← Back

Privacy Policy

Effective 4 August 2026 · Neurobit

1. Scope

This Privacy Policy (the "Policy") describes the manner in which Neurobit ("Neurobit", "we", "us", or "our") collects, processes, stores, discloses, and otherwise handles personal data in connection with the Neurobit application and all related services, features, and interfaces (collectively, the "Service"). This Policy applies to every user of the Service ("you", or a "Data Principal" within the meaning of India's Digital Personal Data Protection Act, 2023 (the "DPDP Act")). Enquiries concerning this Policy may be directed to privacy@neurobit.in.

3. Categories of personal data processed

We process the following categories of personal data:

  • Account and identity data — name and email address, furnished at registration and profile completion.
  • Academic profile data — year of study and institution, processed to provision the appropriate curriculum path.
  • Learning-activity data — records of content accessed and completed, progression state, bookmarks, revision scheduling data, and session timing, processed to operate core Service functionality and for aggregated product analysis.
  • Assistant interaction data — the text of queries submitted to the in-app study assistant and associated response feedback. Assistant responses are generated from our curated study material or, where unavailable, from general machine-generated knowledge identified as such within the interface; such output is provided without warranty of accuracy and must be independently verified before reliance. Certain responses are retained within your account for a period of ninety (90) days and may be deleted by you at any time.
  • User-submitted materials — where you submit photographs or documents of your own study notes, such materials and the text extracted therefrom by automated character-recognition processing are stored within your account and may be deleted by you at any time or upon account deletion.
  • Feedback submissions — the content of feedback you submit through the Service, together with contextual references to the material concerned, processed for quality assurance and relayed to internal operational channels for triage.
  • Notification data — where you opt in to reminders, the technical subscription identifiers required to effect delivery of push notifications to your device. Opt-out is available at any time through your device or browser settings.
  • Device and technical data — device type, operating system, browser characteristics, and a coarse, non-identifying technical signal derived therefrom, processed for service integrity, abuse prevention (including detection of account sharing), and analytics accuracy. Such data is not used for cross-application tracking or advertising.
  • Approximate location data — country-, region-, and city-level location inferred from network (IP) address at authentication, processed for security monitoring and aggregate usage analysis. Precise (GNSS-level) location is not collected.
  • Usage and diagnostic data — interface views, in-application interactions, session replays of such interactions, and associated network telemetry generated in the course of your use of the Service, processed for diagnostics and product improvement. Text entered into input fields, including credentials, is masked and is not recorded. Such collection is confined to activity within the Service.

We do not collect financial account information (beyond that processed by a payment provider where applicable), precise location, health records, contacts, communications, or data from other applications on your device.

4. Purposes of processing

Personal data is processed for the following purposes:

  • establishment, administration, and security of your account;
  • provision and personalisation of the Service and its features;
  • delivery of notices and reminders to which you have subscribed;
  • aggregated analysis of Service usage, including analysis within internal, non-identifying groupings which are used solely in aggregate and are not disclosed to you or to any other user; and
  • prevention and detection of fraud, abuse, and technical failure, and compliance with applicable legal obligations.

5. Disclosures

We do not sell personal data and do not disclose personal data to third parties for advertising purposes. Personal data is disclosed only to data processors engaged to operate the Service on our behalf, each bound by contractual confidentiality and data-protection obligations restricting processing to the purposes for which it was engaged. Such processors fall within the following categories:

  • Cloud infrastructure and hosting — provision of the computing, storage, and delivery infrastructure on which the Service operates.
  • Authentication and database services — maintenance of account records and application data behind restricted access controls.
  • Product analytics — receipt of usage signals and masked interaction replays, together with name, email address, institution, year of study, and account plan, for the sole purpose of aggregate product analysis. Such data is not used for advertising and is not onward-disclosed.
  • Error monitoring — receipt of technical fault data (device and browser characteristics, fault particulars, and an internal account identifier; never name or email address) for the purpose of fault diagnosis and remediation.
  • Operational alerting — relay of limited operational notices, including feedback text and truncated internal identifiers (never email addresses or complete account identifiers), to internal team channels.
  • Notification delivery — transmission of the push notifications to which you have subscribed.
  • Automated language and vision processing — processing of assistant queries together with relevant study material or scheduling state (never name or email address) solely to generate responses; and conversion of user-submitted note materials to text.

Where the Service makes available features permitting the sharing of study materials between users, personal data is further disclosed to other users solely where sharing is initiated by you and at your direction. Such sharing is subject to your explicit consent, given separately for each category (folder) of user-submitted note materials, recorded at the time it is given, and revocable within the Service at any time; upon revocation, further access by other users is discontinued. Access to shared note materials is confined to registered users of the Service. The categories of personal data disclosed in connection with such sharing comprise your first name, the title and topical structure of the shared collection, only where per-category consent has been given, the user-submitted note materials within the consented categories, and, where you elect to share flashcards, the text of the flashcards you select. Your first name and the title and topical structure of a shared collection are visible to any person in possession of the sharing link. The text of shared flashcards is disclosed only to registered users who elect to receive them, and not to any person merely in possession of the link. Text extracted from note materials by automated character-recognition processing is not disclosed to other users.

Where you elect to share flashcards, a copy is created in the account of each recipient who receives them, and that copy is thereafter the material of the recipient. Withdrawal of sharing prevents the creation of further copies and does not delete copies already created. This is disclosed to you before sharing and to the recipient before receipt.

We may further disclose personal data where required by law, regulation, or legal process, or where reasonably necessary to protect the rights, safety, or security of users, the public, or the Service.

6. Retention

Personal data is retained for the duration of your account's existence and thereafter only to the extent required by applicable law or for the establishment, exercise, or defence of legal claims. Upon account deletion, personal data is removed from active systems in accordance with Section 8.

7. Security

We maintain technical and organisational safeguards appropriate to the nature of the data processed, including encryption of data in transit and least-privilege access controls under which each user's data is accessible only to that user and to authorised administrators. No security measure is absolute, and we do not warrant that the Service is immune from compromise.

8. Rights of the Data Principal

Subject to applicable law, you are entitled to:

  • access the personal data held in relation to you;
  • correction of inaccurate or incomplete personal data;
  • erasure of your personal data and deletion of your account;
  • withdrawal of consent to processing; and
  • nomination of another individual to exercise these rights in the event of death or incapacity.

Requests may be made from your registered email address to privacy@neurobit.in and will be verified and actioned within the periods prescribed by applicable law. Profile data may be corrected directly within the Service, and account deletion is available in-application.

9. Minors

The Service is intended for students enrolled in higher education. Individuals under the age of eighteen (18) may use the Service only with the verifiable consent of a parent or lawful guardian as required by the DPDP Act. We do not knowingly process the personal data of a child absent such consent; notify us at the address above if you believe such processing has occurred and it will be addressed without undue delay.

10. Amendments

This Policy may be amended from time to time. Material amendments will be reflected in the effective date above and, where appropriate, notified within the Service. Continued use of the Service following the effective date of an amendment constitutes acceptance of the amended Policy.

11. Grievance redressal

Questions concerning this Policy, requests to exercise the rights described herein, and grievances concerning the handling of personal data may be addressed to the Grievance Officer at privacy@neurobit.in. Grievances will be acknowledged and resolved within the periods prescribed by the DPDP Act.

Grievances concerning material submitted or shared by users of the Service, including complaints that such material is infringing, unlawful, or otherwise objectionable, may likewise be addressed to the Grievance Officer at the address above or raised through any reporting mechanism provided within the Service, and will be acknowledged and disposed of within the periods prescribed by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and other applicable law.

See also our Terms of Use.