Privacy policy

Last updated: 10 September 2026

The short version: the only personal data Vidhipandit collects from a visitor is an email address, and only if you type one into the launch notification box and then confirm it. There are no accounts, no cookies, no analytics, no advertising, no tracking pixels, and no third-party scripts of any kind on this site. Our own web server does not record your IP address.

That is unusual enough that the rest of this page is mostly evidence for it.

Who we are

For the purposes of the Digital Personal Data Protection Act, 2023, the Data Fiduciary is Anurag Choubey, a sole proprietor trading as The Knowledge Tree (GSTIN 10AHDPC5941L2ZN), whose principal place of business is B-5, A. G. Colony, Patna, Bihar 800025, publishing at vidhipandit.com. Our Grievance Officer's name and contact details are on the Grievance page.

What we collect, and why

The launch notification list

If you ask to be told when Vidhipandit launches, we store, for that address and nothing more:

We do not store your IP address, your browser's user agent, the page you came from, a device fingerprint, or a name. Not "we do not use them" -- they are not written down. This is enforced by a test that reads the source of the code handling that form and fails the build if it ever starts capturing any of them.

The purpose is a single email. We will send you one message, when the site launches. We will not use that address for marketing, will not add it to any other list, and will not share, sell or transfer it. If we ever want to use it for something else we will have to ask you again, in those words, and you will be free to say no.

Your consent is taken twice, and neither is pre-ticked. The checkbox on the form ships unchecked and a submission without it is refused. Ticking it only proves that whoever was at that browser ticked it -- so nothing is sent to your address until you click a confirmation link we email you. An address that never confirms never receives the launch email.

Withdrawing is one click. Every email we send carries a working unsubscribe link. It takes effect immediately, needs no login, and needs no reply from us. Withdrawal is as easy as consent because it has to be.

Server logs

Our web server keeps an access log, as every web server does. Ours has been configured to write no client IP address, no user agent and no referring page -- a line records the time, the request path and the response status, and nothing that identifies who made it. The log is kept for three days and then discarded. That is short on purpose: those log lines sit next to confirmation and unsubscribe URLs, and a retained IP address beside one of those would undo the data minimisation the rest of this page describes.

Rate limiting

To stop somebody signing up thousands of addresses they do not own, the notification form counts recent requests from a network address. That address is never stored: it is immediately turned into a salted hash held only in the running process's memory, discarded within minutes, and lost entirely when the process restarts -- at which point the salt changes too, so even the hash of a given address is different afterwards. It is never written to a file, a database, or a log.

What we do not do

Judgments, and the people named in them

Judgments contain personal data about real people who did not choose to be published. We take our position on this seriously, so we will state it rather than bury it.

Personal data that has been made publicly available by a person under an obligation of law to make it public is outside the Digital Personal Data Protection Act, 2023, by section 3(c)(ii)(B). Courts publish their judgments under such an obligation, and that is the basis on which we hold and publish them. We should be candid that this application of section 3(c)(ii)(B) to judgments has not been tested by any court.

Two consequences follow, and they cut in opposite directions. First, the right of erasure under section 12 of that Act is a right over data processed on your consent -- and a litigant named in a judgment never consented to anything, so that section is not a route to having a judgment about you taken down. Second, and more importantly, the Act not applying does not mean nothing applies. The criminal identity protections described in our editorial policy apply in full, our redaction gate exists precisely because of them, and our review route is open to anyone named in a judgment whether or not the DPDP Act gives them a right to use it.

Your rights

As a Data Principal, in respect of the personal data described above, you have the rights the Digital Personal Data Protection Act, 2023 gives you:

You may also complain to the Data Protection Board of India. We would rather you came to us first, but nothing here requires you to.

In practice, for the notification list, all of this is one line to the Grievance Officer: tell us the address, and we will tell you what we hold, change it, or remove it.

How long we keep things

Where a law requires us to retain something for longer than the periods above, we retain it for that period and no longer.

Where the data sits, and who can see it

The notification list is held in a database we run ourselves, on a server we control, hosted at [PENDING-OPERATOR-FACT: country and provider of the server the corpus and notification list are hosted on]. The one third party involved is the transactional email provider that delivers the confirmation and launch emails, which necessarily receives the address in order to deliver to it. We use no other processor: no analytics provider, no advertising platform, no data broker, no customer relationship system, and no third party is given this list for any purpose of its own.

Children

This is a legal research site intended for adults. We do not knowingly collect the personal data of a child, and the only collection point is a launch notification form. If you believe we hold a child's data, tell the Grievance Officer and we will remove it.

If something goes wrong

If personal data we hold is breached, we will notify the Data Protection Board of India and every affected person, as the Digital Personal Data Protection Act, 2023 requires. Given what we hold, the worst case is that a list of email addresses becomes known -- which is a real harm, and the reason the list is as short and as plain as it is.

Changes to this policy

This page is dated. If it changes materially we change the date and describe what changed. We will not quietly widen the purpose of data already collected -- that requires asking you again.

Reviewed by counsel: pending. This text was drafted in-house on 10 September 2026 and has not yet been reviewed by an advocate. It states what we actually do and we stand behind it; it has not had a professional legal review.