Privacy Policy
2.2
Last updated:
MisarBlog privacy policy – how we collect, use, and protect your data.
<p class="text-muted-foreground mb-8">Last updated: October 6, 2026 · <a href="#changelog" class="text-primary hover:underline">Version changelog ↓</a></p> <section class="mb-8"> <h2 class="text-2xl font-semibold tracking-tight mb-4">1. Introduction</h2> <p class="text-muted-foreground mb-4">Misar.Blog is operated by <strong>Misar AI Technology Pvt Ltd</strong> ("we", "our", or "us"), a company incorporated in India. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.</p> <p class="text-muted-foreground mb-4">This policy complies with India's <strong>Digital Personal Data Protection Act 2023 (DPDPA)</strong>, the EU/UK <strong>General Data Protection Regulation (GDPR)</strong>, and the <strong>California Consumer Privacy Act (CCPA)</strong>.</p> </section> <section class="mb-8"> <h2 class="text-2xl font-semibold tracking-tight mb-4">2. Information We Collect</h2> <h3 class="text-xl font-medium mb-2">Account Information</h3> <p class="text-muted-foreground mb-4">When you create an account, we collect your email address, username, and any profile information you choose to provide (display name, bio, avatar). We also record your consent to our Terms of Service, including the version accepted and the timestamp.</p> <h3 class="text-xl font-medium mb-2">Content</h3> <p class="text-muted-foreground mb-4">We store the articles, comments, and other content you create on the platform. You retain ownership of your content.</p> <h3 class="text-xl font-medium mb-2">Usage Data</h3> <p class="text-muted-foreground mb-4">We collect analytics data about how you use the platform, including page views, reading time, and interaction patterns. This helps us improve the service.</p> <h3 class="text-xl font-medium mb-2">Payment Data</h3> <p class="text-muted-foreground mb-4">Payment transactions are processed by Stripe. We store subscription status and payout records but do not store full card numbers.</p> <h3 class="text-xl font-medium mb-2">Newsletter Subscribers</h3> <p class="text-muted-foreground mb-4">If you subscribe to a writer's newsletter on Misar.Blog, we collect your email address, the date you subscribed, and delivery and engagement data for the newsletters you receive (for example, whether an email was delivered or opened). The writer whose newsletter you joined can see your email address and subscription status. You can unsubscribe at any time from the link in every newsletter.</p> <h3 class="text-xl font-medium mb-2">Connected Applications and API Access</h3> <p class="text-muted-foreground mb-4">You can connect Misar.Blog to AI assistants and other tools — for example ChatGPT, Claude or Cursor through our MCP server — or to your own scripts through our API. When you authorise a connection, we record the application, the permissions (scopes) you granted, and the access tokens issued to it.</p> </section> <section class="mb-8"> <h2 class="text-2xl font-semibold tracking-tight mb-4">3. How We Use Your Information</h2> <ul class="list-disc pl-6 text-muted-foreground space-y-2"> <li>To provide and maintain the platform</li> <li>To process payments and prevent fraud</li> <li>To send you notifications about your account and content</li> <li>To improve our services through analytics</li> <li>To respond to your inquiries and support requests</li> </ul> <h3 class="text-xl font-medium mb-2">Legal Basis for Processing (EU/EEA and UK)</h3> <ul class="list-disc pl-6 text-muted-foreground space-y-2 mb-4"> <li><strong>Performance of a contract</strong> — to create and run your account, host and publish your content, process payments and payouts, and provide the features you use, including connected applications you authorise.</li> <li><strong>Legitimate interests</strong> — to secure the platform, prevent spam and fraud, moderate content, and improve the service through aggregated analytics. You can object at any time by contacting privacy@misar.io.</li> <li><strong>Consent</strong> — for marketing emails and non-essential cookies. You can withdraw consent at any time without affecting earlier processing.</li> <li><strong>Legal obligation</strong> — to keep billing and tax records and to respond to lawful requests.</li> </ul> </section> <section class="mb-8"> <h2 class="text-2xl font-semibold tracking-tight mb-4">4. AI Processing Disclosure</h2> <p class="text-muted-foreground mb-4">We use automated AI systems for the following purposes:</p> <ul class="list-disc pl-6 text-muted-foreground space-y-2 mb-4"> <li><strong>Content moderation</strong> — published articles and comments are screened for policy violations before going live.