Privacy Policy
Effective 17 September 2026 · version 2026-09-17
This policy explains, in plain language, what personal data ("Abhiyas AI") collects when you use the service, why we collect it, and the choices you have. It is written to meet the Digital Personal Data Protection Act, 2023 (DPDP) and the Information Technology Act, 2000.
01What we collect
- Account details — name, email, mobile number (verified by OTP), password (stored only as a salted hash), and your consent record (date and version of these terms).
- Study profile — the exam and attempt you chose, target score, class, daily study time, and every answer, test attempt, mistake, revision and mission you complete. This is the data the product runs on.
- AI tutor conversations — the questions you ask and the answers given, together with the page/chapter you were on, so the tutor can stay in context.
- Payments — the plan or pack you bought, amount, currency, order and payment identifiers from Razorpay, and coupon used. We never receive your card, UPI or bank credentials; Razorpay processes them under its own policy.
- Parent link — if you or a parent link a parent account, the parent's email/mobile and the weekly digest we send them.
- Technical data — IP address, browser, device type and error reports needed to keep the service secure and working.
02Why we use it (lawful purpose)
- To provide the service you signed up for: build your plan, score your work, run the AI tutor, deliver purchases.
- To send service messages: OTPs, mission reminders and weekly digests you have switched on, payment receipts, and notices about these policies.
- To keep the platform secure: fraud and abuse detection, rate limiting, audit logs.
- To improve the product using aggregated, de-identified usage — never to sell your data.
03Consent and children
We process your data on the basis of the consent you give at sign-up. You can withdraw it at any time by deleting your account (below); withdrawal does not affect processing already done lawfully.
If you are under 18, DPDP requires your parent or legal guardian to consent. At sign-up you confirm that your guardian has done so, and we record that attestation. We do not show behavioural advertising to any user, do not track children across other services, and do not sell data. A guardian may ask us to delete a child's account at any time by writing to .
06How long we keep it
- Account and study data — while your account is active, and up to 30 days after deletion for backups to cycle out.
- Payment records — 8 years, as required by Indian tax and accounting law, in anonymised form after account deletion.
- Security and audit logs — 12 months.
- OTP codes — deleted on use or expiry (10 minutes).
07Your rights
Under DPDP you can:
- Access a summary of your personal data and how it is used — your profile and progress pages show most of it; email us for a full export.
- Correct your name in your profile; contact us for other corrections.
- Erase your account from your profile — this anonymises your identifiers and deactivates the account immediately.
- Grievance redressal — write to our grievance officer; if unresolved you may approach the Data Protection Board of India.
- Nominate someone to exercise these rights on your behalf, by writing to us.
08Security
Data is encrypted in transit (TLS). Passwords are hashed, sessions use secure httpOnly cookies with cross-site request protection, access to admin tools is role-restricted and audit-logged, and payment webhooks are cryptographically verified. No system is perfectly secure; if we learn of a breach affecting you we will notify you and the Data Protection Board as the law requires.