Adult account information, learner profiles and private learning content
This Privacy Policy explains how BhashaMitra Edtech Private Limited, having its registered office at 11/3125, Thomas Tower, Infopark Express Highway, Kochi, Kerala 682039, India (the “Operator”, “Bhashamitra”, “we”, “us” or “our”), processes personal data when an adult uses the Bhashamitra mobile application and related services (the “Service”) personally or for a child.
The Service is offered in India. An individual must be at least 18 years old to create and operate an account, purchase a package or accept the Terms of Use (the “Account Holder”). The Account Holder may use the Service personally as an adult learner or may create and manage a learner profile for a child for whom the Account Holder is a parent or lawful guardian. A “Learner” therefore means either the Account Holder when using the Service personally or a child whose learner profile is created and managed by a parent or lawful guardian. A “Child Learner” means a Learner below 18 years of age. The Service is designed primarily for school-age children, particularly those aged 6–15, but that age range describes the product’s principal audience and does not prevent an adult from using the Service personally. A child does not independently create an account, purchase a package or accept the Terms of Use.
This Policy should be read with the Terms of Use and the short, itemised privacy notice shown to the Account Holder when consent is requested.
Payment-card, UPI or bank credentials are processed by the selected app store or payment provider and are not intended to be stored by Bhashamitra.
For each learner profile, the Account Holder may provide a nickname and grade. We do not ask for a Child Learner’s full name, email address, mobile number, school, class section, admission number, photograph or date of birth. The Account Holder’s verified mobile number and Google or Apple account information are processed separately as account data.
If the feature is enabled after legal approval, the Service may record the number of difficult words practised and total learning time for display to the Account Holder. We do not infer intelligence, diagnose a condition, predict examination performance, publicly compare learners or create advertising profiles. Persistent Child Learner activity recording will not be enabled unless management has confirmed that the feature is lawful under applicable child-data rules.
A notebook scan or other page may accidentally contain names, marks, teacher comments or other personal information. The Account Holder should crop the image and avoid submitting information that is not needed for the lesson.
The Service and its contracted providers may process device type, operating-system and app version, IP address, approximate network region, timestamps, crash information, security events and diagnostic logs. We use these data to authenticate, secure, support and improve reliability—not to advertise to children.
| Purpose | Data used |
|---|---|
| Create and protect the Account Holder’s account | Account Holder identifiers, login, consent and security records |
| Create a learner profile | Account Holder-selected nickname and grade |
| Deliver a selected lesson | Selected page, extracted text, generated explanations, Q & A and requested audio |
| Manage the paid package | Purchase status, page allowance, failed-processing credits and transaction records |
| Show approved progress information | Difficult-word count and learning time, only if the feature is legally approved and enabled |
| Secure and support the Service | Technical data, logs and support communications |
| Meet legal obligations and resolve complaints | Relevant account, transaction, consent, security and communication records |
We do not sell personal data, use learner information for targeted advertising or cross-service profiling, share learner activity with schools or teachers, or use uploads and outputs to train general-purpose AI models.
Before we create a Child Learner profile or process a child’s personal data, we ask the parent or lawful guardian to review an itemised notice and provide affirmative consent. The parent or lawful guardian may refuse or withdraw optional consent without losing access to unrelated features. Withdrawal is designed to be as easy as giving consent, although it does not affect processing already lawfully completed or records that must be retained by law. These child-specific consent requirements do not apply when the Account Holder uses the Service solely for the Account Holder’s own learning.
A mobile OTP or Google/Apple sign-in verifies control of an account; it does not by itself establish that the Account Holder is an adult or is a Child Learner’s parent or lawful guardian. We will use a proportionate, legally compliant method to check that the person giving parental consent is an identifiable adult when required. We prefer an age or identity verification result or token over retaining a copy of an identity document.
The Account Holder controls the account and may delete lesson material, a learner profile or the account. A parent or lawful guardian must supervise a Child Learner’s use of the Service.