</li> <li><strong>Semantic embeddings</strong> — article content is converted to vector embeddings for search and discovery features (Discovery Score). Embeddings are derived data and are not shared.</li> <li><strong>Spam detection</strong> — user-submitted forms and API requests are rate-limited and screened.</li> </ul> <p class="text-muted-foreground mb-4">These features run on <strong>Assisters</strong> (assisters.dev), an AI platform operated by Misar AI, which may use third-party AI model providers to process the requests.</p> <p class="text-muted-foreground">Your content is <strong>never used to train AI models</strong>. AI decisions that affect your account (e.g. content moderation flags) can be reviewed by contacting <a href="mailto:privacy@misar.io" class="text-primary hover:underline">privacy@misar.io</a>.</p> </section> <section class="mb-8"> <h2 class="text-2xl font-semibold tracking-tight mb-4">5. Data Sharing and International Transfers</h2> <p class="text-muted-foreground mb-4">We do not sell your personal information. We may share data with:</p> <ul class="list-disc pl-6 text-muted-foreground space-y-2 mb-4"> <li>Service providers (hosting on Hetzner/Germany, payment processing via Stripe, email delivery via our own mail infrastructure)</li> <li>Legal authorities when required by applicable law</li> <li>Other users (only your public profile and published content)</li> <li>Writers whose newsletters you subscribe to (your email address and subscription status)</li> <li>AI assistants and applications you connect — only the data needed for the requests you make through them, such as your articles, drafts, comments, series, newsletter subscriber lists or analytics. Each application handles that data under its own privacy policy, and we never share your data with an application you have not authorised.</li> </ul> <h3 class="text-xl font-medium mb-2">International Data Transfers — Stripe</h3> <p class="text-muted-foreground mb-4">Payment processing is handled by <strong>Stripe, Inc.</strong> (United States). When you make or receive payments on Misar.Blog, certain payment data is transferred to Stripe's infrastructure in the US. This transfer is governed by <strong>Standard Contractual Clauses (SCCs)</strong> approved by the European Commission under GDPR Art. 46(2)(c), as documented in <a href="https://stripe.com/legal/data-transfer-addendum" target="_blank" rel="noopener noreferrer" class="text-primary hover:underline">Stripe's Data Transfer Addendum</a>. Stripe is also certified under the EU–US Data Privacy Framework.</p> <p class="text-muted-foreground mb-4">All other data processing (article storage, analytics, authentication, email) remains within the EU on Hetzner infrastructure in Germany. No other third-country transfers apply.</p> <p class="text-muted-foreground">For data subjects in India: transfers to Stripe fall under the adequacy-equivalent SCC mechanism, consistent with DPDPA §16 cross-border transfer requirements. We maintain a Data Processing Agreement with Stripe.</p> </section> <section class="mb-8"> <h2 class="text-2xl font-semibold tracking-tight mb-4">6. Your Rights</h2> <ul class="list-disc pl-6 text-muted-foreground space-y-2"> <li>Access your personal data</li> <li>Correct inaccurate data</li> <li>Delete your account and data</li> <li>Export your content</li> <li>Opt out of marketing communications</li> </ul> <p class="text-muted-foreground mt-4">You can exercise most rights directly from <a href="/dashboard/settings/account" class="text-primary hover:underline">Account Settings</a>. For requests requiring manual review, email <a href="mailto:privacy@misar.io" class="text-primary hover:underline">privacy@misar.io</a>.</p> </section> <section class="mb-8"> <h2 class="text-2xl font-semibold tracking-tight mb-4">7. Cookies</h2> <p class="text-muted-foreground mb-4">We use essential cookies for authentication and session management. We also use analytics cookies to understand how the platform is used. You can control cookie preferences in your browser settings.</p> </section> <section class="mb-8"> <h2 class="text-2xl font-semibold tracking-tight mb-4">8. Security and Data Retention</h2> <p class="text-muted-foreground mb-4">We implement industry-standard security measures to protect your data, including encryption in transit and at rest, row-level security on all database tables, CSRF protection, rate limiting, and content sanitization.