Who we are
FormYaar ("we", "us", "our") is a product developed and operated by Hemant Chauhan (trading as ExcuseME Brother), an individual entrepreneur based in Bareilly, Uttar Pradesh, India. We are the data fiduciary for the data described in this policy, in the sense given by India's Digital Personal Data Protection Act, 2023.
FormYaar helps Indian citizens fill government forms — PAN card applications today, with other forms following — on the official government portals themselves. It does not submit anything on your behalf and does not act as an agent between you and the government. We are not affiliated with, endorsed by, or connected to the Government of India, the Income Tax Department, Protean (formerly NSDL) e-Gov, UTIITSL, Parivahan, Passport Seva, UIDAI, or any other government entity.
Contact:
Email: formyaar@gmail.com
Website: formyaar.in
Location: Bareilly, Uttar Pradesh, India — 243001
Scope of this policy
This is a single policy covering every place FormYaar runs. There is no separate policy for the app and the extension — the rules below apply to both, and wherever a platform differs, this document says so explicitly.
| Product | Where you get it | Identifier |
|---|---|---|
| FormYaar Android app | Google Play Store | in.formyaar.app |
| FormYaar Chrome extension | Chrome Web Store | "Form Yaar" |
| Website | Public web | formyaar.in |
| Payment page | Opened during checkout | formyaar.in/pay |
| Backend API | Called by all of the above |
formyaar-backend-production-9da7.up.railway.app
|
This policy does not apply to the government portals you reach through FormYaar — the Protean/NSDL PAN portal, UTIITSL, Sarathi Parivahan, Passport Seva, and others. Those are operated by the Government of India and its agencies under their own privacy policies. FormYaar's role is to populate the fields of a form you are filling yourself; everything you then submit travels from your device to the government, and not through us.
In the Android app, the government form opens inside the app's own browser view. That is a real, direct connection between your phone and the government's server — the same one your browser would make. FormYaar's code types into that page on your device; it does not relay the page back to us, and your application data never passes through our servers on its way to the government.
The core principle
Everything below follows from one decision taken before any of this was built: we do not want your application data. Holding it would create a target, and the product does not need it — filling a form is something that can be done entirely on the device where the form is open.
This is why we deliberately ruled out the easier engineering path. We could have filled forms server-side with a headless browser, which would have meant your Aadhaar details passing through and resting on our machines. We chose the harder route — a script inside your own browser on desktop, an in-app browser view on Android — precisely so that never happens.
The PAN application asks only for the last 4 digits of your Aadhaar, and that is all FormYaar collects for it. Collecting or storing Aadhaar data without UIDAI's KUA registration is prohibited under the Aadhaar Act, 2016 — we comply by design, not just by promise. Where a different form genuinely requires a full document number (an Aadhaar, passport, or TIN number on a correction application), that value is treated as sensitive: it is held in session storage on desktop and in memory only on Android, it is never written to durable storage, it is never sent to us, and our servers additionally strip and discard those three fields if any client ever sends one by mistake.
Data we collect
Below is every category of data FormYaar touches. The Your device tag means the data never leaves the device it was typed on. The Our server tag means it reaches us — and every one of those is explained in full.
4A. Application details you enter — device only
These are the fields FormYaar types into the government form for
you. In the Chrome extension they live in
chrome.storage.local; in the Android app they live in
the app's private storage on your phone.
None of them is transmitted to our servers — with
the single, named exception of your mobile number, covered in
Section 5.
