Privacy Policy
Last updated: 13 September 2026
This Privacy Policy explains how [COMPANY LEGAL NAME] ("Classphere", "we", "us", or "our"), a company incorporated under the laws of India with its registered office at [REGISTERED ADDRESS], collects, uses, discloses, and protects personal data through the Classphere platform — including the web application accessible at classphere.com and any institute subdomain (e.g. an institute's “.classphere.com” portal or its own custom domain), and the Classphere Android applications (institute and admin variants).
Classphere is a business-to-business (B2B) software-as-a-service platform. Coaching institutes (“Institutes”) use Classphere to conduct, manage, and analyze competitive exam preparation (JEE, NEET, and other exams) for their students and staff. This Policy applies to Institutes, their staff (teachers, test department members, institute administrators), and students who access the platform.
1. Who Is Responsible For Your Data
Classphere's role differs depending on the data involved:
- Student and staff data uploaded by an Institute (for example, bulk student rosters, individual staff records): the Institute determines what data is collected and why, and is the Data Fiduciaryfor that data under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”). Classphere acts as a Data Processor, processing this data only on the Institute's instructions and solely to provide the Service.
- Institute account and billing data, and data collected directly by Classphere (for example, through our public contact/demo request form): Classphere is the Data Fiduciary.
If you are a student or staff member with questions about your personal data, your Institute is usually the right first point of contact, since it controls your enrollment and account. You may also contact us directly using the details in Section 12.
2. Information We Collect
2.1 Student data
Institutes provision student accounts by uploading a roster (individually or in bulk via CSV/Excel). For each student, this includes:
- Name
- Phone number (used as the student's login identifier)
- Date of birth— this is also used, in normalized form, as the student's account password. We do not separately collect or set a distinct password for student accounts.
- Batch or class assignment within the Institute
Students do not self-register and do not provide a personal email address to create an account. A student may optionally add a display name and email later (for example, to set an exam target preference) once logged in.
2.2 Staff and faculty data
For teachers, test department staff, and institute administrators, Institutes provide: name, email address, phone number, role/position, subject(s) taught, and (for faculty) performance ratings visible internally to the Institute. Staff accounts authenticate with an email and password, and may receive an email invitation to join the platform.
2.3 Institute account data
We collect the information an Institute provides to configure its portal: subdomain or custom domain, branding and theme settings, support contact email, and billing configuration (billing model and pricing terms agreed with Classphere). We do not currently collect bank account or payment card details through the platform — payment processing is not yet active (see Section 6 of our Terms of Service).
2.4 Test and performance data
When a student takes a test, we collect their responses, time spent per question, flagged/marked-for-review questions, and the resulting performance analysis (for example, subject and chapter-wise accuracy, time management, and syllabus gap analysis). This data is tied to the individual student's identity and is visible to that student and to authorized staff at their Institute. In-progress (not yet submitted) answers are not visible to staff while the student is still attempting a test.
2.5 Technical and device data
We use automated error-monitoring tooling (Sentry) on both our web and backend systems to detect and diagnose crashes and performance issues. This can include stack traces, request metadata, and device/browser information. We have not configured automatic redaction of personal data from these reports; we are working to reduce what is captured here. If you use our Android applications, we also collect a device push-notification token (via Firebase Cloud Messaging) to deliver notifications.
2.6 Uploaded exam content
Institutes and Classphere staff may upload PDF question papers, which are processed by an AI-assisted extraction pipeline (using Cerebras Cloud AI) to convert them into structured questions. This process is applied to exam content, not personal data.
2.7 Contact and demo requests
If you fill out a “Request a demo” or contact form on our marketing site, we collect your name, email address, stated interest, and message, and use it solely to respond to your inquiry by email.
3. How We Use Information
- To provide, operate, and maintain the platform, including authenticating logins
- To generate performance analytics and insights for students, teachers, and Institutes
- To enable Institute staff to manage batches, tests, and student progress
- To send service-related communications and push notifications
- To monitor, diagnose, and fix technical issues
- To respond to support requests and demo/contact inquiries
- To comply with applicable law and enforce our Terms of Service
We do not sell personal data, and we do not use student data for third-party advertising.
4. Children's Personal Data
Many students on Classphere are under 18 years of age, which the DPDP Act defines as a “child.” Because Institutes enroll students and upload their data on the Institute's own instructions (rather than students self-registering), theInstitute is responsible for obtaining any necessary consent from a student's parent or lawful guardian— typically as part of its own admission or enrollment process — before providing that student's personal data to Classphere. Classphere processes this data only as instructed by the Institute and solely to provide the Service.
India's DPDP Rules, 2025 introduce specific requirements for verifiable parental consent (including identity-verification mechanisms) that come into force in phases through 2026 and 2027. As these requirements take effect, we will update our practices — and this Policy — accordingly, in coordination with Institutes.
5. Sharing of Information
We share personal data only as needed to operate the platform, with the following categories of service providers (“sub-processors”), each bound by contractual confidentiality and data protection obligations:
| Provider | Purpose |
|---|---|
| Supabase | Database hosting and authentication |
| Cloudflare (R2) | File storage (uploaded PDFs, generated assets) |
| Upstash (Redis) | Caching, background job queues, in-progress answer storage |
| Sentry | Error and performance monitoring |
| Cerebras | AI-assisted extraction of exam content from uploaded PDFs |
| Google Firebase | Push notifications to the Android app |
Within an Institute, student and staff data is visible to that Institute's own authorized staff according to their role. We do not share personal data across Institutes. We may disclose information if required by law, legal process, or to protect the rights, safety, or property of Classphere, our users, or the public.
6. Data Retention
We retain personal data for as long as an Institute maintains an active relationship with Classphere, and for a reasonable period afterward to meet legal, accounting, or dispute resolution needs. We do not currently offer an automated self-service tool to delete or export your data. To request deletion or export, please contact your Institute administrator, or reach us directly using the details in Section 12 — we will work with the relevant Institute to process the request.
7. Your Rights
Once fully in force, the DPDP Act gives individuals (“Data Principals”) rights including access to their personal data, correction and erasure, grievance redressal, and the ability to nominate another person to exercise these rights on their behalf (for example, in case of death or incapacity). You can exercise these rights today by contacting your Institute or Classphere directly; we are working toward more direct, self-service tooling as these requirements come into force.
8. Security
We use industry-standard safeguards, including encryption of data in transit (HTTPS) and database-level row-level security policies that isolate each Institute's data from every other Institute. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Cookies and Similar Technologies
We use cookies and local/session storage strictly necessary to keep you signed in and to operate the platform (for example, authentication session tokens). We do not currently use third-party advertising or cross-site tracking cookies.
10. International Data Storage
Some of our service providers (listed in Section 5) may store or process data on servers located outside India. Where this occurs, we require our providers to maintain appropriate safeguards for that data.
11. Changes to This Policy
We may update this Policy from time to time, including as India's data protection rules come into force in phases. We will update the “Last updated” date above when we do, and will notify Institutes of material changes.
12. Contact Us / Grievance Officer
For any questions about this Policy, or to exercise a right described above, please contact:
Grievance Officer: [GRIEVANCE OFFICER NAME]
Email: [SUPPORT EMAIL]
Address: [REGISTERED ADDRESS]