Last updated: 16 May 2026
Privacy Policy
ExamGrind respects your privacy. This Privacy Policy explains what we collect, why we collect it, and the choices you have. It applies to anyone who uses the ExamGrind website or services (“Service”), operated by [Your Registered Business Name].
1. Information we collect
a. Information you give us
- Account info — when you sign in with Google we receive your name, email address, and profile photo from Google.
- Your quiz activity — which subjects, chapters, and topics you practise; the answers you select; time spent on each question; XP earned; streak history; mastery progress.
- Payment info — handled entirely by Razorpay (an RBI-authorised payment aggregator). We never see or store your full card number, CVV, UPI PIN, or bank credentials. We do store the transaction reference, amount, status, and the masked last four digits Razorpay shares.
b. Information collected automatically
- Standard server logs (IP address, browser type, pages requested, timestamps) used to keep the Service reliable and secure.
- A small set of cookies needed to keep you signed in (Supabase auth session tokens). We do not currently use third-party advertising cookies.
2. How we use your information
- To run the Service — generate quizzes, score answers, show progress.
- To generate personalised AI analyses of your quiz answers, which is the core feature of ExamGrind. Question text and your answers are sent to Anthropic's API to produce the analysis; Anthropic does not retain customer data for training under our agreement.
- To process payments and prevent fraud (in coordination with Razorpay).
- To send you essential service messages (e.g. payment receipts, account notices). We will not send marketing email without your consent.
- To improve the Service in aggregate, anonymous form.
3. Who we share information with
We share information only with the following processors:
- Supabase — our database and auth provider. Your profile and quiz data sit in our Supabase project (hosted in the Asia-Pacific region).
- Anthropic — receives quiz text and answers when generating questions or analyses. Used only to fulfil your request; not retained for training.
- Razorpay — receives payment details directly from you (we never see them). Acts as a processor under their own privacy policy.
- Vercel — hosts the website and serves it to your browser. Standard web logs apply.
- Google — provides the Sign-in with Google flow.
We do not sell your personal information to anyone. We may disclose information when required by a valid Indian legal process.
4. Your rights under the DPDP Act, 2023
You have the right to:
- Access the personal data we hold about you.
- Correct any inaccurate data.
- Request deletion of your data (subject to legal retention limits).
- Withdraw consent at any time (this will end your access to the Service).
- Nominate someone to exercise your rights in case of incapacity.
- Make a complaint to the Data Protection Board of India.
To exercise any of these rights, write to us via the contact page. We'll respond within 30 days.
5. How long we keep your data
We keep account and quiz data for as long as your account is active. If you delete your account, we delete personal data within 30 days, except where Indian tax, accounting, or anti-fraud law requires us to retain payment records for a longer period.
6. Security
Communication with the Service is encrypted in transit (TLS). Database access is restricted via row-level security policies — your rows can only be read or modified by your own authenticated session. No system is perfectly secure; please use a strong Google password and contact us immediately if you suspect unauthorised access.
7. Children
ExamGrind is built for Indian competitive-exam aspirants (currently CUET UG, SSC CGL, and NEET UG). If you are under 18, you may use the Service only with a parent or legal guardian's consent. We do not knowingly collect personal data from anyone under 13.
8. Changes to this policy
We'll change the “Last updated” date at the top when we revise this policy. Material changes will be notified by email or in-app.
9. Contact
Privacy questions, deletion requests, complaints — please use the contact page.