Privacy Policy
Last updated: 14 September 2026
This policy explains what personal data ExamPrep (operated by Toshi Consulting Services) collects, why, and the choices you have. It is written with the Digital Personal Data Protection Act, 2023 in mind, and with the fact that many of our users are children whose accounts are set up by a school or a parent.
1. What we collect
- Account details — name, email, password (stored hashed), role, class or grade, and for school accounts the school’s name, address, city, state and PIN code.
- Learning data — the questions you answer, your answers, scores, time taken, tests assigned to you, bookmarks, streaks, XP and league standing, and the AI reports and study plans generated from them.
- AI tutor conversations — the messages you send to the AI tutor and its replies, so the conversation can continue and so we can review quality.
- Test integrity signals — during a test: tab or window switches, unusual timing and similar events. These are shown to the student’s own school.
- Billing data — plan, invoices and payment status. Card details are entered on Razorpay’s pages and never reach our servers.
- Technical data — IP address, browser and device type, and the pages you use, collected in server logs and error reporting so we can keep the Service secure and working.
- Newsletter — the email address you enter in the “Subscribe” box on our website, if you use it.
2. Children
Student accounts for children under 18 are created or approved by the child’s school, or by a parent or guardian registering on their behalf. By doing so the school or parent gives consent for the processing described here. We do not show advertising to children, do not track them across other websites, and use their learning data only to provide the Service to them, their teachers and their school.
3. Why we use it
- to run your account and deliver practice, tests, analytics, reports and the AI tutor;
- to let teachers and school administrators see the progress of the students they are responsible for;
- to bill schools and independent students, and to issue GST invoices;
- to keep the Service secure, prevent cheating and abuse, and fix faults;
- to send you service emails (verification, password resets, invoices, important notices) and, only if you opt in, the newsletter;
- to improve the question bank and the Service, using aggregated or de-identified data wherever possible.
4. Who can see it
A student’s data is visible to that student, to teachers of their sections and to their school’s administrators. Independent students’ data is visible only to them. Toshi Consulting Services staff access data only to operate and support the Service.
We share data with service providers who process it for us under contract: payment processing (Razorpay), transactional email (Resend), AI model providers for the tutor and report generation (only the content needed for the request), error reporting and hosting. We do not sell personal data. We may disclose data where the law requires it.
5. Where it is kept and for how long
Data is stored on servers we control and is backed up. Account and learning data is kept while the account is active. A school can deactivate, archive or permanently delete its students’ and teachers’ accounts; permanent deletion removes personal data after a short grace period, keeping only what we must retain for invoicing and legal purposes. Server logs are kept for a limited period for security.
6. Your rights
You (or, for a child, the school or parent) can ask to see, correct or delete personal data, withdraw consent, or object to a use of it. Students and teachers can update their own profile in the app; schools manage their students and teachers from the school portal. For anything else, or to raise a grievance, write to info@toshiconsulting.com and we will respond within the time the law allows.
7. Cookies
We use strictly necessary cookies to keep you signed in (httpOnly session cookies) and a small amount of local storage for preferences such as dark mode. We do not use advertising cookies.
8. Security
Passwords are hashed, traffic is encrypted, access is role-based and logged, and we keep an audit trail of administrative actions. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the authorities as the law requires.
9. Changes
We may update this policy. The date at the top will change and material changes will be notified by email or in the app.
10. Contact
Data protection queries and grievances: Toshi Consulting Services · info@toshiconsulting.com