| Data | Example | Where it lives | What it is for |
|---|---|---|---|
| Full name | First, middle, last name | Your device | Name fields on the form |
| Name as per Aadhaar | The name printed on the card | Your device | The government matches this against Aadhaar letter for letter |
| Date of birth | DD/MM/YYYY | Your device | Date of birth fields |
| Gender | Male / Female / Other | Your device | Gender selection |
| Aadhaar — last 4 digits | e.g. "4892" | Your device | The Aadhaar verification field. The full 12-digit number is never collected for this form |
| Father's and mother's names | Parent name fields | Your device | The family details section |
| Address | House, street, city, state | Your device | The address section of the form |
| PIN code | 6-digit area PIN | Your device Our server | Saved on your device for the address section — and the PIN alone is sent to our server to look up the AO code the PAN form requires. It is also kept with our usage records, so we can see which areas the lookup fails for and add them. In the Android app those records carry your mobile number, so there the PIN is stored alongside it. See 4C |
| Email address | example@gmail.com | Your device | Contact fields on the form. Separately given to Razorpay at checkout if you want a receipt |
| Mobile number | 10-digit Indian number | Your device Our server | Contact fields on the form — and the one field that also reaches us. See Section 5 |
| Place of verification | City name | Your device | The "Place" field in the declaration |
| Proof of DOB, source of income | "Aadhaar Card", "Salary" | Your device | Document-type and income selections |
| Supporting document (Android app) | A PDF or photo you attach | Your device | Handed by you into the government form's own upload field. We never receive it, and it is never sent anywhere by us |
| Aadhaar, passport or TIN number, where a form requires it | A full document number | Your device — memory only | Held only while the app or browser is open, never written to durable storage, never sent to us |
4B. Usage events — pseudonymous, sent to our servers
FormYaar records which step of the process you reached, so we can see where applications break. Government portals change their pages without notice, and this is how we find out that a field stopped filling before hundreds of people hit the same wall. Each event carries:
| Field | What it is | Identifies you? |
|---|---|---|
| Event name |
e.g. home_screen_view,
payment_success, field_fill_failed
|
No |
| Form type | e.g. pan_card |
No |
| Anonymous id | A random id generated once per app install or browser profile. Not your device id, not an advertising id, not derived from anything about you or your phone | Pseudonymous |
| Session id | A second random id that dies when you close the app or browser, so one sitting can be told apart from a return visit | Pseudonymous |
| Platform and version |
android or extension, plus the
version number, so a fault can be traced to a release
|
No |
| Timestamp | When the event happened on your device | No |
| Event details | Technical context — which field failed, which page, the order id for a payment event, and your PIN code on the events about the AO-code lookup. Length-capped, and scrubbed of the sensitive fields named in Section 3 | No |
| Mobile number (Android app only) | Attached to events only after you have typed your own number into the form, so a run of events can be joined to your application. The Chrome extension does not attach it | Yes — see Section 5 |
Because pseudonymous is the honest word. A random per-install id still links your events to each other, and in the Android app those events can carry the mobile number you typed. Calling that "anonymous" would be marketing, not a privacy policy.
4C. PIN code and AO code lookup
The PAN form needs an Area Office (AO) code, which depends on where you live. When you enter your PIN code it is sent to our backend, which answers with the state, city, and AO code. If that PIN is not in our own index, our server — not your device — queries the public India Post pincode API to resolve it.
We also keep the PIN code. It is attached to the usage events that record whether the lookup succeeded, because the most useful thing we can know about our coverage is which PIN codes we cannot answer for — that list is what tells us which areas to add next. In the Android app every usage event carries your mobile number once you have typed one, so on that platform your PIN code is stored next to your number; in the Chrome extension it is not. Both go with the rest of the usage records on the schedule in Section 14, and immediately if you ask us to delete your data.
4D. Payment data
Payments are processed entirely by Razorpay Software Private Limited. We do not see, store, or process your card number, CVV, UPI ID, or bank details at any point. What we do store is the order id, the Razorpay payment id, the amount, the timestamp, and the mobile number the order belongs to. Full detail in Section 12.
4E. In-app help chat (Chrome extension only)
The extension has a help chat that answers questions about a specific form field. When you send a message, the text you typed and the name of the field you are on are sent to our backend and from there to Anthropic, whose model writes the answer. Nothing else about you is attached — not your name, not your form data, not your ids — and we do not keep a record of these conversations. Please do not type document numbers into it; it does not need them.
4F. Server logs
Our backend generates ordinary HTTP access logs — IP address, timestamp, and the endpoint called — held by our hosting provider for security monitoring and debugging. We do not use them to build profiles of people and do not combine them with form data.
No location. No contacts. No photo or media library access. No microphone or camera. No SMS or call logs. No list of installed apps. No browsing history. No device identifier, IMEI, or advertising id. No third-party advertising or analytics SDK is bundled in the Android app or the extension — the usage events in 4B go to our own backend and nowhere else.
Your mobile number — the one we treat most carefully
Two things you type reach us: your mobile number, and your PIN code (Section 4C). Every other personal detail stays on your device. The number is the one that identifies you, so we would rather say what happens to it plainly on its own page than bury it in a table.
We use it for: contacting you if your application appears to have got stuck ("we noticed your PAN application didn't finish — did something go wrong we can help with?"), matching a payment to an application, and supporting refunds.
We do not: sell it, rent it, trade it, add it to a marketing list, send you promotional SMS or WhatsApp campaigns about unrelated products, or share it with any party other than the processors named in Section 8.
You can have it deleted at any time. Email formyaar@gmail.com with the subject "Data Deletion Request" and the number, and we will delete it and every record attached to it, other than payment records we are legally required to keep. Details in Section 15.
Why we collect this data
We collect only what the product needs to work, and nothing that merely might be interesting later. Purpose by purpose:
Under the Digital Personal Data Protection Act, 2023, the lawful basis for all of the above is your consent, given when you choose to use FormYaar and enter your details — except for payment records, which we retain to comply with a legal obligation.
How and where data is stored
On Android
- Your part-filled application is written to the app's private storage — a sandbox that, on a non-rooted device, no other app can read. It survives the app being closed, so you do not lose a half-finished form.
- A document you attach is stored the same way, inside the app's own private files. When you tap to preview it, a single read-only copy is handed to the PDF viewer you choose, for as long as that view lasts, through Android's standard file-sharing mechanism. Nothing else in the app is exposed to that viewer.
- Aadhaar, passport and TIN numbers — where a form asks for them — are held in memory only, never written to disk, and are gone when the app process ends.
- The app is configured so that Android's automatic cloud backup does not copy its data to Google Drive.
- Everything above is deleted when you tap Discard in the app, when you clear the app's data from Android settings, or when you uninstall the app.
In the Chrome extension
-
Your details are stored in
chrome.storage.local, inside your own Chrome profile. No website and no other extension can read it. -
The state of an in-progress fill, plus any passport or TIN number,
lives in
chrome.storage.session, which Chrome clears when you close the browser. Those numbers are never written to persistent storage. - Everything is deleted when you use the extension's own delete control, or when you uninstall the extension.
On our servers
Our backend runs on Railway and stores its data in Supabase (a managed PostgreSQL service). The complete list of what is stored there is:
- Contact records — a mobile number, the form type, and when it was first and last seen.
- Payment records — order id, Razorpay payment id, amount, timestamp, mobile number, and any coupon used.
- Usage events — as itemised in 4B.
- Operator and distributor accounts — for business partners only, not for ordinary users; see Section 13.
That is the whole list. There is no table anywhere on our infrastructure holding your name, your date of birth, your parents' names, your address, your Aadhaar digits, or your uploaded document — with the one exception described in Section 13, which applies only when a counter operator fills a form on your behalf.
Every connection between FormYaar and our backend uses HTTPS with TLS 1.2 or higher. The Android app is configured to refuse cleartext HTTP outright. Data at rest on Supabase is encrypted by the provider.
Who else sees data
FormYaar does not sell, rent, lease, or trade personal information to data brokers, advertisers, or anyone else. For your application details this is structural rather than a promise — we do not hold them, so there is nothing to sell.
