1. Who we are
This website (the "Service") is operated by Pranav Prashant ("we", "us", "our"). We are the data controller responsible for your personal data. If you have any questions about this policy or your data, contact us any time via our contact page.
2. Information we collect
We only collect what we need to run the Service. Specifically:
Account information
- When you sign up with email, we store your name, email address, and a securely hashed password.
- When you sign in with Google or GitHub, we receive your name, email address, and profile image from that provider. We never receive your password for those accounts.
- We store email-verification and session records needed to keep you signed in.
Content you create
- Comments and reactions you post, including their text and the article they belong to.
- Your reading streak (current streak, longest streak, and last active day).
Membership & payment information
We never see or store your card, UPI, or bank details. All payments are processed directly by Razorpay, a PCI-DSS compliant payment provider. We only store the transaction record it returns to us: the plan purchased, amount, currency, Razorpay order ID, and payment ID, plus your membership start and expiry dates.
Messages you send us
- If you use the contact form, we store the name, email, subject, and message you submit so we can respond.
Technical & security data
- We temporarily process your IP address to rate-limit forms and prevent abuse. It is stored only as part of short-lived counters and is not used to profile you.
- We use a small number of cookies and local storage — see Section 6.
3. How we use your information
- To create and secure your account and keep you signed in.
- To provide membership access and record your purchases.
- To display your comments, reactions, and reading streak.
- To send essential emails (email verification, password reset). We do not send marketing emails without your consent.
- To respond to your support messages.
- To protect the Service against fraud, spam, and abuse.
4. Legal bases for processing
Where the EU/UK GDPR applies, we rely on: contract (to provide your account and membership), legitimate interests (to secure the Service and prevent abuse), consent (where you choose to provide optional information), and legal obligation (to keep transaction records). If you are in India, we process your data in accordance with the Digital Personal Data Protection Act, 2023.
5. Who we share your data with
We do not sell your personal data. We share it only with the service providers ("processors") that make the Service work, and only as needed:
| Provider | Purpose |
|---|---|
| Razorpay | Payment processing (card/UPI/bank data handled entirely by them) |
| Turso (libSQL) | Database hosting for your account, comments, and membership records |
| Vercel | Website hosting and content delivery |
| Resend | Sending transactional emails (verification, password reset) |
| Google & GitHub | Optional social sign-in, only if you choose them |
We may also disclose data if required by law, to enforce our Terms, or to protect the rights and safety of our users.
6. Cookies & local storage
- Essential session cookie — set when you sign in, to keep you authenticated. It is
HttpOnly,Secure, andSameSite=Lax. Without it, you cannot stay signed in. - Theme preference — stored in your browser's local storage to remember dark/light mode.
- Membership flag — a short-lived value in session storage so premium members don't see a flash of upgrade prompts. It is cleared when you sign out.
We do not use advertising or third-party tracking cookies.
7. How long we keep your data
- Account data is kept while your account is active. If you ask us to delete your account, we remove your personal data, and your comments are removed or anonymized.
- Transaction records may be retained for as long as required for tax, accounting, and legal compliance.
- Rate-limit counters expire automatically within hours.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and associated personal data.
- Object to or restrict certain processing, and withdraw consent.
- Receive a copy of your data in a portable format.
To exercise any of these, contact us via the contact page. We will respond within a reasonable time and as required by applicable law.
9. Security
We protect your data with encryption in transit (HTTPS), hashed passwords, signed and verified payment webhooks, and access controls. Card data never touches our servers. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. International transfers
Our providers may process data in countries outside your own. Where required, we rely on appropriate safeguards for such transfers.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you.
13. Contact us
Questions or requests about your privacy? Reach us through our contact page and we'll be happy to help.