Privacy Policy

Effective date: 6 June 2026 - Last updated: 6 June 2026

This Privacy Policy is published in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules made thereunder. It explains how we collect, use, share, store and protect your personal data, and the rights available to you.

StudyBench ("we", "us" or "our") collects, uses, processes, discloses and safeguards the personal data of users ("you", "your", "User" or, under the DPDP Act, the "Data Principal") who access or use the StudyBench website, web application and related services (collectively, the "Platform").

For the purposes of the DPDP Act, 2023, StudyBench is the Data Fiduciary that determines the purpose and means of processing your personal data. By creating an account or using the Platform, you confirm that you have read and understood this Policy. If you do not agree, please do not use the Platform.

1. Key Definitions

  • Personal Data means any data about an individual who is identifiable by or in relation to such data.
  • Data Principal means the individual to whom the personal data relates (you).
  • Data Fiduciary means the entity that determines the purpose and means of processing (StudyBench).
  • Data Processor means a person who processes personal data on behalf of a Data Fiduciary (e.g. our hosting and payment partners).
  • Processing means any operation performed on personal data, including collection, storage, use, sharing and erasure.
  • Sensitive Personal Data or Information (SPDI) has the meaning given under the IT Rules, 2011 (e.g. passwords and financial information).

2. Information We Collect

We collect only the data needed to provide and improve the Platform:

a) Account & identity data

  • Email address and an authentication credential. Passwords are never stored in plain text - they are salted and hashed by our authentication provider (Supabase).
  • If you choose Google Sign-In, the basic profile information Google shares (name, email and Google account identifier) under your Google consent.

b) Educational profile data

  • Name, college/institution, branch/stream and expected graduation year.
  • Academic indicators you choose to enter, such as CGPA.
  • Your target companies and preparation preferences.

c) Usage & performance data

  • Quiz and mock-test scores, chapter progress, your Placement Readiness Index (PRI), XP, levels, streaks, badges and topic-wise accuracy.
  • Interactions with lessons, practice questions and daily challenges.

d) Payment-related data

  • Subscription status and transaction references for any premium purchase.
  • We do NOT collect or store your card number, CVV or UPI PIN. All payments are processed on the secure, PCI-DSS-compliant infrastructure of our payment gateway (Razorpay). We receive only a payment confirmation and reference identifier.

e) Technical & device data

  • IP address, browser type, device and operating-system information, and approximate location derived from IP.
  • Log data, session cookies and similar identifiers necessary to keep you signed in and to secure the Platform.

3. How We Collect It

  • Directly from you - when you register, complete onboarding, edit your profile, take quizzes/mocks, or contact us.
  • Automatically - through cookies, log files and analytics when you use the Platform.
  • From third parties - from Google (if you use Google Sign-In) and from our payment gateway (payment status only).

4. Purposes and Lawful Basis of Processing

We process your personal data on the basis of your consent and, where applicable, the legitimate uses permitted under Section 7 of the DPDP Act, 2023. We use your data to:

  • Create and manage your account and authenticate you securely.
  • Personalise your preparation, compute your PRI and estimated placement probability, and recommend chapters, practice and mocks.
  • Operate gamification features (XP, levels, streaks, badges) and analytics (weakest/strongest topics).
  • Process subscriptions and provide customer support.
  • Maintain security, prevent fraud and abuse, and debug and improve the Platform.
  • Send service communications and, only with your consent, product updates. You can opt out of non-essential communications at any time.
  • Comply with applicable law and respond to lawful requests.

We do not sell your personal data, and we do not use your data for automated decisions that produce legal or similarly significant effects on you. Your PRI and placement probability are study aids and estimates only, not determinations about your employability.

6. Children's and Students' Data

The Platform is intended for college students and job-seekers. Under Section 9 of the DPDP Act, 2023, where a User is a child (below 18 years of age), we will process personal data only after obtaining verifiable consent from a parent or lawful guardian, and we will not undertake tracking, behavioural monitoring or targeted advertising directed at children, nor any processing likely to cause harm to a child.

