Privacy Policy
Privacy Policy
Abhranti (“we”, “us”) is an educational self-assessment platform operated by Abhranti, 14057, sobha dream acres, Panathur Main road, Belagere, Varthur, Bangalore-560087, India. This policy explains what personal data we collect through the Abhranti app and website (abhranti.ai), why we collect it, and the rights you have over it. It is written to comply with India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules made under it, under which we act as a Data Fiduciary.
1. Who this policy covers
Abhranti serves three kinds of users:
- Students, who take assessments and receive learning reports. Most of our students are under 18 — see section 4, which governs everything else in this policy for them.
- Parents and guardians, who create and manage the family account, give consent for their children, view progress reports, and make payments.
- Teachers and schools, who may view class-level or student-level reports where the student’s parent or the school has authorised that access.
2. What we collect
Account and sign-in data. You sign in with Google or Apple. From the sign-in provider we receive your name, email address, and profile photo (if any). If you use Apple’s “Hide My Email”, we receive and use the relay address — a real email address is not required. We never see or store your Google or Apple password; authentication is handled by Amazon Cognito.
Profile data. Student name or nickname, class/grade, education board, and subjects, entered by the parent or student; the link between a parent account and its student profiles; teacher and classroom associations where applicable.
Learning and assessment data. Answers submitted in assessments, scores, time taken, topics mastered, and the areas of misunderstanding our system identifies — used solely to build the student’s own reports and study recommendations.
Payment data. If you buy a subscription, payment is processed by our RBI-authorised payment gateway Razor. Your card, UPI, or bank details go directly to the gateway and never touch our servers — in line with RBI card-tokenisation rules, we cannot and do not store them. We keep only transaction metadata: plan purchased, amount, transaction ID, and status, for receipts, refunds, and tax records. Purchases are made by the parent account, not the student.
Device and usage data. App version, device type, and technical logs needed to keep the service working and secure. We do not collect advertising identifiers and we do not use third-party advertising or ad-tracking SDKs.
3. Why we collect it
- To provide the service: run assessments, score them, and generate progress reports for the student and their linked parent or teacher.
- To improve question quality and difficulty calibration, using aggregated and de-identified data.
- To process payments and provide receipts and refunds.
- To provide support and respond to your requests.
- To keep the platform secure and to meet legal obligations.
We do not sell personal data. We do not show advertising. We do not use personal data for purposes beyond those above without asking for fresh consent.
4. Children’s privacy
Under the DPDP Act, everyone below 18 is a child. Abhranti is built around that:
- A parent or guardian creates the account and student profiles, and we obtain the parent’s verifiable consent before processing any of the child’s personal data. Students do not sign up independently.
- We do not serve targeted advertising to children, and we do not track, behaviourally monitor, or profile children. Assessment analytics exist only to produce the child’s own learning reports, visible to the child and the adults their parent has authorised.
- A parent can review, correct, or delete their child’s data, or withdraw consent entirely, at any time (sections 8 and 9).
5. Who we share data with
We share personal data only with the processors that run the service, under contracts that restrict what they may do with it:
- Amazon Web Services (Mumbai region, ap-south-1) — hosting, storage, and Amazon Cognito authentication.
- Google and Apple — only as your chosen sign-in provider; their handling of your sign-in is governed by their own privacy policies.
- Razor — payment processing, as described in section 2.
Within the product, a student’s reports are visible to the parent account that manages the profile, and to a teacher or school only where that access has been authorised. Beyond this, we disclose personal data only if required by law or to protect the safety and integrity of the service. We never sell personal data.
6. Where data lives and how it is protected
Personal data is stored in India (AWS Mumbai, ap-south-1). Data is encrypted in transit and at rest, access inside Abhranti is restricted on a least-privilege basis, and our systems are segregated so that services only reach the data they need. In the event of a personal data breach we will notify affected users and the Data Protection Board of India as the DPDP Act requires.
7. How long we keep data
- Account and profile data: for as long as the account is active, and deleted within 90 days of account deletion or consent withdrawal.
- Learning and assessment data: for as long as the student profile exists, so reports and progress remain available; deleted with the profile.
- Transaction records: retained as required by Indian tax and accounting law (currently 8 years), even after account deletion.
- Technical logs: up to 12 months, then deleted or anonymised.
8. Your rights
Under the DPDP Act you (and, for a child, the parent who gave consent) have the right to:
- Access a summary of the personal data we hold and how it is processed.
- Correct or complete inaccurate data.
- Erase personal data that is no longer needed for the purpose you consented to.
- Withdraw consent at any time, as easily as it was given — after which we stop the related processing.
- Have grievances addressed (section 10).
- Nominate another person to exercise these rights if you die or become incapacitated.
Exercise these from the app’s settings, or by writing to privacy@abhranti.ai. We respond within the timelines prescribed under the DPDP Rules.
9. Deleting your account
You can delete your account (or an individual student profile) from Settings inside the app, or by emailing privacy@abhranti.ai from the account’s registered address. Deletion removes profile and learning data per the schedule in section 7; transaction records are kept only as long as law requires.
10. Grievances and contact
Grievance Officer: Raghunandan, privacy@abhranti.ai, 14057, sobha dream acres, Panathur Main road, Belagere, Varthur, Bangalore-560087, India. We acknowledge grievances promptly and resolve them within the period prescribed under the DPDP Rules. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
11. Cookies
The web app uses only the cookies and local storage needed to keep you signed in and remember your preferences. We do not use third-party advertising or cross-site tracking cookies.
12. Changes to this policy
When we change this policy we will update the date at the top and, for material changes, notify you in the app or by email. Where a change expands how we process children’s data, we will seek fresh parental consent before it applies.
13. Governing law
This policy is governed by the laws of India.