Privacy policy

dreamcatcher privacy policy.

This page describes the data the dreamcatcher editorial desk collects from its readers. The publication is read-first and collects no personal data beyond standard server logs.

Updated: 11 Aug 2026 Editorial scope: verification-first reference
A privacy reference still life with a printed KYC document photographed edge-on, a folded letter and a slim pen on a pale linen desk
Reference

What the publication collects

Server logs

Standard server logs (IP address, user agent, referrer) for the purpose of operating the website.

No personal data

No personal data beyond standard server logs.

No tracking cookies

No tracking cookies beyond standard analytics.

No ad trackers

No third-party advertising trackers.

Reference

What the publication does not collect

No sign-up data

No name, email or phone number at sign-up.

No KYC

No KYC documents.

No payment

No payment information.

No geolocation

No precise geolocation data.

Reference

Reader rights

Request logs

The reader can request a copy of the server logs that mention their IP address by emailing the desk.

Request deletion

The reader can request deletion of any mention from the server logs.

Request transcript

The reader can request a transcript of any communication with the desk.

Data collected

The four categories of data the publication handles.

The dreamcatcher editorial desk is an editorial publication, not a transactional service. The categories of data the desk handles are narrower than the categories a rummy platform handles. The list below is exhaustive: any data the desk handles falls into one of these four categories.

01 · Server logsStandard HTTP server logs: IP address, user agent, referrer, requested URL, response status. Retained for thirty days for operational debugging, then deleted automatically. Not used for advertising, profiling or reader tracking.CAT-01
02 · Editorial emailMessages sent to the editorial inbox on the contact page. Retained for the duration of the editorial dialogue plus twelve months, then deleted. Used only for the editorial purpose the reader initiated; never shared with third parties.CAT-02
03 · Aggregated traffic countsAnonymous, aggregated page-view counts surfaced by the hosting provider. No individual reader identifier, no cross-site tracking, no advertising profile. Used to plan editorial revision cycles.CAT-03
04 · No other categoriesThe desk does not collect names, emails, phone numbers, payment information, KYC documents, precise geolocation, biometric data, advertising identifiers, social-media identities or any other category of personal data beyond the three above.CAT-04
Retention windows

How long each category of data is retained.

Server logs: thirty days

Server logs are retained for thirty days for operational debugging, then deleted automatically by the hosting provider's rotation policy. The desk does not back up logs to secondary storage. Logs older than thirty days cannot be retrieved because they no longer exist.

Editorial email: twelve months after resolution

Editorial email is retained for the duration of the editorial dialogue plus twelve months. After twelve months the email is deleted from the desk's mailbox. The desk does not export editorial email to any external system.

Aggregated counts: indefinite, anonymous

Aggregated anonymous traffic counts are retained indefinitely by the hosting provider. Because the counts are aggregated at the hosting level, no individual reader can be identified from the counts.

Reader-requested deletion

Where a reader requests deletion under the reader rights section, the desk acts on the request within five business days. The desk confirms deletion in writing once the underlying records have been removed.

Third-party services

The third-party services the publication uses.

Google Fonts

The publication loads Manrope and Noto Sans Devanagari from Google Fonts. The fonts are served from fonts.googleapis.com and fonts.gstatic.com. Google records the request as a font-fetch; the desk has no visibility into what Google does with that record. The desk does not load any other Google service.

Hosting provider

The publication is hosted by the desk's hosting provider. The hosting provider sees the visitor's IP address on every request. The desk has chosen a provider that publishes a GDPR-compliant data-processing addendum.

No analytics scripts

The publication does not load Google Analytics, Meta Pixel, LinkedIn Insight, Hotjar, Microsoft Clarity or any other third-party analytics or advertising script. The desk uses only the aggregated counts surfaced by the hosting provider.

No advertising networks

The publication does not run advertising, sponsored content or affiliate links that pass reader identifiers to a third-party advertising network. The first-party affiliate link to the responsible-play page is a self-link within the same first-party domain.

Changes

How the desk handles a change to this privacy policy.

