This document is a living record. Last reviewed: July 2025.  |  All policy changes are committed to our public GitHub repository with a full diff history.
Data methodology

How we use
your data.

Every grievance submitted to this platform goes through a documented, multi-stage process before it appears on the public dashboard. This page describes that process in full — what we collect, how we verify it, what we publish, what we delete, and what you can ask us to do with your information.

We are not a government body and we are not a corporation. We have no legal obligation to publish this. We publish it anyway because the platform's credibility depends on it being legible — to citizens, to journalists, and to the officials whose work it documents.

Stage 01

Data collection — the submission form

A citizen reports a grievance through a native site form linked on the dashboard. The form is designed to collect the minimum information needed to verify and geolocate the complaint — nothing more.

01
Citizen submits the site form
Entry point — report-issue.html
Input
The form collects structured information about a local infrastructure or service failure. It is available in English and Hindi. No login, no account, no app required. Submissions are accepted 24 hours a day.
Question / Field Name
What is collected / Description
Required
1. Biggest Area Issue (Ignored by Administration)
Aapke kshetra ki aisi sabse badi samasya kya hai...
Constituents describe the primary infrastructure, service, or administrative grievance completely ignored by local authorities in their assembly region.
Yes
2. Issue Related Photo / Video
Photo ya Video isse related (optional)
Optional file upload (up to 10 MB limit) supporting the grievance. Used to visually verify the broken infrastructure on the ground and geo-verify the location.
No
3. Development Priority #1
Pure Himachal ke vikas ke liye agli sarkar...
Citizens state their top priority choice for the overall development of Himachal Pradesh in the next state governance cycle.
Yes
4. Development Related Photo / Video
Photo ya Video isse related (optional)
Optional visual upload (up to 10 MB limit) corroborating development requirements, infrastructure templates, or local concerns.
No
5. MLA Evaluation & Re-election Sentiment
Kya aapko lagta hai ki aapke vartaman MLA...
Captures whether the resident feels their local MLA understands the needs of the youth and society, and if they plan to vote for them again. Drives the MLA Approval Rating.
Yes
6. Required Leadership Model
Ek behtar kal ke liye, Himachal ko abhi...
Gathers feedback on the type and qualities of leadership Himachal Pradesh needs most to build a better future.
Yes
7. Pin Code
Aapka Pin Code kya hai?
Six-digit postal code of the submitter's area. Used to automatically map the grievance to the correct assembly constituency and district boundaries.
Yes
8. WhatsApp Number
Drop your WhatsApp number...
Optional contact number used exclusively to share the compiled district reports and request clarification. Never published publicly. Stored separately and encrypted.
No
!
We do not collect: Aadhaar numbers, voter ID, caste, religion, income level, or any information that could be used to identify or profile the submitter beyond what is needed to verify the grievance.
02
Submission enters the raw queue
Automated intake — Site Form → internal database
Automated
On submission, the form sends a payload to our intake endpoint. The raw record is written to an internal database table with status raw. It is not yet visible on the public dashboard. A timestamp and a unique submission ID are generated automatically.
Auto-assigned fields
submission_id — unique reference
received_at — UTC timestamp
status — set to raw
source — set to site_form
What happens next
The submission ID is logged. An automated duplicate-check runs against the last 90 days of submissions from the same PIN code and category. If a likely duplicate is detected, status is set to duplicate_review.
Typical queue depth
3–12 unverified submissions waiting at any given time. Volume spikes after district-level media coverage or social media sharing of the dashboard.
Time in raw queue
24–72 hours for standard submissions. High-priority issues (health emergencies, road closures affecting multiple villages) are flagged for same-day verification.
Stage 02

Ground verification

No submission is published without at least one independent confirmation from a source other than the original submitter. This is the most resource-intensive part of the process and the reason donations matter.

