Privacy Policy

Last Updated: February 10, 2026

EduNxtAI ("us", "we", or "our") operates the EduNxtAI mobile application and web platform (the "Service"). This Privacy Policy informs you of our policies regarding the collection, use, disclosure, and protection of personal information when you use our Service.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, do not use the Service.


1. Information We Collect

1.1 Personal Information You Provide

We collect information that you voluntarily provide when using our Service:

1.1.1 Account Registration

  • Parent/Guardian Information:
    • Full name
    • Email address
    • Mobile phone number
    • Password (encrypted)
    • Country/Region
  • Student Information:
    • Student's first name and last name
    • Date of birth
    • Gender
    • Educational details (board, standard/grade, stream)
    • Preferred language
    • Profile picture (optional)

1.1.2 Payment Information

  • Payment method details (processed by third-party payment gateways)
  • Transaction history
  • Billing address (if applicable)

Note: We do not store complete credit card or payment card information. Payment processing is handled by secure third-party providers (Razorpay, UPI payment systems).

1.1.3 User-Generated Content

  • Question reports and feedback
  • Report descriptions and issue details
  • Communication with support team
  • User preferences and settings

1.2 Information Automatically Collected

1.2.1 Usage Data

  • Exam attempts and results
  • Questions answered and response patterns
  • Time spent on questions and exams
  • Study progress and performance analytics
  • Login timestamps and session duration
  • Feature usage patterns

1.2.2 Device Information

  • Device type, model, and operating system
  • Unique device identifiers
  • Mobile network information
  • IP address
  • Browser type and version (for web access)
  • Time zone and language settings

1.2.3 Location Data

  • Approximate location based on IP address
  • Country and region information
  • We do NOT collect precise GPS location data

1.2.4 Cookies and Similar Technologies

We use cookies, web beacons, and similar technologies to:

  • Maintain user sessions
  • Remember user preferences
  • Analyze usage patterns
  • Improve Service performance

You can control cookies through your browser settings, but disabling cookies may limit Service functionality.

1.3 Information from Third Parties

1.3.1 Firebase Authentication

If you use social login or phone authentication:

  • Phone number verification status
  • Firebase user ID
  • Authentication tokens

1.3.2 Payment Providers

  • Transaction confirmation data
  • Payment status and timestamps
  • Payment method metadata (not full card details)

2. How We Use Your Information

2.1 To Provide and Maintain the Service

  • Create and manage user accounts
  • Authenticate users and maintain security
  • Process exam attempts and generate results
  • Track student progress and performance
  • Provide personalized study recommendations
  • Generate performance analytics and reports

2.2 To Process Payments

  • Process subscription payments and renewals
  • Issue invoices and receipts
  • Detect and prevent fraudulent transactions
  • Manage refunds and disputes

2.3 To Communicate with You

  • Send transactional emails (account verification, password reset)
  • Notify about exam results and reports
  • Respond to support inquiries and reported issues
  • Send service updates and announcements
  • Marketing communications (with your consent, opt-out available)

2.4 To Improve Our Service

  • Analyze usage patterns and user behavior
  • Identify and fix technical issues
  • Develop new features and functionality
  • Improve content quality and accuracy
  • Conduct research and data analysis

2.5 For Security and Legal Compliance

  • Detect and prevent fraud, abuse, and security threats
  • Enforce our Terms and Conditions
  • Comply with legal obligations and regulatory requirements
  • Protect rights, property, and safety of users and the public
  • Respond to law enforcement and legal requests

3. Data Retention

3.1 Active Accounts

We retain your personal information for as long as your account is active or as needed to provide the Service.

3.2 Account Deletion

When you delete your account:

  • Personal identification information is deleted within 30 days
  • Exam history and performance data may be retained in anonymized form for analytics
  • Billing and transaction records are retained for 7 years for legal and tax compliance
  • Backup copies may persist for up to 90 days in our backup systems

3.3 Legal Retention

Some information may be retained longer if required by:

  • Legal or regulatory requirements
  • Pending legal proceedings or investigations
  • Detection and prevention of fraud

4. Data Sharing and Disclosure

4.1 We Do NOT Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

4.2 Service Providers

We share data with third-party service providers who perform services on our behalf:

  • Cloud Hosting: AWS, Google Cloud (for data storage and hosting)
  • Payment Processing: Razorpay, UPI payment systems
  • Authentication: Firebase Authentication
  • Email Services: SendGrid, AWS SES (for transactional emails)
  • Analytics: Google Analytics, Firebase Analytics
  • Customer Support: Support ticket and chat systems

These providers are contractually obligated to protect your data and use it only for specified purposes.

4.3 Business Transfers

If EduNxtAI is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Service before your data is transferred and becomes subject to a different Privacy Policy.

4.4 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal processes (subpoenas, court orders)
  • Government or regulatory requests
  • Protection of rights, property, or safety
  • Investigation of fraud or security issues
  • Enforcement of our Terms and Conditions

4.5 Aggregated and Anonymized Data

We may share aggregated, de-identified, or anonymized data that cannot be used to identify you:

  • Industry research and analysis
  • Educational statistics and trends
  • Service improvement and optimization

5. Data Security

5.1 Security Measures

We implement appropriate technical and organizational measures to protect your data:

  • Encryption: Data transmission via HTTPS/TLS, password encryption using bcrypt
  • Access Controls: Role-based access, multi-factor authentication for administrators
  • Secure Storage: Data stored in secure, access-controlled databases
  • Regular Audits: Security assessments and vulnerability testing
  • Monitoring: Logging and monitoring for suspicious activity
  • Backup: Regular encrypted backups with secure storage

5.2 Limitations

IMPORTANT: No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for:

