Who is responsible
Mishra.info is operated by Dhruv Mishra as an individual. Questions about this policy, and requests to see, correct or delete your information, go through the contact form and are handled by that person directly - there is no support desk in between.
What is collected
When you request an identity: your name, the username you want, your existing email address, phone number, chosen plan, and optionally your city, gotra and a note about how you intend to use the address. Your IP address is recorded with the request. If you asked for a redirect, the destination URL is stored too.
When you use the contact form: your name, email address, the subject you chose, your message, and your IP address.
When you browse: the site sets one cookie for your language choice and, if you submit a form, a session cookie. There is no analytics service, no advertising network, no tracking pixels and no third-party scripts of any kind. The web server keeps standard access logs.
Family material you send: whatever you choose to send. Please do not send documents about living people who have not agreed to it.
Why it is collected
Your details are used to fulfil what you asked for and for nothing else:
- To check that the username is available and acceptable
- To match your payment to your request
- To create the mailbox or DNS record and send you the credentials
- To remind you before your renewal date
- To reply to your message
IP addresses are kept for one purpose only: to limit automated abuse of the forms.
Your information is never sold, rented or shared for marketing. There is no mailing list you are added to without asking.
How long it is kept
- Active identity holders: for as long as you hold the address, plus one year after it lapses, so a renewal or a dispute can be resolved
- Requests that were never paid: twelve months, then deleted
- Contact messages: two years
- Access logs and IP records: ninety days
- Payment references: as long as required for basic accounting
Mailbox contents are held for thirty days after deactivation and then deleted by the mail provider.
Family and lineage information
This deserves its own section, because it is the most sensitive material the site handles.
Nothing about a family is published without consent. Gotra, city and the purpose you write on the request form are used to fulfil your request and are not shown publicly. They appear on a profile page only if you ask for them to.
Vanshavalis and family histories sent to the site are published only if you say you want them published, and only after checking that living people named in them have agreed. If you send material for reference rather than publication, say so and it will be kept unpublished.
Anything published can be removed. A request from any person named on a page, or from an immediate family member acting for a deceased person, is acted on without requiring a reason and without argument. Removal from the site is normally same-day; where a page has been indexed by search engines, removal is requested from them as well, although the timing of that is not in this site's control.
Deceased people. Genealogy necessarily involves the dead, who cannot consent. The approach taken is to publish what the submitting family provides, to remove on request from a descendant, and not to publish material about a deceased person that their living relatives object to.
Your rights
You may ask, at any time and without giving a reason, to:
- See everything held about you
- Correct anything that is wrong
- Delete your information, subject to keeping the minimum needed for accounting where a payment was made
- Withdraw consent for anything published about you or your family
- Take your data in a plain file you can keep
Write from the email address on your record if you have one, which saves an identity check. Requests are normally answered within seven days.
Deleting an active identity record means the address stops working, since the record is what allows it to exist - that consequence is spelled out before anything is deleted.
Security, honestly stated
The site is served over HTTPS, form submissions are protected against cross-site request forgery, the database is not reachable from the web, and the administrative area requires a password.
It is also a small project run by one person, not a bank. No system is perfectly secure, and it would be dishonest to imply otherwise. The practical consequences of that are why so little is collected in the first place, why no payment details ever touch this site, and why family material is only published when someone has asked for it.
If you find a security problem, please report it through the contact form before disclosing it elsewhere.
Changes to this policy
If this policy changes in a way that affects what is collected or how it is used, existing identity holders are emailed before the change takes effect. The date at the top of this page always shows the current version.
Questions about any of this, or a request to have your information removed, go through the contact form and are answered by a person. Contact.