Who is responsible
James Munluah, sole proprietor, trading as Yedid Studio. Under India’s Digital Personal Data Protection Act 2023 that makes us the data fiduciary for everything described below, which in plain terms means we decide what is collected and why, and we are the ones answerable for it.
The person answerable is James Munluah, reachable at privacy@yedidstudio.com. That is a real address read by a real person, not a form that goes nowhere.
No database, except the room
This is the single most useful thing to know about how the studio handles your data, so it goes near the top rather than buried in a clause. Nothing you submit through a form on this site is written to a database. Every form sends an email and stops.
The members’ room is the one exception, and it is a real one rather than a technicality. It stores your handle, your account, and every message you post, and its own section further down says exactly what that means. This sentence used to read “there is no database” with no exception at all, which stopped being true the day the room opened.
For everything else, what really holds your information is an inbox, and the retention promise further down is a promise about a mailbox that a person keeps by hand. We would rather say that plainly than describe an automated deletion process we do not run.
What each form collects
The contact form
Collects your name, your email address, your organisation (optional), what the message is about, the message itself.
To read your message and reply to it.
It is emailed to the studio inbox and you get an automatic acknowledgement. It is not written to any database.
The project enquiry form
Collects your name, your email address, your company, what you want to achieve, the problem in your words, your budget range, your timeline.
To judge whether the studio is a fit for the work before either side spends an hour on a call finding out.
It is emailed to the studio inbox and you get an automatic acknowledgement. It is not written to any database.
The checklist request form
Collects your name, your email address, which checklist you asked for.
To send you the checklist you asked for, and so the studio knows which problem brought you here.
It is emailed to the studio inbox and the checklist is emailed to you. It is not written to any database, and you are not added to a mailing list.
The room itself
Collects the email address your invite arrived at, which is checked and never stored: what is kept in its place is a one-way fingerprint of it, the handle you choose, which is shown next to everything you post, the passphrase you set, which is stored only as a scrambled form that cannot be turned back into what you typed, a shared room code, on one path only and checked without being stored: claiming a handle that posted here before accounts existed, for which no invite address was ever collected, the code carried in your invite link, which your browser sends once and which is checked and never stored. It is worked out from your handle and the fingerprint of your address rather than kept anywhere, how many wrong passphrases have been typed against your name recently and when, kept only to lock out guessing and cleared the moment you sign in correctly, the date your account was made and the date you set your passphrase, the messages you post in the room, the date you first came in, and the time you were last in the room, recorded to the second and refreshed while the page is open, which is what the member count in the header is made of, how far you have read: the room keeps the number of the most recent message you have been sent, so the person who wrote a message can be told it was seen. It is one number that only ever moves forward, not a record of what you opened or when.
To let you in, to keep your handle yours rather than anyone else’s, to show other members who said what, to keep the conversation readable when you come back, and to show the room how many members it has and how many are here now, and to tell somebody their own message was read.
Your handle and your messages are stored in our database and are visible to every other member of the room. So is the fact that you are a member and the time you were last here, though other members see only the totals, never a list of who is online. They are not public, not indexed, and not shared outside it. We do not keep your email address itself. What we keep instead, for everybody invited since 2026-09-09 and for anybody claiming a handle carried over from before accounts existed, is a one-way fingerprint of it, enough to check a later answer against and not enough to write to you or to identify you without our server key. That fingerprint is still personal data under the Act and every right below applies to it. Your passphrase is never stored as you typed it. One thing to know before you pick a handle: typing one into the enter screen tells you, and tells anybody else who tries, whether that handle already belongs to a member, and we accept that trade so a returning member is not asked for a code they no longer have. How far you have read is shown ONLY to the person who wrote the message you have reached, and only as your handle beside their own message: no member can ask what anybody else has read, and there is no page anywhere that lists it. It goes with your roll entry when you delete your account. Ask and your messages go, your roll entry with them so the member count stops counting you, and your account too, which frees the handle for somebody else.
Your member profile
Collects a short bio you write about yourself, up to 280 characters, up to six interests you tag yourself with, one link you choose to share, which may be a website or a way to reach you, a profile photo, if you upload one. It is re-encoded before it is stored, which removes the location and camera data your phone attaches to it, the date you last changed any of this, if you choose to delete your account, the word you type to confirm it, which exists so that an accidental tap on a phone cannot erase everything you have written.
So the other members of the room know who they are talking to, and nothing else. None of it is required, and the room works exactly the same if you leave every field empty.