03
Desk verification pass
Within 24 hours of submission
Verify
A team member conducts an initial desk check using publicly available sources. This is not sufficient for publication but is used to prioritise and pre-screen submissions before committing field resources.
Desk check sources
PWD complaint portals, HP government press releases, local news archives, Google Street View (where available), social media cross-reference, prior submissions from same tehsil.
Outcomes
Pre-verified — corroborating public record found, moves to priority ground verification.
Plausible — standard ground verification queue.
Implausible — flagged for rejection review.
04
Ground-level verification call or visit
Minimum one independent source required
Field Verify
The core verification step. A community reporter or team member contacts at least one independent source in the relevant tehsil to confirm the grievance is active, accurately described, and correctly located. For high-severity issues, two independent confirmations are required.
Acceptable verification sources
Tier 1 (preferred): On-site field visit with photographic record.
Tier 2: Phone call to a second local resident, ASHA worker, shopkeeper, or gram panchayat member who can independently confirm the issue.
Tier 3: Documented PWD / municipal complaint record showing an unresolved prior filing.
What is recorded
Verifier ID (internal reference only), verification method used, source type, date and time of verification, any contradictions with the original submission, and a confidence rating (high / medium / low).
Identity of verifying sources
Never published. Sources who verify grievances are protected by the same non-disclosure standard as the original submitter. Their contact details are stored in an encrypted column and are not accessible to the public-facing data pipeline.
Verification cost
₹200–₹500 per verified grievance depending on method. Field visits cost more; phone verifications cost less. This is the primary use of donated funds. See the fund usage breakdown.
Verification standard: We aim to publish nothing that a reasonable person, upon visiting the location, could not independently confirm. If there is reasonable doubt, the submission is held — not rejected — pending additional verification.
05
Verification decision tree
Applied to every submission before status changes
Decision
Verification checklist — all conditions evaluated in order
#
Condition checked
Outcome if fails
1
Is the issue currently active? Not resolved by the time of verification.
RejectedMarked resolved if administration has already acted. Optionally published as a closed case.
2
Is the location verifiable? Can we confirm the tehsil and approximate area from independent sources?
HeldReturned to submitter (if contact provided) for location clarification. Published with district-only pin if clarification not received within 14 days.
3
Does the description match the verification? No material factual contradictions between submission and ground source.
AmendedPublished with corrected description. Original wording retained in internal record. Amendment noted in the entry.
4
Is this a likely duplicate? Same location, same category, same approximate issue as an existing entry filed within 60 days.
MergedSubmission count on existing entry incremented. New submission details reviewed for any additional information before merging.
5
Does it contain personal data of third parties? Names, phone numbers, or addresses of individuals not party to the submission.
RedactedThird-party personal data is removed before publication. Submitter is notified if contact was provided.
6
All conditions above pass?
Approved for publicationStatus set to verified. Moves to classification stage.
Stage 03

Classification and tagging

Verified submissions are tagged with structured metadata that drives the map visualisation, category filters, and constituency-level aggregation on the dashboard.

06
Structured classification pass
Applied after verification is confirmed
Classify
A team member assigns final tags. The category selected by the submitter is confirmed or corrected — for example, a broken water tank reported under "Roads" is reclassified to "Water" before publication. Constituency and district assignments are verified against the official delimitation order.
Category taxonomy
Roads — surface damage, blocked routes, missing bridges, landslide clearance.
Water — supply cuts, contamination, broken mains, Jal Jeevan gaps.
Health — PHC closures, staff vacancies, medicine shortages, ambulance access.
Power — unscheduled cuts, transformer failures, billing disputes, new connections.
Youth / Employment — skill centre gaps, placement failures, MGNREGA non-payment.
Severity rating
Critical — direct threat to life, health, or access to essential services for 50+ households.
High — significant hardship for 20+ households, ongoing for more than 3 months.
Standard — all other verified grievances.
Constituency mapping
Tehsil is cross-referenced against the 2008 Delimitation Commission order to assign the correct Vidhan Sabha constituency number. Kinnaur, Bharmour (ST), and Lahaul-Spiti are flagged separately due to geographical complexity.
RTI cross-link
If an RTI request has been filed on the same issue, the submission is linked to the RTI record. The outcome of the RTI (response, non-response, partial disclosure) is updated on the dashboard entry when received.
Stage 04

Publication to the dashboard

Verified, classified submissions are published to the public dashboard. This is what appears on the map, the live feed, and the district-level aggregation charts.

