Privacy Policy

What personal data we collect, why, and your rights under India's DPDP Act.

Last updated: 25 July 2026

Neev (नींव) ("Neev", "we", "us") is a service operated by Neev Study, a sole proprietorship, at neevstudy.com. This Privacy Policy explains what personal data we collect, why, who we share it with, and your rights. We act as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). By using the Service you consent to the processing described here for the stated purposes.

1. Data we collect

  • Account and authentication data. Your email address (and, if you sign in with Google where available, your Google account identifier and name). Authentication is handled by our provider, Supabase Auth. Your password, if you set one, is stored by Supabase in hashed form; we never see it in plain text.
  • Profile data. Display name, preferred language (Hindi/English), target exam year, medium, study-hours preference, and a public community handle if you use community features.
  • Your submissions. Descriptive answers you type; photos of handwritten answers you upload; the text extracted from those photos (OCR); custom questions or prompts you enter; and questions you ask the AI mentor.
  • Learning activity. Your MCQ attempts and answers, quiz and mock-test results and timings, spaced-repetition cards and reviews, saved notes, study plans, and reading and progress signals.
  • Community data. Discussion posts, votes, answers you choose to share for peer review, and reports you file. These are visible to other users under your handle or display name.
  • Usage analytics. First-party product events (for example, that a chapter was opened) tied to your account, used to operate and improve the Service. We do NOT use third-party advertising or tracking analytics (no Google Analytics, Meta, Mixpanel, and the like).
  • Device and notification data. If you enable push notifications, your browser's push subscription (endpoint and keys) and browser or device string.
  • Payment data. When you buy Pro, our payment partner Razorpay processes your payment. We receive and store order and payment identifiers, amount, currency, and subscription status — never your full card number or CVV (see 'Payments — Razorpay' below).
  • Trial-integrity signal. On sign-up we store a one-way salted hash of your IP address (never the raw IP) solely to detect abuse of the free-trial system. It is reviewed only manually and is never used to profile you.

Email addresses and any phone number are held within our authentication provider (Supabase Auth), not in our application profile records.

2. How we use your data

We use your data to provide and operate the Service; to run AI evaluations, OCR, and the mentor and generate your feedback, scores and model answers; to track your progress and personalise study recommendations; to process payments and manage your plan; to send account and service-related communications; to keep the Service secure and prevent abuse; to comply with law; and to improve the Service using aggregated or first-party usage data.

3. AI processing and the data we send to AI providers

Several features are powered by third-party AI providers. When you use these features, the relevant content is transmitted to the provider to generate a result:

  • Anthropic (Claude models) receives: your typed answer text and question when you request an evaluation; your uploaded handwritten page images for transcription (OCR) and, for the presentation score, the first page image; your mentor and doubt questions and conversation; and, where you use in-depth mentor research, your topic (which may be used with the provider's web-search tool). Community posts are also screened for abuse, spam, and personal information by an AI model.
  • OpenAI receives text (for example, your mentor question and question text) to create numeric "embeddings" used for search and to find relevant study material. Your descriptive answer text is not sent to OpenAI.

These providers process the content to return a result to us. Under their commercial API terms as of the date of this Policy, Anthropic and OpenAI state that they do not use API inputs or outputs to train their models, and delete them within their standard retention window (generally up to 30 days for abuse-monitoring). We do not control these providers; please refer to their own policies for details. We send only what a feature needs to function.

4. Payments — Razorpay

Payments are processed by Razorpay Software Private Limited. Your card, UPI, or bank details are entered on Razorpay's secure checkout and are handled by Razorpay under its own privacy policy and PCI-DSS obligations. We do not receive or store your full card number or CVV. We store the payment and order identifiers, amount, subscription status, and the payment processor's transaction records needed to provide your subscription and meet legal and accounting obligations.

5. Emails

Account emails — such as login one-time-passwords, sign-up confirmation, and password reset — are sent through our authentication provider, Supabase Auth, using its built-in email service. We do not currently run separate marketing email campaigns.

6. Who we share data with (sub-processors)

We do not sell your personal data. We share it only with service providers that help us run the Service, under their terms:

  • Supabase — hosting, database, storage, and authentication. Involves your account, profile, all your learning data, and uploaded images.
  • Anthropic — AI evaluation, OCR, mentor, and content moderation. Involves your answer text, uploaded images, mentor questions, and community post text.
  • OpenAI — text embeddings for search and study-material matching. Involves your mentor questions and question text.
  • Razorpay — payment processing. Involves payment and transaction data (no full card data is held by us).

If we enable error-monitoring (Sentry) in production, limited diagnostic and request data may be shared with it; this Policy will reflect it when active. We may also disclose data where required by law or to protect rights and safety.

7. International transfers

Some providers above (notably the AI providers) process data on servers outside India. Where we transfer personal data internationally, we do so in accordance with the DPDP Act and applicable law. By using the AI features you consent to this transfer for the purpose of providing them.

8. Data retention

We retain your personal data for as long as your account is active and as needed to provide the Service, and thereafter as required to comply with legal, tax, and accounting obligations or to resolve disputes. Uploaded handwritten images and their transcriptions are retained to show your submission history unless you request deletion. AI providers retain API data only for their own limited retention window (see 'AI processing' above).

9. Your rights

Under the DPDP Act you have the right to:

  • Access your data — you can download your practice attempts and answer submissions with their AI evaluations from Profile → Settings → Export my data. For a copy of other data we hold, contact us.
  • Correct or update your profile data in the app, or by contacting us.
  • Erase your data or delete your account — self-service account deletion is not yet available in the app; to request deletion, email [email protected] and we will delete your account and associated personal data, subject to any records we must retain by law.
  • Withdraw consent for optional processing (for example, disable push notifications in Settings), and nominate another person to exercise your rights in the event of death or incapacity, as provided by the DPDP Act.
  • Grievance redressal — see 'Grievance and contact' below.

10. Security

We protect your data with measures including: strict per-user database access controls (row-level security), so one user cannot read another user's data; authenticated, token-verified API access; private storage for your uploaded images, isolated to your own account so no other user can access them; signed, verified payment webhooks; a salted hash instead of a raw IP for the trial signal; and encryption in transit (HTTPS/TLS) for data moving between you, us, and our providers. Data at rest is protected by our hosting provider's encryption. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children

The Service is intended for candidates preparing for the UPPSC examinations and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

12. Grievance and contact

For any questions, requests, or grievances about your personal data or this Policy, contact our grievance contact at [email protected]. We will acknowledge and address grievances within the timelines required by the DPDP Act (within 90 days).

13. Changes

We may update this Policy. Material changes will be reflected in the "Last updated" date and, where appropriate, notified in the app. Continued use after changes means you accept the updated Policy.