1. Who We Are
NeetFlash is a brand and trading name of Suravija Technologies Private Limited ("Suravija", "we", "us", "our"), a company incorporated in India. Suravija Technologies Private Limited develops, owns, and operates the NeetFlash app and is the Data Fiduciary responsible for your personal data under the DPDP Act, 2023. Throughout this Privacy Policy, references to "NeetFlash", "we", "us", or "our" mean Suravija Technologies Private Limited.
NeetFlash is a mobile application designed to help students prepare for the NEET (National Eligibility cum Entrance Test) examination in India. This privacy policy explains how we collect, use, store, and protect your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
2. Lawful Basis for Processing
We process your personal data on the following bases under the DPDP Act, 2023:
- Consent - You provide consent when you create an account, agree to these terms, and use features that collect data (e.g., search queries).
- Legitimate use - Certain processing is necessary to provide the service you requested (e.g., scheduling spaced repetition reviews, enforcing usage limits, processing payments).
- Legal obligation - We may process data to comply with applicable Indian law or valid legal process.
3. Information We Collect
Account Information
- Phone number - Used for OTP-based login authentication
- Google account email - If you sign in with Google
- Display name - A name you set when you create your account. Providing a name is required (the default placeholder must be replaced before you can use the app), and you can change it anytime in Settings. It is shown on your home screen and to your school if you join one under a school licence.
Parental Consent Contact Details (for users under 18)
- Parent's mobile number - Collected during onboarding (Path A). It is the only thing that connects a parent to their child: the parent signs in to NeetFlash with that number, and the number they prove they control is matched against the one the student gave. We do not ask the student for their parent's email address. See Section 11 for full details on how this is used and retained.
Referrals
- Referrer-referee relationship - If you sign up using another user's referral code, we record who referred you and the timestamp, in order to credit the referrer with the applicable reward and enforce referral caps. We do not share your identity with the referrer beyond the fact that a successful referral occurred.
Card Reports
- Reports you submit on flashcards - If you flag a card as incorrect or misleading, we store the card identifier, the reason you provided, and your user ID so we can follow up if needed.
Study Data
- Flashcard progress - Which cards you've reviewed, your ratings, and spaced repetition scheduling data
- Assessment results - Baseline assessment scores and subject-wise performance
- Usage statistics - Daily counts of cards reviewed, tutor questions asked, and searches performed
- AI credit ledger - your AI credit balance and an append-only record of credit grants, purchases, and spends (including which AI feature spent them and when), kept so we can meter AI usage accurately and resolve any billing query
- Streak data - Consecutive days of study activity
Parent-Child Linking
- A parent becomes linked to a student either by approving them in the app (after signing in with the mobile number the student gave) or by sharing an invite code the student redeems. In both cases the parent can then view the student's study progress (read-only). Parents cannot access the student's personal data beyond study statistics.
School Licence (for students enrolled by a school or institution)
- Seat-allocation details - If your school enrols you by reserving a seat for you, your school provides us with your mobile number and email address so we can hold that seat; the seat is claimed automatically when you first sign in with that number. Alternatively, you may join by entering a single-use join code your school gives you. A join code is tied to your account only once you redeem it.
- Visibility to your school administrator - While you are enrolled under a school licence, your school's administrator can view your roster entry and your study-activity analytics (read-only) for the duration of the licence - the same study insights a linked parent can see: your streak and activity, subject coverage and readiness, retention forecast, weak spots, and your mock-test and chapter-test history. Your school administrator cannot see or change your account credentials, and cannot modify your study data. How schools may use this is governed by our School Agreement.
Exam Jam Data (Optional multiplayer feature)
- Display name - Captured as a snapshot when you join a jam room. Shown in the live participant roster and on result screens, and broadcast in real time to other participants in the same room.
- Session statistics - Your score, correct/wrong counts, best in-session streak, and per-question response time within an Exam Jam session. These are separate from your daily study streak.
- Answer events - The option you selected on each jam question, whether it was correct, and whether the question auto-advanced before you answered.
- Spectator flag - Whether you joined the room as a participant or as a read-only spectator.
- Session timestamps - When you joined and when you finished a jam room.
Exam Jam display names and live scores are visible only to participants in the same room while the session is active. They are not shown outside the room and are not used for advertising or profiling.
Analytics and Crash Reporting
- Firebase Analytics (Google) - We collect anonymised app usage events (e.g., cards reviewed, searches performed, sessions completed, upgrades) and a user property indicating your subscription plan. This data helps us understand how the app is used and improve the experience. Firebase Analytics may collect device model, OS version, and app version. No personally identifiable information is sent to Firebase.
- Sentry (Functional Software) - If enabled, crash reports are sent to Sentry for error monitoring. These reports may include device model, OS version, app version, and technical stack traces. No flashcard content, AI Tutor messages, or personal study data is included in crash reports.
