Privacy Policy
Last updated:July 12, 2026
ShatteredBulbs (“we,” “us,” “our”) operates the website at shatteredbulbs.com and associated domains (the “Site”). This Policy explains what we collect, what we do with it, and what rights you have. For the purposes of applicable data-protection law, the operator of ShatteredBulbs is the data controller / data fiduciary.
We have written this to be read, not survived. If anything is unclear, email us and we will explain it.
Who we are
The Site is operated by the operator of ShatteredBulbs, based in India. Contact: hello@shatteredbulbs.com.
The short version
We are a movie and TV review site. You do not need an account to read it, and we do not want your data. We do not run advertising. We do not use analytics. We have no comments, no forms, and no mailing list.
This Site sets no cookies at all.
What we collect
Automatically — server logs. Our hosting provider records standard technical information when you visit: IP address, browser type, device and operating system, referring URL, pages viewed, and the time of access. This is ordinary web-server logging, used for security, abuse prevention, and diagnostics.
If you email us. Whatever you choose to send — typically your name, your email address, and your message.
That is the whole list. We do not use analytics. We do not serve advertising. We set no cookies. We run no accounts, comments, forms, or mailing list. We do not knowingly collect sensitive personal data. We do not sell, rent, or trade personal information, and we never will.
Cookies and similar technologies
This Site sets no cookies. Not one — not first-party, not third-party, not before you click anything, not after.
The complete list of what we store on your device is in our Cookie Policy. That page is the single source of truth, and it is updated before anything changes.
Nothing that is not strictly necessary is ever stored without your consent.
How we use information
To operate, secure, and maintain the Site; to diagnose faults; to answer messages you send us; and to meet legal obligations. Nothing else.
Legal bases
- EU / UK GDPR: our legitimate interests in operating and securing the Site (server logs), and consent for anything non-essential. We currently run nothing non-essential.
- India, DPDP Act 2023: your consent, or the legitimate uses the Act permits.
- Elsewhere: the equivalent lawful basis under your local law.
Who handles your data
Processors — companies that handle data strictly on our behalf, under contract:
- Vercel Inc. (United States) — website hosting and server logs.
- Sanity.io (Norway / United States infrastructure) — content management and image storage.
That is the complete list, and it is exhaustive. We use no independent third parties — no advertising networks, no analytics providers, no affiliate programmes. We do not sell or share your personal information with anyone, for any purpose.
This section is updated before anything changes.
International transfers
We are based in India. Our providers operate in the United States and Europe, so data does cross borders.
Where personal data is transferred out of the EEA or the UK, we rely on the safeguards in our providers’ data processing agreements — which incorporate the European Commission’s Standard Contractual Clauses, and, for the UK, the ICO’s International Data Transfer Addendum. Where other laws apply, we rely on the mechanism those laws require.
How long we keep things
Server logs. These are generated and held by our hosting provider as part of its platform, for security and diagnostics. We do not export them, copy them, or keep any separate copy of our own. They are deleted automatically under our provider’s platform retention settings, which are short-term.
Email correspondence. We keep your message for as long as it takes to deal with it, and for up to 12 months afterwards. Then we delete it.
We keep nothing longer than we need it, and we keep nothing we do not need.
Your rights — wherever you live
Regardless of where you live, and regardless of whether your local law requires it, you may ask us to:
- tell you what personal data we hold about you
- correct it
- delete it
- stop processing it
- give you a copy of it
- withdraw any consent you gave us
Email hello@shatteredbulbs.com. We will honour the request. No form, no account, no charge, and we will not treat you differently for asking.
This is deliberate. Rather than list which country grants which right — a list out of date within months — we extend all of them to everybody.
Frameworks that may also apply to you:
- EU / EEA / UK (GDPR) — all of the above, plus the right to complain to your supervisory authority.
- India (DPDP Act, 2023) — access, correction, erasure, grievance redressal, the right to nominate, and the right to complain to the Data Protection Board of India.
- United States (state privacy laws) — the rights to know, delete, and correct, and to opt out of the sale or sharing of personal information. We do not sell or share it.
- Everywhere else — see above. Just ask.
Global Privacy Control
We honour the Global Privacy Control (GPC) signal. If your browser sends one, we treat it as a valid opt-out of any sale or sharing of your personal information — though, as stated, we don’t do either.
Withdrawing consent
As easy as giving it. Today there is nothing to withdraw, since we set no cookies and run nothing non-essential. If that changes, you’ll be able to update your choice via the Cookie Settings link in the footer, or by emailing us — and withdrawal never affects anything done beforehand.
Complaints
Email us first — we’d rather fix it. If we don’t resolve it, complain to your local data-protection authority: in the EU or UK, your supervisory authority; in India, the Data Protection Board of India.
Grievance Officer (India — DPDP Act, 2023)
For DPDP grievances, the contact is the operator of ShatteredBulbs, at hello@shatteredbulbs.com. We aim to acknowledge and resolve grievances within the timeframes prescribed by law.
Language (India — DPDP Act, 2023)
This notice is published in English. On request we will provide it in any language listed in the Eighth Schedule to the Constitution of India. Email us.
Children
The Site is for a general audience and is not directed at children. Under the DPDP Act a “child” is anyone under 18; in the US the COPPA threshold is 13. We do not knowingly collect children’s data and we do not direct advertising at children. If you believe a child has given us personal data, tell us and we will delete it.
Automated decision-making
We make no decision about you by automated means.
Security and breach notification
We take reasonable technical and organisational measures to protect information. No method of transmission or storage is perfectly secure, and we cannot promise absolute security.
If a personal-data breach occurs:
- Under the GDPR — we will notify the relevant supervisory authority within 72 hours where required, and affected individuals without undue delay where the risk to them is high.
- Under India’s DPDP Act and the DPDP Rules — we will notify the Data Protection Board of India and every affected individual, in the form and within the timeframes the Rules prescribe, including the 72-hour deadline for detailed particulars.
- Elsewhere — as the applicable law requires.
Third-party links
We link out. We are not responsible for what those sites do with your data. Read their policies.
Changes
We will update this Policy when our practices change. Changes take effect when posted with a revised “Last updated” date — which always reflects when the text last changed.