  • Maintaining confidentiality of your password
  • Logging out of shared devices
  • Reporting suspected security breaches

5.3 Data Breach Notification

In the event of a data breach that may compromise your personal information:

  • We will investigate and assess the breach
  • We will notify affected users within 72 hours (where legally required)
  • We will take steps to mitigate harm and prevent recurrence
  • We will cooperate with regulatory authorities as required

6. Your Rights and Choices

6.1 Access and Correction

You have the right to:

  • Access your personal information
  • Correct inaccurate or incomplete data
  • Update your profile information through account settings
  • Request a copy of your data in portable format

6.2 Deletion and Account Closure

You have the right to:

  • Delete your account and associated data
  • Request deletion of specific information (subject to legal retention requirements)
  • Withdraw consent for optional data processing

To exercise these rights, contact us at support@edunxtai.info

6.3 Marketing Communications

You can opt out of marketing communications:

  • Click "Unsubscribe" in marketing emails
  • Adjust notification preferences in account settings
  • Contact our support team

Note: You cannot opt out of essential service communications (account verification, security alerts, transaction confirmations).

6.4 Cookie Management

You can control cookies through:

  • Browser settings (block, delete, or restrict cookies)
  • Opt-out tools for advertising networks
  • Mobile device settings for app tracking

6.5 Do Not Track

Our Service does not currently respond to "Do Not Track" (DNT) signals from browsers.


7. Children's Privacy

7.1 Parental Consent

  • Our Service is intended for students of all ages under parental supervision
  • Students under 18 years must have accounts created and managed by parents/guardians
  • We require verifiable parental consent for users under 18

7.2 Information from Minors

  • We collect minimal information necessary for providing the Service
  • Parents can review, modify, or delete their child's information
  • Parents can refuse further collection of their child's data

7.3 Parental Control

Parents/guardians have the right to:

  • Access and review their child's information
  • Modify or delete student profiles
  • Disable or delete student accounts
  • Monitor their child's activity and performance

To exercise parental rights, log in to the parent account or contact support@edunxtai.info


8. International Data Transfers

8.1 Data Location

  • Our primary servers are located in India
  • We may use cloud service providers with data centers in other countries
  • Data may be transferred to countries with different data protection laws

8.2 Safeguards

When transferring data internationally, we ensure:

  • Compliance with applicable data protection laws
  • Use of standard contractual clauses (where applicable)
  • Implementation of appropriate security measures

By using our Service, you consent to the transfer of your information to India and other countries where we operate.


9. Third-Party Links and Services

9.1 External Links

Our Service may contain links to third-party websites, services, or applications. We are not responsible for:

  • Privacy practices of third-party sites
  • Content or accuracy of external resources
  • Third-party terms and conditions

We encourage you to review privacy policies of any third-party services you use.

9.2 Third-Party Integrations

  • Firebase: Authentication and analytics services (Google Privacy Policy applies)
  • Razorpay: Payment processing (Razorpay Privacy Policy applies)
  • Google Analytics: Usage analytics (Google Privacy Policy applies)

10. Changes to This Privacy Policy

10.1 Policy Updates

We may update this Privacy Policy from time to time to reflect:

  • Changes in our practices or Service features
  • Legal or regulatory requirements
  • Industry best practices

10.2 Notification of Changes

We will notify you of significant changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last Updated" date
  • Sending email notification (for material changes)
  • In-app notifications or banners

10.3 Continued Use

Your continued use of the Service after changes to this Privacy Policy constitutes acceptance of the updated policy. If you do not agree with changes, you should stop using the Service and delete your account.


11. Data Protection Rights (For Indian Users)

Under the Digital Personal Data Protection Act, 2023 (once in effect), and other applicable laws, Indian users have rights including:

  • Right to Access: Request information about personal data we process
  • Right to Correction: Request correction of inaccurate data
  • Right to Erasure: Request deletion of personal data (subject to legal exceptions)
  • Right to Grievance Redressal: Lodge complaints with our Grievance Officer
  • Right to Nomination: Nominate another person to exercise rights in case of death or incapacity

To exercise these rights, contact our Grievance Officer (see Section 13).


12. California Privacy Rights (For California Residents)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

12.1 Right to Know

Request disclosure of:

  • Categories of personal information collected
  • Sources of personal information
  • Business purposes for collection
  • Categories of third parties with whom we share data

12.2 Right to Delete

Request deletion of personal information we collected from you (subject to exceptions).

12.3 Right to Opt-Out

We do not "sell" personal information as defined by CCPA. If this changes, we will provide an opt-out mechanism.

12.4 Non-Discrimination

We will not discriminate against you for exercising your CCPA rights.

To exercise CCPA rights, email privacy@edunxtai.info with "California Privacy Request" in the subject line.


13. Contact Us

13.1 Privacy Questions

For questions about this Privacy Policy or our data practices, contact us at:

13.2 Grievance Officer (India)

As required under Indian law, our designated Grievance Officer is:

The Grievance Officer will acknowledge complaints within 24 hours and resolve them within 15 days.

13.3 Data Protection Officer (If Applicable)


14. Consent and Acknowledgment

By using the Service, you acknowledge that:

  • ✓ You have read and understood this Privacy Policy
  • ✓ You consent to the collection, use, and disclosure of your information as described
  • ✓ You understand that content errors may exist and we are not liable for consequences
  • ✓ You are aware of your rights and how to exercise them
  • ✓ You consent to international data transfers (if applicable)
  • ✓ If creating an account for a minor, you have parental authority and provide consent

IF YOU DO NOT AGREE WITH THIS PRIVACY POLICY, DO NOT USE THE SERVICE.