The short version
M.I.L.F. Shiksha has no account system, no ad network, and nothing to sell. In plain terms:
- You never give us your name, email or phone number — no form on this site asks for them.
- The only personal things that reach us are the words you choose to type in, and this page tells you exactly where they go.
- Your IP address is hashed with a daily salt for rate limiting, then forgotten — it is never stored raw.
- We do not sell, rent or share data with advertisers. There are no advertisers.
- The one cookie we set remembers your language.
What this policy covers
This policy explains what M.I.L.F. Shiksha ("the site", "we") collects, why, who processes it, how long it is kept, and the choices you have. It applies to the site and all of its pages. It is a plain-language summary of our actual behavior as implemented in code, not marketing copy.
Information you give us
Questions you ask
When you submit a question on the Ask page, we store:
- the question text (10–2,000 characters),
- a language code (
en,hiorbn), - a randomly generated public handle (for example
CuriousKolkata44), - a moderation status.
We never receive your IP address, email or device fingerprint together with a question: the rate limiter hashes your IP before the request reaches the question handler, and that handler never sees the raw IP.
A safety screen rejects questions containing phone numbers, email addresses, full names with a city, or crisis keywords before anything is written to the database. Pending questions older than 30 days are deleted automatically by a scheduled job.
Text you paste into Wingman
Wingman accepts text only — never an image. The screenshot never leaves your phone: there is no upload field, no image endpoint, and the on-device OCR seam is not enabled. Each analysis works like this:
- the pasted text is sent from your browser to our server;
- our server forwards it to Groq, an AI infrastructure provider, to generate the analysis;
- only anonymous metrics are written to our database — a tone verdict, two energy scores, the model id and the latency;
- a scheduled job deletes those metric rows within 15 minutes.
The transcript itself is never written to our database or to application logs (fields such as body.question are redacted from logs). If the AI provider is unreachable, times out, or returns something unusable, your browser falls back to a local heuristic — the answer is labelled Offline guess and no text leaves your device.
A pre-flight screen rejects pasted text containing phone numbers, email addresses, or "name + city" patterns before it is sent to the model. It is a regex screen, not a guarantee — the surest protection is not pasting identifying details in the first place.
Tool inputs
Sliders, dates and checklist answers in tools such as the Sperm Score Calculator are sent to the server only when a tool needs a calculation, and nothing from them is stored — the result renders and the data disappears with the tab. Other tools (ED assessment, size reality check, trackers, planners) never send your answers anywhere; they compute in the browser.
Information collected automatically
Rate-limiting hash
To keep the free limits honest (5 Wingman analyses per day, 10 questions per hour, 60 searches per minute), your IP is hashed as SHA-256(IP + daily salt) and only that opaque hash plus a counter is sent to Upstash Redis. The salt rotates daily, so yesterday's buckets cannot be linked to today's. The raw IP never leaves server memory and never reaches application logs — IP fields are on the log redaction list.
Request logs
Our host (Vercel) keeps standard request logs — IP address, path, timestamp, response status — for security and debugging, under Vercel's own privacy policy. We do not use them to build profiles.
Vercel Web Analytics
We use Vercel Web Analytics to count visits and see which pages are read. The vendor documents the product as cookieless: no advertising identifiers and no cross-site tracking. The site works fully if you block the script with any content blocker.
Storage on your device
Drafts — your unsent question, the conversation you are pasting, tracker entries — are saved in your browser's localStorage under milf.* keys so a refresh does not lose them. They never sync to a server. Press Esc (the panic button) and they are wiped before the screen changes. The full key list lives in the Cookie Policy.
Cookies
One cookie: NEXT_LOCALE, written by the language switcher, valid for one year, storing only your language preference. Full details in the Cookie Policy.
Who processes your data
All of this runs server-side; the app's own code makes no browser-side calls to these providers — only same-origin requests leave the page. We do not sell data, and there are no third-party advertising or social trackers.
Retention
- Wingman metric rows — deleted within 15 minutes by an automated purge.
- Pending questions — deleted after 30 days by an automated purge.
- Rate-limit counters — expire inside a 24-hour sliding window.
- Everything else — only for as long as it is needed to run the service.
Your rights
Depending on where you live (GDPR, the UK GDPR, India's DPDP Act, CCPA and similar laws), you may have the right to access, correct, or delete personal data we hold. Because we hold so little, requests are usually simple:
- Delete a question — email us its public ID (for example
Q-7F3K2M) and it will be removed. - Ask what we hold about you — email us. The honest answer will be short.
- Opt out of analytics — block the
/_vercel/insights/path or use any script blocker; nothing else changes.
Email: anuragpanda.dev@gmail.com
Security
HTTPS on every page, salted hashing for identifiers, row-level security in the database, redacted application logs, and a strict Content-Security-Policy that pins the origins the browser may talk to. No system is perfectly secure. If you find a vulnerability, please report it privately by email instead of publishing it first, and we will work on a fix with you.
Children
This site is intended for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe we have, email us and it will be deleted.
Changes to this policy
This page is updated when the site's behavior changes; the date at the top shows the last revision. If a change is material — a new data flow, a new processor — it will be called out here in plain language.
Contact
Questions about privacy: anuragpanda.dev@gmail.com. More ways to reach us on the Contact page, and quick answers in the FAQ.