Privacy Policy
My Train Rescue • Last updated 18 September 2026
1. What this service does
My Train Rescue helps passengers search railway journeys, view live railway information, check PNR-related information when supported by the data provider, view coach position, review railway rules and estimate certain refund scenarios. You may create an account, save passengers, view account trips, or save a travel plan on this device. In-app railway ticket booking and live payment remain unavailable until an authorized partner integration is approved and verified.
2. Information you may provide
- Origin and destination stations, journey date, passenger count, class, quota and concession choice. For certain quotas or concessions, you may enter age, gender, pregnancy or travelling-alone information, or declare eligibility and whether a required document is available. MTR does not request a pass number, pass PIN or document upload for these enquiries; a declaration does not verify eligibility or apply a discount.
- Train number and boarding station for journey-day tools.
- A 10-digit PNR when you choose to use PNR Rescue or explicitly import an existing railway booking into your signed-in My Trips account.
- Inputs you enter into railway-rules or refund tools.
- If you create an account: email address, account name and password handled by Netlify Identity.
- If you explicitly save passengers: name, age, gender and berth preference. A berth preference is not an assigned seat.
- If in-app booking later becomes available: exact train, run and boarding dates, stations, class, quota, passenger manifest, fare quote, booking state and payment order/payment identifiers. An issued ticket may include a PNR and ticket reference.
Do not submit payment card details, Aadhaar numbers, government identity documents or other information that the service does not request. Enter your account password only in the account sign-in or recovery form.
3. How information is used
You can paste ticket or SMS text, or choose a ticket PDF, PNG or JPEG, on the guest PNR page or in My Trips. The reader works on your device. Its software and English text-recognition model load from MTR, but the pasted text, selected document, images and full extracted text are not uploaded or written to account or browser storage by the reader. Only the PNR and optional train, journey date and station references appear in an editable review. Files are limited to 5 MB and PDFs to three pages; check every extracted digit against your ticket.
Use reviewed PNR only fills the next form. On the guest page, pressing Check PNR sends that PNR through MTR to the railway-data provider for a status check; it does not save an account booking. In My Trips, the separate permission and Add to My Trips action are required before lookup and account import. Clear extracted details or leaving the page removes the local reader/review state. Clear document cancels or clears document-owned work while preserving an unrelated pasted review. Reading a document does not verify its ticket status or entitlement.
Inputs are used only to perform the feature you requested, such as obtaining railway data, displaying a journey result or calculating a rule-based refund estimate. PNRs and similar inputs may be transmitted to the railway-data provider and hosting infrastructure as necessary to return the requested result.
PNRs, passenger names, voice transcripts and WhatsApp message contents are not intentionally stored in application analytics or event logs. An imported PNR and its checked railway status are stored only after you sign in and explicitly authorize that import; other account records described below are stored only when you use those features. Browser voice search is processed by your browser or speech-service vendor. Tapping the microphone starts voice input and, when available, selects cloud transcription for Auto language mode or a browser-speech fallback. There is no extra in-app consent panel. MTR keeps your cloud voice choice as a boolean preference in browser storage; your browser still controls microphone permission and asks for it when needed. You can type instead of tapping the microphone. When cloud voice is on, a recording of up to 25 seconds is sent to MTR’s same-origin voice function. After you start a voice conversation, “Hey Humsafar” wake listening can remain active while this page is visible. When cloud voice is used, wake detection sends short clips containing detected speech to the same transcription service. Unrelated transcripts are discarded and silence is not uploaded. Wake listening can stay enabled during idle periods while this page is visible; hiding the page pauses capture and closing it ends the session. You can turn it off at any time. Recording can end automatically after speech and a quiet pause, or you can stop or cancel it. When configured, the function sends the recording as WebM/Opus audio to Sarvam Saaras v4 for transcription after the pause; cloud transcription does not show interim words. If Sarvam responds with a quick rate-limit or server error and Google Gemini is connected, MTR may convert that same recording to WAV in memory and make one Google Gemini audio transcription attempt. A timeout, authorization error or malformed