Privacy policy
Effective 9 October 2026
YesStudy helps coaching institutes, colleges and academies give students short quizzes on what was taught in class. This policy explains what we collect, why, who we share it with, and the choices you have. YesStudy is run by [Legal name of the business running YesStudy — to be confirmed] (“we”, “us”). Questions or requests: contact@yesstudy.org.
The short version
- We collect only what is needed to run quizzes for your institute: your name, mobile number, your class, your answers and the material your teacher uploads.
- We do not show ads, sell data, or use tracking or analytics tools.
- Your institute’s owners and teachers can see students’ names, mobile numbers and quiz results in their institute. Other institutes cannot.
- An AI service (OpenAI) processes class material, quiz questions and messages to Aria, to write and check quizzes and to answer questions.
- You can ask us to see, correct or delete your data at any time.
What we collect
- Account details: name, mobile number, and for institute staff optionally an email address. Passwords are stored only as a secure one-way hash; we cannot see them.
- Institute and class: which institute and batches you belong to and your role (owner, teacher or student).
- Class material: photos and PDFs that teachers upload (board, notes, textbook pages), and the text read from them.
- Quizzes and results: the questions, each student’s answers, time spent per question, scores and when quizzes were submitted.
- Aria conversations: students’ messages to Aria, the AI tutor, and its replies, kept so a conversation can continue.
- Device for notifications: if you allow notifications, a push token that lets us tell your phone a new quiz is ready.
- Technical data: server logs including IP addresses, used to keep the service secure and to limit abuse, not to track you.
On the website we store only your sign-in in your browser so you stay signed in; in the app it is kept in the phone’s secure storage. We do not use cookies or local storage for tracking or advertising.
Why we use it
- To run your account and your institute’s classes, quizzes and results.
- To write quizzes from class material and check their answers, and to let Aria help students with what they were taught.
- To show students their progress and show teachers and owners how their batches are doing.
- To send quiz notifications you have allowed.
- To keep the service secure, prevent misuse, control costs, and fix problems.
We do not use your data for advertising, and we do not sell it.
Students under 18
Many students preparing for MHT-CET, NEET and JEE are under 18. Students join through their institute. Institutes must make sure a parent or guardian has agreed to their child using YesStudy, and a student under 18 should join only with a parent’s or guardian’s agreement. We do not show ads to anyone, and we do not track or profile children for advertising. A parent or guardian can contact us to see or delete their child’s data.
Who can see your data
- Your institute: owners see their institute’s staff and students and all its batches’ results; teachers see the students and results of the batches they teach.
- Other students do not see your answers or scores.
- YesStudy staff can see account details to set up institutes and help with sign-in problems. Our staff tools do not show lesson content or answers; we access such data only when needed to keep the service running or when the law requires it.
Services we use
We use these providers to run YesStudy. They process data only to provide their service to us.
- OpenAI (USA): reads class material, writes and checks quiz questions, and powers Aria. Under OpenAI’s API terms, data sent through the API is not used to train their models by default, and may be kept for a limited time for abuse monitoring.
- Fly.io (servers in Singapore): runs the YesStudy service.
- Neon (database in Singapore): stores accounts, classes, quizzes and results.
- Cloudflare R2: stores uploaded class material privately.
- Vercel: hosts the yesstudy.org website.
- Expo: delivers app notifications.
- Hostinger: handles email to contact@yesstudy.org.
Some of these providers process data outside India. We choose providers that protect data in line with applicable law.
How long we keep it
We keep your data while your account is in use. When an institute removes someone, they lose access straight away; their past results stay available to the institute for its records unless deletion is requested. If you ask us to delete your account, we will delete or anonymise your personal data within 30 days, except where the law requires us to keep something. Backups are overwritten on a rolling basis.
Security
Data is encrypted in transit. Uploaded material is stored privately and shown only through short-lived links. Each institute’s data is kept separate, and access is checked on every request. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.
Your choices and rights
- Ask for a copy of your data, or correct it.
- Ask us to delete your account and data.
- Turn off notifications in your phone’s settings at any time.
- Withdraw consent, which means we stop processing your data and close your account.
- Complain to us, and if not satisfied, to the Data Protection Board of India.
Email contact@yesstudy.org from your registered details, or ask your institute to contact us. We may need to confirm it is you before acting.
Grievances
Contact for privacy questions and grievances: [Legal name of the business running YesStudy — to be confirmed], [Registered address — to be confirmed]. Email: contact@yesstudy.org.
Changes
We will update this policy when the service changes and show the new effective date here. For significant changes we will tell institutes in advance.