These are the only third parties involved, each one a processor acting on our instructions or a service we depend on to operate:
| Who | What they get | Why |
|---|---|---|
| Razorpay | Your payment details, entered directly into their checkout; the order amount; your email if you want a receipt | To take the payment. India, RBI-authorised payment aggregator |
| Supabase | Everything our backend stores — contact records, payment records, usage events | Our database provider |
| Railway | Backend requests and server logs | Hosts our backend API |
| Cloudflare | Standard web request data (IP, headers) for the website and payment page | Website hosting, CDN and DDoS protection |
| Meta (Facebook) | A SHA-256 hash of your mobile number and the order value, on a completed purchase. The raw number is never sent | Measuring which advertising actually leads to a completed application. See below |
| Anthropic | The text you type into the extension's help chat and the name of the field you are on | Generates the answer. Extension only |
| India Post pincode API | A 6-digit PIN code, sent by our server, with nothing attached to it | Resolving a PIN we do not have indexed to a district and city |
| Telegram | Technical breakage alerts — the event name, form, and which field or page failed. No personal data | How we find out within minutes that a government portal changed |
| Google Play | Install, crash and rating data that Google collects as the app store, under its own policy | Distributing the Android app |
| Google Ads | On our website only: a cookie recording that you arrived from one of our ads, and — if you go on to pay — that a purchase happened and for how much. No name, no number, no application data | Measuring which advertising actually leads to a completed application. See below |
About the Meta advertising signal
We advertise FormYaar on Meta's platforms. Without knowing which clicks turned into completed applications, that advertising finds more people who click and fewer who are actually helped. So when a payment completes, our server tells Meta that a purchase happened and for how much, identifying it with a one-way SHA-256 hash of your mobile number. Meta can match that hash against a number it already holds; it cannot reverse it into your number, and your actual number never leaves our servers. No application data, no name, no email, and no device identifier is included, and there is no Meta pixel or SDK inside the app, the extension, or our website.
If you would rather this did not happen, email us and we will exclude your number.
About the Google Ads tag
We also advertise on Google, and it needs the same answer Meta does: did this click lead to anyone actually being helped? The Google tag on formyaar.in writes a first-party cookie when you arrive from one of our ads, and reads it again on the payment page to report that a purchase happened and its value. That is the whole of it — no name, no mobile number, no email, and nothing at all from the form you are filling in, which never passes through our website to begin with.
The tag is on the public website only. There is no Google Ads tag inside the extension or the Android app, so nothing you do while a form is open is visible to it. Browser settings that block third-party or advertising cookies stop it working, and nothing on the site depends on it.
Legal requirements
We may disclose information where we are required to by law, court order, or a lawful demand from a government authority under Indian law — including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 — limited to what is actually required. Note again that we cannot produce your application details under any such demand, because we do not hold them.
Google Play data safety
Google Play asks every app to declare what it collects and shares.
This section is the plain-language version of that declaration for
in.formyaar.app, so you can hold the two against each
other.
| Data type | Collected? | Shared? | Purpose & notes |
|---|---|---|---|
| Phone number | Yes | Yes — hashed, to Meta; in the clear to our own processors only | App functionality, support and payment matching. Required to complete an application, since the government form asks for it. See Section 5 |
| Name, date of birth, parents' names, street address, other form fields | No — stays on your device | No | Typed into the government form from your device. Never transmitted to us |
| PIN code | Yes | Only to the public India Post API, and only when we cannot resolve it from our own index | App functionality — resolving the Area Office code the PAN form requires — and analytics, to find the areas our index cannot answer for. Stored with usage events; on Android those also carry your mobile number. See 4C |
| Email address | No — stays on your device | Only if you enter it at Razorpay's checkout for a receipt | Filling the form's email field |
| Files and documents | No — stays on your device | No | A document you attach is uploaded by you into the government portal. It never reaches us |
| Payment information | No — handled by Razorpay | No | We receive a payment confirmation, never card or UPI credentials |
| App interactions (usage events) | Yes | No | Analytics and app functionality — finding where applications break. See 4B |
| Crash and diagnostic logs | Yes — error events, plus whatever Google Play collects | No | Diagnosing faults |
| Approximate or precise location | No | No | We never request location. Your PIN code is typed by you, not derived from the device |
| Contacts, SMS, call logs, calendar | No | No | Not requested, not accessed |
| Photos, videos, music, media library | No | No | Attaching a document uses Android's document picker, which hands the app only the one file you choose |
| Device or advertising identifiers | No | No | No Android ID, no advertising id, no IMEI. Our anonymous id is a random value we generate ourselves |
| Health, financial, or biometric data | No | No | Not collected in any form |
Android app permissions
The FormYaar Android app declares exactly one Android permission. There is no second one, and nothing is requested at runtime.
