Quick Reply: Your RTI replies, postal receipts and site photos are the case. Here is the custody checklist for keeping them private, intact and recoverable in 2026.
The reply that proves your point is worth nothing if you cannot produce it. Most citizens lose the case file long before they lose the case — to a snatched phone, a cloud account that will not let them back in, or a gallery that someone else scrolled through.
Direct answer. Treat the paperwork behind an RTI, a complaint or a court matter as three separate jobs, not one. Keep the original untouched — you may need to prove it was never edited. Keep a working copy private — encrypted on a device you control, not in a shared gallery or an open cloud folder. Keep a backup you can actually restore — one that does not depend on an email account you might get locked out of. No statute requires the department to keep your copy for you. Custody is entirely your problem, and the day you need the file is usually the day you cannot get to it.
The following is a composite of situations this helpdesk sees repeatedly, not a single named case.
A resident files an RTI asking for the measurement book and payment records of a drain that was billed as completed but never built. He photographs the empty site on his phone, dated. The Public Information Officer stalls, so he files a first appeal, then a second appeal. Fourteen months in, he has a folder that matters: the original application, the speed-post receipt, the tracking printout, the postal order counterfoil, two partial replies, his appeal memos, and forty photographs of a drain that does not exist.
Then his phone is stolen at a bus stand.
His photographs were in the phone gallery, backing up to a cloud account whose recovery number was the SIM in the stolen phone. The receipts were loose paper in a drawer at home. The replies were PDFs in a messaging app that had cleared its media cache. He rebuilt roughly half the file over the next three months, and the half he could not rebuild was the half that mattered — the timestamped site photographs that made the paper trail mean something.
Nothing in that story is a legal problem. All of it is a custody problem, and custody is the part nobody plans for.
Before you can protect it, list it. A working RTI or grievance file usually holds:
The replies and receipts can, with effort and more RTIs, usually be reconstructed. The photographs cannot. Weight your protection accordingly.
Lost, stolen, snatched, dropped in water, or seized. Whatever is only on that phone is gone with it. This is the ordinary case, and it is the one people plan for least.
Automatic photo backup feels like a safety net until the recovery path fails. If the recovery number is the SIM in the missing phone, or the recovery email is an address you last opened in 2019, the backup exists and you still cannot reach it. A copy you cannot restore is not a backup.
A phone handed over to be “checked”. A shared family device. A repair shop. An abusive relative. A person who takes the phone and demands the PIN. In each case the file was encrypted at rest and it did not help, because the device was unlocked and the folder was in the ordinary gallery with everything else.
The quiet one. You clear space on the phone, and the deletion propagates to every synced copy. Or a messaging app clears its media cache and takes the only copy of a PDF reply with it.
Section 6(2) of the Right to Information Act, 2005 is genuinely protective on one point. In the words of the Act:
“An applicant making request for information shall not be required to give any reason for requesting the information or any other personal details except those that may be necessary for contacting him.”
So you never have to explain why you want the information, and an officer who demands a reason is acting outside the Act. But read the exception carefully: the details necessary for contacting you are required. Your name and your address go on the application, and the Public Information Officer sees them. RTI is a right to ask without justifying yourself. It is not a right to ask anonymously, and any guide that tells you otherwise is wrong.
That matters for storage, because the person on the other side of an inconvenient RTI often knows exactly who filed it. The Commonwealth Human Rights Initiative maintains a public tracker of attacks on RTI users in India, recording incidents of murder, assault and threats against people who asked for records. We are deliberately not quoting a running total here: the figures reported in secondary coverage disagree with one another, and at the time of writing the tracker's own site (attacksonrtiusers.org) does not load over a valid certificate, so we could not confirm a current figure — which is why we name it but do not link it. The point stands without a number. For some applicants, the contents of the case folder are a safety matter and not merely a filing matter.
There is no provision in the RTI Act obliging a public authority to preserve, or re-issue, the copy of a reply it already sent you. Departments do destroy records under their own retention schedules. If your copy is gone, your remedy is another application and another wait — assuming the record still exists at the other end.
If any of this is ever going into a court, the governing rule is Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, which requires a certificate — including the file's hash value — to accompany a digital record every time it is produced. Our full walkthrough is at Electronic Evidence in Court: BSA Section 63 Certificate Rules, and the first instruction there is the one that governs this entire article: preserve the original, and do not edit it.
This is the single most common mistake people make when they finally do get organised. They crop the photograph, brighten it, rotate it, and store the tidy version. The tidy version is now a different file with a different hash, and the original it came from has been deleted. Whatever you keep, keep the untouched original.
Where police search a place or seize property, Section 105 of the Bharatiya Nagarik Suraksha Sanhita, 2023 requires the process to be recorded by audio-video electronic means and forwarded to the Magistrate. See Police Search Without Video? Your BNSS Section 105 Right. Note the boundary clearly: that section is about how a lawful search must be conducted and recorded. Nothing in this article is a method for defeating a lawful search or a court's production order, and the law on compelling a person to reveal a password or biometric in India is unsettled. The threat this article addresses is a private one — theft, snatching, blackmail, a household member or a stranger with your unlocked phone in their hand.
The Digital Personal Data Protection Act, 2023 sets duties for the organisations that hold data about you, and gives you rights against them; see our DPDP Act 2023 guide and how to exercise your DPDP rights. It does not reach into the files you keep on your own device for your own purposes. That cuts both ways: nobody regulates your shoebox, and nobody is coming to fix it either.
