Parent and child privacy
Privacy Notice
- Version
- privacy-live-v1
- Effective date
- 24 July 2026
This notice itemises the data and purposes used to run a parent-managed family learning workspace.
1. Family roles and contact
Data Fiduciary: GSPHERE TECH PRIVATE LIMITED, a private limited company. Principal address: JJ 287, Assetz Marq Phase-2, Kannamangala Village, Whitefield-Hoskote Road, Kannamangala, Bangalore South, Bengaluru, Karnataka, 560067, India.
The parent or lawful guardian creates and manages child profiles, selects paid coverage and gives or obtains the required permissions. A child cannot purchase a package. Privacy and data-rights requests go to privacy@preppilot.study.
School representatives who submit the public pilot form receive a separate, purpose-specific School Inquiry Privacy Notice. It does not change the family and paid-policy version shown on this page.
2. Itemised data and purposes
| Data | Why PrepPilot uses it |
|---|---|
| Parent UID, name, verified email, sign-in/session/security state | Create/secure/recover the account, authenticate actions and send service/policy notices |
| Family, memberships, invitations, roles and status | Operate the workspace and prevent cross-family access |
| Child ID/display name, board/programme, class/level, handle, salted PIN verifier and access/reset state | Provide child access, suitable material and selected-child package scope |
| Assignments, answers, attempts, scores, rubrics, AI evidence, feedback and review/correction history | Deliver/evaluate practice, release results, review errors and meter allowance |
| Progress summaries, comparisons, recommendations and exports | Provide package-dependent parent/child tools |
| Quote/package/selected-child scope, prices, policy acceptance, Razorpay references, receipts, refunds and disputes | Verify/fulfil/reconcile payment, issue receipts, prevent duplicates and meet consumer/accounting duties |
| Support, grievance and privacy ticket/reference, messages and necessary attachments | Investigate/respond, verify protected requests and retain an accountable action trail |
| Request/action IDs, times, authorization outcomes, integrity hashes, incidents and bounded technical logs | Secure, audit, investigate and recover the service |
| Coarse product/performance/error events | Aggregate reliability/usability with family, child, answer, payment and ticket joins excluded |
3. Purposes, necessity and consent
PrepPilot processes data to provide the requested family service, perform a paid purchase, comply with law, protect children/families and handle requests. Where consent applies, the request must be clear, specific, informed and limited to necessary data. Withdrawal must be as accessible as giving consent, though it may stop a feature that genuinely requires the data.
Paid-policy acceptance proves the versions bound to a purchase; it is not blanket consent for unrelated processing.
4. Child consent and protections
The production flow verifies the parent/guardian and obtains verifiable parent consent where required, with proportionate due diligence and no excessive identity collection.
- No targeted advertising using child data.
- No sale of child data.
- No tracking or behavioural monitoring of children for advertising.
- No solely automated official-grade, intelligence, diagnosis, admission or other high-stakes child decision.
5. Providers and processors
- Google Firebase / Google Cloud for authentication, hosting, Firestore, trusted workloads, security and related infrastructure.
- Approved Google AI services for rubric-grounded evaluation and explicitly disclosed AI features.
- Razorpay and participating banks/networks for payment, refund, dispute, fraud/security and transaction records.
- Zoho Mail for transactional receipts and the support, grievance and privacy role-address workflow.
- Configured aggregate analytics/error tooling with the exclusions stated below.
Providers receive defined purposes, access/security, incident and deletion/return terms. A materially new provider or purpose requires review and a new notice version when necessary.
6. AI use
For supported written answers, PrepPilot may send the minimum question, rubric, answer and necessary learning context to the approved AI provider. It does not send payment IDs, support tickets, unrelated family data or a child PIN. Output is schema-validated, review/confidence gated and retained with evidence needed to explain or correct a result.
Future model training, unrelated research or another materially different purpose requires separate review, notice and a valid basis first.
7. Payment and analytics boundaries
Razorpay handles payment credentials. PrepPilot stores opaque provider references and the minimum immutable evidence needed to fulfil/reconcile a purchase. It does not receive or store card PIN, UPI PIN, CVV or bank password.
Analytics must exclude child/family IDs, names, answers, scores, entitlement joins, provider/payment/refund IDs, receipts, ticket content/joins, raw coupon codes and paid-policy acceptance joins. It is not used for child advertising profiles.
8. Retention
Each category is retained only for the stated service purpose, requested family history, security/recovery, a live request/dispute, or applicable legal/accounting requirements. Account/profile data is kept while active plus the approved recovery/deletion period; learning/results follow the approved family-history and review schedule; purchase/acceptance/receipt/refund/audit evidence follows the approved legal/accounting period; tickets follow resolution plus the approved complaint period; operational logs use a bounded period.
Operational owners apply the approved internal schedule and review continued necessity. Package expiry/refund does not automatically erase answers, released results, receipts or immutable financial evidence. A lawful retention exception is explained when it prevents immediate erasure.
9. Security and incidents
Safeguards include Firebase Authentication, active membership and server authorization checks, default-deny rules, environment separation, managed secrets, untrusted/AI-output validation, idempotency/duplicate fences, integrity hashes, least privilege, audit evidence and recovery/incident controls. If a personal-data breach occurs, PrepPilot will contain/investigate it and notify affected people and the competent authority as applicable.
10. Access, export, correction and erasure
A verified parent may request a data summary/access record, available family export, correction/completion, erasure where no lawful exception applies, consent withdrawal where consent applies, and status of a prior request. Email privacy@preppilot.study and complete the signed-in verification step when requested.
Correction does not rewrite an immutable receipt, payment, accepted policy, score version or audit event; PrepPilot records an appropriate linked correction.
11. Complaints
Privacy requests use the address above. Escalate with the same reference to Umasri Prathapaneni at grievance@preppilot.study. Consumer complaints are acknowledged within 48 hours and grievances targeted for redress within one month. The privacy workflow follows the applicable statutory period; the notified DPDP Rules allow a specified grievance period not exceeding 90 days.
12. Cross-border processing
Approved cloud, AI, payment, email or security providers may process or provide support access outside India. PrepPilot will maintain the provider/location inventory, contractual/security/access and deletion/return safeguards, comply with Central Government transfer restrictions and applicable stricter sectoral requirements, and review a materially new country/provider/purpose before use.
13. Notified DPDP timeline
India notified the DPDP Rules and commencement schedule on 13 November 2025. The notification schedules the Consent Manager registration rule after one year (13 November 2026) and the principal processing, consent, child, rights, grievance and most operational provisions after eighteen months (13 May 2027).
PrepPilot is building toward the notified end-state now: itemised notice, minimization, affirmative/withdrawable consent where applicable, processor controls, security, verifiable-parent consent, child protections, rights, grievance and cross-border governance. Staged commencement does not weaken current child safeguards.
14. Version changes
The version/hash accepted for a paid purchase remains bound to it. A new purpose, provider category, retention rule, child-consent method or material rights change creates a new immutable notice and receives the required notice/consent treatment.