Dhem Privacy Policy
Effective Date: April 5, 2026
Last Updated: April 5, 2026
Table of Contents
- Introduction & Scope
- Plain-Language Summary
- Who We Are & Contact Details
- Scope: What This Policy Covers and What It Excludes
- Information We Collect
- How We Use Your Information
- Artificial Intelligence, Machine Learning & External Model Processors
- Analytics & Tracking Technologies
- Cookies, Local Storage & Client Tokens
- Information Sharing, Third-Party Processors & Disclosures
- Cross-Border & International Data Transfers
- Data Retention, Storage Limits & Account Deletion
- Security Architecture & Operational Safeguards
- Your Legal Rights & Choices
- Children's Privacy
- Third-Party External Links & Scraped Content
- Grievance Redressal Officer & Inquiries (India DPDP & IT Rules)
- Changes & Version Changelog
- App-Specific Appendices
1. Introduction & Scope
Welcome to Dhem (also referred to as "Dhem Org", "we", "us", or "our"). Dhem operates a technology ecosystem consisting of unified developer tools, web applications, mobile applications, and shared application programming interfaces (APIs). Our services are built upon a centralized identity and infrastructure foundation designed to provide seamless access across multiple software products.
This Privacy Policy explains how Dhem collects, uses, stores, processes, shares, and protects your personal data when you interact with Dhem and the products or services operating under it (including dhem.io, our central accounts, APIs, mobile applications, and connected developer tools), sign in to a central Dhem account, connect to our central API server, make payments through our unified billing mechanisms, or access any application published by Dhem that links to or incorporates this policy.
Please read this Privacy Policy carefully. By interacting with Dhem and the products or services operating under it, creating a Dhem account, accessing our websites, downloading our mobile applications, or utilizing any connected service, you acknowledge that you have read, understood, and agree to the data collection and processing practices described herein.
2. Plain-Language Summary
We believe privacy policies should be transparent and straightforward. Here is an executive summary of our core practices:
- Unified Account: A single central account operated through our authentication service allows you to log in across current and future applications and products operating under Dhem. We only store essential profile identifiers: your email address, unique user ID, display name, avatar, and authentication timestamps.
- We Do Not Sell Your Data: We do not sell, rent, monetize, or trade your personal information to third parties, data brokers, or advertising networks. Ever.
- Privacy-First Analytics: For website and application performance, we utilize privacy-preserving, cookieless analytics hosted on our own infrastructure. Our analytics do not store tracking cookies, do not track you across different websites, do not collect personal identifiers, and respect visitor privacy by design.
- AI Processing Transparency: Many products and services operating under Dhem incorporate artificial intelligence models. When you submit text, research queries, or prompts, they are routed through reputable AI providers (such as OpenRouter, Mistral AI, Groq, Cerebras, and underlying foundational models). Your private inputs and uploaded documents are not used to train our internal models or sold to third parties.
- Specific Clinical Data Rules (Thesis Maker): When using Thesis Maker, you may upload research datasets. You are strictly required to upload only de-identified, anonymized data. Direct patient identifiers must be removed prior to upload. Datasets are stored in secure cloud storage, accessed via short-lived temporary presigned links, and biostatistical computations are performed in isolated, secure execution environments.
- Global Operation with Indian Headquarters: Dhem is founded and operated in Jammu & Kashmir, India. While data may be processed in secure cloud infrastructure located in multiple international regions (such as the United States and the European Union), your data protection rights are fully recognized under India's Digital Personal Data Protection Act, 2023 (DPDP Act), the European Union General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
3. Who We Are & Contact Details
The data controller responsible for the personal data processed under this Privacy Policy is:
- Entity / Individual Operator: Murtaza Baanihali (operating as Dhem / Dhem Org)
- Jurisdiction: Jammu & Kashmir, India
- Primary Website: https://dhem.io
- Direct Privacy & Legal Inquiries:
support@dhem.io - Data Protection / Grievance Officer: Murtaza Baanihali (
support@dhem.io)
For any questions, rights requests, data deletion inquiries, or concerns regarding your privacy, you may contact us directly via the designated email address.