This is the part to keep. Whatever tool you use, on whatever platform, it should satisfy these eight properties. Each one closes a specific failure from section 2.
If you are on Android, take that list to whatever you choose and test it point by point. We are not naming Android apps here because we have not verified any of them to the standard this wiki applies to everything else it publishes.
On iOS we use Tijori — Secure Vault, because it was built against exactly the list above. It is free, and it is on the App Store here. Section 8 explains our connection to it, which you should read before you take our recommendation.
Because we hold ourselves to a verify-or-drop rule, we are attributing rather than certifying. The following are the developer's own published claims on the App Store listing and the privacy policy at bighelpers.in/tijori, not an independent audit, and we say plainly at the end what that means.
Mapped against the checklist:
| Checklist requirement | What Tijori's listing states |
|---|---|
| Offline, no account | “no servers, no accounts and no internet access”; Apple's privacy label reports that the developer collects no data |
| Per-file encryption | Individual file encryption using XChaCha20-Poly1305 |
| Slow key derivation, hardware backing | Argon2id PIN strengthening, with Secure Enclave protection |
| Separate lock per folder | Folders with independent PIN or Face ID locks |
| Failed-attempt record | Break-in reports logging failed unlocks, with optional camera capture |
| Decoy layer | A decoy vault with a separate PIN |
| Auto-lock and switcher hiding | Auto-lock, and hiding of contents in the app switcher |
| Backup you hold, offline recovery | Encrypted local backup export; a recovery passphrase with no cloud account |
It also has a private gallery with pinch-zoom, an audio and video player, and a built-in editor for crop, rotate, adjust, annotate and blur. Section 6 explains why you should be careful with that editor.
What we are not claiming. Tijori is at version 0.2.2 and first shipped on 24 July 2026. It is new. We have not commissioned a third-party security audit of it, we are not aware of any published independent audit, and we are not calling it battle-tested or “military-grade”. Named algorithms in a listing tell you what a developer implemented, not how well it was implemented — which is worth remembering about every vault app you are offered, ours included.
Any vault with a built-in editor invites you to fix your photographs. Resist it for anything that might become evidence.
Put the other way round: use the vault to keep the file private and recoverable. Do not expect the vault to make the file admissible — that job belongs to the certificate procedure in our Section 63 guide, and it starts from an original nobody has touched.
Disclosure. Tijori — Secure Vault is our own product. It is published by Big Helpers, the same organisation that publishes RTI Wiki, and the developer listed on the App Store is Shrawan Pathak — Dr. Shrawan Kumar Pathak, this wiki's editor. Its privacy policy sits on the Big Helpers domain at bighelpers.in/tijori. We are not a neutral reviewer of it, and you should read section 5 with that in mind.
We are telling you for three reasons.
First, because a recommendation without a disclosure is an advertisement pretending to be advice, and this wiki does not do that.
Second, because it lets you discount us accurately. The checklist in section 4 is the part we would stand behind whether or not Tijori existed: every item on it answers a specific failure from section 2, and it is written so that you can hold any product to it, ours included. What we will say for the app is a matter of design position rather than marketing. It is offline-only by choice, because a wiki that spends its days telling citizens to demand records from institutions has no business turning round and asking those same citizens to upload their case files to a server we control.
Third, because it constrains us. Having said this out loud, we cannot quietly drop the caveats in section 5, and you are entitled to hold us to them.
What you get, and what you pay. Tijori is free, has no in-app purchases listed, requires iOS 15 or later (or macOS 12 or later on Apple silicon), and is about 31 MB. Apple's privacy label reports no data collection. If you would rather use something else, section 4 is the checklist, and it works just as well against somebody else's product as against ours.
Building the file in the first place:
No. Section 6(2) means you never have to give a reason, but the same sub-section allows the authority to require the details necessary to contact you. Your name and address are on the application and the Public Information Officer sees them. Plan your storage on the assumption that the other side knows who filed.
Usually not, for a file that matters. Many such features hide items from the main view without individually encrypting them, and they are all behind the single unlock you have already given to anyone holding the phone. The test is section 4: per-file encryption, a separate lock, and a record of failed attempts.
No, and this is the most important misunderstanding to clear up. Admissibility comes from the certificate procedure under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, built on an unedited original and its hash. A vault protects confidentiality and guards against loss. Keep the original untouched, edit only copies, and see our Section 63 guide.
No. This article does not offer a method for defeating a lawful search or a court's production order, and Indian law on compelling disclosure of a password or biometric is unsettled. The decoy feature addresses private coercion — a snatched phone, blackmail, a household member demanding you open it.
Use the checklist in section 4 and test any candidate against all eight points, particularly the offline-and-no-account requirement and per-file encryption. We have not named an Android app because we have not verified one to the standard we apply to the rest of this site, and we would rather give you a test than a guess.
You lose everything that exists only there — which is why section 7 has you export an encrypted backup to separate storage and write the recovery passphrase on paper kept elsewhere. A vault with no exported backup converts a device loss into a total loss.
No. They are the developer's published claims on the App Store listing and the privacy policy, and we have said so in section 5 and disclosed our ownership in section 8. No third-party audit of Tijori has been published. Apply the same scepticism to any other vault app you are offered.
You can file a fresh RTI asking for a copy, and often it will work. But nothing in the RTI Act obliges an authority to preserve or re-issue what it already sent you, and records are destroyed under retention schedules. Treat re-issue as a fallback, not a plan.
Last reviewed: 8 August 2026.