It is stored in our database and shown to every other member of the room. It is not public, not indexed, not shared outside the room, and not used to send you anything. You can change any of it whenever you like. Deleting your account removes it, along with your messages and any file you shared, and that deletion is permanent rather than a hiding.
Files, photos and video you share in the room
Collects the image, video or document itself, its size and format, and for an image its dimensions, the handle you posted it under, and when, the caption you typed with it, if any.
To show what you shared to the other members of the room, and to let the room see how much of its storage is in use.
It is stored in a private bucket. It is never public: a file is reached only through a temporary signed link that the room hands to members, and it is not indexed anywhere. IMAGES are re-encoded before storage, which removes the location and camera data your phone attaches to them. VIDEO AND DOCUMENTS ARE NOT: they are stored exactly as you sent them, so a video filmed on a phone may still carry the place it was filmed, and a PDF may still carry the name of whoever made it. The room says so at the moment you attach one rather than only here. A moderator who removes a file deletes it outright rather than hiding it, and deleting your account deletes everything you shared.
Pinning a file, and reacting to a message
Collects which file you pinned, and the fact that you pinned it rather than somebody else, which message you reacted to, which of the eight emoji you chose, and that you may remove it again at any time, the handle you are using in the room, attached to both, because the room shows other members who pinned a file and who reacted.
So the room can put the files people thought were worth keeping at the top of the shared list, and so a message can be acknowledged without another message. Naming who did it is deliberate: an anonymous pin is an unattributed edit to what everybody else sees.
Both are stored in our room database, as rows readable only through the room. A reaction disappears the moment you remove it. A pin disappears when anyone unpins it, which any member may do. Removing a message removes every reaction on it, deleting your account removes everything you pinned and reacted to, and neither is ever sent anywhere outside the room.
A private message in the room
Collects what you wrote, exactly as you typed it, who you wrote it to, and who wrote to you, when it was sent, and when the person you sent it to first opened it.
So you can leave something for one member that the rest of the room does not see, and so they find it waiting when they next sign in. The moment it was first opened is stored for one reason only: it is what turns the red count on your side off, and there is nothing else in the room that reads it.
Stored in our room database as rows readable only through the room, and never sent anywhere outside it. No other member can read a message you did not send or receive. The studio can, because the studio holds the database: a private message is private FROM THE ROOM, not from us, and anyone who needs the stronger thing should not use a website for it. Deleting your account deletes the whole of every private conversation you were part of, in both directions, and that last part is stated plainly because it costs somebody else something: the other person loses their own words in that thread too. A two-party conversation with one party erased is not a conversation any more, and the alternative would be keeping an erased person’s name and the messages sent to them indefinitely.
Moderation of the room
Collects the action a moderator took, such as hiding a message or banning a handle, one field holding whichever the action concerns: the id of a message or file, or the handle of a member, a short reason the moderator typed, if they gave one, the moderator code itself, when somebody enters it, which is compared and never stored.
So that a removal is a record rather than a hole in the conversation, and so the room can show that its own rules were applied rather than merely claimed.
It is stored in our database and is not shown to other members. It is kept even after the message it concerns is gone, because a log that disappears with the thing it describes proves nothing. If you delete your account, the log keeps one line recording that an erasure happened, and that line carries no content of yours: it exists so the studio can show your request was honoured.
The room join form
Collects your email address, the handle you post under, which is not your legal name, one line on what you cannot do yet, nothing new at any later stage: approving a request seals your email address, your handle and the time the request arrived into an invite link inside the studio copy of this email, and the line about what you cannot do yet is deliberately not in it. That link stays usable for thirty days and can be pressed more than once, which is what lets the studio re-send an invite that failed to arrive.
To decide whether to send you an invite, and to send it to you.
It is emailed to the studio inbox and nowhere else. While it waits to be read it is not written to any database, you are not added to a mailing list, and there is no automatic acknowledgement: the reply is written by a person. If the studio approves you, two things are then written to the room so the invite can be claimed by you and nobody else: the handle you asked for, which is held for you from that moment, and a one-way fingerprint of your email address. The address itself is still never stored. Ask and it is deleted.
The prayer request form
Collects your name, your email address, your phone number, the prayer request itself, the topics you tag it with, which include anxiety, grief, health, relationships and family, whether you would like someone to talk to you.
So the request can be prayed for, and so someone can contact you if you asked them to.
It is delivered by FormSubmit.co, a third-party form service, to the ministry inbox. It is not written to any database.