Two things the app does that look like they should need a permission, and why they do not:
- Attaching a document uses Android's system document picker. You choose one file; the app receives that file and nothing else. It never gets access to your storage, your gallery, or any other document.
- Opening your attached document in a viewer hands one read-only copy to the app you pick, for the duration of that view, through Android's standard secure file-sharing mechanism.
It contains no advertising SDK, no third-party analytics SDK, and no social login. It does not read your device identifiers, does not run in the background, does not use accessibility services, and does not ask for "display over other apps" or any other high-risk permission. Remote debugging of the in-app browser is switched off in release builds, so the page you are filling cannot be inspected from a connected computer.
Chrome extension permissions
The extension requests the minimum set of permissions that lets it work, and no more.
chrome.storage.local on your own machine, and keeps
the state of an active fill in
chrome.storage.session. Without it the extension
cannot remember anything between pages.
onlineservices.proteantech.in,
onlineservices.nsdl.com,
www.utiitsl.com, passporthub.gov.in,
sarathi.parivahan.gov.in, formyaar.in,
and our own backend. It does not request
<all_urls>, so it cannot run on any other
website you visit.
No browsing history, no cookies, no bookmarks, no downloads, no geolocation, no camera, no microphone, and no clipboard access. We cannot see any page you visit outside the list above.
Payments and Razorpay
FormYaar uses Razorpay Software Private Limited as its payment gateway. Razorpay is authorised by the Reserve Bank of India as a Payment Aggregator and is PCI-DSS Level 1 certified.
How the flow works
- FormYaar asks our backend to create an order. The price is set on our server, never by the app or the extension.
- Checkout opens at formyaar.in/pay — in a new tab on desktop, inside the app on Android — and loads Razorpay's own checkout. Card numbers, UPI IDs and bank credentials are typed into Razorpay's interface, not ours.
- Razorpay notifies our backend that the payment completed. We verify that notification cryptographically before trusting it.
- FormYaar checks with our backend rather than believing the page, and unlocks the fill once payment is genuinely confirmed.
What we receive
The Razorpay order id, the payment id, the amount, the timestamp, the mobile number the order belongs to, and any coupon code used. We never receive or store your card number, CVV, UPI ID, bank account number, or any other payment credential.
Coupons and distributor codes
If you enter a distributor's coupon code, that code is sent to our backend to apply the discount, and the resulting order is recorded against that distributor so they can be paid their referral commission. The distributor is told that a referral happened and is not given your mobile number, your name, or any application detail.
Refunds
Refunds are made back to your original payment method through Razorpay. Email formyaar@gmail.com with your payment or order id. The conditions are set out in our Terms & Refund Policy.
FormYaar does not process, transmit, or store payment card data at any point. It is handled end to end by Razorpay under their PCI-DSS certification.
Operator-assisted fills
Most people use FormYaar themselves. Some use it through a CSC centre, internet café, or shop, where an operator fills the form for them. That case works differently, and it is the one place where application details do reach our servers — so it gets its own section rather than a footnote.
When you fill the intake form an operator sends you (a
formyaar.in link they share), your details — name,
parents' names, date of birth, mobile, email, city, state, PIN
code, gender, source of income, proof of DOB, and the last 4
digits of your Aadhaar — are
stored on our servers so they appear in that
operator's queue. This is the only way the operator can pick your
application up and complete it. It applies solely to this route;
it does not happen when you use FormYaar yourself in the app or
the extension.
- A stored intake record is visible to the operator you sent it to and to us, and to nobody else. Operator accounts are authenticated and can only read their own queue.
- Full Aadhaar, passport and TIN numbers are never part of an intake record — only the last 4 Aadhaar digits, which is what the form asks for.
