Privacy Policy
Last updated: May 15, 2026
1. What we collect
- Account: name, email, password hash (bcrypt — we never see your raw password), Google profile photo if you sign in with Google.
- Activity: which lessons you opened, batch enrollments, payment status.
- Communication: emails you send us, WhatsApp messages to our community number, form submissions.
- Technical: IP, browser, device — collected by Vercel and used only for security and aggregated analytics.
We do not collect bank details, Aadhaar, PAN or any other government ID.
2. Why we collect it
- Run your account, deliver paid content, and provide support.
- Send transactional emails (login links, receipts, batch reminders).
- Send our newsletter — only if you opted in. You can unsubscribe any time.
- Detect fraud, abuse, and prevent account sharing.
3. Payments
UPI / Razorpay handle all payment data directly. We only see the confirmation that a payment succeeded, the amount, and the transaction id — never your card number, UPI PIN, or bank login.
4. Who we share with
We share the minimum data needed with these processors:
- Vercel — hosting
- Neon — database (Singapore region)
- Google — only if you choose "Sign in with Google"
- Resend — sending email
- Razorpay / UPI providers — payments
- WhatsApp (Meta) — when you message our community
We do not sell your data, run ad tracking pixels, or share your email with any third-party marketer.
5. Cookies
We use one essential session cookie (signed JWT) to keep you logged in. No third-party analytics or advertising cookies. If we add analytics later (e.g. Plausible, Vercel Analytics), it will be privacy-friendly and aggregate only — no per-user tracking.
6. Data retention
- Active account data — kept as long as you have an account.
- Deleted account — wiped within 30 days, except payment records which are retained for 7 years for tax compliance (Indian GST rules).
- Email/log backups — rotated out within 90 days.
7. Your rights
You can at any time:
- Download a copy of your data
- Correct any wrong information
- Delete your account
- Opt out of the newsletter
- Withdraw consent for Google sign-in
Email hello@cloudadhar.in with "Data request" in the subject. We aim to respond within 7 working days.
8. Children
Cloudadhar is not intended for users under 16.
9. Security
Passwords are stored as bcrypt hashes (cost 12). Connections use TLS. Database is in a private network with no public internet ingress. We are a small team and cannot guarantee perfect security, but we follow the same practices used at large SaaS companies and patch quickly when issues arise.
10. Changes
We may update this policy. We'll announce material changes by email and on the site at least 14 days before they take effect.
See also our Terms of Service.