4. Scope: What This Policy Covers and What It Excludes
4.1 What Is Covered (In-Scope)
This Privacy Policy governs all platforms, digital properties, software, APIs, and mobile applications developed, owned, and operated directly under the central Dhem ecosystem, including:
- The primary portfolio and organization portal at
dhem.ioanddeveloper.dhem.io. - The centralized API server hosted at
api.dhem.io. - The centralized authentication service hosted at
accounts.dhem.io. - Badr and Badr Play (web platform, APIs, and the mobile application package
com.dhem.badr). - Thesis Maker (web client and associated processing pipelines).
- Shared billing, subscription, and credit balance systems administered via Polar.sh and RevenueCat.
- Any future application, product, or service developed and operated under Dhem that references, displays, or links to this Privacy Policy.
4.2 Explicit Scope Exclusion (Out-of-Scope Products)
Certain commercial software products previously or independently created by the founder operate as separate entities with independent infrastructure, distinct data stores, separate user directories, and dedicated legal terms.
Specifically excluded from this policy are: iReplyy, DheGEN, Dhesend, and any other standalone service that maintains its own distinct privacy policy and terms of service.
These products share only founder attribution and historical branding with Dhem Org; they share no user records, authentication sessions, billing records, or analytics infrastructure with the central Dhem platform. Their data collection and retention practices are governed exclusively by their respective individual privacy notices and not by this document.
5. Information We Collect
We collect information to deliver high-performance applications, maintain secure environments, verify account access, and fulfill transactions when you interact with Dhem and the products or services operating under it. The information collected falls into three categories:
5.1 Information You Provide Directly
- Account Registration Data: When you create or register a Dhem account through our authentication portal (
accounts.dhem.io), we collect:- Your email address (and verification status).
- Your chosen display name or username.
- Your profile avatar or picture URL (if provided or imported via single-sign-on identity providers).
- Credentials and authentication secrets (managed securely through our authentication service; passwords are encrypted and never accessible in plain text to our APIs).
- Academic & Research Information (Thesis Maker):
- Document metadata: thesis or synopsis title, research topic descriptions, target page budgets, and formatting selections.
- Academic metadata: student name, academic degree program (e.g., MD, MS, DNB, DM, MCh, DrNB, Diploma), university or college name, medical department, academic session/year range (e.g., 2024–2027), supervisor name, and co-supervisor name.
- Ethical clearance status: Institutional Ethics Committee (IEC) clearance indicator and official clearance reference number (or placeholder selection).
- Uploaded research datasets: tabular files (
.csvor.xlsxformat, up to 25 Megabytes) containing research variables, laboratory indices, demographic summaries, and outcome metrics. - Uploaded manuscript drafts: prior research drafts or legacy thesis PDF files provided for refinement.
- Communication Data: If you contact us through our portfolio contact form or directly via email, we collect your name, email address, message subject, and message content.
- User Interactions & Feedback: Feedback, customer support inquiries, and issue reports submitted through our applications.
5.2 Information Collected Automatically Through Infrastructure & Telemetry
When you interact with Dhem and any products or services operating under it (including our web applications, mobile apps, or APIs), our servers automatically log technical metadata necessary to route traffic, enforce rate limits, and detect abuse:
- Network & Addressing Data: Your Internet Protocol (IP) address (extracted from standard request headers), TCP socket addresses, and incoming HTTP request headers.
- Route & Request Telemetry: The HTTP request method (e.g., GET, POST), requested URL path, response status codes, payload sizes, and connection duration.
- Rate-Limiting State: Temporary rate-limiting counters associated with your IP address or session to prevent denial-of-service attacks and brute-force traffic.
- System Logs & Observability: Server diagnostic logs to ensure reliability, security, and performance. Sensitive information (including authorization tokens, session cookies, passwords, and API keys) is strictly redacted prior to log storage.
- Aggregated Performance Metrics: Aggregated runtime performance metrics (request throughput, latency, error rates) monitored across applications without personal identity associations.