- When an operator uses the extension at their own counter, the customer's details are held on the operator's own device under the same device-only rule as everyone else.
- Operators are responsible for handling customer data lawfully, for not keeping it beyond the application, and for telling customers what they are doing with it.
- You can ask us to delete an intake record at any time by emailing formyaar@gmail.com.
Data retention
We keep data only as long as the purpose it was collected for lasts. Where a period below depends on us running a deletion rather than the platform doing it automatically, we say so — a policy that describes a schedule nobody runs is worse than no policy.
| What | How long | Gone when |
|---|---|---|
| Your details on your device | Until you delete them | You tap Discard, clear app data, or uninstall the app or extension |
| Aadhaar / passport / TIN numbers | The length of one session | The app process ends, or the browser closes. Never written to disk in the first place |
| Attached document (Android) | Until the application is finished or discarded | You tap Discard, clear app data, or uninstall |
| Contact record (mobile number) | 180 days if you never paid and we never rang you. If either happened, until you ask us to delete it | A nightly job, or on your request. A number that paid or that we actually contacted is deliberately kept, because it belongs to a real customer conversation — ask and it goes |
| Usage events (including PIN codes) | 90 days | A nightly job, once that day has been summarised. Events carrying your mobile number are also removed on a deletion request. What outlives them is a daily count per event — how many people reached a step on a given day, with nothing in it about any person |
| Payment records | 7 years | Kept for the period Indian tax and financial record-keeping rules require. These cannot be deleted earlier on request |
| Resume-a-payment session | 14 days of usefulness, deleted after 21 | Stops working 14 days after payment — long enough to come back and finish an application you have already paid for. The row is deleted a week after that, or on request |
| Operator intake records | 7 days after completion; 90 days regardless | Deleted by the operator from their queue, or by us on your request |
| Server access logs | Our hosting provider's own window — around 30 days | Rotated out by the provider. We keep no separate archive |
| PIN codes sent on to India Post | No separate log | We keep no record of the outbound call itself. The PIN is kept in our usage events — the row above |
| Help chat messages | Not retained by us | Answered and discarded |
Your rights, and how to delete your data
Under the Digital Personal Data Protection Act, 2023 you have rights over your personal data. Here is how each of them works in practice with FormYaar.
Delete everything on your device — immediate, one tap
- Android app: tap Discard on the home screen. Your saved application, your attached document, and your session are wiped from the phone at once. Clearing the app's data from Android settings, or uninstalling it, does the same thing.
- Chrome extension: use the delete control on the FormYaar home screen. All saved details and session data are wiped immediately. Uninstalling the extension does the same.
Delete what we hold on our servers
Email formyaar@gmail.com with the subject "Data Deletion Request" and the mobile number you used. We will delete that number, the contact record, the usage events attached to it, and any operator intake record, and confirm to you when it is done — within 30 days, usually much sooner. The only thing we cannot delete on request is a payment record, which we are legally obliged to keep for the period in Section 14.
There is no account to delete. FormYaar has no sign-up, no password, and no user profile — which is why a mobile number is all a deletion request needs. (Operators and distributors do have accounts; they can ask us to close theirs the same way.)
Access and correction
Your application details are on your own device, where you can open and edit any field at any time. For what we hold on our servers, email us and we will tell you exactly what is there against your number and correct anything wrong.
Portability
Your data lives in your app or your Chrome profile, both of which you control. Nothing about you is locked inside our servers where you cannot get at it.
Withdrawing consent
Stop using FormYaar and delete your data — uninstalling clears everything on the device, and a deletion request clears everything on our side. You can also ask us to stop attaching your number to usage events, or to exclude it from the Meta advertising signal in Section 8, without deleting anything else.
Nominating someone, and complaining
The DPDP Act lets you nominate a person to exercise these rights on your behalf if you die or become incapacitated; tell us in writing and we will honour it. If you think we have handled your data badly, write to formyaar@gmail.com first — we answer within 48 hours. If our answer does not satisfy you, you may complain to the Data Protection Board of India.
