Legal

Privacy Policy

Last updated 17 August 2026

The short version

We collect the minimum needed to run a learning platform: who you are, what you enrolled in, and how far through it you are. We do not sell your data, we do not run advertising trackers, and you can have your account deleted by asking.

What we collect

From Google, when you sign in

  • Your email address and Google account identifier
  • Your display name
  • Your profile picture URL

We request only the openid, email and profile scopes. We cannot read your Gmail, Drive, Calendar or contacts, and we never post on your behalf.

From your use of the service

  • Which courses you enrol in and when
  • Which lessons you mark complete, and which lesson you last opened
  • Certificates issued to you
  • If you create an internship profile: your institution, programme, profile photo, marksheet, college ID and the front and back of your Aadhaar card
  • Messages you send us through the contact form

The public profile shows your name, institution, programme, profile photo and issued achievements. Identity and education documents are private and are not displayed on the public profile.

Technical data

  • Server logs containing request paths, timestamps and error details
  • A hashed form of your IP address on contact-form submissions, used solely for abuse rate limiting — we do not store the raw address

Why we collect it

  • To provide the service — you cannot have an account or saved progress without an identifier. Lawful basis: performance of a contract.
  • To issue and verify certificates — a certificate is worthless if it cannot be checked. Lawful basis: performance of a contract.
  • To verify an internship profile — when you choose to create one, supporting documents help us confirm identity and education details. Lawful basis: your explicit consent and steps connected to the internship programme.
  • To answer support requests — we keep the thread so we do not ask you to repeat yourself. Lawful basis: legitimate interests.
  • To keep the service secure and working — logs, rate limiting, abuse prevention. Lawful basis: legitimate interests.

We do not use your data for behavioural advertising, and we do not build profiles for sale.

Cookies

We set exactly two things in your browser:

  • A session cookie (gt_session). It contains an opaque random identifier and nothing else — no email, no name. It is HttpOnly, SameSite=Lax, and Secure over HTTPS. It is strictly necessary; the site cannot keep you signed in without it.
  • A theme preference in localStorage, so the site remembers whether you chose light or dark. It never leaves your device.

No analytics cookies, no advertising pixels, no third-party trackers.

Who we share it with

Only where necessary to run the service:

  • Google — for authentication only, when you choose to sign in.
  • Our payment processor — handles card details directly; we receive only the transaction result.
  • Our hosting and database providers — who store data on our instructions under contract.
  • Law enforcement — only where legally compelled, and we will notify you unless prohibited from doing so.

We never sell personal data. We never share it for marketing purposes.

How long we keep it

  • Account and enrolment data — while your account exists, since access is lifetime.
  • Internship profile documents — while your profile is active or until you withdraw consent and ask us to remove them, subject to any record we must retain by law.
  • Certificate records — indefinitely, because certificates must remain verifiable. Only the name, course, hours and issue date are retained for this purpose.
  • Support messages — 24 months.
  • Server logs — 90 days.

Your rights

You can ask us to:

  • Show you everything we hold about you, in a portable format.
  • Correct anything inaccurate.
  • Delete your account and personal data. Note that we retain the minimum certificate record needed to keep an already-issued certificate verifiable; tell us if you want the certificate revoked instead.
  • Object to or restrict processing based on legitimate interests.

Submit a request through our contact form using the address registered to your account. We respond within 30 days.

How we protect it

  • All traffic is served over HTTPS with HSTS.
  • Sessions are server-side; the browser holds only an opaque identifier, rotated periodically and regenerated on sign-in.
  • State-changing requests require a CSRF token.
  • A strict Content Security Policy blocks injected scripts and third-party resources.
  • Credentials and API secrets live in environment configuration outside the web root, never in source code.
  • Uploaded identity documents are re-encoded as images, stored outside the public webroot and served only through an authenticated owner endpoint.
  • Access to production data is limited to staff who need it.

No system is perfect. If we suffer a breach affecting your data, we will notify you and the relevant authority without undue delay, with what happened and what to do about it.

Children

The service is not directed at children under 16. If you believe a child has given us personal data, contact us and we will delete it.

Changes

We will post any change here and update the date at the top. Material changes affecting how we use your data will be notified by email before they take effect.

Contact

Use our contact form for privacy requests.
,


Written to be understood rather than to be exhaustive. Have it reviewed against the DPDP Act 2023 and, if you serve EU learners, the GDPR, before relying on it.