Privacy Policy
Last updated: October 2, 2026 · Version 2026-09-16
Gri-Learn, by Grishu, is a learning platform for B.C.A. students, on the web at grilearn.com and as the Gri-Learn mobile app. It is built and run by one person in Gujarat, India. This page says what we store when you use either one, why, who else touches it, how long we keep it, and how to get rid of it. If anything here is unclear, write to us and a person will answer.
Who is responsible: Grishu, contactable at info@grilearn.com. Under India’s Digital Personal Data Protection Act, 2023 we are the data fiduciary for everything below, and that address is also our grievance contact.
What we collect, and why
Your account
- Your name and email address, to sign you in and to address you inside the app. If you set a password we store only a bcrypt hash of it, never the password itself.
- How you sign in. If you use Continue with Google or Sign in with Apple, we store the account identifier that provider gives us so we recognise you next time. We never receive your Google or Apple password.
- Your date of birth, asked once when you first sign in. We use it for one thing: knowing whether an account belongs to someone under 18, which the law treats differently. See Students under 18 below.
- Your consent record: when you agreed, which version of this page you agreed to, and whether you asked for reminder email. Every change to that is recorded, so we can show you what you agreed to and when.
Where you study
- Your university, your college and your semester, so the app opens on the right syllabus and the right year. If you type in a college that is not in our list, we keep that name so we can check it and add it.
- Your exam date, if you set one, for the countdown.
What you do in the app
- Your learning: which topics you finish, the answers you give to the questions inside a lesson, your points, stars, streak and challenge scores. This is the product: without it there is no progress to show you and no streak to keep.
- Sign-in records: each time you sign in, register, change your password or delete your account, we record that it happened, with your name and email address, so we can look into a problem with your account or an attempt to get into it.
- Sign-in link requests: when anyone asks for an emailed sign-in link or a password reset, we store the address it was sent to and a hash of the link, until the link is spent. This happens even for an address that has no Gri-Learn account, because that is how we send the email.
Numbers that are not about you
- Topic views: which topic was opened, on web or on the phone, and when. No account and no device is attached, so we can count what is read without knowing who read it.
- Installs: the mobile app sends one ping a day with a random identifier it generates for itself, the platform, the app version and your study year. It is not linked to your account and we use it only to count installs and active devices.
- Visits, sign-ups and shares: for each day, how many times our public pages were opened, how many accounts were made and how many times a share button was pressed, split by where the visitor came from when the link they used carried a tag (for example a link shared from the app). No account, no device and no address is attached to these numbers. If you arrive through a tagged link, your browser keeps that tag, and nothing else, in a cookie for 30 days, so that signing up adds one to that tag’s count.
- Opened from the app: when the Gri-Learn app opens a page of this website, your browser keeps a second cookie, which lapses an hour after you stop studying there. It holds no identifier, only a mark that the visit came from the app, so the website leaves out its links to prices and payment. It is read only by our website, linked to no account, and counted nowhere. On Android the app’s browser shares cookies with Chrome, so Chrome on the same phone sees the mark too until it lapses.
When something breaks
If the app or the server hits an error, we send a crash report to Sentry containing the error, the code path it came from, the page or route, and your database identifier so we can tell one student’s reports apart. Those reports are deliberately stripped of your email address, your cookies, request headers, request bodies, query strings and your IP address before they leave us.
A report from the phone app also carries your device model, your Android or iOS version and which build of the app you are running. That is how we can fix a crash that only happens on one kind of phone, which is otherwise invisible to us. It never includes a screenshot, a recording of your screen, or a copy of what is on it: those are switched off in the code, not merely left unused.
On your device only
Both surfaces keep a few things locally that never reach us: your chosen language and theme, recently viewed topics, and any lesson you finish while offline, which is sent as soon as you are back online and then removed. Clearing the app’s storage clears all of it.
What we do not do
- We do not sell your personal data, and we never will.
- We show no advertising and carry no advertising or tracking SDK, on either surface.
- We do not collect your location, your contacts, your photos or your files.
- We do not use your work to train an AI model, and we do not send your answers to any AI service.
Who else processes it
We do not share your data with anyone who wants it for their own purposes. We do rely on these companies to run the platform, and they process it on our instructions only:
- Supabase (Singapore) hosts the database everything above lives in.
