Compliance · Data protection
Privacy & Data Protection Notice
Drafted 2026-08-13 · Revised 2026-08-14 · Status: draft, not in force
What this means. This notice is published so it can be read and challenged before it binds anyone. It is not yet a commitment we are held to.
What happens next. It becomes binding when the founders and counsel sign it off and this block is removed, not by a silent edit. Items marked TBD are deliberately unfinished rather than invented; each one names the decision that is missing.
Drafted 13 August 2026 against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (notified 13 November 2025; the notice-and-consent provisions take effect 13 May 2027).
Fourthuman records first-person video of people doing real physical work, and turns it into training data for robots. That makes personal data, including video of real people and real homes, the material of our business. This notice states what we collect, why, what we never share, and how you withdraw. Where most privacy policies ask you to trust a sentence, ours points at a mechanism you can check: consent here is a hash-chained ledger entry, and withdrawal is a deletion you can verify. You ask for it in the app rather than by email, the app shows the request back to you on the phone you asked from while it is with us, and we process every withdrawal request within seven business days.
1. Who is processing your data
Fourthuman (the Data Fiduciary under the DPDP Act) is an India-based training-data company. For anything in this notice: [email protected].
Grievance officer: Krishna Nithariya, at [email protected]. We respond to a grievance within 30 days. Set 09-09-2026.
2. What we collect, and what each item is for
Itemised as the Act requires: each category tied to its purpose, no bundling.
| Who | Personal data | Purpose, and nothing else |
|---|---|---|
| Capture Partners | Name, mobile number, email | Your account, and reaching you about tasks and payouts |
| UPI / bank details (VPA) | Paying you: from ₹229/hr, on QA approval. Nothing else | |
| Egocentric video you record | Creating annotated robotics training datasets: the purpose you consent to, per recording task, in the consent ledger | |
| Device identifier, city | Capture metadata inside your consent record, so the record describes the actual capture | |
| Commissioning labs | Business contact details, enquiry contents | Answering the enquiry and managing the engagement |
| Site visitors | Whatever you type into a contact form | Replying to you. Every asset, fonts included, is served from our own origin. One third-party script is not: Cloudflare Web Analytics, described under cookies and analytics below |
2a. Cookies, analytics, and what is kept in your browser
This site sets no cookies. Not for advertising, and not to remember that you read this sentence.
One third-party script is served on every page: Cloudflare Web
Analytics. It loads from static.cloudflareinsights.com. It is
cookieless, it stores nothing on your device, and it cannot follow you to another
site. What it counts is page views and where they came from.
Corrected on 10-09-2026. This page previously said there was no third-party tracker on any page and that the site fetched from no origin but our own. That was not true: the analytics had been switched on at our domain and this page had not been updated to say so. It is written here rather than quietly edited because a privacy page that changes without saying what changed is worth less than one that admits it was wrong.
It does not currently run. Our own content security policy permits scripts from this site only, which blocks it — so at the time of writing we receive nothing from it. We are deciding whether to allow it deliberately or switch it off, and this page will say which.
Three things are kept in your browser's local storage, and all three exist only so the
apps work. fh_api_base remembers which server the app is talking to;
fh_admin_token and fh_commissioning_lab_token keep you signed
in. They stay on your device, are never sent to anyone else, and clearing your browser
data removes them.
Anything beyond the strictly necessary is asked for first: refusing takes exactly one click, and nothing runs unless you say yes. You can see and change that choice at any time from your privacy choices in the footer of every page. The analytics described above was switched on at our domain without passing through that gate, which is the reason this section was rewritten.
3. What never leaves, and what is removed
- Faces are blurred before any human reviews the footage. Automated detection and redaction runs as a pipeline stage; if the detector cannot run, the pipeline stops rather than passing footage through unblurred.
- Your identity is never shipped to a buyer. Delivered datasets and their audit records carry a consent receipt (proof consent exists), never your name, Capture Partner identifier, or device identifier.