</p> <h3 class="text-xl font-medium mb-2">Data Retention</h3> <p class="text-muted-foreground mb-4">We keep personal data only for as long as we need it for the purposes in this policy:</p> <div class="overflow-x-auto mb-4"><table class="w-full text-sm text-muted-foreground"> <tbody> <tr class="border-b border-border"><td class="py-2 pr-4 align-top">Account and profile data</td><td class="py-2 pr-4 align-top">For as long as your account is active. Deleted immediately when you delete your account.</td></tr> <tr class="border-b border-border"><td class="py-2 pr-4 align-top">Articles, drafts, comments, series and newsletters</td><td class="py-2 pr-4 align-top">Until you delete them, or immediately when you delete your account.</td></tr> <tr class="border-b border-border"><td class="py-2 pr-4 align-top">Newsletter subscriber records</td><td class="py-2 pr-4 align-top">Until the subscriber unsubscribes or the writer removes them; deleted with the writer's account.</td></tr> <tr class="border-b border-border"><td class="py-2 pr-4 align-top">Usage analytics and engagement events</td><td class="py-2 pr-4 align-top">2 years, then deleted automatically.</td></tr> <tr class="border-b border-border"><td class="py-2 pr-4 align-top">Notifications</td><td class="py-2 pr-4 align-top">90 days after you read them; unread notifications after 1 year.</td></tr> <tr class="border-b border-border"><td class="py-2 pr-4 align-top">Connected-application access</td><td class="py-2 pr-4 align-top">Access tokens expire after 1 hour. Authorisations last until revoked or until you delete your account, which removes them along with your API keys.</td></tr> <tr class="border-b border-border"><td class="py-2 pr-4 align-top">Payment, payout and tax records</td><td class="py-2 pr-4 align-top">As long as tax and financial regulations require.</td></tr> <tr class="border-b border-border"><td class="py-2 pr-4 align-top">Server logs</td><td class="py-2 pr-4 align-top">Rotated automatically and kept only briefly for security and troubleshooting.</td></tr> <tr class="border-b border-border"><td class="py-2 pr-4 align-top">Backups</td><td class="py-2 pr-4 align-top">Kept for up to 30 days, after which deleted data no longer exists in them.</td></tr> </tbody> </table></div> <p class="text-muted-foreground mb-4">When you delete your account, your personal data is deleted immediately, except where we must keep it to meet a legal obligation (such as payment and tax records). Any active subscription is cancelled first.</p> <h3 class="text-xl font-medium mb-2">Disconnecting Applications</h3> <p class="text-muted-foreground mb-4">You can disconnect an application at any time from that application's settings. To also revoke its access on our side, email privacy@misar.io. API keys you created yourself can be revoked at any time under Dashboard → Settings → API keys.</p> </section> <section id="dpdpa" class="mb-8 scroll-mt-8 border border-border rounded-lg p-6 bg-muted/30"> <h2 class="text-2xl font-semibold tracking-tight mb-4">9. India — Digital Personal Data Protection Act 2023 (DPDPA)</h2> <h3 class="text-xl font-medium mb-2">Data Fiduciary</h3> <p class="text-muted-foreground mb-4"> <strong>Misar AI Technology Pvt Ltd</strong><br/> Registered in India · We monitor our obligations under the DPDP Act 2023 and its Rules and will comply with Data Protection Board of India processes as they become operative<br/> Grievance contact: <a href="mailto:privacy@misar.io" class="text-primary hover:underline">privacy@misar.io</a> </p> <h3 class="text-xl font-medium mb-2">Your Rights as a Data Principal</h3> <ul class="list-disc pl-6 text-muted-foreground space-y-2 mb-4"> <li><strong>Right to Information (§11)</strong> — This policy lists all data categories, purposes, and retention periods.</li> <li><strong>Right to Access & Portability (§11)</strong> — Export all your data as JSON from <a href="/dashboard/settings/account" class="text-primary hover:underline">Account Settings → Export Data</a>, or via <code>GET /api/gdpr/export</code> (authenticated, rate-limited).</li> <li><strong>Right to Correction (§12)</strong> — Update your profile from <a href="/dashboard/settings" class="text-primary hover:underline">Dashboard → Settings</a>.</li> <li><strong>Right to Erasure (§12)</strong> — Delete your account and all associated data from <a href="/dashboard/settings/account" class="text-primary hover:underline">Account Settings → Delete Account</a>. Stripe billing is cancelled first; your data is purged transactionally.