answer does not start that fallback. A configured OpenRouter speech endpoint using Mistral may be used when Sarvam is not configured. MTR keeps the audio recording only in request and page memory and does not write audio to its application database or browser storage. After transcription, spoken words may become a visible question in your current Humsafar conversation and remain in this tab’s session storage as described below. If you speak an explicit PNR, MTR may briefly keep only its 10 digits in browser session storage to open PNR Rescue without putting it in the page address; the PNR page removes that handoff when it opens. After a PNR result whose identity matches your request, choosing “Track in My Trips” may keep those 10 digits in this tab for up to 15 minutes while MTR opens sign-in or the import form. The form consumes that handoff and only pre-fills the PNR; MTR does not add it to your account until you explicitly authorize and submit the import. A clear transcript may automatically start a read-only train search or live-status check; an uncertain station, train or date stays in the assistant for clarification. Voice-triggered answers may be spoken automatically; typed questions receive text replies. When Sarvam speech is configured, MTR sends the text of the answer and selected language through its same-origin speech function to Sarvam Bulbul to generate audio. That audio returns to this tab for playback and is cleared from MTR page memory after playback or Stop; MTR does not save generated audio in its account database or browser storage. Sarvam speech supports 11 configured languages. For another language or when Sarvam is unavailable, Humsafar may use your browser’s speech synthesis, sometimes with an English fallback; available browser voices vary. Sarvam may process submitted answer text and generated audio under its own terms and retention policies. After you start a voice conversation, Humsafar can listen again after each spoken answer until you stop it. Wake-word listening starts with your voice conversation and can be stopped using “Stop conversation”. Microphone capture stops when the page is hidden or closed, or you stop the conversation. Live partial captions depend on the browser speech service; cloud recordings are transcribed after a pause. Hosting and model providers may process cloud audio under their own terms and retention policies.
3A. Journey details and plans on this device
During a search or journey review, MTR keeps the selected route, dates, class, quota, concession choice and any eligibility details you entered in this tab’s session storage so those choices can move between pages. A selected journey may also include the displayed railway-data result and its source information. These temporary selections are separate from an account record and from a saved travel plan; closing the tab normally clears session storage.
When you choose “Save travel plan” and check its consent box, My Trips stores the route, train name and number, run and boarding dates, displayed times, class, quota, concession choice and passenger count in this browser’s local storage. The plan also keeps any quota or concession eligibility details you entered, which can include age, gender, pregnancy, travelling-alone information and eligibility or document-availability declarations. It does not store passenger names, fare, PNR or an issued ticket, and it is not a reservation. Device plans are not saved in MTR’s account database.
Choosing “Save timetable offline” additionally saves the selected scheduled stops and arrival/departure times, exact train run and segment, and save/retrieval timestamps in this browser. This optional offline copy contains no live location, platform, delay, seat availability, fare or PNR. It is available until seven days after the scheduled arrival and can be removed separately or with its plan.
You can remove a saved travel plan in My Trips. Avoid saving plans with eligibility details on a shared or public device. Clearing browser/site data can also remove saved plans, temporary selections and preferences. An imported account PNR is separate from device plans and can be refreshed or removed in My Trips.
3B. Booking reminders and live watches
Booking reminders, Tatkal reminders, current-seat watches and station alarms can be saved in this browser with their train, date, station, class, timing, optional note and alert state. Current-seat watches and station alarms run only while the relevant MTR page is active and require suitable fresh railway evidence. Calendar-file reminders are controlled by your calendar app.
If you are signed in and explicitly enable a background booking or Tatkal opening reminder, MTR stores an encrypted Push subscription endpoint and browser authentication keys, plus encrypted train number, origin and boarding dates, class, lead time and opening-rule basis in your owner-scoped account. Scheduling and delivery also require limited owner, timing, state, attempt and endpoint-digest metadata. These background notifications contain no PNR, passenger, route, seat or fare information. Your browser chooses its Push network, which may be Google FCM, Mozilla Push or Apple Push, and that network processes the delivery request under its own terms.
