Your ownership document never stays with us.
We read two fields off your receipt — your name and your flat number — and then the file is destroyed. Sixty seconds, enforced by the system, not by a policy page.
Watch it happen on the right before you upload anything.
Five steps, then nothing is left
Every step below is something the backend does automatically. No step involves a person opening your document.
You upload
Allotment letter or payment receipt, sent over an encrypted connection.
Two fields are read
Automated text extraction pulls your name and flat number. Nothing else is parsed or kept.
Matched to RERA data
Your flat is checked against the community's RERA-registered unit list, not against a neighbour's word.
Status recorded
We keep first name, tower, unit and a verified flag. That is the entire record.
File destroyed
Deleted within 60 seconds of the check finishing — and the deletion itself is logged.
If your flat number is already claimed, the request is not auto-approved. We ask you first: keep the receipt for 72 hours so a human admin can review it, or decline — in which case the file is deleted immediately and only the attempt is recorded.
“Who in my building can see my number?”
Your admin is a neighbour, not a company. So contact details are hidden from them by default, and every single reveal is written to an audit trail with their name on it.
Misuse is not a matter of trust. It is a matter of record.
Even we cannot edit the log
The audit collection is create-only at the database permission level. Not “we promise not to delete it” — the delete permission does not exist for our own service account.
Sample of the events recorded against a single request.
What owners ask us before they upload
Then you stay unverified. There is no other route — no admin can wave you through, because approval requires a system-side RERA match. That restriction protects you as much as it inconveniences you.
They see a directory of first names, towers and units. Mobile and email are masked until they click to reveal one member at a time — and each reveal is logged with their identity. Repeated reveals are visible to the platform operator and are grounds for removing their admin role.
A second claim on a verified unit is never auto-approved. It is flagged and routed to a human admin, and the claimant must consent to their receipt being held for up to 72 hours for that review. If they decline, the file is deleted at once and the attempt is recorded.
No. There is no public directory. The public search page shows a community, its locality and a count of verified members — never a name, a flat number or a contact detail.
A failed deletion raises an alert rather than passing silently, and storage-level lifecycle rules delete anything left behind as a backstop. Two independent mechanisms have to fail before a file outlives its window.