07
Published to public dashboard
Status set to live — visible to all
Live
Once approved, the entry is written to the public database and appears on the dashboard within 15 minutes. The following fields are published. Everything else stays internal.
Field published What it shows Visibility
description The verified grievance text. If amended during verification, the corrected version is published. Submitter's exact wording is not guaranteed to appear verbatim. Public
district The HP district the grievance is located in. Used for map choropleth colouring. Public
tehsil Approximate tehsil marker placement on the map. Not a precise GPS coordinate — placed at the tehsil centroid, not the exact complaint location. Public
category Roads, Water, Health, Power, or Youth. Drives the filter pills and bar chart on the dashboard. Public
constituency Vidhan Sabha constituency number and name, used for the assembly map tab and unresolved rate tracking. Public
received_at Shown as a relative timestamp ("2 hours ago"). Exact date is not displayed publicly to prevent reverse-engineering the submitter's identity through timing. Public
submission_id Internal reference. Not displayed publicly, but available if a submitter needs to follow up on their entry. Internal
contact details Phone number or email provided optionally by the submitter. Never published under any circumstances. Never published
photo / media If provided and of sufficient quality, published with EXIF metadata fully stripped. GPS data, device model, and creation timestamp are removed before upload. Public (EXIF stripped)
raw submission text Original wording before any verification edits. Retained internally for audit purposes. Never published. Internal only
The dashboard does not display any information that could identify the submitter. The combination of district + tehsil + category + timestamp is the finest granularity we publish. We do not display street addresses, GPS coordinates, or any personal identifiers.
Stage 05

Flagging, disputes, and corrections

Published entries can be disputed by any party — including government officials, the submitter, or a third party with direct knowledge. All disputes are reviewed within 7 days.

08
Dispute and correction process
Available to all parties after publication
Dispute
If a government official, MLA office, or any member of the public believes a published entry is factually incorrect, resolved, or misleading, they can submit a dispute using the contact form. We treat government disputes with the same process as citizen disputes — neither gets preferential treatment.
Grounds for correction
Issue resolved — administration has addressed the grievance. Evidence required (photo, government order, or independent confirmation).
Factual error — description is materially incorrect. Correction with evidence required.
Wrong location — district or tehsil is incorrectly assigned.
What we will not remove
A verified entry will not be removed on the grounds that it is embarrassing to an official, that the official disputes it without evidence, or that legal pressure is applied without a court order. We publish our dispute log publicly.
Resolution outcomes
Upheld — entry stands unchanged.
Corrected — entry updated with correction note visible.
Resolved — entry marked as resolved, retained in archive.
Removed — only on verifiable factual error or court order.
Timeline
All disputes acknowledged within 48 hours. Decision published within 7 calendar days. If a dispute is filed against an entry and is under active review, the entry is marked under review but not removed during the review period.
!
Government threats and legal notices: All legal notices received are published in full on our GitHub repository within 7 days of receipt. We do not remove entries in response to informal pressure. We respond to all formal legal notices through proper legal process.
Data inventory

Complete record of what data we hold

This is a full inventory of every data type we collect, where it is stored, who can access it, and what happens to it.

Last audited: July 2025  ·  Next audit: October 2025  ·  Full audit log available on GitHub
Data type Where stored Access Retention Visibility
Verified grievance text Public database (Supabase, EU region) HAP team + public read Indefinite (archive) Public
District, tehsil, category Public database HAP team + public read Indefinite Public
Raw submission text (before edits) Internal database (encrypted at rest) HAP team only 2 years, then deleted Internal
Submitter contact details (if provided) Encrypted column, separate table Verification team only 90 days, then deleted Never published
Verifier notes Internal database HAP team only 2 years, then anonymised Internal
Media / photos (EXIF stripped) Object storage (Cloudflare R2) HAP team + public read Indefinite if published Public (no metadata)
PIN codes Internal database, hashed Duplicate check only 90 days, then deleted Never published
Site form submission logs Server logs HAP infrastructure team 30 days rolling Internal
Dashboard analytics (page views) Vercel Analytics (cookieless) HAP team only 90 days Internal
Donor payment records Razorpay (PCI-DSS compliant) HAP finance + Razorpay 7 years (legal requirement) Internal
Privacy protections

How we protect submitters

Submitting a grievance about a government official or infrastructure failure can carry social or professional risk in small communities. These are the protections in place.

