Skip to content

privacy

What we keep, and what we refuse to

Most people using StudyBuddy are under 18. India's Digital Personal Data Protection Act 2023 has things to say about that, and so does plain decency, so this page is written to be read rather than to be survived.

Last updated 31 August 2026.

What we collect

Your email address
It is how you sign in, and how a password reset or a verification link reaches you.
Your password, hashed
Stored as a one-way hash. Nobody here can read it, including us — a reset replaces it rather than recovering it.
An age band — not a date of birth
Under 13, 13 to 17, or 18 and over. The law asks whether you are a child; it does not ask when you were born, so we keep only the narrower answer.
Your class year and which exams you are preparing for
It decides which syllabus you are shown. A Class 11 student has not been taught Class 12, and testing them on it would measure the calendar rather than them.
Which chapters you say you have studied
So a test can be built from material you have actually covered.
Your answers, scores and how long each question took
This is the product. Without it there is no diagnosis, only a mark out of ten.
Your name, if you give one, and your Google account identifier if you sign in with Google
The name is optional and is only ever shown back to you. Google tells us who you are; it does not tell us how old you are, which is why we ask separately.
A parent or guardian's email address, if you are under 18
So they can be asked to consent, and so they can see how you are getting on if you both agree to a link.

What we do not collect

Not “we may collect these in future”. These are not in the product and are not planned:

  • Your contacts
  • Your precise location
  • Device fingerprinting
  • Advertising identifiers
  • Third-party ad SDKs
  • Behavioural advertising, ever

There are no advertising trackers on this site and we do not sell or rent anything about you to anybody. There is nothing to opt out of, because there is nothing running.

If you are under 18

You tell us your age band when you sign up. If it is under 18, we ask for a parent or guardian's email address and write to them. Until they agree, the account does not start.

We record how and when that consent was given — not just a tick in a box — so it can be shown later. A guardian can withdraw it at any time.

Agreeing to let us process a child's data is a separate thing from agreeing to receive progress updates about them. They are asked for separately and either can be withdrawn on its own.

What a parent can see

A parent link has to be asked for by one side and confirmed by the other. An unconfirmed link shows a parent nothing at all.

Once it is active, a parent sees a readiness figure, chapter and topic mastery, recent test scores and the current recommendation. They never see question wording, answer keys, or which option you picked — a parent who can read the paper their child is about to sit is a leak, not a feature.

A parent is never shown a number the student is not shown. Where a figure is withheld for want of evidence, it is withheld from them too.

A student can cut the link at any time, on their own. A parent cannot stop them.

Who else sees anything

Google, only if you choose to sign in with Google. We ask them for your name, email address and account identifier — nothing else. No Drive, no contacts, no calendar.

Our email provider, to deliver the messages this product sends: verification, password reset, and guardian consent.

A payment provider, when you buy something. Card details go to them and never reach us; we keep a record that a payment happened.

That is the list. No advertisers, no data brokers, no analytics company.

Someone on our team can look at an identified account only with a written reason, and doing so leaves a permanent record of who looked, at whom, and why. Everyday work is done against pseudonymous data with no names in it.

Deleting your account

You can delete your account from your settings. When you do, your email address, name and password are removed and your tests are detached from you, so what is left points at nobody. Your sessions are ended immediately rather than at the next expiry.

One thing survives, and we would rather say so than hide it: the aggregate statistics each question has built up — how often it is answered correctly, how long it tends to take. Those are facts about the question, not about you, and they are what keeps the bank honest for everyone else. They carry nothing that identifies you.

Backups are kept for fourteen days and then deleted, so a copy of your data can persist in a backup for up to that long after you delete it.

Your rights

Under the DPDP Act you can ask what we hold about you, ask us to correct it, ask us to erase it, and withdraw a consent you gave. If you are under 18, your parent or guardian can do these on your behalf.

Write to admin@innocorelabs.com and we will answer. If you are not satisfied with how we handle it, you can complain to the Data Protection Board of India.

Keeping it safe

Traffic is encrypted in transit. Passwords are stored as one-way hashes. Sign-in cookies cannot be read by scripts and are only sent over a secure connection. The database is not reachable from the internet.

No system is perfect, and anyone claiming otherwise is selling something. If you find a problem, please tell us at the address above.

Changes

If this policy changes in a way that affects what we collect or who sees it, we will say so here and update the date at the top. For a change that needs your consent, we will ask for it rather than assume it.

See also our terms of service.