Legal

Privacy Policy

What is collected, why, where it is kept, and how to have it deleted. Written to be read rather than to be survived.

Effective 10 August 2026

The short version

This website has no analytics, no advertising, no trackers, and sets no cookies for visitors. The only personal data it collects is what you type into the contact form, plus the ordinary server logs any web server keeps.

One button on the writing pages is loaded from Google — the "preferred source" control at the end of each article. It is the only thing on this site fetched from another company, it appears nowhere else, and there is a section below explaining exactly what it does.

Nothing is ever sold, rented, or shared with advertisers or data brokers. If you hold an account in one of the apps, the developer may email you about updates and new products — every such email carries an opt-out, and the address goes to nobody else. You can ask for your data to be deleted at any time and it will be, without conditions.

The rest of this page is the detail behind those sentences.

Who is responsible for your data

"Drish Labs" is a trading name used by an individual sole proprietor based in India. That individual is the data controller for the purposes of the EU and UK General Data Protection Regulation, and the Data Fiduciary for the purposes of India's Digital Personal Data Protection Act, 2023.

There is no company, no team, and no third party with administrative access. Every request made under this policy is read and answered by the same person who writes the software.

All contact, including data rights requests and grievances, goes through the contact form linked at the bottom of this page.

What this policy covers

This policy covers the drishlabs.com website and the software published under the Drish Labs name.

Each app also carries an "App Privacy" declaration on its App Store product page. That declaration is made to Apple, is app-specific, and is authoritative for that app. Where it and this page could be read differently for a particular app, the App Store declaration governs.

Freelance and client work is carried out under a separate written agreement, and any data handled in the course of it is governed by that agreement rather than this page.

What the website collects

Two things, and nothing else.

  • CONTACT FORM SUBMISSIONS. The name, email address and message you type, an optional links field, and which enquiry category you picked. These are stored in a database on the server described below. Nothing is pre-filled, inferred, or enriched from any other source.
  • PROJECT BRIEFS. If you fill in the brief at /contact/brief, the answers you give are stored in the same database and in the same row as your name and email address. That includes anything you type into it — a business name, a current web address, a WhatsApp number, an Instagram handle, a budget range. Every field except your name and email address is optional and can be left blank. Nothing in it is shared with anyone, and it is used only to quote and carry out the work you are asking about.
  • SERVER LOGS. Like every web server, the machine records requests: IP address, the page requested, a timestamp, the referring page, and the browser user-agent string. These exist for security and diagnostics — identifying an attack, or working out why a page failed — and are not used to build a profile of anyone.

What the website does not do

  • NO COOKIES FOR VISITORS. This site sets no cookies when you browse it. The only cookie the application can issue is an administrator login session, which requires a password only the operator holds; visiting any public page cannot cause it to be set.
  • NO ANALYTICS. There is no Google Analytics, no Plausible, no Meta pixel, no heatmap tool, and no analytics SDK of any kind. Visitor numbers are not measured.
  • NO ADVERTISING, and no ad network has ever been embedded.
  • NO TRACKING ACROSS SITES, no fingerprinting, and no data brokers.
  • NO MAILING LIST. There is no newsletter and no way to subscribe to one. A table that could have held addresses was deleted from the database in 2026 having never contained a single row.
  • NO SALE OR SHARING of personal data, in the specific senses those words carry under the California Consumer Privacy Act. This has never happened and there is no mechanism by which it could.
  • ONE EXCEPTION TO "NOTHING IS STORED IN YOUR BROWSER", stated here rather than buried. The project brief at /contact/brief keeps a draft of your answers in that browser’s local storage, so a twenty-question form survives a dropped connection or a closed tab. It never leaves your device until you press send, it is not a cookie and is not readable by this server or by anyone else, it is deleted the moment the brief is submitted, and it expires by itself after thirty days. Nothing else written by this site goes into your browser’s storage — the free tools at /tools write nothing at all. The one piece of code on these pages that this site did not write is the Google button described in the next section; what that stores is Google’s to govern, not this policy’s, and it runs on the writing pages only.

The one thing loaded from another company

Google runs a feature that lets a reader mark a site as a "preferred source", after which Google gives that site's new articles more prominence in that reader's own Search, Discover and News. There is a button for it at the end of every article and in the header of the writing index, and those are the only pages on this site that load anything from a third party.

