Compliance
How this site maps to data protection law
Most "we are compliant" pages are a list of law names with a green tick next to each one. This page is the opposite: it names the specific law, what it actually requires, and the specific thing Scult does that answers that requirement — for India's DPDP Act, the older IT Rules it is replacing, the EU's GDPR, and California's CCPA. Where a law simply does not apply to a free tools site of this size, it says that plainly instead of claiming coverage anyway.
The short version: there is very little data to protect
Every privacy and data-protection law in every section below is a set of rules about what an organisation may do with personal data it collects. The single biggest thing this site does about all of them at once is architectural, not legal: 13 of 15 tools process your files, text and numbers entirely inside your own browser tab. That data is never transmitted to us, so there is nothing for a data-protection law to regulate on our end — we simply never receive it. The full, tool-by-tool breakdown of what does and does not touch a network is on the privacy page. There are no accounts, no passwords and no payment details collected anywhere on the site, which removes an entire category of obligation (breach notification for stored credentials, for example) that most of these laws spend significant text on.
What is left, after that: anonymous analytics (Google Analytics 4) and masked session replay (Microsoft Clarity), both of which load only after you interact with the page and are described in full — including Clarity's strict masking mode, which replaces on-page text and anything you type with placeholder blocks before it is ever sent — on the privacy page. Every section below is about that remaining, genuinely small surface.
India — the Digital Personal Data Protection Act, 2023
Scult is based in Noida, Delhi NCR, so India's data protection law is the one that actually governs this site, not a foreign law borrowed for appearances.
The Digital Personal Data Protection Act, 2023 ("DPDP Act") and its implementing Digital Personal Data Protection Rules, 2025 were notified by India's Ministry of Electronics and Information Technology on 13–14 November 2025 (see the official PIB notification). It is being brought into force in phases rather than all at once: the procedural provisions took effect immediately in November 2025, and the substantive obligations on data fiduciaries — consent, notice, and the data principal rights described below — are scheduled to be fully in force by 13 May 2027. We are stating that timeline plainly rather than implying the Act is already fully in force, because it is not — but the practices below are ones we already follow, ahead of that deadline rather than because of it.
What the Act requires, and what we do about it
- Clear notice of what is collected and why. The privacy page lists exactly what is collected — analytics, masked session replay, one localStorage flag — and why, in plain language rather than legal boilerplate.
- Data minimisation. We do not ask for data we do not need to operate a tool. No tool on this site requires an account, an email address, or any personal identifier to produce a result.
- A published grievance contact. The Act requires every data fiduciary to publish contact details for a grievance officer and resolve a complaint within a reasonable window. Ours is connect@scult.in, the same address used for security and accessibility reports on this site — see "Contact for a data protection concern" below for our specific commitment on response time.
- No sale of personal data. We do not sell, rent or trade any data collected through this site to any third party, under any circumstance.
- Reasonable security safeguards. Detailed on the security page — SSRF protection on the two tools that call a server, rate limiting on every API route, and the response headers set on every page.
India — the older IT Rules, still partly in force
Before the DPDP Act, India's main data-protection framework was Section 43A of the Information Technology Act, 2000 and the Reasonable Security Practices and Sensitive Personal Data or Information Rules, 2011 ("SPDI Rules") made under it. Those SPDI Rules remain technically in force today and are due to be repealed and folded into the DPDP Act on the same 13 May 2027 date above — so, for now, both frameworks apply in parallel. The SPDI Rules' definition of "sensitive personal data" — passwords, financial information, health records, biometrics — is a useful checklist in its own right: this site collects none of it. There are no passwords because there are no accounts, no financial information is collected (the invoice generator computes entirely in your browser and nothing you type in it is ever sent to us), and no health or biometric data is requested by any tool.
The EU & UK — GDPR
The GDPR's territorial-scope rule (Article 3) applies to an organisation outside the EU only if it specifically targets EU users — offering goods or services to them, or monitoring their behaviour — not merely because a website happens to be reachable from Europe. We do not price in euros, do not run EU-specific marketing, and do not operate any feature aimed at EU visitors in particular, so we are not asserting GDPR controller status here.
That said, an EU visitor can and does use this site, and the practices that matter to GDPR are the same ones described above regardless of who is asking: data minimisation by default, masked session replay, no sale of personal data, and a clear, working contact point for a data concern. If you are visiting from the EU or UK and have a specific concern, the same connect@scult.in address reaches us.
California — CCPA / CPRA
The California Consumer Privacy Act, as amended by the CPRA, applies to a for-profit business only above specific thresholds: roughly $26.6 million in annual gross revenue, or deriving over half of annual revenue from selling personal information, or processing 100,000 or more California residents' records a year — see the California Attorney General's CCPA page for the current figures. Stated plainly: a free tools site of this size and reach is very unlikely to meet any of those thresholds, and we are not claiming to be a "business" as CCPA specifically defines the term.
Threshold aside, the one commitment CCPA visitors most often look for is easy to make honestly, because it is already true: we do not sell or share personal information with any third party, so there is nothing to opt out of.
Accessibility — WCAG 2.2 AA
Digital accessibility is a legal requirement in a growing number of jurisdictions — the EU's European Accessibility Act and the ADA in the United States both point to the same underlying standard, the Web Content Accessibility Guidelines. We build every page and every tool against WCAG 2.2 Level AA, and unlike most of this page, that one is not a legal test with an exemption threshold — it is a specific, checkable engineering target, detailed in full on the accessibility page, including the one thing we are explicit about not having done: a third-party audit.
Security practices behind all of the above
Every framework above eventually asks the same underlying question — are "reasonable security safeguards" in place. The specific, checkable answer is on the security page: SSRF protection on the two tools that call a server, rate limiting on every API route, and the four response headers set site-wide in next.config.ts. It also states clearly what we do not have — no SOC 2 or ISO 27001 certification, no penetration testing, no bug bounty — for the same reason this page does: an unverified certification claim is worse than an honest gap.
Contact for a data protection concern
Email connect@scult.in with what data you are asking about and what you would like done — accessed, corrected, or deleted from wherever it might be held (in practice: an analytics record, since there is rarely anything else to find). We aim to acknowledge and resolve a genuine data protection request within 7 days of receiving it.
What this page is not
This is a plain-language mapping of real practice to real law, written and maintained by the team that builds this site — not a legal opinion, not a certification issued by any regulator or auditor, and not a substitute for a qualified lawyer's advice if you are relying on this page to make your own compliance decision. Laws named here — especially the DPDP Act's phased timeline — will keep changing between now and 2027; this page will be updated as they do, and the date at the top of its source reflects when it was last reviewed. If anything above reads as broader than what is actually true of the site, tell us at connect@scult.in and we will correct it.
See also: Privacy, Security, Accessibility and Terms.

