Privacy Policy
Last updated: 5 October 2026
DrBull's Matrix is built to work without knowing who you are. This page says what little we keep, why, and for how long. It is written for the Information Technology Act, 2000 and its rules, and for the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
The operator is DrBull Media, a sole proprietorship ("we", "us"). Who we are, our address and our contact details are on our Contact page.
What we never ask for
Your name, email address, phone number, postal address, date of birth, NEET roll number, photo or any document. (When you pay, Razorpay's checkout asks for your mobile number: see Payments below.)
What we keep, and why
| What | Why | How long |
|---|---|---|
| Your username (random, made by us) | To identify your account | Until you delete the account, then a year (see "When you delete your account") |
| Your password and recovery code, stored only as secure hashes | To let you sign in and reset your password. We can't read either | Until you delete the account |
| That you confirmed you're 18 or older and agreed to the Terms of Use (with the Disclaimer), this Privacy Policy and the Refund Policy, which version of each, and when | To show what you agreed to | Until you delete the account |
| Your credit balance and credit history | To give you what you paid for | Until you delete the account, then a year |
| Payment records from Razorpay: payment ID, order ID, amount, date, status, and any refund | To add credits, handle refunds, and meet tax law | As long as Indian tax law requires |
| A scrambled code of the UPI ID each payment came from (never the ID itself), with the season | So that one UPI ID pays for one account a season: one account is for one candidate | With the payment record, also after the account is deleted |
| What you enter for reports (rank or score, category, the boxes you tick, states and quotas, filters), the reports made from it, and your saved choice lists | To build your reports and let you reopen them; and, if a copy of a report is found shared or sold, to find the account it came from (by its hidden mark, or by comparing its contents with stored reports) | Until you delete them or the account, or a later report changes the rank, category or state they were made for. Then a hidden copy of the report is kept for 1 year, used only to trace a leaked copy back to the account, and erased |
| The rank and category fixed to the account by its first report for each exam (each NEET-PG year, and each INI-CET session), the states (up to two) fixed by reports with a state's quota in each NEET-PG year, and when you confirmed you meet each one's rule (with which wording of the rule you saw), and the category and state rank fixed for each state | So that one account serves one candidate: a paid account can't be used to look up other people's ranks | Until you delete the account |
| A change you ask us for (what is fixed to the account now, and what you asked for), and whether we OK'd it | So that we can OK or decline a change you can't make yourself | Until you delete the account |
| If you sign up with a code, or add one: which code. If you make your own code to share: the code, and how many accounts signed up and bought with it | To give the code's bonus credits, and to pay the channel or person who shared a partner code their share of sales. They see only counts and amounts, never your username | Until you delete the account; sales counts stay with the code, with no link to any account |
| Your review, if you write one: its stars, text, whether to show your username, the label we add, and whether we showed it or left it out (and why). If you asked us not to ask for one, that too | To show buyers' reviews honestly | Until you delete the account |
| A device code: a random code the site leaves in your browser when you sign up or sign in; we keep only a scrambled code of it, per season | So that one account is used on at most 2 devices a season, and one device holds at most 2 accounts | Until you delete the account; the browser keeps its cookie for up to 400 days |
| If a report's marks are changed on the page while it shows | A note of which report and what changed, kept on your account, to look into copying | Until you delete the account, or longer if we pause or close it |
| If the account makes more reports, or uses more credits, than one candidate usually needs (more than 20 reports or 100 credits in 180 days), a note of how many it made and what it spent; its new reports are paused until we check it | To spot copying of the data | Until you delete the account, or as the next row says |
| What we did to the account (credits we gave, a pause or closure and why, a change we OK'd or declined, a report we opened or took off), with dates. You see it on your account page | A record of our own actions, to answer questions and complaints | While the account exists. After it is deleted, each entry is erased once it is a year old |
| If we pause or close an account (Terms of Use, section 8): its reports and their marks, its payment records and codes, and why we acted | To look into misuse or copying, and to take legal action | As long as we need them for that; meanwhile the account can't be deleted by its owner |
| Network codes: a scrambled code made from the network address of each sign-up, each report, and each report request that found no seats (never the address itself), with its time and, for a report or request, its ranks. They aren't stored with your account | To enforce the limits per network, spot copying of the data, and investigate attacks on the Service | 1 year, also after an account is deleted |
| The server's own logs: errors (by a reference code), payments and refunds by their IDs, accounts paused for review (by an internal number), flagged network codes, and our own sign-ins to the server. They hold no network addresses of visitors | To keep the Service working and secure, and because Indian law (CERT-In's directions under the IT Act) asks us to keep logs | 1 year |
| One sign-in cookie | To keep you signed in | Until you sign out, or 30 days |
Your browser also keeps your last report form's choices on this device, so you don't have to enter them again. They aren't sent to us, and deleting the account clears them in that browser.