A Push service accepting a message does not prove that your browser displayed it or that you heard it. Device settings, network conditions, browser restrictions and expired subscriptions can prevent display. Cancelling a reminder or signing out disables future sends associated with that record or device, but cannot retract a message already in flight. Use My Account to export your own reminder context and endpoint digests; the export excludes Push endpoint tokens and browser authentication keys. Eligible account deletion removes Push subscriptions, reminders and their rate-control rows in the same account-deletion transaction. You can also use the calendar or page-active options when background delivery is unavailable.
Navkar Wake is never inferred. It would require a separate explicit opt-in and remains unavailable until audio rights and delivery reliability are proven.
3C. Account and booking records
Netlify Identity manages account sign-in, confirmation and recovery. MTR stores saved passenger details and booking quote manifests in encrypted, owner-scoped Netlify Database records; the account password is not stored in MTR’s application database. A quote records exact journey identity, passenger details, fare and expiry. A booking record keeps its state separate from payment and ticket issuance. A payment capture is not a ticket. MTR stores a PNR and ticket reference in an account trip only after an authorized ticket provider confirms issuance.
Live ticketing and payment are currently disabled. If an approved integration is activated later, MTR will send the details needed for an exact fare and booking to the authorized partner and use a payment processor for orders and payment confirmation. MTR’s account database may then keep order and payment IDs and minimal verified webhook event identifiers and types for deduplication and financial follow-up. Payment card details are handled by the payment processor, not entered into MTR’s account database.
If you choose to import an existing railway booking, MTR sends the PNR to RailRadar to verify that the returned ticket identity matches. MTR then stores the PNR and a limited status snapshot with authenticated encryption in an owner-scoped account record. The snapshot excludes passenger names, contact details, identity documents and the provider’s raw response. My Trips displays only a masked PNR, journey details and supported status fields. Refreshing the record sends the stored PNR to the provider again. An imported booking was issued elsewhere: MTR did not issue, manage, change or cancel it, and a cached status must be rechecked before travel.
When you explicitly open journey-problem guidance from an imported booking, MTR keeps a one-use page-memory handoff for up to five minutes containing the train number, origin and boarding dates, boarding and destination station codes, expiry, and an account-owner binding. A fresh, exact-run disruption card may use the same one-use page-memory handoff and may select a matching guide reason. These handoffs do not contain the PNR, passenger details or payment identifiers, are not written to browser storage, and do not establish eligibility or submit or cancel anything.
If you prepare a railway complaint draft, MTR can place those limited journey details and the problem category you choose into editable page memory. Text you add stays on the current page unless you explicitly copy it; copying places it on your device clipboard. MTR does not save or send the draft, and the Rail Madad link does not put the draft or journey in its URL. Review the text and remove PNRs, names, phone, payment, login and document numbers before sharing it because MTR cannot detect every sensitive detail.
3C.1. Saved Humsafar trip workspaces
A Humsafar trip starts as a local browser draft. It stays on that device until you clear it, clear browser data, or explicitly choose Save to account. Saving is optional: it stores the normalized trip brief, such as route, dates, party size, budget, requirements and any clearly labelled planning choices. It does not store raw voice audio or transcripts, raw provider responses, PNRs, passenger identity details, payment details or documents in this trip workspace.
For an account-saved Humsafar trip, MTR calculates and shows an exact deletion deadline. By default it is 90 days after the end of the latest saved departure, return, check-in or check-out date in India time, and every accepted save or edit is retained for at least 30 days from that write. An accepted edit recalculates the deadline. A configured post-trip period may be between 1 and 365 days, but MTR will not silently schedule deletion before the saved journey ends. The system has a hard two-year horizon from a write; if a requested future journey cannot fit inside that horizon, it rejects the save or edit instead of accepting a plan that would expire before travel. The Save confirmation and saved-trip details show the applicable deadline. Eligible account export includes retained trip workspaces, and eligible account deletion removes their workspace and revision records together.