//
No identity attached to published entries
Nothing published on the dashboard can be traced back to the submitter by a third party. District and tehsil are the finest granularity we use. We never publish names, phone numbers, or submission times precise enough to identify an individual.
Σ
Aggregation only at tehsil level
Map pins are placed at tehsil centroids — the geographic centre of the tehsil — not at the precise location of the complaint. A submission from a small village of 200 people appears on the same pin as submissions from the tehsil town.
No tracking, no cookies, no fingerprinting
The dashboard and this page set no tracking cookies. Analytics are cookieless page-view counts via Vercel Analytics. We do not fingerprint browsers, track IP addresses across sessions, or sell any data to any third party.
Photographs are stripped of metadata
All photos submitted are processed to remove EXIF data — including GPS coordinates, device model, creation timestamp, and any embedded personal information — before being stored or published. We use ExifTool with a full-strip flag on all incoming media.
Contact details are encrypted and time-limited
If you provide a phone number or email address, it is stored in an AES-256 encrypted column in a separate database table. It is accessible only to the verification team. It is deleted after 90 days regardless of whether it was used.
§
We do not cooperate with informal data requests
We will not share submitter information with government officials, police, or political parties in response to informal requests. We respond only to court orders, and we publish all such orders on our GitHub repository within 7 days of receipt.
Retention policy

How long we keep each type of data

Different data types have different retention periods based on their purpose. Contact details are deleted quickly. Verified public grievance records are kept permanently as part of the civic archive.

Data type
Retention period
After retention expires
Verified grievance records (public)
Indefinite
Archived permanently — public record
Submitter contact details (phone / email)
90 days
Hard deleted — no backup retained
Raw submission text (pre-edit)
2 years
Hard deleted
Verification notes and source details
2 years
Anonymised — verifier identity removed
PIN codes (hashed)
90 days
Hard deleted
Server and webhook logs
30 days rolling
Automatically purged
Dashboard analytics (page views)
90 days
Automatically purged by Vercel
Donor payment records
7 years
Retained — statutory accounting requirement
Rejected / unverified submissions
6 months
Hard deleted with all associated data
Your rights

What you can ask us to do

These rights apply to any person who has submitted a grievance, provided contact details, or donated to the platform. Contact us at data@himachal-accountability.in to exercise any of them.

01
Access — see what we hold about you
You can request a copy of all data we hold that is associated with your submission ID, contact details, or donation record. We will respond within 14 days. No fee charged.
→ Email data@ with subject: DATA ACCESS REQUEST
02
Correction — fix an error
If any data we hold about you is factually incorrect, you can ask us to correct it. For published entries, corrections are made with a visible amendment note. We do not silently edit published records.
→ Email data@ with subject: CORRECTION REQUEST + submission ID
03
Deletion of personal data
You can ask us to delete your contact details at any time, including before the 90-day automatic deletion. Deletion of personal data does not automatically remove the associated verified grievance from the public record.
→ Email data@ with subject: DELETE MY DATA + submission ID
04
Withdrawal of a grievance submission
If you submitted a grievance and want it removed from the public dashboard, you can request withdrawal. We will assess whether the public interest in retaining it outweighs the request. If the issue has been resolved, we will mark it closed rather than delete it.
→ Email data@ with submission ID and reason
05
Objection to processing
You can object to us processing your data for any purpose. We will assess the objection and respond within 14 days with either a decision to stop processing or a documented reason why public interest requires us to continue.
→ Email data@ with subject: OBJECTION TO PROCESSING
06
Portability — get your data in a usable format
You can request your submission data in JSON or CSV format. All verified public grievance data is also available as a bulk download from the dashboard — no request needed.
→ Email data@ with subject: DATA PORTABILITY REQUEST