EduLevel — Privacy Policy

    Last Updated: 12 July 2026

    This Privacy Policy describes how APEXLEVEL TECHNOLOGIES PRIVATE LIMITED, a company incorporated under the Companies Act, 2013, CIN U62099UP2026PTC249198 (the "Company", "we", "us" or "our"), collects, uses, shares and protects personal data in connection with the EduLevel platform — the EduLevel website, web application, Android application and all related features and services (collectively, the "Services").

    This Privacy Policy is published in accordance with the Information Technology Act, 2000 and the rules made thereunder (including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011) and the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules thereunder. For the purposes of the DPDP Act, the Company is the data fiduciary for personal data processed through the Services.

    This Privacy Policy is incorporated into, and forms part of, the EduLevel Terms and Conditions (the "Terms"). Capitalised terms not defined here have the meanings given in the Terms. By registering for, accessing or using the Services — or, in the case of a user under 18 years of age, by a parent or legal guardian permitting such registration or use — you consent to the collection, use, processing, storage, transfer and disclosure of personal data as described in this Privacy Policy. If you do not agree, do not use the Services.


    1. Scope

    This Privacy Policy applies to personal data collected through the Services from all users — students, parents/guardians and teachers. It does not apply to third-party websites, apps or services that we link to or that you use alongside the Services (including your bank or UPI app), which are governed by their own policies.

    2. Information We Collect

    2.1. Information you provide

    • Account and profile data: mobile phone number (used for OTP-based login), name, class/grade, board, language preference, and, where provided, a parent's or guardian's name and phone number, school and city.
    • Learning inputs: questions you ask, chat and text messages exchanged with AI features, selections you make (subjects, chapters, topics, plans), and answers you submit in practice and tests.
    • Voice and audio data: when you use voice-based features (such as AI teaching sessions, doubt-solving or consultations), your microphone audio is captured and streamed for processing while the feature is active; transcripts of what you and the AI say are generated and stored. If you receive or place telephone calls with us (including automated/AI-voiced calls), those calls and their transcripts may be recorded and stored.
    • Uploaded files and images: documents and images you upload or capture using your device camera or photo library, such as answer sheets and question papers submitted for AI evaluation.
    • Payment-related data: plan selected, transaction amounts, timestamps, payment status, masked payment-instrument details and identifiers provided by our payment processor. We do not collect or store your full card number, CVV, UPI PIN or banking passwords — payments are processed by third-party payment gateways.
    • Communications: messages you send to our support channels, feedback, survey responses and call interactions.

    2.2. Information collected automatically

    • Usage and engagement data: features used, sessions started and completed, lesson and topic progress, practice and test activity and scores, revision history, streaks, study minutes, plan activity, in-app events and interactions, and timestamps.
    • Device and technical data: device type and platform (web/Android), operating system and browser, app version, IP address, approximate region derived from IP, device/push-notification tokens, identifiers needed for notifications, language settings, crash and error logs, and network performance data.
    • Local storage: we store session tokens and limited preferences in your browser's/app's local storage to keep you signed in and remember settings. We do not use third-party advertising cookies.
    • Proctoring and integrity events: for certain test features, events such as attempted screenshots/screen recording or app-switching may be logged.
    • Attribution data: where permitted, install/signup source information (for example, that you arrived from a particular campaign or link).
    • Device permissions: with your device-level permission, we access your microphone (for voice features), camera and photo library (for uploading or capturing answer sheets and study material) and notifications (for push messages). You can revoke these permissions at any time in your device settings, but the features that depend on them will stop working.

    2.3. Information from linked accounts and third parties

    • Linked accounts: if a parent, guardian or teacher account is linked to a student account, we associate the accounts and share learning-activity information between them as described in Section 6.
    • Service providers: payment confirmation and status from payment processors; delivery status from SMS/WhatsApp/call providers.

    2.4. Mandatory information

    Certain information — such as your mobile number and class — is mandatory to create an account and provide the Services. If you choose not to provide mandatory information, we may be unable to provide some or all of the Services. Other fields are optional and may be left blank.

    3. Children and Parental Consent

    3.1. The Services are intended for school students, many of whom are under 18. For any user under 18, we require the consent of a parent or legal guardian to the processing of the child's personal data as described in this Privacy Policy. By registering a child, permitting a child to register or use the Services, providing your number as the parent/guardian contact, or linking a parent account, you represent that you are the child's parent or legal guardian and you provide such consent.

    3.2. We process children's personal data only for purposes connected with providing, securing, personalising and improving the educational Services and as otherwise described in this Privacy Policy. We do not serve third-party targeted advertising to children and we do not undertake behavioural monitoring of children for advertising purposes. Analytics performed on children's usage is limited to first-party product measurement, quality, safety and service improvement.

    3.3. A parent/guardian may review the child's information, withdraw consent or request deletion of the child's account and data by contacting us as per Section 14. Withdrawal of consent may result in discontinuation of the Services for the child.

