At Medhashine, we believe educational curiosity thrives only in an environment of total digital safety. We do not sell student data, we do not run behavioral advertising networks, and we hold ourselves to the highest global data protection standards.
Effective Date: September 19, 2026•Policy: Version 2.4 (Enterprise Edition)•DPDP Act (India) 2023 & COPPA Compliant
Zero Data Selling
We never monetize, rent, trade, or auction learner or teacher data to data brokers or advertisers.
Student-First Safety
Full protection for minors under Section 9 of the DPDP Act 2023 & US COPPA. No behavioral tracking of kids.
Enterprise Security
AES-256 encryption at rest, TLS 1.3 in transit, HttpOnly SameSite cookie isolation, and robust CSRF defense.
Full Data Sovereignty
You own your information. Complete rights to download, rectify, or permanently purge your account anytime.
Section 1
Our Privacy Charter & Core Promise
Medhashine operates a premier digital educational reading platform and pedagogical publishing network. We believe that genuine academic curiosity, intellectual depth, and independent critical thinking can only flourish when individuals are free from digital surveillance and deceptive data extraction.
This Privacy Policy describes our practices regarding the collection, handling, storage, and protection of information across the Medhashine portal, teacher tools, and related services.
The Medhashine Guarantee
We never sell your personal information or school reading logs to third parties.
We never display targeted third-party advertisements to students or educators.
We never engage in behavioral profiling or automated surveillance of minors.
Section 2
Categories of Information We Collect
In strict adherence to the data minimization principle under modern privacy legislation, we only collect data that is strictly necessary to deliver high-quality educational experiences.
A. Account Registration & Profile Data
Account Registration & Profile Data: When you voluntarily create an account as a student or educator, we collect your name, email, encrypted password hashes, and academic grade preferences.
B. Educator Verification Data
Educator Verification Data: To maintain rigorous pedagogical standards, educators provide verified academic credentials, teaching experience, and a mandatory 10-digit mobile number used solely for two-factor identity verification and administrative governance.
C. Technical & Security Telemetry
Technical & Security Telemetry: We collect IP addresses and browser user-agents strictly to protect the platform against brute-force attacks, DDoS, and account hijacking.
Teacher Data & Identity Protection Guarantee
An educator's personal mobile number, private email, date of birth, and verification credentials are encrypted at rest and never made public on learner portals. For intellectual property & copyright rules on teacher-authored insights, please review our Terms & Copyright Charter.
Section 3
How We Use Educational Data
We process your information exclusively under lawful bases defined by applicable data protection laws: performance of contract, legitimate interest, and explicit consent.
Peer Feedback & Discussions: Facilitating teacher-moderated student comments and intellectual discussions on essays and guides.
Network Defense: Identifying automated bots, blocking Cross-Site Request Forgery (CSRF), and enforcing rate-limiting thresholds to protect platform integrity.
Direct Notifications: Sending essential administrative emails (password resets, application reviews, ticket resolutions). We do not spam.
Section 4
Student & Minor Privacy (Under 18 Protection)
Medhashine is fundamentally built for learners, many of whom are young students. Protecting children is our paramount legal and moral duty under the Digital Personal Data Protection Act, 2023 (India) and the Children’s Online Privacy Protection Act (COPPA, USA).
Student & Minor Privacy (Under 18 Protection):
Section 9 DPDP Act (India)Section 9 DPDP Act (India): No tracking, behavioral monitoring, or targeted advertisements directed at individuals under 18 years of age.
Parental RightsParental Rights: Parents and legal guardians may review, request a copy of, or instruct the permanent erasure of their child’s account at any time by contacting privacy@medhashine.in.
Section 5
Technical Architecture & Security Safeguards
Session Encryption & Isolation
Session Encryption & Isolation: User sessions are managed through cryptographically secured, browser-isolated authentication cookies equipped with strict security flags (HttpOnly and Secure), preventing unauthorized client-side script interception.
Input Sanitization & Injection Defense
Input Sanitization & Injection Defense: Every piece of incoming content passes through multi-stage sanitizers that strip raw HTML, neutralize cross-site scripting (XSS) vectors, and escape search queries to prevent NoSQL injection attacks.
CSRF Origin Validation
CSRF Origin Validation: Our API enforces strict Origin and Referer validation on all mutating HTTP methods to reject unauthorized cross-site requests originating from malicious third-party websites.
Intelligent Rate Limiting
Intelligent Rate Limiting: Multi-tier IP rate limiting prevents brute-force authentication attempts, automated content scraping, and denial-of-service spamming across public endpoints.
Section 6
Zero Data-Selling & Authorized Service Providers
We never monetize, rent, or trade your personal data. To provide reliable, globally available educational services, we partner strictly with vetted enterprise service providers who act as data processors on our behalf under legally binding Data Processing Agreements (DPAs).
Service Provider Category
Purpose & Educational Role
Data Scope Handled
Compliance & Security Standard
Cloud Compute & Hosting Infrastructure
Platform uptime, server infrastructure, and secure API execution
Encrypted application workloads and session routing
SOC 2 Type II, ISO/IEC 27001
Encrypted Database Storage Providers
Secure, isolated persistence of educational posts, taxonomy, and profiles
Account data, authored insights, and learning interactions
AES-256 encryption at rest, TLS 1.3 in transit
Media Content Delivery Networks (CDNs)
Fast, optimized delivery of educational diagrams and teacher profile images
Authorized educational illustrations and avatar images
Strict file verification & secure caching
Transactional Email Infrastructure
Critical account verification, password resets, and support alerts
Recipient email address and system notification text
SPF, DKIM, TLS end-to-end transport security
All service providers are bound to strict SOC 2, ISO 27001, and TLS 1.3 encryption standards with zero rights to independently use or monetize user data.
Section 7
Data Retention & Right to Complete Erasure
Active Accounts: Retained while your profile remains open to preserve your bookmarks and educational contributions.
Teacher Content: When an educator deletes an insight, it is placed in a 30-day soft-delete Recycle Bin, after which it is permanently purged from production databases.
Permanent Account Deletion: You have an absolute right to account closure. When you request erasure, all personal identifiers are permanently purged within 30 days.
Section 8
Your Legal Rights as a Data Principal
Under the Indian Digital Personal Data Protection Act (DPDP Act, 2023), GDPR, and associated international laws, you hold unambiguous rights over your data:
Right to Access and Confirmation: Request a full summary of the personal data we hold about you.
Right to Correction & Rectification: Update inaccurate or incomplete biographical and educational data.
Right to Erasure ('Right to Be Forgotten'): Instruct us to permanently delete your personal profile and credentials.
Right of Grievance Redressal: Have your privacy concerns addressed by our designated Grievance Officer within statutory response timelines.
Section 9
Cookies & Session Technologies Policy
We use cookies exclusively for functional authentication, platform security, and user session continuity.
Cookies & Session Technologies Policy:
Authentication & Session Continuity Cookies: Strictly necessary, cryptographically secure session cookies that keep you safely signed in as you explore learning topics.
Security & CSRF Protection Markers: Temporary security verification tokens used to confirm that requests originate legitimately from you and protect against cross-site request forgery.
Educational Preferences: Ephemeral settings that remember your selected subject filter or reading layout preference.
We do NOT use invasive advertising tracking cookies, marketing pixels, or third-party behavioral profiling.
Section 10
Grievance Officer & Official Regulatory Contact
Pursuant to Rule 5(9) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the provisions of the Digital Personal Data Protection Act, 2023, the details of our designated Grievance Redressal Officer are published below: