Technology Act, 2000. This Privacy Policy governs the collection, processing, storage, and statutory rights concerning personal data in compliance with the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Fuse operates as a semi-anonymous platform designed for youth and student communities. While public-facing social anonymity is protected, users remain strictly accountable under Indian law for all communications created through their accounts.

02Categories of Data We Process

Under the DPDP Act, 2023, we collect only data strictly necessary for service operation:

Account Info
Google authentication account identifier, verified email address, system-generated User ID (UID), and registration timestamp.
Profile Data
Permanent username (frozen at registration), custom avatar image URL, interface language preference.
Private Vault
Internal record of joined communities, stored in isolated private database partitions inaccessible to other users.
Communications
Community posts, comments, attached media links, card styling themes, and reaction counts.
Audit Vault
Cryptographic author records (`author_data`) preserved behind every post, comment, and reaction to enforce safety and statutory accountability.
Notifications
Device push tokens used exclusively to alert users to new posts, comments, and reactions.
Access Requests
Vouch queue records (username temporarily displayed to active community members during peer-approval workflows) and 48-hour decline lockout logs.
Telemetry Logs
IP addresses, browser/user-agent signatures, screen views, and session interactions gathered via platform protections and analytics.
03Logical Data Partitioning & Cryptographic Isolation

Fuse utilizes multi-tiered, zero-trust database partitioning to eliminate unauthorized cross-collection harvesting:

  • Strict Vault Isolation: Account email addresses, terms compliance records, and individual community lists are physically sealed within private subcollections (`/users/{uid}/private/secure_data`). Database security rules prevent third-party querying or enumeration of this data.
  • Public Profile Minimization: The public root user record contains solely non-sensitive display parameters (username, avatar image URL, language preference).
  • Anonymous Post Vaulting: Within anonymous communities, post bodies contain zero author identifiers. The author's true UID is sealed in an uneditable subcollection (`/private/author_data`) restricted exclusively to the original author and authorized platform moderators.
  • Device Origin Validation: Platform-level origin checks verify incoming requests, blocking unauthorized third-party scripts, bots, and crawlers.
04Purpose of Processing (DPDP Act, Sec 4 & 6)

We process personal data solely for specified, explicit, and lawful purposes:

  • To verify identity and prevent duplicate or automated registrations.
  • To deliver core community discussion, comment ripping, card styling, and reaction features.
  • To dispatch transactional push notifications when other users interact with your content.
  • To operate real-time and automated moderation systems that prevent cyberbullying, harassment, and unlawful content.
  • To fulfill legal obligations under the Information Technology Act, 2000, and court orders issued by competent judicial authorities.
05Sneak Peek & Vouch Queue Disclosures

Certain platform workflows involve specific visibility states:

  • Sneak Peek Mode: If a community founder enables Sneak Peek, the first 5โ€“8 posts in that community may be previewed by prospective non-members prior to entering a password or submitting a vouch request. Users posting in these communities acknowledge this public preview window.
  • Decentralized Vouch Queue: If a user requests admission without a community password, their username is temporarily displayed to active community members in a dedicated vouch queue for voting. Once an absolute majority votes to vouch or decline, the request document is permanently deleted from the queue.
  • 48-Hour Decline Lockout: If an access request is declined by an absolute majority, an automated cryptographic lockout log is created to enforce a 48-hour cool-down period before another request can be filed.
0624-Hour Burner Content & Statutory Retention

Front-End Display vs. Legal Retention: Posts published with the "24-Hour Burner" flag automatically cease rendering and expire from user feeds exactly 24 hours following publication.

Statutory Preservation under Indian Law: In strict accordance with Rule 3(1)(h) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, an intermediary is required to retain user registration details, transactional records, and audit logs for a minimum period of 180 days. Accordingly, expired burner content, platform activity logs, and author audit trails are preserved securely in access-restricted backend storage for at least 180 days, and may be retained as long as necessary for platform integrity, investigation of violations, dispute resolution, and legal compliance.