    4. How We Use Personal Data (Purposes)

    We use personal data to:

    1. Provide the Services — create and authenticate accounts (phone OTP), deliver AI teaching, doubt-solving, practice, tests, evaluation, planning and revision features, sync progress across sessions and devices, and operate linked parent/teacher views.
    2. Process voice and AI interactions — capture, stream, transcribe, analyse and respond to your voice and text inputs using AI systems (see Section 5).
    3. Personalise learning — adapt content, plans, difficulty, revision scheduling (spaced repetition) and recommendations to the student's class, activity and performance.
    4. Process payments and subscriptions — facilitate purchases, trials, recurring mandates, renewals and payment-status reconciliation via our payment processors.
    5. Communicate with you — send OTPs, transactional and service messages, payment and pre-debit related notifications, study reminders and nudges, progress reports (including to linked parent numbers), and, subject to your right to opt out, promotional and educational communications via voice calls (including automated/AI-voiced calls), SMS, WhatsApp, email, in-app messages and push notifications.
    6. Monitor quality and safety — monitor (including in real time), record, transcribe and review sessions, calls and interactions to assess quality, ensure the safety of users (including minors), detect and prevent misuse, fraud and abuse, moderate content, and train and coach our systems and personnel (see Section 7).
    7. Maintain security and integrity — authenticate access, secure our systems, enforce quotas and fair-use limits, run proctoring/integrity features, detect fraud, and enforce the Terms.
    8. Improve and develop the Services — measure feature usage, debug and fix errors, run analytics and experiments (including A/B tests), evaluate and improve our content, prompts, AI configurations and product experience.
    9. Comply with law — meet legal, tax, accounting and regulatory obligations, respond to lawful requests from authorities, and establish, exercise or defend legal claims.
    10. Publish testimonials and success stories — where you (or the parent/guardian) submit a testimonial, review, rating or success story, or otherwise consent to such use, publish and use it — including the student's first name, class, city, scores and results — within the Services and in our marketing and promotional materials, as described in the Terms.

    Where the DPDP Act applies, we process personal data on the basis of the consent you (or the parent/guardian) provide when registering and using the Services, and for "legitimate uses" recognised under that Act (such as voluntary provision of data for a specified purpose, compliance with law, and responding to legal process).

    5. Voice, Audio and AI Processing — Important Disclosure

    5.1. The Services are AI-powered. When you use voice features, your microphone audio is streamed in real time to our AI service providers (currently including Google's Gemini AI services) for processing and generating spoken responses. Text you type into AI features is similarly processed by AI providers. Uploaded answer sheets and papers are processed by AI for evaluation.

    5.2. Transcripts of AI interactions (what you said/typed and what the AI said) and derived data (such as topic progress, evaluations and summaries) are stored by us and used for the purposes in Section 4.

    5.3. AI personas within the Services (including any teacher persona such as "Vidya ma'am") are artificial characters. Interactions with them are interactions with software, and are logged and processed accordingly.

    5.4. Our AI service providers process data as our processors under contractual terms; however, their infrastructure, availability and processing behaviour are outside our direct control, and your use of AI features is subject to the disclaimers and liability limitations in the Terms.

    6. Sharing and Disclosure of Personal Data

    We do not sell personal data. We share personal data only as follows:

    1. Service providers (data processors): with vendors that process data on our behalf to run the Services, under appropriate contractual safeguards, including: cloud hosting and database providers (e.g., Supabase and associated cloud infrastructure), AI model providers (e.g., Google Gemini), authentication and push-notification providers (e.g., Google Firebase), payment gateways and aggregators (e.g., Razorpay), SMS/OTP providers (e.g., MSG91), voice-telephony providers (e.g., Exotel), WhatsApp/messaging providers, analytics providers (e.g., Mixpanel), and customer-support tooling.
    2. Linked accounts: with the parent/guardian and/or teacher accounts linked to a student account — including the student's profile, activity, progress, plans, test performance and engagement summaries. Students' interactions may also be visible to authorised Company personnel under Section 7.
    3. Payment ecosystem: with payment processors, banks and UPI apps to execute transactions, mandates, refunds (where applicable) and dispute handling.
    4. Legal and safety: with courts, law-enforcement, regulators or other authorities where required by law or legal process, or where we believe disclosure is necessary to protect the rights, property or safety of any person (including a child), to enforce the Terms, or to detect and prevent fraud or security issues.
    5. Corporate transactions: with counterparties and advisors in connection with any merger, acquisition, financing, restructuring or sale of all or part of our business or assets, in which case personal data may be transferred as part of that transaction subject to this Privacy Policy or equivalent protections.
    6. With your direction or consent: where you direct us to share data or otherwise consent.
    7. Aggregated and de-identified data: we may use, share or publish aggregated, anonymised or otherwise de-identified information that cannot reasonably be used to identify you (for example, usage statistics, performance trends and campaign metrics) for any lawful purpose, including research, product announcements, investor reporting and marketing-campaign measurement.

