Effective Date: September 18, 2026
Jurisdiction: DPDP Act 2023 (India), GDPR (EU), CCPA/CPRA (California)
1. Data Processing Architecture
KLG Ancient World collects and processes personal and telemetry data strictly to maintain authentication, execute epigraphic interpretations, sync educational quests, and analyze academic portal interest.
2. Personal Data We Collect
- Authentication Metadata: Email address or mobile phone number collected during OTP login routines. We do not store, salt, or hash static passwords.
- Researcher Inquiries: Full name, institutional email address (
.edu,.org,.gov,.pt), affiliated university/department, and proposed research topics submitted via the Research Portal. - Patronage Transaction Records: When making a financial contribution via Razorpay, we log the transaction ID, date, currency, contribution amount, and billing name. Full credit card, debit card, or UPI PIN credentials are handled directly by Razorpay on PCI-DSS certified servers; we never store your core payment details.
- Visual Inputs & Camera Stream: The MythiLens Artifact Scanner and Ancient Inscription Translator process live camera feeds or selected gallery photos. Image bytes are processed locally or transmitted over encrypted TLS tunnels to vision models for classification and epigraphic translation.
- Spatial & Geolocation Coordinates: With explicit device permission, coarse or fine GPS location is processed on-device by the Heritage Explorer to calculate distances to nearby cataloged monuments.
- Web & Diagnostic Telemetry: Anonymous browser fingerprints, device operating system versions, Google Tag Manager (GTM) analytics, and crash logs.
3. Purpose & Legal Basis for Processing
- Consent: Processing OTPs to unlock your member account or processing camera frames to translate stone inscriptions upon your active request.
- Legitimate Interests: Monitoring system load, running Discord webhook alerts for server-side errors, preventing denial-of-service abuse, and prioritizing research collaborations from verified universities.
- Contractual Necessity: Fulfilling electronic receipts and digital perks associated with voluntary patronage or quest pass unlocks.
4. Local-First Caching & The Adler-32 Cache Guard
MythiLens features a local-first embedded database architecture (LibSQL / SQLite):
- Captured monument photos are converted into on-device Adler-32 non-cryptographic checksum hashes before any external network connection is established.
- If a matching hash exists in your local SQLite replica (
mythilens.db), translation and historical details are loaded directly from your device storage in sub-2ms, without transmitting your image over the public internet. - Only when a cache miss occurs is the compressed image routed to cloud vision processing APIs.
5. Third-Party Sub-Processors & Data Sharing
We do not sell, rent, or trade your personal data. We exchange minimal technical data exclusively with the following vendors:
- Razorpay Software Private Limited: Payment gateway orchestration, billing validation, and statutory settlement (India).
- Turso (ChiselStrike Inc.): Distributed LibSQL cloud database replication and edge server synchronization.
- Google Cloud / Google Generative AI: Vision-language processing for stone script decipherment and archaeological categorization.
- Resend API: Transactional transmission of 6-digit verification passcodes.
- Vercel Inc.: Edge hosting, serverless compute functions, and front-end content delivery networks.
- Discord Inc. (Webhooks): Real-time administrative logging for operational exceptions and institutional inquiry alerts.
- Google Tag Manager / Analytics: Anonymous session duration, bounce rates, and traffic origin tracking.
6. Data Retention Protocols
- Authentication OTPs: Expire automatically after 10 minutes and are permanently purged from database memory.
- Session Cookies (
klg_session): Retained on client browsers for a maximum of 30 days unless cleared manually by the user. - Local Mobile Data: Stored in your device application sandboxed storage until you clear app cache or uninstall MythiLens.
- Institutional Inquiries: Retained for up to 36 months to document long-term academic and scientific collaborations.
7. Statutory Data Subject Rights (DPDP Act 2023 & GDPR)
You maintain the following statutory entitlements:
- Right to Access & Confirmation: You may request an export summary of all personal information we maintain regarding your identity.
- Right to Correction & Erasure: You can request the correction of inaccurate profile data or the permanent deletion of your account records.
- Right of Grievance Redressal: You have the right to file an inquiry regarding any data handling practice.
- Right to Nominate: Under the DPDP Act 2023, you may designate a representative to exercise your data rights in the event of death or incapacity.
8. Designated Grievance Redressal Officer
In compliance with Section 10 of the DPDP Act, 2023 and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, our designated contact is:
Officer: Data Redressal Cell
Entity: KLG Ancient World
Communication Desk: contact@klgancientworld.com
Escalation WhatsApp: +91 7013225927
Registered Location: Andhra Pradesh, India
Response Window: Grievance acknowledgment within 48 hours; resolution within 30 statutory days.