We use no advertising or tracking cookies. Visit counts come from Cloudflare Web Analytics, which uses no cookies.
When you delete your account
The account closes at once: it can't be signed in to or used again, and its reports, choice lists, the rank, category and states fixed to it, its devices, requests and review are deleted. As the law asks, a hidden record is kept for a year and then erased: the username, when it was made and deleted, its credit history and the IDs of its payments, and a hidden copy of its reports (used only to trace leaked copies). Payment records themselves stay as tax law requires, with no link to any account after that year. Network codes expire on their own after a year.
Deleted data can stay for up to 30 days in our backups, until those backups are replaced.
Payments
When you buy credits, you pay by UPI on Razorpay's checkout. Razorpay's checkout asks for your mobile number, and may ask for an email address, to process the payment. These go to Razorpay and are handled under Razorpay's own privacy policy. From Razorpay we receive the payment ID, the amount, whether it succeeded and the UPI ID it came from; Razorpay's payment record also carries the phone number and email you gave it. We keep only a scrambled code of the UPI ID (see the table above) and don't store the UPI ID, phone number or email.
Where your data is, and who processes it for us
- DigitalOcean hosts the Service. Its servers, our database and DigitalOcean's weekly backup copies of our server are in Bengaluru, India. Our own encrypted backups are kept in India.
- Cloudflare carries every visit to the Service, protects it from attacks, runs the bot check at sign-up and for each report (Turnstile), and counts visits. To do this it sees your browser's details and network address; from the bot check we receive only whether it passed. Its servers can be outside India.
- Razorpay takes payments.
Each works under its own terms and data protection commitments. We don't sell or rent your data. We don't use it for advertising, and nobody will call or message you. We share data only if the law requires it, for example with a court, the police or CERT-In.
Your rights
You can see the data we hold about your account, have it corrected, have it erased, and withdraw your consent by deleting the account. You can also name someone to use these rights for you if you die or become unable to.
- Most of this you can do yourself: your account page shows everything we hold about the account and lets you delete saved reports or the whole account.
- Because we don't know who you are, we can act on a request only from someone signed in to the account, or who can show one of its payment IDs. Quote your username or a payment ID.
- For anything else, and for any question about your data, write to our Grievance Officer (see Contact). We acknowledge within 48 hours and resolve the request within one month.
- If you aren't satisfied with our answer, you can complain to the Data Protection Board of India.
Security
- Passwords and recovery codes are stored only as slow, salted hashes, all traffic uses HTTPS, and the backups we make are encrypted. Only we can reach the systems that hold account data.
- If a breach affects personal data, we will tell you in your account (a notice when you next sign in), post a notice on this site, and report it to CERT-In and the Data Protection Board as the law requires.
Age
The Service is only for people aged 18 or over. You confirm it when you sign up.
Changes
We will post any change here with its date. If DrBull moves to a company that we own or control, that company will hold this data for the same purposes and on the same terms, and we will post a notice here before the move.
Contact
Our Grievance Officer's name and email are on the Contact page. They answer questions about your data too.
