Privacy Policy
Dee Product counts page visits with self-hosted, cookieless analytics — no tracking pixels, no session replay, no advertising, and nothing that follows you off this site. The only personal data here is what you typed into a form yourself — your name, your email, and your message. You can have it deleted by sending one email.
Last updated 16 July 2026
Who is responsible
Dee Product is run by Deepakkrishna R, an individual operating as Dee Product. For data protection purposes I am the data controller— meaning I decide what is collected and why, and I’m the one accountable for it. There is no company behind this; it’s one person.
Contact for anything on this page, including deletion requests and complaints: deepakkrishnar1618@gmail.com.
What I collect, and only when you hand it over
There is no hidden collection. Every piece of personal data below exists because you filled in a form:
- Idea signups. When you sign up for an idea in the Product Catalog, I store your name, your email address, the message you wrote, which idea it was for, and the date.
- Follow the build. When you follow along, I store your name, your email address and the date. Nothing else.
- Hearts.The heart on an idea increments a counter. The count is a number and nothing more — it is not linked to you, your email or your device. Which ideas you’ve hearted is remembered in your own browser’s local storage and is never sent to me.
- Server logs. My host records standard request logs — IP address, browser user agent, time, page requested. Every website receives this by technical necessity. I don’t build profiles from it and don’t connect it to signups.
What I don't do
This list matters more than the one above, and I’d rather state it plainly than bury it:
- No third-party analytics. No Google Analytics, no heatmaps, no session recording or replay. Visit counts come from Umami, self-hosted on my own infrastructure, which sets no cookies and stores nothing that identifies you.
- No tracking or advertising cookies. No pixels, no ad networks, no retargeting.
- No selling or sharing your data. Not to anyone, for any price, ever.
- No profiling, and no automated decision-making that has any legal or similarly significant effect on you.
- No newsletter list rented, bought, or shared. If you get an email from me it's because you asked.
Why I'm allowed to hold it (lawful basis)
Under the UK/EU GDPR every use of personal data needs a lawful basis. Mine are:
- Your consent (Article 6(1)(a)) for your name, email and message. You gave it by submitting the form, and you can withdraw it at any time by emailing me — withdrawing is as easy as giving it, and withdrawing doesn’t affect anything done before you did.
- Legitimate interests (Article 6(1)(f)) for server logs and keeping the site standing up — security, debugging and abuse prevention. My interest is a working, un-abused site; the data is minimal and not used to profile you.
If India’s Digital Personal Data Protection Act, 2023 applies to you, this page is the notice required under Section 5, and your consent is the ground under Section 6. You may withdraw it at the same address.
Who else touches it
I keep the supply chain deliberately short. Three parties, all processors acting on my instructions:
- Vercel hosts the site and the database your signup is stored in, and also runs the analytics instance described above.
- Neon hosts the Postgres database behind that analytics instance. It holds visit counts only, never your name or your email.
- YouTube (Google) serves the video thumbnails on project pages. Because your browser fetches those images directly, Google can see your IP address and may set its own cookies under its own policy — I have no control over and no access to that. If this bothers you, a content blocker stops it.
Beyond those, I’ll disclose data only where the law actually compels me to.
Where it goes
Vercel’s infrastructure is global, so your data may be stored or processed outside the UK, the EEA or India. Where that involves a transfer out of the UK/EEA, it relies on the UK Addendum and the European Commission’s Standard Contractual Clauses in Vercel’s Data Processing Agreement. You can ask me for details.
How long I keep it
I’ll be honest rather than invent a policy I don’t follow: signups are kept until you ask me to delete them, or until the idea they relate to is retired and the list is no longer useful — whichever comes first. There is no automatic expiry clock. If you want to be forgotten, ask, and it’s gone.
Your rights
Under the UK/EU GDPR you have the right to: access a copy of your data; have it corrected; have it erased; restrict or object to how it’s used; receive it in a portable format; and withdraw consent at any time.
Under India’s DPDP Act, 2023 you have the right to access a summary of your data, to correction and erasure, to grievance redressal, and to nominate someone to exercise these rights if you die or are incapacitated.
Exercise any of them by emailing deepakkrishnar1618@gmail.com. No form, no account, no hoops. I’ll respond within 30 days, and it’s free — I won’t charge you to leave.
If I get it wrong, you can complain to a regulator: in the UK the Information Commissioner’s Office (ico.org.uk), in the EEA your national supervisory authority, in India the Data Protection Board. You don’t have to come to me first — though I’d rather you did, so I can fix it.
Analytics
I count visits so I know which projects people actually open. That runs on Umami, self-hosted on my own infrastructure rather than handed to a third-party analytics company, so the numbers never leave my control and are never joined to an advertising profile.
What a visit records:
- The page you opened, and the site that linked you here, if any.
- Your browser, operating system, device type, screen size and language.
- A country, derived from your IP address. The IP itself is never written to the database.
- A few named actions — opening a panel, following a link out to one of my projects, submitting a form. Which control you used, never what you typed into it.
There is no cookie, no fingerprint, and no identifier that persists across days or follows you to another website. Nothing here is linked to a name or an email, including for people who have signed up — the counts and the form submissions are kept apart and I have no way to join them. Because none of it identifies you, there is nothing to consent to and no banner to click.
Cookies
The public site sets no cookies. Nothing to consent to, which is why there’s no cookie banner.
One cookie exists, dee_admin, and it is only ever set on my own browser when I sign in to manage ideas. It’s strictly necessary, holds no personal data, is HttpOnly, and expires after 8 hours. Visiting the site as a visitor never sets it.
Your browser’s local storage holds which ideas you’ve hearted. That stays on your device, is never transmitted, and clearing your browser data removes it.
Security
Traffic is served over HTTPS. Database queries are parameterised. The admin area is behind a passcode held only as a server-side environment variable and a signed, HttpOnly session cookie the browser cannot read.
What I won’t claim is that any of this makes the site unbreakable — no honest site can say that. If a breach affects your rights and freedoms, I’ll report it to the relevant regulator within 72 hours where the law requires, and tell you directly where the risk to you is high.
Children
Nothing here is aimed at children, and I don’t knowingly collect data from anyone under 16 (or under 18 where India’s DPDP Act applies). If you believe a child has sent me their details, email me and I’ll delete them.
Changes
If this policy changes materially I’ll update the date at the top of the page. Continuing to use the site after a change means the updated version applies. The Terms of Service cover the rest of the arrangement.