If you are below 18, please use the Platform only with the involvement and consent of your parent or guardian. If we learn that we have collected a child's data without the required consent, we will delete it promptly.

7. Cookies and Similar Technologies

We use strictly necessary cookies to keep you signed in and to secure sessions, and limited functional/analytics cookies to understand and improve usage. You can control cookies through your browser settings; disabling essential cookies may break sign-in and core features.

8. How and With Whom We Share Data

We share personal data only as described below, and never sell it:

  • Data Processors / service providers - engaged under contract to process data on our instructions, including Supabase (cloud hosting, database and authentication), Razorpay (payment processing) and our email/communication providers.
  • Legal and safety - where required by law, court order, or a lawful request by a government authority, or to protect the rights, safety and property of StudyBench, our Users or the public.
  • Business transfers - in connection with a merger, acquisition, restructuring or sale of assets, subject to the acquirer honouring this Policy.
  • With your consent - for any other purpose disclosed to you at the time.

9. Sub-Processors and Cross-Border Transfer

Our infrastructure provider hosts data in a data-centre region (currently the Asia-Pacific / Mumbai region). Where any processing or storage occurs outside India, such transfer is undertaken in accordance with Section 16 of the DPDP Act, 2023 and applicable government notifications, with contractual safeguards requiring our processors to maintain confidentiality and security comparable to those described in this Policy.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes set out in this Policy, to provide the Platform, and to comply with legal, tax and accounting obligations. When you delete your account, we will delete or irreversibly anonymise your personal data within a reasonable period, except where retention is required by law or for the establishment, exercise or defence of legal claims.

11. Security Safeguards

In line with Section 43A of the IT Act, 2000 and the IT Rules, 2011, and the security obligations of the DPDP Act, 2023, we implement reasonable security practices, including encryption of data in transit (HTTPS/TLS) and at rest, hashed passwords, row-level access controls so each User can access only their own records, least-privilege access for staff, and monitoring. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security; you are responsible for keeping your credentials confidential.

12. Personal Data Breach Notification

In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act, 2023, and will comply with applicable CERT-In directions (2022) on incident reporting.

13. Your Rights as a Data Principal

Subject to applicable law, you have the right to:

  • Access a summary of the personal data we process about you and the processing activities.
  • Correction, completion and updating of inaccurate or incomplete data (you can edit most fields in Settings).
  • Erasure of your personal data where it is no longer required.
  • Withdraw consent at any time.
  • Grievance redressal - to readily raise grievances with our Grievance Officer.
  • Nominate another individual to exercise your rights in the event of death or incapacity.

To exercise any right, email smartonboardai@gmail.com or contact our Grievance Officer (Section 16). We may need to verify your identity before acting on a request.

14. Your Responsibilities

Under the DPDP Act, 2023, you agree to provide accurate and genuine information, not to impersonate another person, not to suppress material information, and not to file false or frivolous grievances. You are responsible for the data you enter (such as CGPA or college details).

15. Third-Party Links and Services

The Platform may reference or link to third-party websites and services (including official company career pages and educational resources). We are not responsible for the privacy practices or content of those third parties; please review their policies separately.

16. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified through the Platform or by email, and the "Last updated" date will be revised. Your continued use after changes take effect constitutes acceptance.

17. Grievance Officer and Contact

In accordance with Rule 3(2) of the IT (Intermediary Guidelines) Rules, 2021 and the DPDP Act, 2023, the details of our Grievance Officer are:

Grievance Officer: The Founders, StudyBench - Email: smartonboardai@gmail.com - Address: Erode, Tamil Nadu - 638001, India - Response acknowledged within 24 hours and resolved within 15 days, in line with the IT Rules, 2021 and the DPDP Act, 2023.

General privacy queries: smartonboardai@gmail.com - General support: smartonboardai@gmail.com.

18. Governing Law and Jurisdiction

This Policy is governed by the laws of India. Subject to the Terms & Conditions, the courts at Erode, Tamil Nadu, India shall have jurisdiction over any dispute arising out of or relating to this Policy.