- Mobile Device Telemetry (Badr Play): Operating system version, device architecture, application version, and runtime platform flags.
- Device Storage & Permissions (Badr Play): Where explicitly granted by you, local storage and photo/media library write permissions strictly utilized to save offline video downloads directly to your device gallery.
5.3 Information Received from Third Parties
- Authentication Providers: If you register or authenticate using third-party social providers or Single Sign-On (SSO) integrations (e.g., Google or GitHub), we receive your verified email address, identity provider subject ID, and publicly available profile name or avatar.
- Payment & Merchant-of-Record Processors: When purchasing subscriptions, credits, or digital products:
- Polar.sh: For web transactions, Polar operates as the Merchant of Record. Polar collects and processes billing names, payment card information, postal addresses, and local tax identifiers. Polar provides us with transactional confirmation, customer identifiers, subscription status, and billing tier. We do not store your raw credit card numbers or bank account details on Dhem servers.
- RevenueCat & Mobile App Stores: For purchases initiated within mobile applications, Apple App Store and Google Play Store process transactions. RevenueCat validates receipts and synchronizes entitlement status with our backend.
- External Video & Streaming Hosts (Badr): Metadata regarding indexed publicly available channels and media (channel titles, subscriber counts, video views, thumbnails, and public streaming endpoints) retrieved via automated indexing pipelines from platforms such as YouTube, Instagram, TikTok, Dailymotion, Facebook, and the Internet Archive.
- Academic Citation Registries (Thesis Maker): Public bibliographic metadata retrieved from the National Center for Biotechnology Information (NCBI / PubMed) via official E-utilities APIs, CrossRef, and Semantic Scholar to verify citation existence, DOIs, authors, and publication dates.
6. How We Use Your Information
When you interact with Dhem and the products or services operating under it, we process personal data strictly for lawful, legitimate, and contractually defined purposes:
- Authentication & Unified Access: To verify your identity, maintain authenticated sessions across Dhem and products under it, evaluate authorized permissions, and manage account security.
- Core Service Delivery:
- Operating streaming and media indexing pipelines within Badr.
- Performing automated biostatistical analysis, literature synthesis, citation resolution, and document compilation within Thesis Maker.
- Routing and rendering user-requested content and media streams.
- Billing & Entitlement Management: To verify active subscription tiers, apply account quotas or page generation limits, and reconcile payments processed through Polar.sh or RevenueCat.
- Security, Rate Limiting & Abuse Prevention: To monitor server stability, enforce rate limits, detect malicious scraping, mitigate distributed denial-of-service (DDoS) attempts, and prevent fraudulent usage.
- System Observability & Debugging: To diagnose server-side faults, monitor system health, inspect error traces, and maintain platform stability.
- Communication & Customer Support: To reply to messages submitted through our portfolio contact form (delivered via Resend) and provide critical security or account notices.
- Legal Compliance & Enforcement: To enforce our Terms of Service, maintain audit logs, satisfy statutory tax and reporting requirements, and cooperate with lawful orders issued by competent judicial authorities.
7. Artificial Intelligence, Machine Learning & External Model Processors
Several applications and products operating under Dhem leverage advanced Artificial Intelligence (AI) and Large Language Models (LLMs) to provide automated synthesis, classification, and drafting services. We maintain strict standards regarding how user content interacts with external AI providers:
7.1 How AI Processing Works
- Badr Content Classification: Public media metadata (titles, descriptions, channel names) is evaluated through automated AI classifiers to categorize content into Islamic education, history, documentaries, Quranic recitations, and family programming. This process utilizes lightweight models via reputable model providers.
- Thesis Maker Drafting & Research:
- Topic descriptions, proposed chapter structures, and literature queries are processed through commercial LLMs (accessed via enterprise API gateways such as OpenRouter).
- Scientific figures are generated using automated rendering engines and, where requested, AI illustration models.
- Clinical Dataset Protection: Uploaded patient/clinical datasets are never provided in their raw tabular form to third-party LLMs. Raw data processing and biostatistical computations occur within isolated, secure execution sandboxes. Only aggregated statistical digests (summary figures, computed metrics, and verified findings) are supplied to LLMs to draft narrative chapters.