  • IT LOADS ONLY ON THE WRITING PAGES. The homepage, /works, /contact, the free tools at /tools and these legal pages request nothing from Google or from anyone else. The automated test suite checks this on every build, because a scoping promise that nothing verifies is a promise that quietly stops being true.
  • GOOGLE DISPLAYS NOTHING ON THE PAGE. The button you see is drawn by this site, in this site’s own type and colours; only the code behind it comes from Google, and it is told not to put anything of its own on the page. Nothing from Google is shown to you unless you press it, and then it opens in a Google window rather than inside this one.
  • WHAT GOOGLE SEES WHEN THE PAGE LOADS. Your browser fetches the button's code from a Google address, which necessarily tells Google your IP address, roughly when, and that the request came from drishlabs.com. It is not told which article you were reading: this site sends a trimmed referrer, so the address of the page never leaves your browser.
  • IT STILL SETS NO COOKIE FOR THIS SITE. Nothing about it changes the statement above that drishlabs.com sets no cookies. Any cookie involved is Google's own, on Google's domains, under Google's privacy policy — the same ones your browser already holds if you are signed in to Google.
  • PRESSING IT IS A CHOICE, AND IT IS RECORDED BY GOOGLE, NOT HERE. The preference is stored on your Google account and is changed or removed in Google's own settings. This site is never told who pressed it, how many people did, or whether you are one of them — no count, no identifier, no callback of any kind. It is not analytics and cannot be used as any.
  • NOTHING IS REQUIRED. Ignore the button and the pages behave exactly as they did before it existed. Blocking it changes nothing about the article you came to read.

What the free tools do

The tools at /tools run entirely in your browser. There is no server side to them: the page is delivered, and everything after that happens on your own machine.

  • NOTHING YOU TYPE IS SENT ANYWHERE. Text, numbers, passwords and addresses entered into a tool stay in the browser tab and are gone when you close it.
  • FILES ARE NEVER UPLOADED. The tools that accept an image or a document — the app icon generator, the screenshot mockup editor and the markdown reader — read it locally and convert it locally. The file is never transmitted, never stored on the server, and never seen by anyone.
  • NOTHING IS SAVED BETWEEN VISITS. No tool writes to local storage, session storage or cookies, so nothing you did in one is recoverable — by you or by anyone else — once the tab is closed.
  • NO ACCOUNTS, AND NO USAGE MEASUREMENT. There is nothing to sign up for, and no record is kept of which tools are opened or how often.

What the apps collect

Most apps published under this name process everything on your device and send nothing anywhere. Files, photos, text, contacts and documents you open in them stay on your hardware.

Some apps necessarily contact a service to do the job you asked for. Apps that enhance, restore, or generate images send the image you selected to a processing service for that single operation and do not retain it afterwards. Where an app does this, it is stated on that app's App Store page and in the app itself.

No app performs facial recognition, and no biometric template is created, stored or shared by any of them.

Where an app collects diagnostic or usage data, that fact is declared on its App Store product page under "App Privacy". Treat that declaration as the authoritative statement for the app in question. Separately, Apple may send aggregate crash and usage reports if you have opted in under Settings → Privacy & Security → Analytics; that is Apple's collection under Apple's policy, and it can be turned off there.

Purchases and subscriptions are handled entirely by Apple. Card numbers and billing details are never seen, transmitted, or stored by Drish Labs.

  • ANONYMOUS USAGE COUNTS. Some apps send anonymous usage events — which features were used, and whether they succeeded — tied to a random identifier the app makes up for the install. There is no account behind it, and no name, email, file, photo, coordinate, location, or anything you created is ever part of an event. Which apps do this is declared on each app's "App Privacy" label.
  • IN-APP FEEDBACK AND ROADMAP VOTES. Some apps let you send feedback or vote on planned features from inside the app. The message you write and the vote you cast are stored on a server run by Drish Labs. In apps without accounts they are attached only to the random anonymous identifier above, and such apps offer a "Reset anonymous ID" control in their settings that detaches the install from everything it previously sent; you may also request deletion through the contact form below.
  • ACCOUNTS. Apps that offer sign-in store the email address and any name you provided on servers run by Drish Labs, to operate your account. Those details may also be aggregated across Drish Labs apps and used to tell you about updates and new products from the same developer — never sold, never shared with anyone else, and every such email includes a way to opt out. Deleting your account in an app removes it from these systems, including the aggregated list, and you can also request deletion through the contact form below. If you signed in with Apple and chose to hide your email, only Apple's relay address is ever held.
  • REFUND REQUESTS. When you ask Apple to refund an in-app purchase, Apple invites the developer to submit information relevant to the decision. For apps that support this, anonymous usage signals — the age of the install's identifier, whether the purchased features were actually used after purchase, and prior refund history — may be shared with Apple solely to help Apple decide the request. Never the content of anything you made, and Apple's decision remains Apple's alone.

Why it is processed, and on what legal basis

For readers in the EU and UK, the GDPR Article 6 bases relied on are:

  • CONTRACT, or steps taken at your request before entering one — replying to a contact form message about a project, providing an app you have downloaded, and operating the account you created in one.
  • LEGITIMATE INTERESTS — keeping server logs to secure the service against attack and diagnose faults, and telling existing account holders about updates and new products from the same developer. Every such email carries an opt-out, the objection right below applies to it, and where a jurisdiction requires consent for that kind of message, consent is the basis relied on instead.
  • CONSENT — where an app asks permission before sending anything off your device. You can withdraw it at any time by declining the permission or removing the app.
  • LEGAL OBLIGATION — retaining what tax and accounting law requires in respect of a paid engagement.

