Privacy Policy
Last updated: May 2026
BankAgent ("we", "our", or "us") is committed to protecting your personal information in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian law. This policy explains what data we collect, why, and how it is used.
1. Data We Collect
- Account data: name, email address, phone number, and target exam.
- Usage data: test scores, quiz responses, flashcard reviews, and tutor messages.
- Payment data: Razorpay order IDs and subscription status. We do not store card details.
- Device data: browser type, IP address, and FCM push notification token (if you opt in).
2. Purpose of Processing
We process your data to:
- Provide personalised exam preparation features (adaptive tests, smart tutor, study planner).
- Process payments and manage your subscription.
- Send transactional emails (OTP, receipts) and, with your consent, product notifications.
- Improve our AI models and platform quality using aggregated, anonymised data.
3. Consent & Legitimate Interests
By registering, you consent to the collection and use of data described above. You may withdraw consent at any time by contacting us or deleting your account from the Profile page.
4. Data Sharing
We do not sell your personal data. We share it only with:
- Razorpay (payment processing)
- SendGrid (transactional emails)
- MSG91 (OTP SMS delivery)
- Cloud inference providers (your messages are processed to generate responses but not stored or used for training)
- Sentry (error monitoring — stack traces only, no PII)
5. Data Retention
We retain your account data for as long as your account is active. Uploaded documents (Custom Notes feature) are automatically deleted after 90 days. You may request deletion of all data at any time.
6. Security
Passwords are hashed with bcrypt. Data in transit is encrypted via TLS 1.2+. Access tokens expire after 30 minutes; refresh tokens rotate on every use.
7. Your Rights (DPDPA 2023)
You have the right to:
- Access a summary of personal data held about you
- Correct inaccurate data
- Erase your data ("right to be forgotten")
- Nominate a person to exercise these rights on your behalf
- Withdraw consent for non-essential processing
To exercise these rights, email us at privacy@bankagent.in.
8. Changes to This Policy
We will notify you by email of any material changes at least 14 days before they take effect.
9. Contact
BankAgent · support@bankagent.in