This policy covers the KarmSakha website and mobile apps. The information processed depends on the features you use, whether you sign in, and the permissions you choose.
When you sign in or use account features, we process your account identifier, sign-in email and any name or contact details you provide. We use these details to authenticate you, maintain access and respond to support requests.
Learning features can store mock-test answers, scores, attempts and timing; reading and course progress; saved articles and notes; doubt questions and answers; and study plans. Saved preferences can include your target exam, exam date, response language, qualification and the state or job category you want alerts about. A chosen job-search state is a preference, not a reading of your device location.
We use learning activity and preferences to show your progress, recommend revision and personalise study or alert results. Questions, notes and support messages may contain information you choose to write; do not include passwords, payment credentials or unnecessary personal information.
If you submit a product review, we store its text, rating, display name and related order. Approved reviews may be displayed publicly. Joining the leaderboard is optional; when enabled, it can display your formatted name, rank and study results. Changing a profile setting does not necessarily remove an already published review or historical snapshot; contact us about those records.
Notifications and communication choices
If you allow mobile notifications, we register a push token with your platform, app version and last registration time. A token can be stored before sign-in and associated with your account after sign-in. Apple and Google Firebase services help deliver notifications; KarmSakha stores registration information through its backend.
You can turn notifications off in your device settings. This stops permission to display notifications but does not itself delete a token already stored on our servers. You can ask us to remove stored registration information.
Optional WhatsApp alerts collect the phone number, name and alert preferences you submit, together with a record of your topic-specific consent. Follow the STOP or unsubscribe instructions in the message, or contact support to withdraw that subscription. Signing out or deleting a KarmSakha account does not necessarily stop a separately registered phone subscription.
Account, security and order messages support services you use. Optional promotional or topic subscriptions depend on the consent given for that communication; subscribing to one topic does not authorise unrelated marketing.
Usage measurement, device storage and security
KarmSakha records first-party journey events such as starting or completing practice and interacting with learning pages. Events can include a page path, exam or product reference, language, device class, screen-size range and app version. A locally stored random journey identifier and session identifier connect events; the backend stores hashed versions of those identifiers. These are pseudonymous records, not a promise that all activity is anonymous.
We use these records to understand how features work and improve the service. Security processing can also use request metadata, including network addresses, to limit abuse. Sign-in sessions, preferences and locally saved progress use browser or app storage.
Our native Android and iOS shells do not initialise the website's Google Analytics 4 or Google Ads tags. In an ordinary web browser, configured Google tags can measure page views, feature use and advertising conversions. Disabling these tags in the native app does not disable KarmSakha's first-party journey events or embedded third-party video services.
Contact [email protected] to object to optional usage measurement or request deletion of usage records. There is currently no dedicated in-app analytics switch. Clearing local storage removes local identifiers but does not delete existing server records, and a later visit can create new identifiers.
Optional third-party AI assistance
Study plans and doubt assistance include options that work from KarmSakha's stored rules or reference material. Third-party AI generation requires the permission shown for that request. You can leave that permission off and use the available non-generative features; declining does not authorise a background AI request.
If you authorise AI study-plan generation, we send your target exam, saved exam date, language and aggregated practice performance, including subject or topic accuracy, attempted counts and average question time, to OpenRouter and its selected model provider. The generation request does not include your account identifier, email or phone number.
For an authorised doubt request using OpenRouter, the shared material can include your question, response language, recent conversation turns and retrieved reference questions and answers. Your question or conversation may contain personal information if you put it there. For an authorised Sarvam explanation, we send the matched reference-bank question, its answer options and the response language, rather than your original question or conversation history.
Responses and associated learning activity can be saved in your KarmSakha account. Permission applies to the request you submit; leaving it off on a later request prevents a new third-party generation request but cannot undo information already transmitted. Contact us for help with deletion requests. We do not promise a particular AI-provider retention period or that a provider never uses submitted data for other permitted processing.
Payments, providers and external services
Website purchases use Razorpay. We store order, product, amount, payment-reference and access-entitlement information to deliver purchases, restore access and handle support or disputes. KarmSakha does not store full card or banking credentials. The native app provides existing-account access and does not offer website checkout inside the app.
Providers used by the service include Supabase for authentication and data storage; Apple notification services and Google Firebase for mobile notifications; Resend for email; configured messaging services such as Twilio and WhatsApp/Meta for verification or alerts; Razorpay for website payments; and OpenRouter, its model providers and Sarvam for the optional AI functions described above. Hosting and content-delivery providers also process requests needed to serve the app.
Our policy is to share only information needed for the relevant service and to require providers handling it on our behalf to protect it consistently with this policy and applicable requirements. External services may also process information under their own privacy terms. Provider and hosting locations can differ from your country.
The Watch feature embeds YouTube videos using youtube-nocookie.com. An embedded player can load when you select a video or when a Watch-feed video becomes active. YouTube then receives the requests and playback information needed by its player; privacy-enhanced embedding does not mean that Google receives no data. External source links and services have their own privacy practices.
Retention, account deletion and other privacy requests
We retain information for the purpose it supports: maintaining an account and its learning history, delivering requested services, processing support or disputes, keeping necessary security records and meeting applicable record-keeping obligations. Different records have different purposes; this policy does not promise one fixed retention period for every record.
You can request permanent account deletion in Account → Profile by entering DELETE and selecting Delete my account. This removes your sign-in account and the associated access, reader-progress, notes, course-progress, study-plan, doubt, profile and account-linked push records handled by that flow. Deleting the account removes access to its purchased content. Financial order records are retained for tax compliance.
Records not directly linked to the account, including separately subscribed alerts and pseudonymous usage records, may need a separate request to identify and address them. Tell us which phone subscription, published review or other record your request concerns. Deleting your account does not withdraw a permission or erase information already held independently by an external service.
Contact [email protected] for access, correction, deletion, consent-withdrawal or privacy questions, including if you cannot sign in. We may verify ownership before acting. We will explain any records that must be retained and any limits on locating or deleting the requested data; never send a password or sign-in code.
KarmSakha uses YouTube API Services through an owner-operated internal content uploader for the official KarmSakha channel. The tool uploads KarmSakha-created videos, updates titles and descriptions, sets thumbnails, adds captions, creates playlists and verifies upload status.
The uploader accesses authorised channel, video, caption and playlist data needed to perform those actions. It is not offered as a public upload service, does not request viewers' YouTube credentials and does not sell or share authorised YouTube data with advertisers or unrelated third parties.
Google and YouTube process information under their own privacy policy and terms. KarmSakha uses only the OAuth scopes required for the documented publishing workflow.
OAuth tokens are protected as confidential credentials and are retained only while the authorised KarmSakha channel connection remains active. Operational upload records are limited to information needed to prevent duplicate uploads, verify publishing state and maintain the authorised channel.
YouTube API data obtained from YouTube is refreshed or deleted within 30 calendar days unless YouTube policies permit longer retention. When access is revoked, associated authorised data is deleted as soon as reasonably possible and no later than 30 calendar days, except records that KarmSakha is legally required to retain.
The authorising account holder may revoke access through Google Security settings and may contact [email protected] to request deletion of locally retained YouTube-authorisation data.