Privacy Policy — YatriK Rail
Effective date: 4 September 2026
Last updated: 7 September 2026
YatriK Rail ("the app," "we," "us") is operated by Cloudnbots Solutions, a sole proprietorship owned by Kumar Prabhakar ("the developer"). This policy explains what data the app collects, why, and how it's handled.
YatriK Rail is a companion app for Indian Railways travel — PNR status, live train tracking, and station/route search. It is not affiliated with, endorsed by, or operated by Indian Railways, IRCTC, or any Indian government body.
1. What we collect
Information you provide directly
- PNR numbers you enter to check booking status. We send the PNR to our data provider to fetch the official status; we never store or log the PNR itself on our servers.
- Survey responses if you vote in an in-app poll.
Information saved on your device
When you check a PNR, the journey details returned (train number/name, stations, date, class, chart status, quota, and per-passenger booking status/coach/berth/quota/nationality/food preference — never passenger names, which the official data source doesn't provide to us) are saved on your device in encrypted local storage, so you can see your saved trips later. This stays on your device — we don't keep a copy on our servers. It's deleted if you remove the trip in the app, or if you uninstall the app.
Information collected automatically
- A random device identifier — generated on first use, stored only on your device, not linked to your name, email, or phone number. Used to apply fair usage limits, avoid duplicate poll votes, and understand which features and routes are actually used.
- Approximate location (city/region only) — derived from your IP address by our hosting provider. The app does not currently request GPS location — see "Planned features" below for a future, entirely opt-in exception. Used to show regionally relevant content (e.g., a Mumbai-specific survey) and in aggregate usage statistics.
- IP address — inherently visible to our servers while handling your requests, as with any online service. Logged specifically when a request is blocked or rate-limited, to help us investigate abuse.
- Which trains, routes, and stations are looked up — tied to your device identifier, not your identity, used to understand what's popular so we can improve the app.
- An anonymous, device-level usage profile — built from the same lookups above (e.g., whether you mostly look up local or long-distance trains, how often, and your general region), used to make in-app content like surveys more relevant and to guide what we build next. Never tied to your name or identity, and never shared outside the uses described in this policy.
- Smart alert settings, if you set one — the train, station, and timing you chose, tied to your device identifier so we can check that train's status and notify you. Deleted when you cancel the alert.
- Crash reports — if the app crashes, we receive a technical report (what happened, device/OS info) via Firebase Crashlytics, to help us fix bugs. No personal data is deliberately included in these reports.
- Basic app usage (screen views) — via Firebase Analytics, to understand how the app is used overall.
- A push-notification token, once notification permission is granted or requested — see "Notifications" below for an important detail on what declining actually does and doesn't do.
What we do NOT collect
We do not collect your name, phone number, email address, precise GPS location, payment/financial information, contacts, or photos. There is no account or login system — nothing in the app is tied to a real-world identity.
2. Notifications — an important detail
Notifications now have a real, visible purpose: Smart alerts, which you set explicitly on a train, notify you as its live status changes. If you decline the notification permission, you won't receive these — including any alert you've already set — and the app will not show you visible notifications of any kind. However, declining does not prevent your device from being registered to receive silent, invisible messages (used for a background technical check that confirms the app installation is genuine, not for anything visible to you). If you want to stop this entirely, you can disable it from your phone's system settings for the app, or uninstall the app.
3. Who we share data with
- Our data providers (for PNR status, live train tracking, and station/route information) — receive the specific PNR number or train/station identifiers needed to answer your request. They do not receive your device identifier or any other data about you.
- Google Firebase (Analytics, Crashlytics, Remote Config, App Check, Cloud Messaging) — standard infrastructure services; Google processes the data described above (crash reports, usage analytics, push tokens) under its own data-handling terms.
- Cloudflare — our hosting and content-delivery provider; as with any hosted service, it inherently processes network traffic (including IP addresses) to deliver our service.
- Advertising networks (e.g., Google AdMob, and potentially direct advertising partners) — see "Planned features" below. Not yet active as of this policy's last update; disclosed here in advance so the policy doesn't need a surprise rewrite the day it launches.
We do not sell your data, and we do not share data with anyone for their own independent marketing purposes beyond what's described in this policy.
4. Planned features (disclosed in advance)
The two items below are not live yet. We're describing them now, before they ship, so this policy stays accurate on day one rather than needing an update the moment they do — this section will be revised to reflect reality once either actually launches (and the "not live yet" language removed at that point).
In-app advertising. We plan to show ads via third-party advertising networks, starting with Google AdMob, and potentially direct advertising partnerships later. Once active, these networks may collect an advertising identifier, approximate location, and app usage/interaction data to select and measure ads, under their own privacy policies (for AdMob: Google's own privacy policy). Where your device offers ad-personalization controls (e.g., Android's "Opt out of Ads Personalization" setting), those controls will apply to ads shown in this app.
Optional, consented location sharing for live crowdsourced train tracking. We're planning a future feature where you can choose to share your live GPS location while tracking a specific train, to help build a more accurate, crowdsourced picture of train positions and locals crowding for other users — similar in spirit to how some of our own train-position data is itself already crowdsourced by our data providers. This will always be opt-in per session, off by default, and limited to the specific journey you enable it for — the app does not request background or always-on location access, and does not currently request any location permission at all. When this ships, this section will describe exactly what's collected, for how long, and how you can review or revoke access at any time.
5. How long we keep data
- Data saved on your device (trips, device identifier) stays until you delete it or uninstall the app.
- Data on our servers tied to your device identifier is deleted automatically on the following schedule, by a job that runs once a day:
- Security logs (records of blocked or rate-limited requests, including the IP address involved): 180 days.
- Lookup history (which trains, routes and stations were looked up): 180 days.
- Ad and survey interaction records (impressions, clicks, poll votes): 400 days — kept longer because advertisers may need to audit the figures we report to them.
- Smart alert history (alerts that have already fired or been skipped): 60 days. An alert you cancel is deleted immediately, not kept for 60 days.
- You don't have to wait for these periods to elapse — see "Your rights" below for how to request deletion directly.
6. Your rights
You can:
- Delete your on-device data at any time, from within the app or by uninstalling it.
- Request deletion of server-side data tied to your device by contacting us (below) — since there's no account system, we'll need you to describe what to look for (e.g., approximate dates of use); we'll remove what we can identify.
- Ask us what data we hold about your device by contacting us.
7. Children's privacy
YatriK Rail is not directed at children, and we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we'll remove it.
8. Security
We use encrypted on-device storage for saved trip data, and server-side protections (rate limiting, abuse detection, and app-integrity verification) to protect the service. No method of storage or transmission is 100% secure, but we take reasonable, industry-standard steps to protect what we hold.
9. Changes to this policy
We may update this policy as the app changes — for example, when we introduce advertising, location-based features, or other new functionality. We'll update the "Last updated" date above when we do. Continued use of the app after a change means you accept the updated policy.
10. Contact us
Questions about this policy or your data: yatrikrail@gmail.com