Privacy policy
Last updated: 10 September 2026
The short version: the only personal data Vidhipandit collects from a visitor is an email address, and only if you type one into the launch notification box and then confirm it. There are no accounts, no cookies, no analytics, no advertising, no tracking pixels, and no third-party scripts of any kind on this site. Our own web server does not record your IP address.
That is unusual enough that the rest of this page is mostly evidence for it.
Who we are
For the purposes of the Digital Personal Data Protection Act, 2023, the Data Fiduciary is Anurag Choubey, a sole proprietor trading as The Knowledge Tree (GSTIN 10AHDPC5941L2ZN), whose principal place of business is B-5, A. G. Colony, Patna, Bihar 800025, publishing at vidhipandit.com. Our Grievance Officer's name and contact details are on the Grievance page.
What we collect, and why
The launch notification list
If you ask to be told when Vidhipandit launches, we store, for that address and nothing more:
- the email address you typed;
- the date and time you asked;
- the date and time you confirmed the address, by clicking the link in the confirmation email;
- the date and time you unsubscribed, if you do; and
- a code derived from your address, which is what makes the confirmation and unsubscribe links in the email work without asking you to log in to anything.
We do not store your IP address, your browser's user agent, the page you came from, a device fingerprint, or a name. Not "we do not use them" -- they are not written down. This is enforced by a test that reads the source of the code handling that form and fails the build if it ever starts capturing any of them.
The purpose is a single email. We will send you one message, when the site launches. We will not use that address for marketing, will not add it to any other list, and will not share, sell or transfer it. If we ever want to use it for something else we will have to ask you again, in those words, and you will be free to say no.
Your consent is taken twice, and neither is pre-ticked. The checkbox on the form ships unchecked and a submission without it is refused. Ticking it only proves that whoever was at that browser ticked it -- so nothing is sent to your address until you click a confirmation link we email you. An address that never confirms never receives the launch email.
Withdrawing is one click. Every email we send carries a working unsubscribe link. It takes effect immediately, needs no login, and needs no reply from us. Withdrawal is as easy as consent because it has to be.
Server logs
Our web server keeps an access log, as every web server does. Ours has been configured to write no client IP address, no user agent and no referring page -- a line records the time, the request path and the response status, and nothing that identifies who made it. The log is kept for three days and then discarded. That is short on purpose: those log lines sit next to confirmation and unsubscribe URLs, and a retained IP address beside one of those would undo the data minimisation the rest of this page describes.
Rate limiting
To stop somebody signing up thousands of addresses they do not own, the notification form counts recent requests from a network address. That address is never stored: it is immediately turned into a salted hash held only in the running process's memory, discarded within minutes, and lost entirely when the process restarts -- at which point the salt changes too, so even the hash of a given address is different afterwards. It is never written to a file, a database, or a log.
What we do not do
- No cookies. This site sets none -- not for analytics, not for preferences, not for sessions. There is nothing here for a cookie banner to ask you about, which is why you have not seen one.
- No third-party scripts. No analytics, no tag manager, no advertising network, no social widgets, no font service, no content delivery network calling home. Every byte this site serves comes from this site.
- No accounts and no payments. Vidhipandit sells nothing. There is no login, no profile, and no payment instrument to lose.
Judgments, and the people named in them
Judgments contain personal data about real people who did not choose to be published. We take our position on this seriously, so we will state it rather than bury it.
Personal data that has been made publicly available by a person under an obligation of law to make it public is outside the Digital Personal Data Protection Act, 2023, by section 3(c)(ii)(B). Courts publish their judgments under such an obligation, and that is the basis on which we hold and publish them. We should be candid that this application of section 3(c)(ii)(B) to judgments has not been tested by any court.
Two consequences follow, and they cut in opposite directions. First, the right of erasure under section 12 of that Act is a right over data processed on your consent -- and a litigant named in a judgment never consented to anything, so that section is not a route to having a judgment about you taken down. Second, and more importantly, the Act not applying does not mean nothing applies. The criminal identity protections described in our editorial policy apply in full, our redaction gate exists precisely because of them, and our review route is open to anyone named in a judgment whether or not the DPDP Act gives them a right to use it.
Your rights
As a Data Principal, in respect of the personal data described above, you have the rights the Digital Personal Data Protection Act, 2023 gives you:
- Access (section 11) -- to a summary of the personal data of yours we are processing and what we are doing with it.
- Correction and erasure (section 12) -- to have it corrected, completed, updated or erased.
- Grievance redressal (section 13) -- to complain to us first, through the Grievance Officer, on the timetable stated there.
- Nomination (section 14) -- to nominate another person to exercise these rights in the event of your death or incapacity.
- Withdrawal of consent (section 6) -- at any time, by the unsubscribe link, with no reason required.
You may also complain to the Data Protection Board of India. We would rather you came to us first, but nothing here requires you to.
In practice, for the notification list, all of this is one line to the Grievance Officer: tell us the address, and we will tell you what we hold, change it, or remove it.
How long we keep things
- An address that never confirms: it receives nothing at all. The unconfirmed record is retained no longer than the launch it was collected for, and is then removed.
- A confirmed address: kept until the launch email has been sent and you have had a reasonable opportunity to act on it, and then removed. The purpose is then spent, and the Act does not permit us to keep personal data past the purpose it was collected for.
- An address that unsubscribes: the record is marked unsubscribed rather than deleted outright, and is kept as a suppression record so that the same address cannot be re-added and mailed by mistake. It receives nothing. If you would prefer the record erased entirely rather than suppressed, say so and we will erase it -- we simply cannot then guarantee the address will not be re-added by someone else typing it in.
- Access logs: three days.
- Grievance correspondence: kept for as long as we need it to answer you and to report the complaint in the monthly compliance report required by Rule 18(3) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and then removed. Complainants are never named in that report.
Where a law requires us to retain something for longer than the periods above, we retain it for that period and no longer.
Where the data sits, and who can see it
The notification list is held in a database we run ourselves, on a server we control, hosted at [PENDING-OPERATOR-FACT: country and provider of the server the corpus and notification list are hosted on]. The one third party involved is the transactional email provider that delivers the confirmation and launch emails, which necessarily receives the address in order to deliver to it. We use no other processor: no analytics provider, no advertising platform, no data broker, no customer relationship system, and no third party is given this list for any purpose of its own.
Children
This is a legal research site intended for adults. We do not knowingly collect the personal data of a child, and the only collection point is a launch notification form. If you believe we hold a child's data, tell the Grievance Officer and we will remove it.
If something goes wrong
If personal data we hold is breached, we will notify the Data Protection Board of India and every affected person, as the Digital Personal Data Protection Act, 2023 requires. Given what we hold, the worst case is that a list of email addresses becomes known -- which is a real harm, and the reason the list is as short and as plain as it is.
Changes to this policy
This page is dated. If it changes materially we change the date and describe what changed. We will not quietly widen the purpose of data already collected -- that requires asking you again.
Reviewed by counsel: pending. This text was drafted in-house on 10 September 2026 and has not yet been reviewed by an advocate. It states what we actually do and we stand behind it; it has not had a professional legal review.