3D. Problem reports
If you choose to send a report through Help & Support, MTR sends the selected feature, your message, a report reference and an optional reply email to a private Netlify Forms dashboard. The report is used to investigate the problem or suggestion and, if you provide an email, to reply. Reports are separate from account, booking and payment records. Do not include a PNR, passenger details, payment information, passwords or one-time codes. The form does not cancel tickets or handle urgent railway emergencies. Netlify may retain submitted reports under its service terms; MTR does not promise a specific deletion time for those reports.
3E. Optional PayU payment test
If PayU’s test checkout is available and you explicitly choose to try it while signed in, MTR sends your account email, the first name and mobile number you enter, an opaque test reference and a fixed ₹10.00 sandbox amount to PayU. The checkout runs only on PayU’s test site and does not make a real charge, reserve a seat or issue a railway ticket. MTR stores an encrypted copy of the test contact details and an owner-scoped test reference, status and PayU test identifier in Netlify Database so you can review and retry verification. MTR verifies PayU’s returned hash and checks the transaction with PayU before showing a verified test result. The test record is removed with eligible MTR account deletion; PayU may retain its own test records under its policies. Do not enter real card or bank credentials into a test checkout.
3F. Humsafar conversation in this tab
Humsafar keeps the visible questions you type or speak and its visible replies in this tab’s browser session storage, together with validated train number, station code, run date and selected route, class and quota details needed for follow-up questions. It restores that conversation after moving between MTR pages or refreshing this tab. The current conversation is limited to 60 turns, 2,000 characters per turn and 80,000 serialized characters. Before saving conversation turns, MTR masks exact ten-digit numbers and grouped ten-digit numbers identified as PNR or phone details; this masking is not a guarantee that every kind of private information is removed. Choosing “New conversation” clears it; closing the tab normally clears browser session storage. MTR does not copy this general conversation into its account database. Avoid entering private numbers, passwords or payment details in ordinary chat; use PNR Rescue for an authorized ticket check.
For a general question, Humsafar sends the latest question and up to 15 prior general-chat turns to Netlify AI Gateway’s OpenAI model. Prior railway-provider replies and PNR-tool turns are excluded from that model request. Exact ten-digit numbers are removed by the browser before model submission; MTR’s server also removes grouped PNR or phone-like numbers and email addresses. The model can answer ordinary questions, but current train, seat, platform, fare or ticket facts require MTR’s separate railway tools. Hosting and model providers may process submitted chat text under their own terms and privacy policies.
4. Service providers
The service uses third-party infrastructure and railway-data providers, including Netlify for hosting, functions, Identity, Forms and Database; RailRadar for railway-data APIs; and, only when the relevant feature is used or enabled, Sarvam or a configured OpenRouter/Mistral or Netlify AI Gateway/Google Gemini fallback for cloud transcription, Netlify AI Gateway/OpenAI for general Humsafar conversation, Sarvam for requested spoken answer playback when configured, PayU for the optional sandbox payment test, a future approved payment processor for live checkout, and an approved railway ticketing partner for booking. Those providers may process technical request information under their own terms and privacy policies.
4B. Related tickets on this device
If you choose “Link for reference on this device”, MTR saves a local association between one saved plan segment and an imported ticket in your signed-in account. This stores record references and change-detection fingerprints, not the PNR, ticket document or passenger details. The association is not uploaded or included in shared routes, account exports or offline timetables. You can unlink it without removing either record; signing out or deleting the account clears the local association. Linking does not merge tickets or confirm that your planned travellers are included.
5. Sharing a route
When you choose “Share route link” in My Trips, MTR opens your device’s sharing menu if supported, or offers to copy the link. The link contains the route and search choices, not passenger details, eligibility declarations or a PNR. You choose the destination app, recipient and whether to send. My Trips has no dedicated WhatsApp control. Rail Samachar story pages may offer a WhatsApp news-sharing link that prepares a message; you choose its recipient and whether to send. MTR does not send those messages on your behalf. A sharing app you choose processes the shared link under its own policies.
6. Analytics and diagnostics
Operational monitoring is limited to non-sensitive technical information such as feature name, response time, HTTP/provider error category, app version and aggregate usage counts. PNRs, passenger names, phone numbers, exact WhatsApp contents and identity documents must not be included in analytics events.