4. Information We Do NOT Collect
- Health or medical information
- Financial information (payments are processed entirely by the app store — Apple App Store or Google Play — so we never see your card/UPI details)
- Biometric data
- Location data
- Contact lists or SMS
- Photos, camera, or microphone data
- Device identifiers for advertising
5. How We Use Your Information
- Authentication - To verify your identity and maintain your account
- Study experience - To schedule flashcard reviews using spaced repetition, track your progress, and identify weak areas
- Search - To run semantic search across flashcards using Voyage AI embeddings of your query text
- Usage limits - To enforce free-tier daily limits, meter AI-credit balances, and manage premium subscriptions and credit-pack purchases
- Parent monitoring - To allow linked parents to view study progress (if opted in by the parent)
- School licence administration - To reserve and activate Premium seats for students enrolled under a school or institution licence, and to let the school's administrator view roster and study-progress information for those students
- Analytics - To understand aggregate usage patterns and improve the app
- Error monitoring - To identify and fix bugs and crashes
6. Data Storage and Security
- All data is stored on Supabase (hosted on AWS infrastructure in the Mumbai region, ap-south-1)
- Database access is protected by Row-Level Security (RLS) - users can only access their own data
- All API communications use HTTPS encryption
- Authentication tokens are managed by Supabase Auth with automatic refresh
- Admin access requires separate authentication with HMAC-signed session cookies
- Brute-force protection on parent portal login (15-minute lockout after 5 failed attempts)
7. Data Sharing and Third-Party Processors
We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes. We share data only with the following service providers who process it on our behalf:
| Provider | Data shared | Purpose | Privacy policy |
|---|---|---|---|
| Voyage AI (USA) | Search query text | Generating semantic embeddings for search results | voyageai.com/privacy |
| Apple App Store / Google Play (USA) | Payment transaction only | Payment processing for in-app purchases and subscriptions. We receive only purchase and entitlement confirmation, not your card, bank, or UPI details. | apple.com/legal/privacy · policies.google.com/privacy |
| RevenueCat (USA) | App account identifier; purchase receipts and subscription status | Validating in-app purchases and managing subscription entitlements on our behalf | revenuecat.com/privacy |
| Resend (USA) | Parent email address (supplied by the parent from their own account); transactional email content (weekly progress reports, receipts, account notices) | Delivering transactional emails on our behalf | resend.com/legal/privacy-policy |
| SMS provider (see note) | Mobile number; six-digit sign-in code | Delivering the sign-in verification code. Students and parents both sign in with a mobile number, and for a parent that same sign-in is what proves the number is theirs before they can approve a child (Section 11) | — |
| Google Firebase (USA) | Anonymised usage events, device metadata | App analytics | firebase.google.com/support/privacy |
| Sentry (USA) | Crash reports, device metadata | Error monitoring (when enabled) | sentry.io/privacy |
| Supabase / AWS (Mumbai, India) | All account and study data; live Exam Jam session events (display name, scores, answer events) via Supabase Realtime channels while a jam session is active | Infrastructure, database hosting, and real-time multiplayer broadcasts | supabase.com/privacy |
| Law enforcement | As required | If required by Indian law or valid legal process | — |
Note on SMS provider: The specific SMS gateway used for sign-in verification codes will be named here once provisioned.
8. Cross-Border Data Transfers
Some of our service providers (Voyage AI, Resend, Google Firebase, Sentry) process data outside India, primarily in the United States. These transfers are made in compliance with the DPDP Act, 2023. We do not transfer data to any country that the Central Government has restricted under Section 16(1) of the DPDP Act. If such restrictions are notified in the future, we will update our data processing arrangements accordingly.
9. Data Retention
- Account data - Retained as long as your account is active
- Study progress - Retained as long as your account is active
- Usage statistics - Retained as long as your account is active
- Card reports - Retained until reviewed and resolved by our team
- AI credit ledger - Retained as long as your account is active, as the record of credits granted, purchased, and spent; deleted with your account
- Analytics data - Retained as per Google Firebase and Sentry default retention policies (typically 14 months for Firebase, 90 days for Sentry)
- Parent's mobile number given by a student - Retained while the student's account exists, because it is what allows the parent to find and approve their child whenever they choose to sign in. If a person signs in with that number and taps "Not my child", we record that dismissal so we never show them that student again
- School seat-allocation details - A student's mobile number and email provided by a school to reserve a seat are retained for the duration of the school's licence and deleted with the account
- Accounts awaiting parental consent - Full access is maintained while consent is pending; accounts are not restricted or automatically deleted. Dismissing a request with "Not my child" does not delete the student's account (see Section 11). A parent who wishes to withdraw consent and have the account deleted should contact our Grievance Officer (Section 15)
- Inactive accounts - To minimise the personal data we hold, any account - whether a student, parent, or school-administrator account - that has not been used (no login and no activity) for over 12 months is scheduled for deletion. We contact the account holder and, for a student with a linked parent, the parent too, asking them to log back in to keep the account; we send a final reminder about a month later; and if the account is still unused after that, the account and all associated personal data are permanently deleted. Logging in at any time stops this process and resets the inactivity period. Internal staff and administrator accounts are exempt from this automated closure.
