Compliance · Data protection
Privacy & Data Protection Notice
Drafted 2026-08-13 · Revised 2026-08-14 · Status: draft, not in force
What this means. This notice is published so it can be read and challenged before it binds anyone. It is not yet a commitment we are held to.
What happens next. It becomes binding when the founders and counsel sign it off and this block is removed — not by a silent edit. Items marked Founder decision are deliberately unfinished rather than invented; each one names the decision that is missing.
Drafted 13 August 2026 against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (notified 13 November 2025; the notice-and-consent provisions take effect 13 May 2027).
FourthHuman records first-person video of people doing real physical work, and turns it into training data for robots. That makes personal data — including video of real people and real homes — the material of our business. This notice states what we collect, why, what we never share, and how you withdraw. Where most privacy policies ask you to trust a sentence, ours points at a mechanism you can check: consent here is a hash-chained ledger entry, and withdrawal is a deletion you can verify, not a request that disappears into a mailbox.
1. Who is processing your data
FourthHuman (the Data Fiduciary under the DPDP Act) is an India-based training-data company. For anything in this notice: [email protected].
Grievance officer: Founder decision must be a named person with a response SLA before the first capture cohort onboards.
2. What we collect, and what each item is for
Itemised as the Act requires — each category tied to its purpose, no bundling.
| Who | Personal data | Purpose — and nothing else |
|---|---|---|
| Capture Partners | Name, mobile number, email | Your account, and reaching you about tasks and payouts |
| UPI / bank details (VPA) | Paying you — ₹250–400/hr, on QA approval. Nothing else | |
| Egocentric video you record | Creating annotated robotics training datasets — the purpose you consent to, per recording task, in the consent ledger | |
| Device identifier, city | Capture metadata inside your consent record, so the record describes the actual capture | |
| Commissioning labs | Business contact details, enquiry contents | Answering the enquiry and managing the engagement |
| Site visitors | Whatever you type into a contact form | Replying to you. This site sets no third-party trackers — every asset, fonts included, is served from our own origin |
2a. Cookies and what is kept in your browser
This site sets no cookies. Not for analytics, not for advertising, and not to remember that you read this sentence. There is no third-party tracker on any page, and the built site fetches from no origin but our own — fonts included.
Three things are kept in your browser's local storage, and all three exist only so the
apps work. fh_api_base remembers which server the app is talking to;
fh_admin_token and fh_commissioning_lab_token keep you signed
in. They stay on your device, are never sent to anyone else, and clearing your browser
data removes them.
If we ever add anything that is not strictly necessary — measuring which pages get read is the only thing we are considering — you will be asked first, refusing will take exactly one click, and nothing will run unless you say yes. You can see and change that choice at any time from your privacy choices in the footer of every page.
3. What never leaves, and what is removed
- Faces are blurred before any human reviews the footage. Automated detection and redaction runs as a pipeline stage; if the detector cannot run, the pipeline stops rather than passing footage through unblurred.
- Your identity is never shipped to a buyer. Delivered datasets and their audit records carry a consent receipt — proof consent exists — never your name, Capture Partner identifier, or device identifier.
- External AI processing is off by default and consent-gated. A captioning stage exists that can send blurred frames to a third-party AI provider. It refuses to run unless production use has been deliberately enabled and your specific clip's consent is active in the ledger. It has never been enabled to date; if that changes, this notice will name the provider before the first production use.
- Model-generated labels are marked as such. Anything a model
derived from your footage is labelled
derivedin the dataset itself.
4. Your rights, and the actual mechanism for each
| Right (DPDP Act) | How you exercise it here |
|---|---|
| Access your data (§11) | Your consent history — every grant and withdrawal, hash-chained — is available in your account at any time |
| Correction (§12) | Email [email protected]; profile self-service is on the app roadmap |
| Withdraw consent / erasure (§6(4), §12) | Revoking a consent receipt deletes your footage and everything derived from it — the raw video, the blurred copy, working files, and the annotation — and halts any processing job. Each deletion is recorded in an append-only log, and a verification endpoint re-scans storage on demand so the deletion is checkable, not asserted. What survives is the ledger entry recording that you withdrew (the evidence your request was honoured) and a content fingerprint of the deleted file (bytes are gone; the fingerprint proves which bytes) |
| Grievance redressal (§13) | Write to the grievance contact above. Response time: Founder decision the Rules expect a stated period |
| Nominate (§14) | You may nominate a person to exercise these rights for you — email us the nomination |
| Complain to the Data Protection Board of India | If our grievance process fails you, you may complain to the Data Protection Board of India, the adjudicating body under the Act |
5. Sharing, retention, and what we do not claim
- Buyers receive datasets, not identities. If your consent is later revoked, your clips are deleted from our storage including from already-cut dataset releases, whose verification then reports the change to the buyer. Deletion obligations flow down into buyer contracts (see Terms).
- Payment processors receive what a UPI payout requires, for that purpose only.
- Retention: footage and derivatives are retained while your consent is active and deleted on revocation as described above. Account and payout records are retained as Indian financial law requires. Founder decision state the exact statutory periods before cohort onboarding.
- What we do not claim: we hold no third-party certification — no SOC 2, no ISO 27001 — and this notice will say so plainly until the day we do. Our security posture is the verifiable mechanisms described here, not a badge.
6. Languages
This notice is currently available in English. Before the first capture cohort onboards, it will be provided in the languages our Capture Partners actually read — the Act entitles you to any of the languages in the Eighth Schedule of the Constitution. Founder decision which translations, and who verifies them.
7. Changes to this notice
Changes to this notice are made by publishing a new dated version here — the current version is dated at the top of this page. This page, like the rest of the site, loads no third-party resources.