What is collected without you typing it
- A shortened version of your IP address and the time, included in the notification email so abuse of a form can be traced. The last part of the address is replaced with xxx before it is written anywhere. (The contact, project enquiry and checklist request forms only)
- Your full IP address, held in the server’s memory for up to one hour purely to rate-limit the forms. It is never written to disk and is lost when the server instance recycles. (The contact, project enquiry and checklist request forms only)
- Your IP address, sent to FormSubmit.co in full when you submit a prayer request, because your browser posts straight to them rather than through this site. Like most services they may log it. We never see it and it is not shortened, because the request does not pass through our server at all. (The prayer request form only)
- Aggregate page-view counts through Vercel Web Analytics, which sets no cookies and does not build a profile of you. (Every page on this site)
- The country your request came from, read from a header at the edge, used only to decide whether to show prices in rupees or dollars. (Every page on this site)
There is no advertising network on this site, no behavioural tracking, and nothing here is sold or shared for marketing.
Cookies, and why there is no banner
Every public page the studio serves - this one, the home page, the services, the writing, the case studies - sets no cookies. There is no advertising pixel, no tag manager and no third-party script. Booking a call sends you to Cal.com’s own site rather than loading it inside this one.
There is exactly one cookie on this whole domain, and you only ever receive it if you ask for it: going into the members’ room sets a cookie holding the handle you chose there. It is what keeps you in the room without retyping your code. It carries no identifier that follows you anywhere, and if you never enter the room you never receive it.
Once you are inside the room, your browser also saves a small script called a service worker, which is what lets you install the room on your phone or desktop like an app. It keeps no messages and no copy of the room: offline it shows a page saying so rather than an old conversation. Like the cookie, it arrives only after you enter the door code, and removing the app or clearing this site’s data removes it.
Vercel Web Analytics counts page views without a cookie and without an identifier that follows you between visits, which is why there is nothing here to ask your permission for. A banner asking you to consent to tracking that does not happen would be a dark pattern, not compliance, so this page says the position instead.
What is stored on your device (4 things)
If you go into the room, one cookie is set on your device holding the handle you chose, signed so it cannot be edited.
It is what keeps you in the room without retyping the code every visit. It holds nothing but that handle and the date it was issued, it expires after thirty days, it is not readable by JavaScript, and it cannot follow you to any other site. Delete your cookies and you are simply asked for the code again.
Once you are inside the room, a small script called a service worker is saved by your browser, so the room can be installed on your phone or desktop like an app.
It is what makes the install possible, and it is the only reason it is there. It stores no messages and no copy of the room: the room is live only, and offline it shows a page saying so rather than the conversation from yesterday. It is saved only after you enter the door code, never for a visitor who only opens the page, and uninstalling the app or clearing your site data removes it.
If you switch the room between its light and dark appearance, that one choice is remembered in your own browser, using localStorage.
So the room opens the way you left it instead of asking every visit. It stores one word, either "light" or "dark", and nothing else. It never leaves your device, it is never sent to us, it is not readable by anyone else, and it is set only if you press the control: leave it alone and nothing at all is stored, because following your device own setting requires storing nothing. Clearing your browser data removes it and the room simply follows your device again.
Two of the interactive demos in the concepts library keep what you type in your own browser, using localStorage.
It is the feature. A budget tracker that forgets your budget when you refresh is not a budget tracker. It never leaves your device, it is never sent to us, and clearing your browser data removes it.
The exception, stated rather than glossed over
The concepts library holds standalone demo pages. Most were built before the studio wrote this position down and are not as clean as the rest of the site; the ones built since carry no third-party requests at all. If you open one of the older demos:
- Most of the demos, and the prayer request page, load their typefaces from Google Fonts rather than from this site. Your browser asks Google for the font file, which tells Google your IP address and which page you asked for. It does not tell Google what you typed.
- One demo, a restaurant concept, loads its photographs from Unsplash. The same effect, with Unsplash rather than Google.
- That same demo embeds a Google map of a fictional address. This is the one thing on this domain that can set a cookie, and it is Google’s cookie rather than ours. It loads only if you open that particular demo.
None of it is our tracking and none of it tells us anything. It is still a request your browser makes to a company that is not us, which is why it is written here rather than left inside the word “site”. Tidying those pages is on the studio’s own list.
If any of this changes - if the studio adds a tracker, an embed or anything that stores an identifier on your machine - this section changes first and you will be asked properly where the law requires it. That is enforced by an automated test rather than by anyone remembering.
Why we are allowed to hold it
You typed it into a form and pressed send, for a purpose stated on that form. Under the Act that is your consent, and for an enquiry it is also the voluntary provision of your own data for a purpose you approached us about. We use it for that purpose and not for another one.