How a change is published

A change to this privacy policy is published by updating the dateline at the top of the page, revising the affected section and adding a change note at the bottom of the page. The desk does not publish a separate "previous versions" archive; the reader can compare the current version against a cached version via any major search engine.

How a reader is notified

The desk does not maintain a reader email list, so the desk does not send a notification email when this policy changes. The desk relies on the reader to check the dateline at the top of the page when the reader revisits the desk. Where the change is material — for example, where the desk adds a new category of data — the desk notes the change in the rummy newsroom ticker on the homepage.

How the desk handles a regulator change

Where a regulator publishes a new instruction that affects the desk's data-handling practice — for example, where the Digital Personal Data Protection Act, 2023 reaches a new milestone — the desk revises the relevant section on this page and updates the dateline. The desk does not delay a regulator-driven change for any other reason.

How the desk handles a hosting change

Where the desk changes its hosting provider, the desk updates the third-party services section on this page and the dateline at the top of the page. The desk does not move reader data outside the desk's hosting jurisdiction without an explicit policy revision and a change note.

Reader rights in detail

How a reader exercises each right.

Right to access

The reader has the right to access the data the desk holds about the reader. The reader exercises the right by emailing the editorial inbox with the reader's IP address and the date range the reader wants to query. The desk responds within five business days with the data the desk holds in that date range.

Right to correction

The reader has the right to correct any data the desk holds about the reader. The reader exercises the right by emailing the editorial inbox with the data the reader wants to correct and the corrected data. The desk responds within five business days with confirmation that the data has been corrected.

Right to erasure

The reader has the right to request erasure of any data the desk holds about the reader. The reader exercises the right by emailing the editorial inbox with the reader's IP address and the date range the reader wants to erase. The desk responds within five business days with confirmation that the data has been erased.

Right to grievance

The reader has the right to file a grievance about the desk's data-handling practice. The reader exercises the right by emailing the editorial inbox with the reader's grievance and the underlying data-handling practice the reader is raising. The desk responds within fifteen business days.

Right to nominate

The reader has the right to nominate another person to exercise the reader's data-handling rights on the reader's behalf. The reader exercises the right by emailing the editorial inbox with the nominee's name and email address. The desk verifies the nomination with both the reader and the nominee before acting on the nominee's request.

Extended reference

How to read this privacy policy.

The privacy policy above is structured as a ledger and a series of reference sections so a reader can scan the headline and decide whether to read the section. The reader rights section sits at the bottom because the desk treats the rights as the consequence of everything above them.

Why the desk publishes this policy

The desk publishes this policy because the publication serves adult Indian readers and the Digital Personal Data Protection Act, 2023 sets out a notice obligation for any data-handling entity. The desk meets the notice obligation by publishing this policy in clear English, with the categories of data named and the retention windows stated.

How the desk handles a reader request

Where a reader exercises a right under the reader rights section, the desk acts on the request within five business days. The desk confirms the action in writing once the underlying records have been removed. Where the desk cannot fulfil a request, the desk explains the limitation in writing.

How the desk handles a data breach

The desk treats any unauthorised access to its mailbox or its hosting account as a data breach. The desk notifies affected readers within seventy-two hours of confirming the breach. The desk does not maintain a separate security-incident register because the desk's data-handling surface is small enough to investigate by hand.

How the desk handles children

The publication is for adult readers. The desk does not knowingly collect data from readers under eighteen. Where the desk becomes aware that a reader under eighteen has contacted the editorial inbox, the desk deletes the contact and confirms the deletion in writing to the parent's email if one is provided.

How the desk handles international readers

The publication is written for adult Indian readers. Where a reader outside India reads the publication, the desk treats the data the desk collects under the same Indian standards; the desk does not export reader data outside the desk's hosting jurisdiction.

How the desk revises this policy

This privacy policy is revised only when the underlying data-handling practice changes or when the law changes. The last-revision date appears in the dateline at the top of the page. The desk does not revise the policy for marketing or seasonal considerations.

Three pages that complete the picture.

The rules ledger, the safety explainer and the responsible-play framework.

Read the rules Read the safety explainer Read the responsible-play framework