- External AI processing is off by default and consent-gated. A captioning stage exists that can send blurred frames to a third-party AI provider. It refuses to run unless production use has been deliberately enabled and your specific clip's consent is active in the ledger. It has never been enabled to date; if that changes, this notice will name the provider before the first production use.
- Model-generated labels are marked as such. Anything a model
derived from your footage is labelled
derivedin the dataset itself.
4. Your rights, and the actual mechanism for each
| Right (DPDP Act) | How you exercise it here |
|---|---|
| Access your data (§11) | Your consent history (every grant and withdrawal, hash-chained) is available in your account at any time |
| Correction (§12) | Email [email protected]; profile self-service is on the app roadmap |
| Withdraw consent / erasure (§6(4), §12) | You email [email protected] — the app puts the receipt into that mail for you, and your sent mail is the record back to you — with the date you made it and a reference — on the phone you asked from. We process every withdrawal request within seven business days of your asking, business days are Monday to Friday; an Indian public holiday inside that window pushes the date out further. Nothing is deleted and the consent stays active until we process it; there is no automatic approval, so if we go past that date we have missed our own commitment and the app says so. Processing it deletes your footage and everything derived from it (the raw video, the blurred copy, working files, and the annotation) and halts any processing job. Each deletion is recorded in an append-only log, and a verification endpoint re-scans storage on demand so the deletion is checkable, not asserted. What survives is the ledger entry recording that you withdrew (the evidence your request was honoured) and a content fingerprint of the deleted file (bytes are gone; the fingerprint proves which bytes) |
| Grievance redressal (§13) | Write to [email protected], which reaches us today. The named grievance officer named in clause 1 is Krishna Nithariya, and we respond within 30 days — the period the Rules expect. Set 09-09-2026; until then this notice said plainly that neither was set, rather than writing a number we had not committed to. A consent withdrawal is different and does carry a stated period: seven business days, clause 4.1 above. A withdrawal we have missed is visible to us with its age on it |
| Nominate (§14) | You may nominate a person to exercise these rights for you; email us the nomination |
| Complain to the Data Protection Board of India | If our grievance process fails you, you may complain to the Data Protection Board of India, the adjudicating body under the Act |
5. Sharing, retention, and what we do not claim
- Buyers receive datasets, not identities. If your consent is later revoked, your clips are deleted from our storage including from already-cut dataset releases, whose verification then reports the change to the buyer. Deletion obligations flow down into buyer contracts (see Terms).
- Payment processors receive what a UPI payout requires, for that purpose only.
- Email you send us is processed by Google. Our
@fourthuman.aiaddresses run on Google Workspace, so anything you write to us by email — including a privacy request or grievance sent to [email protected] — is held by Google as a processor acting for us. We have not configured a data region for that mail and do not claim one. - Retention: footage and derivatives are retained while your
consent is active, and for at most 90 days from the day we review your
recording for quality. That ceiling covers the original
unedited recording, not only the blurred copy — we say so
because redaction does not make the original disappear, and you should not
have to assume it did. After 90 days it is deleted.
If you withdraw your consent before then, everything is deleted at that point instead, as described above. The 90 days is a ceiling on how long we may keep your footage, never a waiting period on your right to have it removed. Account and payout records are retained as Indian financial law requires. TBD state the exact statutory periods before cohort onboarding. - What we do not claim: we hold no third-party certification (no SOC 2, no ISO 27001) and this notice will say so plainly until the day we do. Our security posture is the verifiable mechanisms described here, not a badge.
6. Languages
This notice is currently available in English. Before the first capture cohort onboards, it will be provided in the languages our Capture Partners actually read; the Act entitles you to any of the languages in the Eighth Schedule of the Constitution. TBD which translations, and who verifies them.
7. Changes to this notice
Changes to this notice are made by publishing a new dated version here; the current version is dated at the top of this page. This page, like the rest of the site, loads no third-party resources.