7.2 Training Data Policy
- No Training on Your Private Data: Dhem does not use your uploaded research datasets, private academic manuscripts, draft text, or personal account details to train foundational machine learning models.
- Provider Settings: We access commercial AI models through enterprise API endpoints. Under standard API terms of our integrated providers, data submitted via API calls is not utilized to train public foundation models.
- No Commercial Content Resale: We never license, sell, or provide your prompts, uploaded files, or generated outputs to data brokers or AI model aggregators.
7.3 Nature of AI Output (Important Notice)
AI models generate text and illustrations based on statistical patterns. Output can occasionally be incomplete, inaccurate, outdated, or hallucinated. While Thesis Maker incorporates multi-source citation verification against PubMed and CrossRef, you remain strictly responsible for reviewing, verifying, and editing all AI-generated text, calculations, and citations before submitting documents to academic institutions, supervisors, or review boards.
8. Analytics & Tracking Technologies
Dhem is committed to minimizing surveillance on the web. We do not use intrusive commercial tracking platforms such as Google Analytics, Meta Pixel, or commercial ad-retargeting beacons.
- Self-Hosted Analytics: We operate our own private, cookieless analytics service hosted at
analytics.dhem.io. - Cookieless Operation: Our analytics configuration does not write tracking cookies to your browser, does not access HTML5 persistent storage for tracking purposes, and does not monitor your browsing behavior across external websites.
- Anonymized Metrics: The analytics service records non-identifiable usage statistics: page URLs visited, referring websites, approximate geolocation (country/region level derived on-the-fly without storing raw IP addresses), browser type, and device screen category.
- Rotating Daily Identifiers: To measure unique visits without tracking individuals, a temporary anonymized daily identifier is generated based on incoming request metadata. This identifier automatically resets every 24 hours, making it impossible to reconstruct user profiles over extended time horizons.
9. Cookies, Local Storage & Client Tokens
Dhem limits client-side storage technologies strictly to those essential for operational functionality, session integrity, and security:
9.1 Essential Authentication Cookies & Tokens
- Central Single Sign-On: Our authentication portal (
accounts.dhem.io) utilizes encrypted, HTTP-only, secure session cookies strictly to maintain user sign-in state, support secure authentication flows, and prevent Cross-Site Request Forgery (CSRF). - Application Tokens: After authenticating, web and mobile clients store cryptographically signed access tokens in secure client-side storage. These tokens are transmitted to our central API to authenticate subsequent requests.
9.2 Local Storage for Interface Preferences
- Our web applications use browser local storage solely to persist non-sensitive user interface preferences, such as Dark/Light theme selection and localized interface states.
9.3 Managing Cookies
Because our cookies are strictly necessary for core functionality (authentication and security), blocking them via browser settings will prevent you from signing in to your Dhem account or accessing protected features across Dhem and the products operating under it.
10. Information Sharing, Third-Party Processors & Disclosures
We share personal data only with trusted infrastructure providers, processors essential for operating the platform, or under mandatory legal requirements. We do not sell personal data.
10.1 Service Providers & Technical Processors
Each provider processes data strictly under our instructions and is bound by data protection obligations:
- Cloud Storage Infrastructure
- Purpose: Secure cloud storage for user files, generated documents, and assets.
- Data Processed: Uploaded datasets, output documents, generated figures, user avatars.
- Notes: Encrypted cloud storage; accessible strictly via temporary, time-limited presigned URLs.
- Polar.sh
- Purpose: Web billing engine and Merchant of Record.
- Data Processed: Billing contact info, transaction history, subscription identifiers.
- Notes: Compliant Merchant of Record handling billing and taxation globally.
- RevenueCat & App Stores
- Purpose: Mobile in-app purchase tracking and receipt validation.
- Data Processed: App store receipt tokens, anonymous mobile user IDs, subscription entitlements.
- Notes: Utilized for mobile purchases across iOS and Android.
