Privacy Policy
Last updated: September 27, 2026 · Version 2026-09-16
Gri-Learn, by Grishu, is a learning platform for B.C.A. students, on the web at grishu.com and as the Gri-Learn mobile app. It is built and run by one person in Gujarat, India. This page says what we store when you use either one, why, who else touches it, how long we keep it, and how to get rid of it. If anything here is unclear, write to us and a person will answer.
Who is responsible: Grishu, contactable at info@grishu.com. Under India’s Digital Personal Data Protection Act, 2023 we are the data fiduciary for everything below, and that address is also our grievance contact.
What we collect, and why
Your account
- Your name and email address, to sign you in and to address you inside the app. If you set a password we store only a bcrypt hash of it, never the password itself.
- How you sign in. If you use Continue with Google or Sign in with Apple, we store the account identifier that provider gives us so we recognise you next time. We never receive your Google or Apple password.
- Your date of birth, asked once when you first sign in. We use it for one thing: knowing whether an account belongs to someone under 18, which the law treats differently. See Students under 18 below.
- Your consent record: when you agreed, which version of this page you agreed to, and whether you asked for reminder email. Every change to that is recorded, so we can show you what you agreed to and when.
Where you study
- Your university, your college and your semester, so the app opens on the right syllabus and the right year. If you type in a college that is not in our list, we keep that name so we can check it and add it.
- Your exam date, if you set one, for the countdown.
What you do in the app
- Your learning: which topics you finish, the answers you give to the questions inside a lesson, your points, stars, streak and challenge scores. This is the product: without it there is no progress to show you and no streak to keep.
- Sign-in records: each time you sign in, register, change your password or delete your account, we record that it happened, with your name and email address, so we can look into a problem with your account or an attempt to get into it.
- Sign-in link requests: when anyone asks for an emailed sign-in link or a password reset, we store the address it was sent to and a hash of the link, until the link is spent. This happens even for an address that has no Gri-Learn account, because that is how we send the email.
Numbers that are not about you
- Topic views: which topic was opened, on web or on the phone, and when. No account and no device is attached, so we can count what is read without knowing who read it.
- Installs: the mobile app sends one ping a day with a random identifier it generates for itself, the platform, the app version and your study year. It is not linked to your account and we use it only to count installs and active devices.
- Visits, sign-ups and shares: for each day, how many times our public pages were opened, how many accounts were made and how many times a share button was pressed, split by where the visitor came from when the link they used carried a tag (for example a link shared from the app). No account, no device and no address is attached to these numbers. If you arrive through a tagged link, your browser keeps that tag, and nothing else, in a cookie for 30 days, so that signing up adds one to that tag’s count.
When something breaks
If the app or the server hits an error, we send a crash report to Sentry containing the error, the code path it came from, the page or route, and your database identifier so we can tell one student’s reports apart. Those reports are deliberately stripped of your email address, your cookies, request headers, request bodies, query strings and your IP address before they leave us.
A report from the phone app also carries your device model, your Android or iOS version and which build of the app you are running. That is how we can fix a crash that only happens on one kind of phone, which is otherwise invisible to us. It never includes a screenshot, a recording of your screen, or a copy of what is on it: those are switched off in the code, not merely left unused.
On your device only
Both surfaces keep a few things locally that never reach us: your chosen language and theme, recently viewed topics, and any lesson you finish while offline, which is sent as soon as you are back online and then removed. Clearing the app’s storage clears all of it.
What we do not do
- We do not sell your personal data, and we never will.
- We show no advertising and carry no advertising or tracking SDK, on either surface.
- We do not collect your location, your contacts, your photos or your files.
- We do not use your work to train an AI model, and we do not send your answers to any AI service.
Who else processes it
We do not share your data with anyone who wants it for their own purposes. We do rely on these companies to run the platform, and they process it on our instructions only:
- Supabase (Singapore) hosts the database everything above lives in.
- Render (Singapore) runs the Gri-Learn server, and Cloudflare sits in front of it, so a request to our API passes through their network.
- Vercel serves the website, so a visit to grishu.com reaches their servers first.
- Brevo delivers our email, so it receives the address a message is going to and its contents.
- Sentry receives the crash reports described above.
- Google and Apple, if you choose their sign-in, confirm to us that the account is yours.
- Google Fonts. The website loads its typefaces and icons from Google’s servers, which means your browser tells Google your IP address and which page asked. We would rather serve those files ourselves and are working towards it; until then, this is the one transfer that happens whether or not you have an account.
Some of these companies are outside India, so your data is processed abroad. We use them because a one-person platform cannot run its own data centre, and we pick the region closest to our students where the choice exists.
Students under 18
A B.C.A. intake includes students who are still 17, so this is not a hypothetical section.
- When you first sign in we ask your date of birth. If it says you are under 18, we ask for a parent or guardian’s name and email address, and for their agreement. Fill that in with them, not for them.
- We then email that parent or guardian a copy of what the account is, what we keep, and a link that removes the account in one press if they did not agree.
- We send no reminder email at all to an account under 18.
- We do no tracking, profiling or targeted advertising for any account, and none for a child in particular. The DPDP Act forbids it, and we had nothing of the kind to remove.
- When that student turns 18, we ask them once, as themselves, and the guardian’s details are removed from the account when they answer.
How long we keep it
- Your account and your learning: until you delete the account, or withdraw your consent, which does the same thing.
- Sign-in records: 180 days, then removed automatically.
- Sign-in link rows: 7 days after the link expires.
- Topic views: 180 days.
- Install pings: a year after a device last opened the app.
- Crash reports: kept by Sentry under their own retention policy, and not copied anywhere else by us.
Your rights, and how to use them
- See what we hold. Most of it is on your own screens: Settings, Progress and your profile. For anything else, email us and we will send you a copy.
- Correct it. Your name, college and semester are editable in Settings (in the app, your name is on Profile). For your email address or your date of birth, email us.
- Delete it. On the website, Settings then Delete account. In the app, Profile then Delete account. Your account, your sign-in, your progress and your quiz history go immediately, your sign-in records stop naming you, and any unused sign-in link for your address is destroyed so nothing can bring the account back.
- Delete it without signing in. grishu.com/delete-account takes an email address and sends that inbox a link with one button on it. You do not need a password, a session or the app installed, which matters if you have changed phone or cannot get back in. It does exactly what the row above does.
- Withdraw your consent. Settings then Your consent then Withdraw consent, on either surface. Because everything we hold about you is held on your permission, withdrawing it deletes the account: there is no honest halfway state where we keep your data but stop using it, so we do not pretend to offer one.
- Stop the reminder email. The switch is in Settings, and every reminder has a one press way out at the foot of it. It does not need your password and it changes nothing else.
- Complain. Write to info@grishu.com and we will answer. If we do not resolve it, you can take it to the Data Protection Board of India.
If something goes wrong
Passwords are stored as bcrypt hashes. Sessions use a token in an httpOnly cookie on the web and secure storage on the phone, and signing out, changing a password or a reset ends every session that token belongs to. If we ever discover a breach that affects your data, we will tell the Data Protection Board of India and every affected student, by email, with what happened and what to do about it.
When this page changes
This page carries a version, and your consent is recorded against the version you read. If we change what we collect or who processes it, the version moves and the app asks you again, showing you the new text first. We do not treat an old yes as an answer to a new question.
Contact
Questions about this policy, or about your data: info@grishu.com.