E
Low-Level DesignHigh-Level DesignCase StudiesCompanies
Legal

Privacy Policy

Last updated: July 25, 2026

This policy explains what information we collect when you use this blog and its membership, why we collect it, who we share it with, and the choices and rights you have over your data.

1. Who we are

This website (the "Service") is operated by Pranav Prashant ("we", "us", "our"). We are the data controller responsible for your personal data. If you have any questions about this policy or your data, contact us any time via our contact page.

2. Information we collect

We only collect what we need to run the Service. Specifically:

Account information

  • When you sign up with email, we store your name, email address, and a securely hashed password.
  • When you sign in with Google or GitHub, we receive your name, email address, and profile image from that provider. We never receive your password for those accounts.
  • We store email-verification and session records needed to keep you signed in.

Content you create

  • Comments and reactions you post, including their text and the article they belong to.
  • Your reading streak (current streak, longest streak, and last active day).

Membership & payment information

We never see or store your card, UPI, or bank details. All payments are processed directly by Razorpay, a PCI-DSS compliant payment provider. We only store the transaction record it returns to us: the plan purchased, amount, currency, Razorpay order ID, and payment ID, plus your membership start and expiry dates.

Messages you send us

  • If you use the contact form, we store the name, email, subject, and message you submit so we can respond.

Technical & security data

  • We temporarily process your IP address to rate-limit forms and prevent abuse. It is stored only as part of short-lived counters and is not used to profile you.
  • We use a small number of cookies and local storage — see Section 6.

3. How we use your information

  • To create and secure your account and keep you signed in.
  • To provide membership access and record your purchases.
  • To display your comments, reactions, and reading streak.
  • To send essential emails (email verification, password reset). We do not send marketing emails without your consent.
  • To respond to your support messages.
  • To protect the Service against fraud, spam, and abuse.

4. Legal bases for processing

Where the EU/UK GDPR applies, we rely on: contract (to provide your account and membership), legitimate interests (to secure the Service and prevent abuse), consent (where you choose to provide optional information), and legal obligation (to keep transaction records). If you are in India, we process your data in accordance with the Digital Personal Data Protection Act, 2023.

5. Who we share your data with

We do not sell your personal data. We share it only with the service providers ("processors") that make the Service work, and only as needed:

ProviderPurpose
RazorpayPayment processing (card/UPI/bank data handled entirely by them)
Turso (libSQL)Database hosting for your account, comments, and membership records
VercelWebsite hosting and content delivery
ResendSending transactional emails (verification, password reset)
Google & GitHubOptional social sign-in, only if you choose them

We may also disclose data if required by law, to enforce our Terms, or to protect the rights and safety of our users.

6. Cookies & local storage

  • Essential session cookie — set when you sign in, to keep you authenticated. It is HttpOnly, Secure, and SameSite=Lax. Without it, you cannot stay signed in.
  • Theme preference — stored in your browser's local storage to remember dark/light mode.
  • Membership flag — a short-lived value in session storage so premium members don't see a flash of upgrade prompts. It is cleared when you sign out.

We do not use advertising or third-party tracking cookies.

7. How long we keep your data

  • Account data is kept while your account is active. If you ask us to delete your account, we remove your personal data, and your comments are removed or anonymized.
  • Transaction records may be retained for as long as required for tax, accounting, and legal compliance.
  • Rate-limit counters expire automatically within hours.

8. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated personal data.
  • Object to or restrict certain processing, and withdraw consent.
  • Receive a copy of your data in a portable format.

To exercise any of these, contact us via the contact page. We will respond within a reasonable time and as required by applicable law.

9. Security

We protect your data with encryption in transit (HTTPS), hashed passwords, signed and verified payment webhooks, and access controls. Card data never touches our servers. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. International transfers

Our providers may process data in countries outside your own. Where required, we rely on appropriate safeguards for such transfers.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you.

13. Contact us

Questions or requests about your privacy? Reach us through our contact page and we'll be happy to help.

EEngineering Blog

Deep dives into system design, distributed systems, and the ideas behind resilient software — for engineers who want the why.

Explore

HomeLow-Level DesignHigh-Level DesignSystem Design Case StudiesPrep by companyRSS feed

More

Go PremiumManage subscriptionYour ProfileHelp & Support
© 2026 Engineering Blog. All rights reserved.
PrivacyTermsRefundsContact