- AI Model Providers (e.g., OpenRouter and integrated model endpoints)
- Purpose: Natural language generation, content classification, and AI assistance.
- Data Processed: Prompt text, literature queries, aggregated statistical findings.
- Notes: API processing; raw clinical datasets are excluded from model calls.
- PubMed / NCBI & CrossRef
- Purpose: Academic literature search and citation verification.
- Data Processed: Literature search queries (scientific keywords, PMIDs, DOIs).
- Notes: Public academic APIs; no personal or patient data transmitted.
- Resend
- Purpose: Transactional email delivery and contact form routing.
- Data Processed: Sender name, sender email, message text.
- Notes: Used for portfolio inquiries and platform communications.
10.2 Legal Demands & Protection of Rights
We may disclose personal data if required to do so by applicable law, regulation, subpoena, search warrant, or court order issued by a court of competent jurisdiction. We may also disclose data when we reasonably believe disclosure is necessary to:
- Investigate, prevent, or address suspected fraud, security breaches, or technical anomalies.
- Enforce our Terms of Service or investigate potential violations.
- Protect the rights, safety, and property of Dhem, the products and services operating under it, its users, or the general public.
10.3 Business Transfers
If Dhem undergoes a merger, acquisition, restructuring, reorganization, or sale of platform assets, user accounts and associated operational data may be transferred as part of the transaction. You will be notified via our website or email of any change in ownership or control of your personal information.
11. Cross-Border & International Data Transfers
Dhem is operated by Murtaza Baanihali from Jammu & Kashmir, India, but our server infrastructure and third-party service providers are distributed globally across regions including:
- The United States and the European Union (e.g., cloud hosting, secure object storage, and AI processing infrastructure).
- Other international cloud availability zones.
When you access our services from outside India or outside the region where our servers are located, your information is transferred across international borders. By interacting with Dhem and the products or services operating under it, you acknowledge and consent to the transfer, storage, and processing of your information in jurisdictions that may maintain data protection laws different from those of your home country.
Where applicable under European data protection laws (GDPR) or UK data protection regulations, cross-border transfers to processors outside the European Economic Area (EEA) are conducted pursuant to Standard Contractual Clauses (SCCs) approved by the European Commission, statutory adequacy regulations, or equivalent contractual safeguards.
12. Data Retention, Storage Limits & Account Deletion
We adhere to data minimization principles and retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, support active accounts, resolve disputes, and satisfy legal obligations.
12.1 Specific Technical Retention Behaviors
- User Profile Data: Maintained for the lifetime of your active account across Dhem and the products operating under it. If an account is deactivated, it is marked as inactive in our records.
- Thesis Maker Datasets & Generated Documents: Uploaded research datasets, generated manuscripts, and exported files remain stored in secure cloud storage associated with your account until you delete the project or request account deletion. Temporary upload files created during processing are removed immediately following ingestion.
- Presigned Download URLs: Presigned download URLs generated for accessing private datasets or generated manuscripts expire automatically after 30 minutes (1,800 seconds).
- Media Streaming Cache: Video extraction and streaming URLs in Badr are cached temporarily to reduce redundant third-party network calls and expire automatically within 1 to 48 hours depending on source platform requirements.
- Rate-Limiting & Security Telemetry: Temporary rate-limiting keys and usage counters expire automatically after their evaluation window (typically between 1 minute and 48 hours).
- Server Logs: Application and diagnostic logs are retained for operational troubleshooting and security auditing for a rolling retention period (typically 30 to 90 days), after which they are permanently purged.
12.2 How to Request Account & Data Deletion
We do not currently offer an automated self-serve deletion button within every client dashboard. To request permanent deletion of your Dhem account, associated records across Dhem and products under it, and uploaded files:
- Send an email from your registered Dhem account address to
support@dhem.io. - Include the subject line: "Data Deletion Request - Dhem Account".
- State your registered email address and user ID.
Upon receiving and verifying your request, we will permanently delete your account and associated records, purge your uploaded datasets and generated files from our storage, and invalidate active authentication sessions within 30 days, subject only to records required to be retained by statutory legal or financial reporting obligations.