- Render (Singapore) runs the Gri-Learn server, and Cloudflare sits in front of it, so a request to our API passes through their network.
- Vercel serves the website, so a visit to grilearn.com reaches their servers first.
- Brevo delivers our email, so it receives the address a message is going to and its contents.
- Microsoft (Microsoft 365) hosts our mailbox, so what you write to info@grilearn.com, and the address you write from, is stored on their servers.
- Sentry receives the crash reports described above.
- Google and Apple, if you choose their sign-in, confirm to us that the account is yours.
- Google Fonts. The website loads its typefaces and icons from Google’s servers, which means your browser tells Google your IP address and which page asked. We would rather serve those files ourselves and are working towards it; until then, this is the one transfer that happens whether or not you have an account.
Some of these companies are outside India, so your data is processed abroad. We use them because a one-person platform cannot run its own data centre, and we pick the region closest to our students where the choice exists.
Students under 18
A B.C.A. intake includes students who are still 17, so this is not a hypothetical section.
- When you first sign in we ask your date of birth. If it says you are under 18, we ask for a parent or guardian’s name and email address, and for their agreement. Fill that in with them, not for them.
- We then email that parent or guardian a copy of what the account is, what we keep, and a link that removes the account in one press if they did not agree.
- We send no reminder email at all to an account under 18.
- We do no tracking, profiling or targeted advertising for any account, and none for a child in particular. The DPDP Act forbids it, and we had nothing of the kind to remove.
- When that student turns 18, we ask them once, as themselves, and the guardian’s details are removed from the account when they answer.
How long we keep it
- Your account and your learning: until you delete the account, or withdraw your consent, which does the same thing.
- Sign-in records: 180 days, then removed automatically.
- Sign-in link rows: 7 days after the link expires.
- Topic views: 180 days.
- Install pings: a year after a device last opened the app.
- Crash reports: kept by Sentry under their own retention policy, and not copied anywhere else by us.
- Payment records: kept for tax and accounting after the account is deleted, with your name and email address removed.
Your rights, and how to use them
- See what we hold. Most of it is on your own screens: Settings, Progress and your profile. For anything else, email us and we will send you a copy.
- Correct it. Your name, college and semester are editable in Settings (in the app, your name is on Profile). For your email address or your date of birth, email us.
- Delete it. On the website, Settings then Delete account. In the app, Profile then Delete account. Your account, your sign-in, your progress and your quiz history go immediately, your sign-in records stop naming you, and any unused sign-in link for your address is destroyed so nothing can bring the account back. If you ever paid, what you bought, the amount, the date, the receipt number, any coupon code, the type of payment (for example UPI or a card network) and Razorpay's reference for it stay. We have to keep these for tax and accounting. Your name and email address are removed from them. Razorpay, which took the payment, keeps its own record of it, and its reference is how the two records match.
- Delete it without signing in. grilearn.com/delete-account takes an email address and sends that inbox a link with one button on it. You do not need a password, a session or the app installed, which matters if you have changed phone or cannot get back in. It does exactly what the row above does.
- Withdraw your consent. Settings then Your consent then Withdraw consent, on either surface. Your account and your learning are held on your permission, so withdrawing it deletes the account, exactly as Delete account does: there is no honest halfway state where we keep your data but stop using it, so we do not pretend to offer one. Payment records, which the law requires us to keep, stay without your name, as described above. Anything your account includes ends with it, including days you have not used, so if you paid for something and want a refund, write to us before you withdraw.
- Stop the reminder email. The switch is in Settings, and every reminder has a one press way out at the foot of it. It does not need your password and it changes nothing else.
- Complain. Write to info@grilearn.com and we will answer. If we do not resolve it, you can take it to the Data Protection Board of India.
If something goes wrong
Passwords are stored as bcrypt hashes. Sessions use a token in an httpOnly cookie on the web and secure storage on the phone, and signing out, changing a password or a reset ends every session that token belongs to. If we ever discover a breach that affects your data, we will tell the Data Protection Board of India and every affected student, by email, with what happened and what to do about it.
When this page changes
This page carries a version, and your consent is recorded against the version you read. If we change what we collect or who processes it, the version moves and the app asks you again, showing you the new text first. We do not treat an old yes as an answer to a new question.
Contact
Questions about this policy, or about your data: info@grilearn.com.