Privacy policy
This policy explains what Thea collects when you read the site, why, who it is shared with, and the rights you have wherever you live.
Last updated · Operated by Thea · Questions: use the contact page
Who we are
Thea is a Windows how-to publication operated from India with readers worldwide. For anything in this policy, use the contact page. We are the data controller (GDPR), the business (CCPA/CPRA) and the data fiduciary (DPDP Act) for the processing described here.
What we collect and why
Server logs. The site is hosted on Vercel. Like every web host, Vercel records standard request data when you load a page: your IP address, the page requested, the time, your browser's user-agent string and the referring page. We use these logs only to keep the site running, to diagnose errors and to block abuse. They are retained for a short period by Vercel and then deleted; we do not export or combine them with other data.
Analytics. Analytics is currently switched off. No analytics script loads and no analytics cookies are set. If we turn it on, this section, the cookie policy and the cookie banner will say so, and it will load only after you accept.
Advertising. No ads are currently shown, so no advertising cookies or identifiers are set. If that changes, the advertising disclosure and the cookie banner will reflect it.
Contact. If you write to us through the contact page, we keep your message and address for as long as needed to answer it and to keep a record of corrections we made because of it. We do not add you to any list.
RSS. Our feed at /feed.xml is a plain file. Your feed reader fetches it directly; we only see the same server-log data as for any page.
IndexNow and search engines. When we publish or update an article we notify search engines through IndexNow and our sitemap. That tells them which URL changed; it contains nothing about readers.
Cookies and browser storage
We set no cookies unless analytics or ads are enabled. The only thing we store in your browser by default is your answer to the cookie banner (in local storage), and the banner itself appears only when analytics or ads are on. Details are in the cookie policy.
Legal bases and purposes
- Running and securing the site (server logs): our legitimate interest in operating a working, safe website.
- Analytics and advertising, where enabled: your consent, given through the cookie banner and withdrawable at any time.
- Answering your messages: our legitimate interest in responding, and, where you ask us to correct an article, in keeping the site accurate.
Who receives data
Vercel (hosting and logs), Google (only if analytics is enabled), and any advertiser whose code is shown in an ad slot (only if ads are enabled). We do not sell personal information and we do not share it for cross-context behavioural advertising. We may disclose data if the law requires it.
International transfers
We operate from India; Vercel and Google process data in the United States and other countries. Where transfer rules apply, those providers rely on standard contractual clauses or equivalent safeguards published in their own terms.
Retention
Server logs: the short period Vercel keeps them. Contact emails: while we handle your request, then as long as a record of a correction is useful. Consent choice: until you clear your browser storage. Analytics data, when enabled: per Google Analytics' retention setting, which we keep at the shortest available option.
Your rights
European Economic Area and United Kingdom (GDPR/UK GDPR). You can ask for access to, correction of, deletion of, or a copy of your personal data, object to processing based on legitimate interest, restrict processing, and withdraw consent at any time. You may complain to your local supervisory authority.
California (CCPA/CPRA). You have the right to know what personal information we collect and how it is used, to delete it, to correct it, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising these rights. We do not collect sensitive personal information and do not process data of readers we know to be under 16.
India (Digital Personal Data Protection Act, 2023). As a data principal you can ask what personal data we hold, have it corrected or erased, withdraw consent, nominate someone to exercise these rights on your behalf, and raise a grievance with us. If we do not resolve it, you may approach the Data Protection Board of India.
Everyone else. We honour the same requests regardless of where you are. Send a “Privacy request” through the contact page; we reply within 30 days and may ask you to confirm the address the request concerns.
Children
The site is written for adults managing their own PCs. We do not knowingly collect personal data from children under 16 (under 18 in India). If you believe a child has sent us data, tell us via the contact page and we will delete it.
Security
The site is served over HTTPS only. Access to our systems is limited to the people who run the publication and protected by credentials that are never stored in the code.
Changes
When this policy changes, the “Last updated” date at the top changes with it. Material changes are noted on the editorial policy page.