13. Security Architecture & Operational Safeguards
We implement defense-in-depth technical, architectural, and operational safeguards designed to protect personal information against unauthorized access, loss, misuse, or alteration across Dhem and all products and services operating under it:
- Transport Layer Security (TLS/HTTPS): All network traffic between client applications and our servers, as well as internal service communications, is encrypted in transit using modern Transport Layer Security (TLS/HTTPS) protocols.
- HTTP Security Headers: We enforce strict HTTP security headers across our APIs to mitigate clickjacking, prevent cross-site scripting (XSS), prevent MIME-type sniffing, and restrict unauthorized resource embedding.
- Cryptographic Authentication: Identity and access tokens are verified cryptographically using industry-standard signature algorithms to ensure only authenticated requests are processed.
- Rate Limiting & Traffic Regulation: Rate-limiting mechanisms regulate traffic across authentication endpoints, document creation routes, and general API queries to prevent abuse, brute-force attacks, and resource exhaustion.
- Execution Sandboxing: Automated document compiling and data manipulation operations execute within isolated, restricted sandboxes, separating execution from underlying host systems.
- Data Redaction in Logging: System logging pipelines automatically redact sensitive credentials and headers—including authorization tokens, session cookies, passwords, and API keys—before logs are stored.
- Ephemeral Private Access: Private user files and generated documents are stored in private cloud storage and accessed solely via cryptographically signed, time-limited presigned URLs. Files are not exposed via open public buckets.
Disclaimer: While we implement rigorous industry-standard safeguards, no electronic transmission over the Internet or digital storage architecture can be guaranteed to be 100% secure. You are responsible for safeguarding your login credentials and ensuring secure access to your devices.
14. Your Legal Rights & Choices
Depending on your country or state of residence, you maintain specific statutory rights regarding your personal data. Dhem honors these rights globally across all products and services operating under it.
14.1 Rights Under India's Digital Personal Data Protection Act, 2023 (DPDP Act)
For users located in India who interact with Dhem and the products or services operating under it, Dhem processes personal data in accordance with the DPDP Act, 2023. You have the right to:
- Right to Access Information: Request a plain-language summary of the personal data we hold about you and the processing activities undertaken.
- Right to Correction and Erasure: Request the correction of inaccurate or misleading data, the completion of incomplete data, or the erasure of personal data that is no longer necessary for the purpose for which it was collected.
- Right to Grievance Redressal: Access an expeditious grievance redressal mechanism regarding our data processing practices (see Section 17).
- Right to Nominate: Nominate any other individual to exercise your data protection rights in the event of death or incapacity.
14.2 Rights Under GDPR / UK GDPR (European Economic Area & UK Users)
If you reside within the European Economic Area (EEA) or the United Kingdom, our lawful bases for processing your data under Article 6 of the General Data Protection Regulation include:
- Contractual Necessity (Art. 6(1)(b)): Processing necessary to provide services you requested (e.g., maintaining your central account, generating requested thesis documents, streaming media).
- Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate interests, provided they do not override your fundamental rights (e.g., maintaining server security, rate limiting, self-hosted analytics, bug diagnosis).
- Legal Obligation (Art. 6(1)(c)): Processing required to comply with statutory accounting, tax, or legal requirements.
- Consent (Art. 6(1)(a)): Where you have granted explicit consent for specific processing activities.
Your GDPR Rights:
- Access (Art. 15): The right to obtain a copy of your personal data.
- Rectification (Art. 16): The right to correct inaccurate personal data.
- Erasure / "Right to Be Forgotten" (Art. 17): The right to obtain the erasure of your personal data.
- Restriction of Processing (Art. 18): The right to restrict how we process your data.
- Data Portability (Art. 20): The right to receive your personal data in a structured, machine-readable format.
- Objection (Art. 21): The right to object to processing based on legitimate interests.
- Lodge a Complaint: The right to lodge a complaint with your local Data Protection Supervisory Authority.