If we ever wanted to use what you sent for something else, we would ask you first. We have no marketing list, so submitting a form does not subscribe you to anything.
How long it is kept
If your enquiry became an engagement, we keep the correspondence for 24 months after the work ends, because a live business relationship is a real reason to hold it.
If it did not, we delete it within 12 months.
You do not have to wait for either. Ask and it goes sooner.
The room is the exception, because it is the one place on this site with a database. Your messages, the roll entry that records that you are a member and when you were last in, your profile and any file you shared, and your account itself (your handle, the scrambled form of your passphrase, and the email fingerprint of the address your invite reached, or of the address you confirmed to claim an older handle) are kept for as long as the room runs. There is no automatic expiry, and that reaches an invite you were approved for and never used: the handle stays held for you until you ask for it to go. Any thirty-day limit you read on an approve link is the life of that LINK, not of anything stored. Private messages you have sent or received are kept the same way, and so is the moment the person you wrote to first opened one. Ask, or delete your account yourself, and all of it goes together and the handle becomes free again. ONE THING SURVIVES, and it is named here rather than left to be found further down the page: a single line in the moderation log recording that an erasure happened, carrying no content of yours. It exists so the studio can show your request was honoured.
Who else touches it
Running a website means other companies handle your data on our behalf. This is the complete list, and each one is named for what it actually does rather than described in a category.
- Vercel - Hosts the site and runs the code that receives the forms. (All pages and forms)
- Resend - Delivers the notification and acknowledgement emails, and the checklists. (Contact, project enquiry and checklist request forms)
- Google Workspace - Hosts the inbox where submissions arrive and rest. (All studio email)
- Cal.com - Takes the booking when you schedule a diagnostic call. (Booking a call)
- FormSubmit.co - Delivers the prayer request to the ministry inbox. (Prayer request form only)
- Supabase - Stores the research papers the site publishes. It holds no visitor data. (The research library)
Several of these are based outside India and store data on servers outside India. The Act permits that except to countries the government specifically restricts, and none of these are in that position as at the date on this page.
The prayer requests, specifically
The prayer form on prayer.yedidstudio.com is a ministry, not a service the studio sells, but it collects the most personal thing on any of these pages and so it gets its own section rather than being folded into a list.
A prayer request often carries illness, family difficulty, or money trouble. It is delivered by FormSubmit.co, a third-party form service outside India, and it arrives in an inbox read by the person who prays for it. It is not published, not shared, and not used for any studio purpose. Your phone number is used only if you asked to be contacted.
Two smaller things about that page specifically, since it is the most sensitive one here. It loads its typefaces from Google Fonts, so opening it tells Google your IP address, though never what you wrote. And because the form posts straight from your browser to FormSubmit.co, your full IP address goes to them and is not shortened the way it is on the studio’s own forms.
If you would rather it were not handled by a third-party form service, email the request to privacy@yedidstudio.com instead and it will reach the same place.
Children
None of these forms is aimed at anyone under 18, and the studio does no profiling or targeted advertising at all, so none of it can be directed at a child. If you are under 18, ask a parent or guardian before sending a prayer request. If you believe a child has sent us something, tell us and we will delete it.
What you can ask us to do
All of these go to privacy@yedidstudio.com. We aim to answer within 30 days; that is our own commitment, not a figure taken from the Act.
Ask what is held on you
Email the grievance officer and you get a summary of what the studio holds, what it has been used for, and who else has touched it.
Correct or complete it
If something is wrong, say so and it is corrected.
Have it erased
Ask and it is deleted, unless there is a legal or contractual reason to keep it, in which case you are told what that reason is.
Withdraw your consent
Email the grievance officer. Withdrawing is deliberately no harder than sending the form was.
Nominate someone
You can name a person to exercise these rights for you if you die or cannot act for yourself.
Complain
Raise it with the grievance officer first. If the answer does not satisfy you, you can take it to the Data Protection Board of India.
If something goes wrong
If your data is exposed in a way it should not have been, we will tell you and we will tell the Data Protection Board. We will not sit on it while deciding how bad it looks.
Changes, and what this page is not
If what we do changes, this page changes with it and the date at the top moves. This notice describes what the studio actually does today. It is not legal advice, and it is not a claim to have been certified by anyone.
The DPDP Rules were still being finalised when this was written, so some mechanics the law will eventually prescribe are not settled yet. Where that is true we have described our own practice rather than assert a standard that does not exist.
The commercial terms live separately. Read the terms.