Privacy Policy
This page explains what information Disha (the ConversalX Tutor product) collects about a student and their guardian, why, and what a guardian can do about it. It is written in plain language, not legal language, and describes what the product currently does — not a promise of what it will always do.
What we collect
- Student account: a username and password/PIN chosen at signup, and the student's class level (1-12). We do not require the student's real name.
- Guardian contact: an email address or phone number, provided by the guardian, used only for account recovery, new-device login notices, and (if enabled) a daily progress email. This is stored in encrypted form, not as plain text.
- Learning activity: questions asked, curriculum topics covered, quiz/exercise interactions, and a points record used to show progress and unlock in-app rewards.
- Generated audio: if a guardian or student uses the "listen" feature, the spoken-audio file for that chapter may be cached for reuse.
- Safety and audit records: a record of AI interactions is kept for safety and accountability purposes, currently retained for 1,095 days (3 years).
How this data is used
To operate the tutoring service itself (answering questions, tracking progress, showing rewards), to let a guardian recover a student's account or receive a progress update, and to maintain a safety record in case a conversation needs human review.
Third-party AI providers
Disha's answers, and (optionally) spoken audio, are generated using third-party AI services (providers such as OpenAI, Groq, and/or Google, depending on what is configured for this deployment at any given time). Before any message is sent to one of these providers, identifying details are replaced with anonymous placeholders — the provider does not receive the student's name, guardian contact, or other direct identifiers.
Where data is processed and how long it is kept
[FOUNDER/LEGAL TODO] This deployment is not currently configured to restrict data processing to a specific region, and is built around India's Digital Personal Data Protection (DPDP) Act. If students or guardians outside India will use this product, or if a specific data residency commitment is needed, that needs to be confirmed and reflected here before this is final. Safety/audit records are kept for 3 years; how long other data is kept after an account is no longer in use has not yet been decided and needs to be filled in here.
A guardian's rights
- Withdraw consent at any time from the consent page — the student's account is immediately paused until consent is given again.
- Review and accept policy updates — if this policy or another one changes in a meaningful way, the guardian will be asked to review and re-accept just the updated part, the next time the student's account is used.
- Request access to or deletion of data — [FOUNDER TODO] this is not yet a self-service feature in the product. Add a real contact method here so a guardian can make this request directly until a self-service option exists.
Questions
[FOUNDER TODO] Add a real contact email or method for privacy questions here.
← Back