14.3 Rights Under United States State Laws (California CCPA/CPRA)
If you reside in California, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) grants you specific rights:
- Right to Know & Access: Request details regarding the categories and specific pieces of personal information collected, the sources of collection, the commercial purposes for collection, and categories of third parties with whom data is shared.
- Right to Delete: Request deletion of personal information collected from you.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do not sell your personal information or share it for cross-context behavioral advertising.
- Non-Discrimination: We will never deny services, charge different prices, or provide a different quality of service because you exercised your statutory privacy rights.
To exercise any of these rights, contact us at support@dhem.io.
15. Children's Privacy
Dhem and the products or services operating under it are not directed to children under the age of 13 (or under 16/18 where specified by local law). We do not knowingly solicit, collect, or process personal data from children without verifiable parental consent.
- Badr "Kids" Category: Badr features a curated "Kids" category containing family-friendly Islamic cartoons, educational media, and moral stories. This category provides age-appropriate content for viewing; however, account registration, subscription purchases, and platform interaction must be performed by a parent or legal guardian.
- Parental Inquiries: If you are a parent or guardian and believe that your child under the age of 13 has provided personal data to Dhem or any products and services operating under it without your consent, please contact us immediately at
support@dhem.io. We will promptly investigate and purge the relevant information from our records.
16. Third-Party External Links & Scraped Content
Applications and products operating under Dhem may contain links to external third-party websites, APIs, or services that are not owned or controlled by Dhem.
- In Badr, video streams and media embeds originate from external platforms (such as YouTube, Instagram, TikTok, and Dailymotion). When you play third-party media or follow external links, third-party hosts may process your IP address or client metadata according to their independent privacy practices.
- We have no control over, and assume no responsibility for, the content, privacy policies, or data handling practices of any third-party website or external streaming service. We encourage you to review the privacy policies of any third-party platform you visit.
17. Grievance Redressal Officer & Inquiries (India DPDP & IT Rules)
In compliance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023, the details of the designated Grievance Officer for Dhem are:
- Officer Name: Murtaza Baanihali
- Role: Founder & Grievance Redressal Officer
- Entity: Dhem Org
- Location: Jammu & Kashmir, India
- Contact Email:
support@dhem.io - Response Timeline: We acknowledge grievances within 48 hours and endeavor to resolve complaints within 30 days of receipt.
18. Changes & Version Changelog
We may update this Privacy Policy from time to time to reflect changes in our infrastructure, product offerings, legal mandates, or data processing practices.
- Notification of Changes: When updates are made, we will revise the "Last Updated" date at the top of this document. For material changes that significantly affect your rights or the manner in which personal data is processed, we will provide prominent notice through our platform, via email to registered account holders, or on the Dhem portal prior to the effective date of the changes.
- Changelog:
- Version 1.0.0 (April 5, 2026): Initial unified Privacy Policy establishing umbrella coverage for Dhem Org, centralized authentication, billing, Badr, Thesis Maker, and privacy-focused analytics.
19. App-Specific Appendices
The following appendices detail specific data processing operations for individual applications operating on the Dhem platform.
Appendix A: Dhem Portfolio & Platform Core (dhem.io)
- What It Collects:
- Contact inquiries: Name, email address, message subject, and inquiry text submitted through the contact form.
- Analytics telemetry: Anonymized page view events, device categories, and referring sites.
- Why: To respond to business, development, and portfolio communications, and to understand aggregate visitor traffic.
- Which Providers Receive Data:
- Resend: Transactional email delivery engine that receives and routes contact form submissions.
- Self-Hosted Analytics: Cookieless, privacy-preserving analytics hosted on Dhem infrastructure (
analytics.dhem.io) for aggregate traffic metrics.
- Retention: Contact emails are retained in operational email boxes for communication history; analytics aggregations are retained indefinitely in non-identifiable aggregate form.
- Special Notes: No account sign-in is required to view the portfolio.
Appendix B: Badr & Badr Play
- What It Collects:
- Account data: User ID, email address, and viewing session tokens.
- Catalog & Interaction Data: Public channel handles, video titles, categories (e.g., Quran, Dawah, Movies, Kids, History), and aggregated video statistics (views, likes, shares, downloads).