Children's privacy
FormYaar is for adults. The account holder using it must be 18 or over, and we do not knowingly collect personal data from anyone under 18. We do not direct the app or the extension at children, and we do not profile or advertise to children.
A PAN application can legitimately be made for a minor by their parent or guardian. Where FormYaar supports that, the adult is the one using the product and giving consent, exactly as the government form requires — and the minor's details, like every other application detail, stay on that adult's own device.
Because application data never reaches our servers, there is no store of children's information for us to hold. If you believe a child has used FormYaar on a shared device, wipe it in one tap using Discard (Android) or the delete control (extension). If you believe we somehow hold data about a minor, email us and we will delete it.
Security measures
These are the concrete measures in place:
- Data minimisation as the first control. The strongest protection for your application data is that we never receive it. There is no server-side copy to breach.
- HTTPS everywhere. TLS 1.2 or higher on every connection; the Android app refuses cleartext HTTP entirely.
- Sandboxed device storage. Extension data is readable only by the extension; app data lives in Android's private app storage and is excluded from cloud backup.
- Sensitive fields never persisted. Aadhaar, passport and TIN numbers are held in memory or session storage only, and are stripped server-side as a second line of defence if a client ever sends one.
- Verified payment webhooks. Razorpay notifications are checked with an HMAC-SHA256 signature compared in constant time, so a forged "payment succeeded" cannot be injected.
- Server-side pricing. Amounts and coupons are resolved on our backend; a modified client cannot set its own price.
- Authenticated operator access. Operator endpoints require a session token and check that the token's owner matches the data being requested.
- Rate limiting and input allowlisting on the public write endpoints, plus standard HTTP security headers and restricted cross-origin access on the backend.
- No secrets in logs. Backend logs record status codes and event names, never request bodies carrying a mobile number.
- Debugging off in release builds. The Android app's in-app browser cannot be remotely inspected from a connected computer in a shipped build.
No system is perfectly secure, and we will not pretend otherwise. If you find a vulnerability in FormYaar, please report it to formyaar@gmail.com — we acknowledge reports within 24 hours and will not pursue anyone who reports one in good faith.
If a breach ever affects your personal data, we will notify you and the Data Protection Board of India as the DPDP Act requires.
Government portals and third-party links
FormYaar operates on top of government portals — the Protean/NSDL PAN portal, UTIITSL, Sarathi Parivahan, Passport Seva and others. These are run by the Government of India and its agencies, under their own privacy policies, terms, and data practices. What you submit there is between you and them; we are not responsible for how those portals handle it, and we cannot see it.
Both the app and the extension show you the live address of the site you are on, and mark the official government hosts explicitly. That is there so you can always tell whether you are on a government page, our checkout, or somewhere else entirely — please check it before typing sensitive details anywhere.
Our website links to third-party sites such as the Chrome Web Store, Google Play, and Razorpay. Those links are for convenience; their privacy practices are their own.
Changes to this policy
We will update this policy as FormYaar changes — new forms, new platforms, or a change in the law. When we do:
- The "Last updated" date at the top of this page changes.
- For a material change — a new category of data collected, a new third party receiving it, or a new purpose — we will say so prominently in the app and the extension, not only here.
- We will not retroactively apply a new purpose to data already collected without telling you and, where the law requires it, asking again.
Continuing to use FormYaar after a change means you accept the updated policy. If you do not, you can uninstall and delete everything at any time, as described in Section 15.
Contact us
Questions about this policy, about your data, or about anything above — write to us. A real person answers.
Data fiduciary: Hemant Chauhan (trading as
ExcuseME Brother)
Privacy & support email:
formyaar@gmail.com
Website:
formyaar.in
Address: Bareilly, Uttar Pradesh, India —
243001
Response time: within 48 hours for questions,
within 30 days for a deletion request.
For a data deletion request, email us with the subject "Data Deletion Request" and the mobile number you used. For a security vulnerability, email us with the details and we will acknowledge within 24 hours. For a complaint you feel we have not resolved, you may approach the Data Protection Board of India.