To limit repeated railway API requests, MTR derives a keyed, pseudonymous code from the network address supplied by its hosting platform. Its request-limit database stores that code, a feature group, a token counter and expiry times; it does not store the raw address, journey query, PNR or account identity. Inactive counters expire after 24 hours and are removed during bounded maintenance on subsequent requests. These counters are used for service protection, not advertising.
6A. Rail Samachar advertising measurement
If a reviewed advertisement is active, MTR may record whether that campaign was served, became viewable or received a genuine link click. Events contain only an ephemeral dedupe value plus campaign, creative and placement identifiers and an event time. Reporting is stored as minimal daily aggregates.
Advertising is contextual to the public Rail Samachar edition. PNRs, passenger names, Voice transcripts or spoken queries, saved or exact journey history, Watch/Reminder state and private Offline Journey Pack data are not used for advertising targeting. MTR does not create a persistent advertising identity or intentionally store raw IP addresses in advertising measurement.
6B. Rail Samachar audience measurement
MTR may record Rail Samachar edition views, story opens, completed share actions, News→Action categories and visits to the advertiser-information page. Referral is reduced on the device to a coarse channel such as direct, WhatsApp/share, search engine, internal MTR navigation or other referral; the full referring URL is not sent.
A random short-lived session identifier is kept in session storage for deduplication and is not presented as a unique-person count. Crawler-like traffic is conservatively separated from human-signal reporting without retaining raw user-agent strings. Audience events do not include PNRs, Voice transcripts, passenger names, saved journeys, Watch/Reminder state, Offline Journey Pack data or exact personal routes. Short-lived dedupe markers are retained for up to 35 days; non-identifying daily aggregates may be retained for up to 400 days.
7. Data retention, export and deletion
Passenger lookup inputs are not intentionally kept in the account database unless you choose a saved feature or a booking record requires them. Saved passengers can be removed individually. Quotes, issued bookings and payment records remain until eligible account deletion or financial follow-up; saved Humsafar trip workspaces follow the displayed bounded retention deadline described above. When account storage is available, Your Account lets you download MTR’s stored passenger, quote, MTR trip, imported-booking, reminder and PayU sandbox-test records, plus retained saved Humsafar trip-workspaces. The private export includes the full imported PNR, so keep that file secure.
When account storage is available, self-service account deletion requires your account email and the word DELETE. It removes eligible MTR account rows, including saved Humsafar trip workspaces, imported PNRs, reminders and PayU sandbox-test records, and asks Netlify Identity to delete your sign-in. A minimal owner identifier and deletion time remain to stop an already-issued login token from recreating records. Device-only travel plans must be removed separately in My Trips or by clearing browser storage. Current-tab Humsafar chat is also separate from account deletion and can be cleared with “New conversation” or by closing the tab. If an account has a payment order, issued ticket, pending booking or refund, self-service deletion pauses so payment, ticket and refund obligations can be handled through Help & Support. MTR does not promise immediate deletion of records held by payment, railway, hosting or transcription providers; their own policies and applicable obligations may govern retention.
8. Security
API keys and secrets remain server-side. Saved passenger profiles, quote manifests, imported PNR snapshots and issued account PNRs use authenticated encryption in MTR’s database, and account APIs check the signed-in owner. Avoid putting passwords, payment card details or identity documents in railway search fields. No online service can guarantee absolute security.
9. Your choices
You can choose not to submit or import a PNR, use cloud transcription, save passengers, save a device plan or share a route link. Basic journey search does not require an MTR account. Your Account provides saved-passenger removal, account-data export and eligible self-service deletion; My Trips provides imported-booking and device-plan removal, and Humsafar offers “New conversation” to clear current-tab chat.
10. Contact
Operator: Praveen Kumar Bhansali, India.
My Train Rescue is operated under the My Train Rescue brand by Praveen Kumar Bhansali. For product help, use the Help & Support page. A dedicated support email will be added after the official My Train Rescue domain is activated.
11. Updates
This policy may change as the product, providers or applicable law changes. The latest version will display its update date.