- Mobile Device Permissions (Badr Play): Read/write access to device storage/photo gallery strictly when you initiate an offline video download.
- Why: To deliver curated Islamic video streaming, provide search and query autocompletion, maintain viewing counters, and save downloaded media directly to your mobile device storage.
- Which Providers Receive Data:
- External Media Hosts: Video streaming requests communicate directly with source hosting platforms (YouTube, Instagram, TikTok, Facebook, Dailymotion, Internet Archive).
- AI Model Providers: Evaluates public channel titles and descriptions to ensure classification matches Islamic family-friendly standards.
- Retention: Cached video stream extraction URLs expire within 1 to 48 hours depending on host platform constraints.
- Special Notes: Client-side YouTube playback streams connect directly between your device and YouTube servers, subject to YouTube's Terms of Service and Google's Privacy Policy.
Appendix C: Thesis Maker
- What It Collects:
- Academic metadata: Student name, degree program (MD, MS, DNB, DM, MCh, DrNB, Diploma), university name, department, academic year range, supervisor and co-supervisor names.
- Ethical clearance: Institutional Ethics Committee (IEC) clearance preference and reference number.
- Uploaded clinical datasets: Tabular files (
.csvor.xlsx, up to 25 MB) containing de-identified clinical variables (e.g., age ranges, laboratory values, clinical scores, surgical times, outcome flags). - Draft manuscripts: Legacy thesis PDF files submitted for document refinement.
- Generated documents: Rendered PDF manuscripts, Microsoft Word (
.docx) files, and generated scientific figures.
- Why: To conduct biostatistical computations, generate publication-grade tables, verify citations against biomedical literature registries, and draft structured academic theses and synopses.
- Which Providers Receive Data:
- Secure Cloud Storage: Encrypted cloud object storage for uploaded spreadsheets, output PDFs, DOCX files, and figures.
- AI Model Providers: Receives scientific planning outlines, section prompts, and aggregated statistical digests (never raw patient-level tables).
- NCBI / PubMed & CrossRef: Receives scientific literature search strings and DOIs to verify and fetch valid citations.
- Isolated Sandboxes: Statistical computation engines and document compilers execute inside isolated execution sandboxes.
- Retention: Uploaded datasets and output documents are retained in private cloud storage until deleted by the user or upon account erasure. Presigned download links expire after 30 minutes.
- Special Notes: Strict De-Identification Mandate: Users are contractually and legally required to de-identify all patient datasets prior to uploading. Direct personal identifiers (patient names, phone numbers, addresses, national identity numbers, hospital registration numbers) must be purged completely.
Appendix D: Dhem Lens (Planned / Incubating)
- What It Collects: User-uploaded source photographs or images submitted for AI enhancement, resolution upscaling, or color restoration.
- Why: To execute image processing, super-resolution, and restoration pipelines requested by the user.
- Which Providers Receive Data: Secure cloud storage for temporary image staging; specialized image restoration models.
- Retention: Source images and enhanced outputs are retained temporarily for user download and purged according to defined cache schedules.
- Special Notes: This product is in development. Detailed parameters will be updated upon public release.
Appendix E: Standard Disclosure Template for Future Dhem Apps
(This template governs any newly launched product operating under the Dhem central API and billing infrastructure prior to formal enumeration above)
- What It Collects: Essential account identity (User ID, email), application-specific user inputs, technical telemetry (IP, route metadata), and payment transaction state (where monetized).
- Why: Strictly to deliver the designated application feature set, authenticate requests, enforce quotas, and ensure platform security.
- Which Providers Receive Data: Dhem core cloud infrastructure, centralized authentication (
accounts.dhem.io), and designated AI or processing APIs disclosed in the application interface. - Retention: Retained during active account usage; eligible for immediate deletion upon verified user request to
support@dhem.io. - Special Notes: Subject to all core protections, zero data resale warranties, and jurisdiction rights established for Dhem and all products and services operating under it.
End of Dhem Privacy Policy.
Review the contract rules, acceptable use, academic data warranties, and arbitration terms.