    7. Session Monitoring, Recording and Human Review

    For quality assurance, safety of users (including minors), abuse prevention, compliance and service improvement: live learning sessions and voice interactions may be monitored in real time by authorised Company personnel; sessions, calls and interactions may be recorded and/or transcribed; and recordings, transcripts, uploads and chat logs may be reviewed by authorised personnel. Access is limited to personnel who need it for these purposes. By using the Services (and, for minors, by the parent/guardian permitting such use), you consent to this monitoring, recording and review.

    8. Cookies and Local Storage

    The Services use local storage and similar technologies for essential functions: keeping you signed in (session tokens), remembering preferences, caching content for performance, and measuring product usage. Within the app, we do not use third-party advertising cookies or cross-site tracking for ads. Our public marketing pages and campaigns may, however, use standard campaign-measurement technologies (such as link parameters, install-referrer information and advertising-platform campaign tools) to measure the effectiveness of our marketing. You can clear local storage through your browser/app settings, but doing so will sign you out and may degrade functionality.

    9. Data Retention

    We retain personal data for as long as your account is active and thereafter as reasonably necessary to: provide the Services; maintain business records; comply with legal, tax and regulatory obligations; resolve disputes; enforce agreements; and maintain security and backups. Transcripts, recordings, uploads and learning history may be retained for the life of the account for continuity of the learning experience, unless earlier deletion is requested. When personal data is no longer required, we delete or anonymise it; anonymised or aggregated data that no longer identifies you may be retained and used without restriction. Where deletion is requested, residual copies may persist in backups for a limited period before being purged in the ordinary cycle.

    10. Security

    We implement reasonable security practices and procedures appropriate to the nature of the data, including encryption of data in transit, token-based authentication, access controls on production systems, restriction of secrets to server-side environments, and internal review of security-sensitive changes. However, no method of transmission or storage is completely secure, and we cannot and do not guarantee absolute security. You are responsible for safeguarding your device, phone number and OTPs. To the maximum extent permitted by applicable law, and subject to our obligations under the DPDP Act and other applicable law, the Company shall not be liable for unauthorised access, hacking, interception or similar incidents that occur despite our reasonable security practices; the limitations of liability in the Terms apply to this Privacy Policy.

    11. Your Rights

    Subject to applicable law (including the DPDP Act), you have the right to:

    1. Access — obtain a summary of the personal data we process about you and the processing activities;
    2. Correction and updating — correct inaccurate or incomplete personal data;
    3. Erasure — request deletion of your personal data and account, subject to retention required or permitted by law;
    4. Withdraw consent — withdraw previously given consent at any time (this does not affect processing already carried out, and may result in discontinuation of some or all Services);
    5. Grievance redressal — raise a grievance with our Grievance Officer (Section 14) and, if unresolved, approach the Data Protection Board of India in accordance with the DPDP Act;
    6. Nominate — nominate an individual to exercise your rights in the event of death or incapacity;
    7. Opt out of promotional communications — via the opt-out mechanism in the communication or by writing to us (transactional/service communications continue while you hold an account).

    For a user under 18, these rights are exercisable by the parent or legal guardian. To exercise any right, contact us as per Section 14; we may need to verify your identity (e.g., via the registered phone number) before acting on a request, and we will respond within the timelines prescribed by applicable law.

    12. Storage Location and Cross-Border Transfer

    Personal data is stored and processed on cloud infrastructure that may be located in India and/or in other jurisdictions where our service providers operate (for example, AI processing and cloud hosting may occur on servers outside India). By using the Services, you consent to the transfer, storage and processing of your personal data in such jurisdictions, subject to the requirements and any restrictions notified under the DPDP Act and other applicable law. Wherever your data is processed, we require our processors to protect it under contractual terms consistent with this Privacy Policy.

    13. Changes to this Privacy Policy

    We may update this Privacy Policy from time to time by posting the revised version within the Services or on our website with an updated "Last Updated" date, and, where required by law, by providing additional notice or seeking fresh consent. Your continued use of the Services after a revised Privacy Policy is posted constitutes acceptance of the revision. If you do not agree, you must stop using the Services and may request account deletion.

    14. Grievance Officer and Contact

    In accordance with the Information Technology Act, 2000, the rules thereunder and the DPDP Act, the contact details of the Grievance Officer are:

    • Name: Yavar Izhar
    • Designation: Grievance Officer, APEXLEVEL TECHNOLOGIES PRIVATE LIMITED
    • Email: yavar@edulevel.ai

    This Privacy Policy must be read together with the EduLevel Terms and Conditions, including the disclaimers, no-refund policy, limitation of liability and indemnity provisions contained there. By using EduLevel, you acknowledge that you have read, understood and consented to this Privacy Policy.