How long it is kept

  • CONTACT FORM MESSAGES are kept while the conversation is useful and reviewed periodically. A message that led nowhere is deleted; one that became a project is kept for the life of that engagement and the period tax law requires afterwards. You may ask for deletion sooner and it will be honoured.
  • ACCOUNT DETAILS are kept while the account exists. Deleting your account in an app removes them, including from the aggregated list described above, within a day.
  • SERVER LOGS rotate on a short cycle in the ordinary course of running the machine and are not archived for analysis.
  • BACKUPS of the database are retained on a rolling basis. A deletion request is executed against live data immediately; the record also disappears from backups as those rotate out.

Who else touches it

Personal data is never sold or shared for anyone else's marketing. A small number of providers necessarily process it in order for the service to exist:

  • HOSTINGER — the hosting provider. The website, the database and the uploaded images run on a private virtual server it provides. Hostinger International Ltd is established in Lithuania, in the EU.
  • CLOUDFLARE — two separate roles. It is the reverse proxy and content delivery network in front of this site: every request reaches Cloudflare before it reaches the server, so it necessarily processes your IP address, the address you asked for and your browser's user-agent string, and it holds a copy of public pages at the edge nearest you. It also provides the object storage (R2) that holds encrypted backups of the database and site configuration.
  • APPLE — distribution, payment processing, and subscription management for every App Store app. Apple's own privacy policy governs everything it collects.
  • IMAGE PROCESSING SERVICES — used only by the specific apps that offer image enhancement, restoration or generation, and only for the single operation you requested.
  • There are no advertising networks, no analytics vendors, and no customer relationship platforms in the chain. No email marketing service holds any of these addresses today; if one is ever used to send the product updates described above, it will be named here before it is used.
  • Data may additionally be disclosed where a valid legal process compels it, or where necessary to establish or defend a legal claim. Nothing has been disclosed on this basis to date.

Where in the world it is processed

The server that runs this site and holds its database is physically located in Frankfurt, Germany, inside the European Union. Hostinger International Ltd, which provides it, is established in Lithuania, also in the EU. Your connection does not reach that server directly: it terminates at whichever Cloudflare edge location is nearest you, anywhere in the world, and Cloudflare forwards it from there. Backups are held in Cloudflare's Asia-Pacific region, which is outside the EU. The sole proprietor who operates all of it is in India. Apple processes purchase data in the regions described in its own policy.

If you are in the European Economic Area, the United Kingdom, or another jurisdiction restricting international transfers, using this site or sending a message through it involves transferring your data outside that jurisdiction. Where such a transfer requires a safeguard, the Standard Contractual Clauses approved by the European Commission — or the UK Addendum, as applicable — are the mechanism relied on, together with the technical measures described under Security below.

This is stated plainly rather than buried because it is the fact most privacy policies of this size leave out, and it is the one a regulator asks about first.

Your rights

Wherever you are, you may ask for a copy of the data held about you, ask for it to be corrected, or ask for it to be deleted. Requests are honoured without argument and without requiring a reason.

Under the EU and UK GDPR you additionally have the right to restrict processing, to object to processing carried out on the basis of legitimate interests, to data portability, and to withdraw consent at any time without affecting processing already carried out.

Under India's Digital Personal Data Protection Act, 2023 you have the right to access, correction, completion, updating and erasure, the right to nominate another person to exercise your rights, and the right to an accessible grievance redressal procedure — which is the contact form below.

Under the California Consumer Privacy Act, as amended, you have the right to know what is collected and why, to delete it, to correct it, and to opt out of its sale or sharing. There is nothing to opt out of: personal information is not sold or shared, and never has been. Exercising any right will never result in worse service or a different price.

Requests are answered within 30 days, and normally far sooner. There is no charge. If a request cannot be honoured — because tax law requires a record to be kept, for example — you will be told which data is affected and why.

If you are in the EEA or the UK and are unsatisfied with the response, you may complain to your national data protection authority. That right exists independently of anything on this page and is not affected by it.

Children

This website and these apps are general-purpose tools and are not directed at children. Personal data is not knowingly collected from anyone under 16.

If you believe a child has sent personal data through the contact form, say so through that same form and it will be deleted on receipt, without any requirement to prove the claim.

Security

  • All traffic to this site is encrypted in transit with TLS. Plain HTTP is redirected, and HTTP Strict Transport Security is set.
  • The database is not exposed to the public internet. Administrative access requires a password held by one person, and the browsing account used for routine database inspection is physically incapable of writing.
  • Uploaded files are validated by inspecting their actual contents rather than trusting the declared file type, and formats that can carry executable script are refused outright.
  • Backups are encrypted at rest with the storage provider.
  • No system is perfectly secure, and anyone claiming otherwise is selling something. If a breach occurs that is likely to result in a risk to your rights and freedoms, the relevant supervisory authority will be notified within 72 hours where the GDPR requires it, and you will be told directly where the risk is high.

Changes to this policy

This page is versioned with the site's source code, so every change to it is recorded with a date and a reason.

The effective date at the top of this page changes whenever the substance does. Material changes — a new category of data, a new processor, a new purpose — take effect only from the date they are published here, and are never applied retroactively to data already collected.

Questions, or a request about your data?

Everything goes through one form, including rights requests. It is read by the same person who writes the software.

Contact