Upon account deletion, all your personal data stored on our systems is deleted within 30 days. Data already processed by third-party providers (e.g., anonymised analytics events) is subject to those providers' respective retention policies.
10. Your Rights Under the DPDP Act, 2023
As a Data Principal, you have the following rights:
- Right to access - Your study progress, streak, and usage are visible in the app. You may request a complete copy of all personal data we hold about you.
- Right to correction - You can update your display name in Settings. For corrections to other data, contact us.
- Right to erasure - You may request deletion of your account and all associated data. We will process this within 30 days.
- Right to data portability - You may request a machine-readable export of your personal data by contacting us.
- Right to withdraw consent - You may withdraw your consent for data processing at any time by contacting us or deleting your account. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Note that withdrawing consent may result in loss of access to some or all app features.
- Right to nominate - You may nominate another person to exercise your rights in the event of your death or incapacity, as provided under the DPDP Act.
- Right to grievance redressal - You may file a complaint with our Grievance Officer (see below). If unsatisfied with our response, you may approach the Data Protection Board of India.
11. Children's Privacy and Parental Consent
NeetFlash is designed for students aged 16 and above preparing for NEET. Under the DPDP Act, 2023, any user under the age of 18 is classified as a child, and verifiable parental consent is required before we process their personal data.
We obtain that consent through one of two paths, both designed to give the parent a real, auditable opportunity to approve or refuse:
Path A - Student-led (default). When a student creates an account, we ask them for their parent's mobile number on the final onboarding step. That is the only parent contact detail we ask the student for; we do not ask for the parent's email address.
Giving us the number links nothing. It records a request, not a relationship. The parent then signs in to NeetFlash with that mobile number — we send a six-digit code to it by SMS, exactly as we do for any sign-in, and signing in successfully is what proves the number belongs to them. Once signed in, they see the student's name and approve with one tap. That tap is the consent, and it is the same action that creates the link. We never connect a parent to a child automatically on the strength of a typed-in number.
That design is deliberate. A single mistyped digit would otherwise hand a stranger access to a child's progress data, and Indian mobile numbers are recycled by operators, so a number can change hands. Because approval requires someone to sign in, see a name, and act, all of those cases end with a person looking at a name they do not recognise. Anyone in that position can tap "Not my child", which dismisses the request permanently; it does not delete the student's account and does not decline consent on the student's behalf.
The student has full access to all app features throughout, with no restriction for non-response. The account is never gated while consent is pending.
Path B - Parent-led. A parent who creates a NeetFlash account first can generate an invite code and share it with the student. When the student enters the code, the accounts are linked and consent is recorded. This path exists for families who share a single mobile handset — where the parent and the student cannot each hold a separate number — and where the number the student entered does not reach the parent.
We retain a tamper-resistant audit log of consent events (the approving parent's account, their stated relationship to the student, the channel - in-app approval or invite code - and the timestamp of approval) so we can demonstrate compliance to the Data Protection Board on request.
The parent's mobile number is stored only for this purpose: to identify the parent when they sign in, to link them to their child on approval, and to show the student whom they should ask. It is not used for marketing.
- Users under 13: We do not knowingly collect data from children under 13. If a parent or guardian believes their child under 13 has registered, please contact us and we will delete the account and data promptly.
- Withdrawal of consent: The parent may withdraw consent at any time by contacting our Grievance Officer; we will immediately delete the student account and all associated data, or as otherwise instructed.
- We do not engage in tracking, behavioural monitoring, or targeted advertising directed at children.
12. Data Breach Notification
In the event of a personal data breach that is likely to cause harm to Data Principals, we will:
- Notify the Data Protection Board of India as required under the DPDP Act, 2023
- Notify affected users through the app and/or email without unreasonable delay
- Provide details of the nature of the breach, the data affected, and the remedial steps taken
13. Cookies and Local Storage
The NeetFlash mobile app does not use cookies. The app stores authentication tokens and local preferences on the device using the platform's standard secure storage facilities (Android SharedPreferences and the iOS Keychain, as managed by the Supabase Flutter SDK). The NeetFlash admin portal uses HMAC-signed session cookies for staff authentication only.
14. Changes to This Policy
We may update this privacy policy from time to time. For material changes - especially those affecting how your personal data is collected, used, or shared - we will notify you through the app and seek your fresh consent before the changes take effect. For non-material changes, continued use of the app after notification constitutes acceptance.
15. Grievance Officer
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023, the details of our Grievance Officer are:
Name: Suresh Damodaran
Email: grievance@neetflash.com
Response time: We will acknowledge your complaint within 24 hours and endeavour to resolve it within 15 days of receipt.
If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India.
16. Contact Us
For privacy-related questions, data access/deletion/portability requests, or concerns:
Company: Suravija Technologies Private Limited (operating the NeetFlash app)
Email: privacy@neetflash.com
This privacy policy is governed by the laws of India, including the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023.