The fine print, in plain English.
What Locara collects about you, why, who else sees it, and how to make us delete it. There is no sign-up here, so the honest answer is: very little, and this page exists to say exactly how little, and where the little there is goes.
The short version
Locara has no accounts. No sign-up, no password, no one-time code, no phone number. We do not know your name unless you type it into the feedback form, and we never ask for it anywhere else.
What we do have: the questions you type, because we have to send them somewhere to answer them, and an anonymous count of which pages get used. Both are explained below, in full, and neither is sold to anyone. That is the whole policy. The rest is detail.
What we collect
Locara is deliberately thin on personal data. Here is the whole list.
The questions you ask
The text you type into Ask, and the locality facts we retrieved to answer it. We store the question text against an anonymous session id, so we can see what people actually want to know and decide which areas and factors to research next. It is not attached to a name, an email or an IP address, because we do not have any of those.
Anonymous usage
- Which pages you visited, in what order, and the site that referred you.
- An anonymous session identifier, held in a cookie called
lsid, so a visit reads as one visit rather than nine unrelated page loads. - Nothing else. We do not store your IP address or your device fingerprint in our own event stream.
If you send feedback
The contact and feedback form takes a message, an optional rating, and your name and email only if you choose to leave them. Leave them blank and it still sends. If you do leave an email, we send a copy to that address too, so you have a record of what you told us.
What we deliberately do not collect
- No name, email, phone number or address, unless you type one into feedback.
- No location. The site never asks your browser for it.
- No advertising identifiers, no cross-site tracking pixels, no data brokers.
- No sensitive personal data of any kind. Please do not type any into the question box.
The questions you type
This is the one part worth reading slowly, because it is the one place your words leave our servers.
When you ask something, the text goes to two AI providers, both in the United States: OpenAI, which turns it into a search embedding and runs a first pass, and Anthropic, which writes the reasoned answer over the facts we retrieved. Both are our processors, both are barred from using your text to train their models, and neither receives anything identifying about you, because we hold nothing identifying to send. But the text itself genuinely does leave, and you should type accordingly: it is a question box about neighbourhoods, not a private notebook.
The offline research that builds our locality profiles also uses web search and AI, but that runs on public place data and never on anything of yours.
Why, and on what basis
Under the DPDP Act we process personal data on consent and, where the Act allows, for legitimate uses. In practice:
- To answer you. Your question is processed because you asked it. That is the whole purpose, and it ends when the answer is written.
- To decide what to research next. We read the questions in aggregate to see which areas and which factors people actually care about.
- To run the site. Counting page views, spotting what is broken, and stopping abuse.
- To reply to you. If you leave an email on the feedback form, we use it to answer you, and for nothing else. We do not add it to a mailing list, because we do not have one.
Cookies and local storage
One cookie of our own: lsid, an anonymous session id used to count a visit as a visit. It identifies a browser session, not a person, and there is no account for it to point at.
We also keep small preferences in your browser's local storage, your light or dark theme choice and your recent questions, so the page looks right when you come back. Those never leave your device, and clearing your browser storage removes them.
PostHog, our product analytics (above), sets a first-party cookie and stores a device identifier in your browser so we can count visits and see which features get used. Beyond that there are no advertising cookies and no third-party advertising or tracking pixels. If we ever add a non-essential cookie beyond analytics, we will ask you first.
Where your data lives
Locara is built and run from Bangalore, on DigitalOcean (blr1). Our data sits in a managed MongoDB Atlas cluster on AWS in Mumbai (ap-south-1). Storage is in India.
Three processors run outside India: OpenAI and Anthropic, which answer your typed questions, and Resend, which delivers feedback email. All three are on US infrastructure, so your question text and any feedback you send cross a border. None of them receives more than that job needs, and if the government notifies restricted territories under s.16 of the DPDP Act, we will re-check all three against that list.
How long we keep it
- Your questions, kept against an anonymous session id while they are useful for deciding what to research. They carry no name, email, phone or IP.
- Anonymous usage events, the same.
- Feedback you send, until you ask us to delete it. If you left an email, it sits in our inbox as well as our database, and we delete both on request.
- Server logs, kept for up to 30 days for debugging and abuse investigation, then rotated away.
There is no account record to delete, because there is no account. Anything already reduced to aggregate counts stays, because there is nothing in it that points at you.
Your rights under the DPDP Act
India's Digital Personal Data Protection Act, 2023 is the law that governs this. It gives you the following rights, and you exercise all of them the same way: email the Grievance Officer, details below.
- Access. Ask for a summary of the personal data we hold about you, what we do with it, and who we have shared it with. In most cases the answer will be "nothing that identifies you", and we will say so plainly.
- Correction and completion. If something we hold is wrong or out of date, tell us and we will fix it.
- Erasure. Ask us to delete your data. We will, unless a law requires us to keep a specific record.
- Withdraw consent. As easily as you gave it. Processing that already happened stays lawful; everything after stops. In practice, stop using the site and clear your browser storage, and nothing of yours remains in play.
- Grievance redressal. Complain to us first. We respond within 30 days.
- Nomination. You may nominate someone to exercise these rights if you die or become incapacitated. Write to the Grievance Officer to record a nominee.
One practical limit, stated honestly: with no account, we usually cannot tell which anonymous rows are yours. If you want a specific question or feedback message removed, tell us roughly when you sent it and what it said, and we will find it.
Grievance Officer
Under s.13 of the DPDP Act, you can raise any privacy question or complaint with our Grievance Officer, and we will respond within 30 days.
Write to support@thelocara.com with "Privacy" in the subject line. It reaches the founders directly; there is no queue in between. If you are not satisfied with how we handle it, you may complain to the Data Protection Board of India.
Children's data
Locara is for adults. Our terms require you to be 18 or over. There is no sign-up, so there is no point at which we could verify an age, and equally no profile, no contact detail and no personal data collected from anyone, of any age, beyond what is described above.
We do not knowingly process a minor's data, we never profile or target anyone, and if you believe a child's personal data has reached us through the feedback form, tell the Grievance Officer and we will delete it.
How we protect it
- Everything is served over HTTPS, and the API only accepts requests from our own site.
- No passwords exist, so none can be stolen or reused.
- No accounts exist, so there is no login to breach and no profile to steal.
- Access to the database and the server is limited to the two founders, over key-based authentication.
- The admin panel is separate, password-protected, and holds no reader data beyond the aggregate counts described here.
We are a two-person team and we will not pretend to enterprise security theatre. What we can honestly say is that the safest data is the data you never collect, and that is the principle this product is built on.
Visitors from the EU and UK
Locara is an India-facing service and we do not target the EU or the UK. If you use it from there, the GDPR may still apply to that use. We will honour access, rectification, erasure, restriction, objection and portability requests made to the Grievance Officer above, on the same terms as everyone else.
Changes to this policy
We update the date at the top whenever this page changes, and keep a summary of anything material at the top. We have no accounts and no mailing list tied to the service, so we cannot email you about a change, and this page is the notice.
If we ever start collecting something new, this page changes before the code does, not after.