07Automated Moderation & Infrastructure Partners

To prevent harassment, hate speech, and unlawful acts, submitted text payloads undergo real-time algorithmic safety evaluations via enterprise AI classification networks. Severe violations (such as CSAM, violent threats, doxxing, or hate speech) are rejected outright before publication.

We partner with vetted, industry-standard third-party service providers to deliver the platform:

  • Cloud Database & Authentication Providers: Secure identity validation, encrypted database hosting, push notification dispatch, and telemetry analytics.
  • Edge Network & Security Services: Distributed edge proxying, network traffic routing, and DDoS mitigation.
  • Media Storage & Content Delivery Networks: Secure cloud storage, compression, and global delivery of community covers and user profile avatars.
  • Digital Media Search Integrations: Curated animated media endpoints queried through secure edge proxies to prevent direct IP leakage.
08Protection of Children & Minors (DPDP Act, Sec 9)

Fuse is designed primarily for students, teenagers, and young adults. In compliance with Section 9 of India's Digital Personal Data Protection Act, 2023, we enforce the following safeguards:

  • Parental/Guardian Consent: Users under the age of 18 represent that they have obtained verifiable consent from their parent or lawful guardian prior to registration.
  • Absolute Ban on Behavioral Tracking: Fuse does not undertake behavioral monitoring, tracking, targeted profiling, or programmatic advertising directed at children or minors.
  • Safe Processing Guarantee: Fuse does not engage in any automated processing of personal data that could cause detrimental or adverse effects on the well-being of a minor.
  • Guardian Proxy Rights: Lawful guardians may exercise statutory rights of access, correction, and erasure on behalf of minor dependents by contacting our Grievance Officer.
09Your Statutory Rights as a Data Principal

Under Chapter III of the DPDP Act, 2023, you are endowed with enforceable rights:

  • Right to Access Information: The right to obtain a summary of your personal data being processed and the categories of third-party processors involved.
  • Right to Correction & Updating: The right to correct inaccurate personal data and update profile avatars or preferences within the application.
  • Right to Erasure (Account Deletion): The right to request the complete erasure of your user profile and active database entries, subject to statutory retention obligations under Indian law.
  • Right of Grievance Redressal: The right to have complaints addressed by our designated Grievance Officer within statutory timeframes.
  • Right to Nominate: The right to designate an individual who, in the event of death or incapacity, shall exercise your rights as a Data Principal.
10Data Disclosure & Law Enforcement Cooperation
๐ŸšซFuse has never sold, leased, or monetized personal user data, and never will.

We disclose user records strictly under the following circumstances:

  • Judicial Process & Statutory Warrants: When compelled by a valid order, summons, or warrant issued by a court of competent jurisdiction or authorized law enforcement agency under Section 91 of the Code of Criminal Procedure, 1973 (or Bharatiya Nagarik Suraksha Sanhita, 2023).
  • Emergency Circumstances: Where disclosure is strictly required to prevent imminent bodily injury, self-harm, cyber-extortion, or child exploitation (under the POCSO Act, 2012).
โš ๏ธInformal complaints by private individuals, institutions, or schools do NOT constitute lawful grounds for disclosing private account credentials or author identities.
11Grievance Redressal Mechanism (IT Rules & DPDP)

In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023, Fuse has designated a formal Grievance Officer:

Officer
Grievance Redressal Officer, Fuse Labs India
Email
shubhfuseapp@gmail.com
Timeline
Acknowledgment within 24 hours; disposal/resolution within 15 days of receipt.
Escalation
Appeals against Grievance decisions may be submitted to the Data Protection Board of India.
12Policy Modifications

We reserve the right to revise this Privacy Policy periodically to reflect technological advancements, legal amendments, or platform updates. Material changes will be accompanied by an updated effective date at the top of this document. Continued use of Fuse following updates constitutes acknowledgment of the revised provisions.