We use contracted processors to provide the Service. These currently include Google services for supported AI or document processing and Sarvam for supported AI or speech processing. We use the specific production products and settings approved by Bhashamitra, require contractual confidentiality and security, and configure inputs and outputs not to be used to train general-purpose models.
We may also use providers for cloud hosting, identity, payments, diagnostics, security and customer support. They may process personal data only for contracted purposes and under our instructions, subject to applicable law. This Policy identifies the categories of providers needed for an informed choice.
Uploaded content and generated output are private to the Account Holder’s account. They are not placed in a shared textbook, audio, question-answer or training repository and are not reused for another user.
Primary production storage and approved AI processing are configured in India. If a necessary provider permits authorised support access or processing outside India, we will apply required contractual and technical safeguards and update this Policy where the change is material.
| Information | Retention approach |
|---|---|
| Complete PDF submitted for page selection | Temporary intake only. Only the Account Holder-selected page is processed; the remaining file/pages are deleted from active systems after extraction and no later than 24 hours. |
| Selected page, extracted text and lesson output | Until the Account Holder deletes the lesson or account, or an earlier service limit applies. |
| Generated audio | Created only on request and retained only for the disclosed playback/cache period; deleted with the related lesson. |
| Learner nickname and grade | Until the Account Holder deletes the profile or account. |
| Learning-time and difficult-word metrics | Only if legally approved and enabled; retained for the disclosed progress period and deleted with the profile or account. |
| Security logs and associated evidence | For the period required for security and legal compliance. From the operative date of DPDP Rule 6, relevant logs and associated personal data will be retained for at least one year unless another law requires longer. |
| Consent, transaction and complaint records | For the applicable contractual, tax, accounting, consumer-protection, limitation and legal period. |
| Backups | Protected and isolated from normal use; deleted through the documented backup cycle, targeted within 45 days after deletion from active systems unless legal preservation applies. |
We may preserve specific records where reasonably necessary for a legal claim, security investigation, statutory obligation or lawful direction. We do not use preserved material for ordinary product purposes.
We do not permit another user to access an Account Holder’s uploads, learner profile, generated text, Q & A or audio.
We use proportionate technical and organisational safeguards, including encryption in transit and at rest, private object storage, access controls, short-lived access links, monitoring, secure development practices, backups and processor contract controls.
Our personnel do not routinely review private learning material. Exceptional access is limited to Account Holder-authorised support, a security investigation, abuse handling or legal compliance. It is role- restricted, purpose-recorded, time-limited where practicable and logged. No electronic service can guarantee absolute security.
We maintain an incident-response process. Where applicable law requires, we will notify affected Account Holders and the Data Protection Board of India without delay and provide further information within the prescribed period. Notices will explain the incident, likely consequences, mitigation, recommended protective steps and a contact for questions.
Subject to applicable law and proportionate identity verification, an Account Holder may exercise rights concerning the Account Holder’s own data and, where the Account Holder is the parent or lawful guardian, data relating to a Child Learner:
The app will provide a direct route to exercise available choices. Requests concerning a Child Learner may be made only by the Child Learner’s parent or lawful guardian, subject to applicable law. We may retain limited data despite a deletion request where the law requires or permits it, and we will explain the basis where appropriate.
The Service may use strictly necessary software components for authentication, payments, security, crash reporting and operation. Bhashamitra does not permit targeted or behavioural advertising directed at learners. Rewards are based only on approved learning activity and do not involve a public leaderboard, cash gambling feature or sale of Learner data.
We may update this Policy when the Service, providers or law changes. We will show the effective date and provide prominent notice to the Account Holder where a change materially affects Learner data or Account Holder choices. We will seek fresh consent where required. We will not introduce targeted advertising, cross-user content reuse, model training, downloads, sharing or materially expanded child analytics through a policy update alone.
The Operator is BhashaMitra Edtech Private Limited. Registered and correspondence address: 11/3125, Thomas Tower, Infopark Express Highway, Kochi, Kerala 682039, India.
We will acknowledge and respond within the periods required by applicable law and will communicate the expected timing where further review is necessary.