Privacy Policy
Last updated 17 August 2026
The short version
We collect the minimum needed to run a learning platform: who you are, what you enrolled in, and how far through it you are. We do not sell your data, we do not run advertising trackers, and you can have your account deleted by asking.
What we collect
From Google, when you sign in
- Your email address and Google account identifier
- Your display name
- Your profile picture URL
We request only the openid, email
and profile scopes. We cannot read your Gmail, Drive,
Calendar or contacts, and we never post on your behalf.
From your use of the service
- Which courses you enrol in and when
- Which lessons you mark complete, and which lesson you last opened
- Certificates issued to you
- If you create an internship profile: your institution, programme, profile photo, marksheet, college ID and the front and back of your Aadhaar card
- Messages you send us through the contact form
The public profile shows your name, institution, programme, profile photo and issued achievements. Identity and education documents are private and are not displayed on the public profile.
Technical data
- Server logs containing request paths, timestamps and error details
- A hashed form of your IP address on contact-form submissions, used solely for abuse rate limiting — we do not store the raw address
Why we collect it
- To provide the service — you cannot have an account or saved progress without an identifier. Lawful basis: performance of a contract.
- To issue and verify certificates — a certificate is worthless if it cannot be checked. Lawful basis: performance of a contract.
- To verify an internship profile — when you choose to create one, supporting documents help us confirm identity and education details. Lawful basis: your explicit consent and steps connected to the internship programme.
- To answer support requests — we keep the thread so we do not ask you to repeat yourself. Lawful basis: legitimate interests.
- To keep the service secure and working — logs, rate limiting, abuse prevention. Lawful basis: legitimate interests.
We do not use your data for behavioural advertising, and we do not build profiles for sale.
Cookies
We set exactly two things in your browser:
- A session cookie (
gt_session). It contains an opaque random identifier and nothing else — no email, no name. It isHttpOnly,SameSite=Lax, andSecureover HTTPS. It is strictly necessary; the site cannot keep you signed in without it. - A theme preference in
localStorage, so the site remembers whether you chose light or dark. It never leaves your device.
No analytics cookies, no advertising pixels, no third-party trackers.
Who we share it with
Only where necessary to run the service:
- Google — for authentication only, when you choose to sign in.
- Our payment processor — handles card details directly; we receive only the transaction result.
- Our hosting and database providers — who store data on our instructions under contract.
- Law enforcement — only where legally compelled, and we will notify you unless prohibited from doing so.
We never sell personal data. We never share it for marketing purposes.
How long we keep it
- Account and enrolment data — while your account exists, since access is lifetime.
- Internship profile documents — while your profile is active or until you withdraw consent and ask us to remove them, subject to any record we must retain by law.
- Certificate records — indefinitely, because certificates must remain verifiable. Only the name, course, hours and issue date are retained for this purpose.
- Support messages — 24 months.
- Server logs — 90 days.
Your rights
You can ask us to:
- Show you everything we hold about you, in a portable format.
- Correct anything inaccurate.
- Delete your account and personal data. Note that we retain the minimum certificate record needed to keep an already-issued certificate verifiable; tell us if you want the certificate revoked instead.
- Object to or restrict processing based on legitimate interests.
Submit a request through our contact form using the address registered to your account. We respond within 30 days.
How we protect it
- All traffic is served over HTTPS with HSTS.
- Sessions are server-side; the browser holds only an opaque identifier, rotated periodically and regenerated on sign-in.
- State-changing requests require a CSRF token.
- A strict Content Security Policy blocks injected scripts and third-party resources.
- Credentials and API secrets live in environment configuration outside the web root, never in source code.
- Uploaded identity documents are re-encoded as images, stored outside the public webroot and served only through an authenticated owner endpoint.
- Access to production data is limited to staff who need it.
No system is perfect. If we suffer a breach affecting your data, we will notify you and the relevant authority without undue delay, with what happened and what to do about it.
Children
The service is not directed at children under 16. If you believe a child has given us personal data, contact us and we will delete it.
Changes
We will post any change here and update the date at the top. Material changes affecting how we use your data will be notified by email before they take effect.
Contact
Use our contact form for privacy requests.
,
Written to be understood rather than to be exhaustive. Have it reviewed against the DPDP Act 2023 and, if you serve EU learners, the GDPR, before relying on it.