This Privacy Policy explains how Nuroversity Technologies Private Limited collects, uses, stores, and discloses your personal data when you use the Nuroversity platform. It is prepared in accordance with the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Identity data: full name, email address, mobile number, date of birth, gender, and country;
Authentication data: hashed passwords, OAuth tokens (if you sign in via Google/GitHub);
Profile and learning preferences: subjects, target exams, study goals, experience level;
Payment and billing data: subscription tier, billing cycle, payment transaction IDs (card details are not stored — processed by Razorpay);
Consent records: version, timestamp, IP address, and method for each consent given.
AI session data: prompts submitted and AI responses received during Smart Study, Smart Exam, and Smart Interview sessions;
Assessment records: quiz answers, scores, certification attempts and outcomes, XP, streaks, and leaderboard positions;
Usage logs: feature interactions, session durations, error logs, and diagnostic data;
Token usage logs: AI API token consumption and credit usage, used for billing and platform cost management.
Device and browser information: IP address, browser type and version, operating system;
Session cookies for authentication and preference storage;
Analytics data: aggregate, anonymised usage patterns (no PII shared with analytics providers).
We collect and process personal data for the following purposes:
Account creation, authentication, and management of your profile;
Delivering AI-generated study content, assessments, certifications, and interview simulations personalised to you;
Processing subscription payments and issuing receipts through Razorpay;
Calculating and enforcing subscription credit limits and plan entitlements;
Tracking your learning progress, XP, streaks, and certifications for in-platform gamification;
Sending transactional communications: subscription confirmations, renewal reminders, and security alerts;
Sending marketing communications if you have explicitly opted in (you may opt out at any time);
Improving and monitoring platform performance, detecting abuse, and ensuring security;
Complying with applicable Indian laws, including tax obligations under GST and the Income Tax Act.
Under the DPDP Act, 2023, we process your personal data on the following bases:
Consent — for account registration, marketing communications, and optional features;
Contractual necessity — to deliver the Services you subscribe to;
Legitimate purpose — for platform security, fraud prevention, and aggregate analytics;
Legal obligation — to comply with Indian tax, financial reporting, and regulatory laws.
We do not sell your personal data. We share personal data only with the following processors and only to the extent necessary to provide the Services:
| Processor | Purpose | Data Shared |
|---|---|---|
| Anthropic (Claude API) | AI content generation | Your prompts and session context; no name or email sent |
| Razorpay | Payment processing | Name, email, amount; card details handled entirely by Razorpay |
| Supabase / Cloud provider | Database and storage hosting | All account and session data, stored on Indian-region servers where available |
| Email service provider | Transactional and marketing emails | Name, email address |
We may also disclose your data if required by Indian law, court order, or a competent government authority, or to protect the rights and safety of users and the public.
| Data Category | Retention Period |
|---|---|
| Account data (identity, profile, auth) | Duration of active account + 2 years post-closure |
| Assessment and certification records | 3 years from date of assessment |
| AI interaction logs | 1 year from session date (anonymised after 90 days from closure) |
| Subscription and billing records | 8 years from billing period end (Indian tax law) |
| Payment transaction records | 8 years (Indian tax law) |
| Audit and event logs | 2 years |
| Consent records | Duration of account + 5 years post-closure |
| Marketing consent records | Until withdrawn + 3 years |
Under the DPDP Act, 2023, you have the following rights regarding your personal data:
Right to Access — Request a summary of personal data we hold about you (email privacy@Nuroversity.com, response within 30 days);
Right to Correction — Request correction of inaccurate or incomplete data;
Right to Erasure — Request deletion of your personal data (subject to retention obligations);
Right to Data Portability — Request a machine-readable export of your data;
Right to Withdraw Consent — Withdraw marketing or optional feature consent at any time via Account Settings;
Right to Grievance Redressal — Lodge a complaint with our Grievance Officer at grievance@Nuroversity.com;
Right to Approach DPBI — Lodge a complaint with the Data Protection Board of India if your grievance is unresolved.
We will not discriminate against you for exercising any of these rights.
All data transmitted between your device and our servers is encrypted using TLS 1.3;
Sensitive data is encrypted at rest using AES-256;
Passwords are stored as bcrypt hashes (cost factor ≥ 12) — plaintext passwords are never stored;
Role-Based Access Control restricts internal access to personal data on a strict need-to-know basis;
All API endpoints require authenticated tokens with rate limiting and input validation;
In the event of a reportable breach, we will notify the DPBI within 72 hours and affected users without undue delay.
We use cookies for:
Session and authentication state (essential — cannot be disabled without losing login);
Remembering your in-app preferences such as dark/light mode (functional);
Aggregate, anonymised usage analytics (no PII shared with third parties);
Recording your consent choices (compliance).
We do not use cookies or tracking pixels for targeted advertising, behavioural profiling, or selling data to advertisers.
For privacy-related requests or complaints, contact our Data Protection contact:
Privacy enquiries: privacy@Nuroversity.com
Grievances: grievance@Nuroversity.com (acknowledged within 24 hours, resolved within 30 days)
All legal matters: legal@Nuroversity.com
If your grievance is unresolved, you may file a complaint with the Data Protection Board of India (DPBI) once its formal complaint mechanism is operational.
We may update this Privacy Policy when there are changes to our data practices or applicable law. Material changes will be communicated via email and in-app notification at least 15 days before taking effect, and will require your re-confirmation via an in-app consent gate.