GK Paar

Privacy Policy

What we collect, why, who sees it, how long we keep it, and how to get it back or have it deleted. Written against the actual system, not from a template.

Last updated · 8 September 2026

Draft — not yet in force. This page still contains placeholder entity and contact details (shown in «guillemets»). Fill ORG in src/content/legal.ts before launch; this notice disappears on its own once none remain.

This policy explains what «REGISTERED LEGAL NAME» ("we") does with personal data when you use GK Paar. It is written to the Digital Personal Data Protection Act, 2023 and to the Information Technology Act, 2000 and rules under it.

We have tried to describe the system as it actually is rather than as broadly as possible. Every category below corresponds to something we really store.

What we collect

To sign you in. Your mobile number or email address, whichever you use. A one-time code is sent to it; we store only a hash of that code, never the code itself. We also record the IP address a code was requested from, the number of attempts and resends, and when the code was used — this is what stops someone else requesting codes against your number.

To keep you signed in. A device identifier and a device label, and a hashed session token, so that you stay signed in and can see and end your sessions.

Your profile. Your name and district if you give them, your language preference, and which exam you are preparing for. Name and district are optional; the service works without them.

Your practice. Every attempt you make and every answer within it — the option you chose, when you chose it, how long you spent, which questions you visited or marked for review, your score, accuracy, marks lost to negative marking, and the topic breakdown computed from all of it. This is the product, and it is the largest thing we hold about you.

Messages we send you. A log of the sign-in codes and notifications we have sent — the channel, the destination, the template, the delivery status and any error. The contents of the message, including the code, are masked before the log is written.

Technical data. Standard server logs, and the small amount of information your browser sends with each request.

What we do not collect

We do not use third-party analytics, advertising or tracking scripts. There is no Google Analytics, no advertising pixel and no session recorder on this service, and no third party is watching you use it. We do not collect your location, your contacts, your photographs, or any document you might upload elsewhere — there is nowhere on this service to upload one. We do not ask for or store any government identity number, and we never ask for your exam roll number, application number or portal password. Nobody from GK Paar will ever ask you for those. If someone does, it is not us.

We do not store card or bank details. When paid packs open, payment will be handled by a regulated payment gateway and your card never reaches our servers.

Why we use it

  • To sign you in and keep your account secure.
  • To run tests, mark them, and produce your report and progress over time.
  • To show you the right content in the right language for the right exam.
  • To send you the messages the service needs to send — sign-in codes, and notices about your account or a change to a test you have taken.
  • To find and fix faults, and to detect abuse of the service.
  • To meet legal obligations, including tax and accounting once payments begin.

We do not sell your personal data, and we do not share it for anyone else's advertising. We do not use your answers to profile you for any purpose outside your own report and study suggestions.

Who else sees it

Only where the service cannot work otherwise, and only what they need:

  • Our SMS and email providers, to deliver sign-in codes and notices. They receive the destination and the message.
  • Our hosting and database providers, who store the data on our behalf under contract.
  • A payment gateway, once paid packs open, to take the payment and tell us it succeeded.
  • Professional advisers or authorities, where the law requires it or to establish or defend a legal claim.

We keep data in India where our providers offer it. If any provider processes data outside India we will only use one that is permitted under the DPDP Act and contractually bound to protect it.

How long we keep it

  • Your account and profile — while your account is open, and for a short period afterwards so that an accidental deletion can be undone.
  • Your attempts, answers and reports — while your account is open. They are the record of your preparation and deleting them early would take away the thing you came for.
  • Sign-in codes — minutes. The record that a code was issued is kept longer for security.
  • Session tokens — until they expire or you sign out or revoke the device.
  • Message logs and server logs — a limited period for delivery troubleshooting and security, then deleted.
  • Payment records — for as long as tax and accounting law requires, once payments begin.

When you delete your account we delete or irreversibly anonymise your personal data, except anything we are required to keep by law. Anonymised, aggregate figures — for example how difficult a question turned out to be across everyone who answered it — are not personal data and may be retained.

Your rights

Under the DPDP Act you may ask us to:

  • give you a copy of the personal data we hold about you, and a summary of how it is processed and who it has been shared with;
  • correct or complete anything inaccurate;
  • delete your data and close your account;
  • withdraw a consent you have given, which is as easy to do as it was to give;
  • nominate someone to exercise these rights if you die or become incapacitated.

Write to «GRIEVANCE@DOMAIN» from the contact on your account and we will respond. There is no charge. If you are not satisfied with our response you may complain to the Data Protection Board of India.

Cookies and what is stored on your device

We do not use advertising or analytics cookies, so there is no consent banner to click through. What we do use:

  • A session cookie holding your refresh token. It is httpOnly and cannot be read by JavaScript. It exists so you stay signed in.
  • Local storage, for your theme, your language, a device identifier, and — while a test is running — a queue of answers not yet saved to our servers. That queue is what makes losing signal mid-test cost you nothing.

Clearing your browser storage signs you out and discards any answers not yet uploaded.

Security

Codes and session tokens are stored hashed, never in the clear. Sign-in codes, tokens and answer keys are masked before anything is written to a log. Access to production data is restricted to the people who need it. No system is perfectly secure, but if a breach affects your personal data we will notify you and the Data Protection Board as the law requires.

Children

The service is for candidates aged 18 or over and is not directed at children. We do not knowingly collect data from anyone under 18; if we learn that we have, we will delete it.

Changes

If we change this policy we will update the date at the top and, for anything material, say so on the page and tell you directly where we reasonably can.

Grievance Officer

«GRIEVANCE OFFICER NAME» · «GRIEVANCE@DOMAIN» · «REGISTERED ADDRESS, JAIPUR, RAJASTHAN «PIN»». We aim to acknowledge within 48 hours and resolve within 30 days.