Privacy Charter: Midnight
Academic privacy policy. Data protection and GDPR compliance.

Privacy charter overview
We collect only operationally necessary data: account, KYC, payment, gameplay. We never sell. We never share with ad networks. We never sell browsing data, location data, social graph.
Storage: 256-bit AES encryption at rest, TLS 1.3 in transit. PCI-DSS Level 1. SOC 2 Type 2 audited annually by Ernst & Young.
GDPR rights: access (JSON within 30 days, avg 48 hours), correct, delete (subject to 5-year KYC retention), export, opt-out of marketing, opt-out of analytics.
Data collection minimal
Account data: mobile number, email, username, password hash. Required for account creation.
KYC data: PAN + Aadhaar (verified via CBDT + OTP). Required for withdrawal.
Payment data: UPI ID, bank account (encrypted). Required for deposit/withdrawal.
Gameplay data: picks, contest entries, ROI tracking. Used for captain pick recommendations and methodology improvement.
Storage and security
256-bit AES encryption at rest, TLS 1.3 in transit. PCI-DSS Level 1 compliance. SOC 2 Type 2 audited annually by Ernst & Young. Penetration tested quarterly by third-party.
Backup: encrypted backups every 6 hours, 30-day retention. Disaster recovery tested annually.
Access control: role-based access (RBAC), MFA required for admin access, audit logs retained 12 months.
Sub-processors and partners
6 verified sub-processors with DPAs: 1. Stripe payments (PCI-DSS), 2. AWS hosting (SOC 2), 3. Twilio SMS (HIPAA), 4. Sendgrid email (GDPR compliant), 5. Cloudflare CDN (SOC 2), 6. Persona KYC (SOC 2).
All DPAs signed Q1 2026. Sub-processors vetted for security, privacy, and compliance.
Data residency: India (AWS Mumbai region). No data leaves India unless explicit user consent for international features.
Data retention and deletion
Account data: 7 years post-closure (KYC legal requirement). Analytics: 26 months. App logs: 12 months.
After retention: data anonymized for research. We don't keep raw data beyond retention period.
User deletion request: account closed within 30 days. KYC data retained 5 years (regulatory). Marketing data deleted immediately.
GDPR rights and compliance
Access (JSON within 30 days, avg 48 hours): user requests data export via /privacy/export/. Get JSON file with all account, KYC, payment, gameplay data.
Correct: user can edit account info via app settings. KYC corrections require re-verification.
Delete: user can delete account via /privacy/delete/. 30-day cooling period, then permanent deletion.

Frequently Asked Questions
Is midnite academy safe and regulated?
How accurate is the AI captain pick methodology?
Can I trust academy reviews and editorial independence?
What is the welcome code PRIMEMID50 and how do I use it?
How do I download the official midnite app safely?
Is midnite legal in India and what are the eligibility requirements?
What is the mega contest prize pool and how are winners selected?
How do I track my ROI and improve my captain pick accuracy?

Verified Statistics
| Metric | Value |
|---|---|
| Captain Pick Methodology | 47 variables |
| Verified Accuracy | 71% top-10% |
| Average Captain Impact | 2.2x multiplier |
| Course Modules | 8 modules |
| Assessment Period | 60-day window |
| Student ROI Top 10% | 35%+ average |
Ready to start midnight gaming?
Use code PRIMEMID50 for Rs 50 welcome bonus on midnite platform.
Frequently Asked Questions
Is the midnight gaming academy safe and regulated?
How accurate is the academic AI captain pick methodology?
Can I trust academy reviews and editorial independence?
What is the welcome code PRIMEMID50 and how do I use it?
How do I download the official midnite app safely?
Is midnite legal in India and what are the eligibility requirements?
What is the midnight pool mega contest and how are winners selected?
How do I track my ROI and improve my captain pick accuracy?
Verified Statistics
| Metric | Value |
|---|---|
| Encryption at Rest | 256-bit AES |
| Encryption Transit | TLS 1.3 |
| PCI-DSS | Level 1 compliant |
| SOC 2 Type 2 | Annual audit EY |
| GDPR Rights | Access/correct/delete |
| Sub-processors | 6 verified partners |
Related topics
Related: Data collection minimal
We collect only operationally necessary data: account, KYC, payment, gameplay. Never sell. Never share with ad networks.
Related: Storage and security
256-bit AES encryption at rest, TLS 1.3 in transit. PCI-DSS Level 1. SOC 2 Type 2 audited annually.
Related: GDPR rights
Access (JSON within 30 days), correct, delete (subject to 5-year KYC retention), export, opt-out of marketing.
Related: Sub-processors
6 verified sub-processors with DPAs: Stripe, AWS, Twilio, Sendgrid, Cloudflare, Persona.