</li> <li><strong>Right to Grievance Redressal (§13)</strong> — Submit a complaint via the form below or email <a href="mailto:privacy@misar.io" class="text-primary hover:underline">privacy@misar.io</a>. We respond within <strong>30 days</strong>. You will receive a ticket reference number.</li> <li><strong>Right to Nominate</strong> — You may nominate another person to exercise your rights in the event of incapacity. Contact <a href="mailto:privacy@misar.io" class="text-primary hover:underline">privacy@misar.io</a> to register a nominee.</li> </ul> <h3 class="text-xl font-medium mb-2">Consent</h3> <p class="text-muted-foreground mb-4">We collect your consent at account creation (age declaration + Terms of Service acceptance). Consent is timestamped and version-tracked. Consent for marketing emails is separate and uses explicit opt-in. You may withdraw consent at any time by deleting your account.</p> <h3 class="text-xl font-medium mb-2">Children's Data</h3> <p class="text-muted-foreground mb-4">Misar.Blog requires users to be <strong>18 years or older</strong>. We do not knowingly collect personal data of minors. If you believe a minor's data has been submitted, contact <a href="mailto:privacy@misar.io" class="text-primary hover:underline">privacy@misar.io</a> immediately for deletion.</p> <h3 class="text-xl font-medium mb-2">Data Localisation</h3> <p class="text-muted-foreground mb-4">Our infrastructure is currently hosted in Germany (Hetzner). DPDPA does not currently mandate data localisation for the categories of data we process. We will update this section if regulatory requirements change or if sensitive personal data categories are added.</p> <h3 class="text-xl font-medium mb-2">Breach Notification</h3> <p class="text-muted-foreground">In the event of a personal data breach, we will notify the Data Protection Board of India (DPBI) within 72 hours of becoming aware. Affected data principals will be notified without undue delay as required under §8(6) DPDPA.</p> </section> <section id="ccpa-opt-out" class="mb-8 scroll-mt-8 border border-border rounded-lg p-6 bg-muted/30"> <h2 class="text-2xl font-semibold tracking-tight mb-4">10. California Privacy Rights (CCPA)</h2> <p class="text-muted-foreground mb-4">If you are a California resident, you have the following rights under the CCPA:</p> <ul class="list-disc pl-6 text-muted-foreground space-y-2 mb-4"> <li><strong>Right to Know</strong> — You may request disclosure of the personal information we collect, use, and share about you.</li> <li><strong>Right to Delete</strong> — You may request deletion of your personal information via <a href="/dashboard/settings/account" class="text-primary hover:underline">Account Settings</a>.</li> <li><strong>Right to Opt-Out</strong> — We do not sell your personal information to third parties.</li> <li><strong>Right to Non-Discrimination</strong> — We will not discriminate against you for exercising your CCPA rights.</li> </ul> <p class="text-muted-foreground">To submit a CCPA request, email <a href="mailto:privacy@misar.io" class="text-primary hover:underline">privacy@misar.io</a> with subject "CCPA Request".</p> </section> <section class="mb-8"> <h2 class="text-2xl font-semibold tracking-tight mb-4">11. Contact Us</h2> <p class="text-muted-foreground mb-2">Questions about this Privacy Policy or data requests:</p> <ul class="list-disc pl-6 text-muted-foreground space-y-1"> <li>Privacy & Data: <a href="mailto:privacy@misar.io" class="text-primary hover:underline">privacy@misar.io</a></li> <li>General: <a href="mailto:hello@misar.io" class="text-primary hover:underline">hello@misar.io</a></li> <li>Grievance form: <a href="/support/privacy" class="text-primary hover:underline">misar.blog/support/privacy</a></li> </ul> </section> <section id="changelog" class="mb-8 scroll-mt-8"> <h2 class="text-2xl font-semibold tracking-tight mb-4">12. Version Changelog</h2> <ul class="list-disc pl-6 text-muted-foreground space-y-2"> <li><strong>v2.2 — October 6, 2026</strong>: Added data retention periods (§8), legal basis for processing (§3), newsletter subscriber data and connected applications and API access (§2), additional recipients (§5), and the AI platform used for automated processing (§4).</li> <li><strong>v2.0 — April 17, 2026</strong>: Added DPDPA 2023 section (§9), AI processing disclosure, Data Fiduciary identity, grievance officer contact, consent versioning, children's data policy, breach notification commitment, version changelog.</li> <li><strong>v1.0 — February 2, 2026</strong>: Initial policy covering GDPR, CCPA, and platform basics.</li> </ul> </section>