Privacy Policy
1. Introduction and Scope
This policy explains how Pennam Ventures, operator of ConceptFirst (a self-study learning platform for Indian exams), collects, uses, stores, and protects personal data when you visit the website, create an account, subscribe, or use any feature.
We are committed to privacy by architecture: we collect the minimum needed, we do not sell your data or share it with data brokers, and we keep raw personal data out of internal logs and AI traces (categories and metadata only). The free and trial tiers of the platform display advertisements to help keep that content free; paid subscribers get an ad-free experience, and ads are never shown in a way that sells or exposes your personal data (see Section 6A). This policy is written to be readable, not to obscure.
It applies to all users. Because many of our users are Indian students — including minors — the India Digital Personal Data Protection Act, 2023 ("DPDP") sections below get particular attention.
2. Children and Students Under 18 (India DPDP Act, 2023)
Many of our users are school students under 18. For such users we process personal data only with verifiable consent of a parent or lawful guardian, we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children, and we limit processing to what is needed to deliver learning. Purchases must be made by an adult. In practice, the parent or lawful guardian creates the account and completes the purchase, giving consent at that point. If you believe a child has provided personal data to us without appropriate consent, contact us and we will delete it.
Advertising and children: where the free or trial tiers display ads, any ad shown to a user we know or reasonably believe to be a child is contextual only — based on the page's subject, never on behavioural profiling — and is never personalised or used for remarketing. We instruct our ad partners accordingly and enable the relevant “child-directed / non-personalised” controls.
3. Data We Collect
- Identity and account: name, email address, authentication identifiers (via Clerk), account creation date, and role (student, admin, reviewer).
- Learning: board/grade/subject preferences, reading progress, bookmarks, personal notes, mock-test attempts and scores, and AI Assistant conversations you choose to keep as threads.
- Purchase and entitlement: orders, subscription term and dates, invoices and credit notes, gift/voucher/comp redemptions, refund requests, and a payment reference from Razorpay. Raw card, UPI, or bank credentials never touch our servers.
- Consent records: your acceptance of the Terms at checkout (which cover the self-study scope and, for minors, parent/guardian consent), and your cookie-consent choices.
- Security and abuse prevention: an active-session identifier used to enforce the single-device policy, plus device/browser info and minimal logs for security, fraud prevention, and reliability. To detect abuse of the free-trial offer (for example, creating many accounts to obtain repeated trials), we use limited technical signals — chiefly your account email, and coarse device/network signals such as an IP-derived approximate location and browser characteristics. This is proportionate anti-fraud use; we do not build advertising or behavioural profiles from it.
- Support: messages you send via the contact form or email.
4. What We Do NOT Collect
We do not collect government-issued ID numbers, raw payment credentials, biometric data, health data, precise location, or any sensitive personal data beyond what Section 3 describes. We do not buy data about you from anyone, and we do not sell or rent your data to anyone. We use Google Analytics and Google Ads (via Google Tag Manager) to measure the product and our own ad campaigns, and — on the free and trial tiers only — we display ads served by Google (Google Ad Manager / AdSense) and other ad partners (Section 6A); paid subscribers see no ads. All of these follow a region-based default (off by default in the EU/UK/Switzerland, on by default elsewhere) and can be changed any time in Cookie settings (see the Cookie Policy). Serving an ad is not the same as selling data — we do not.
5. Why We Process It (Legal Bases)
- Contract performance: delivering your subscription — content access, progress, bookmarks/notes, mock tests, invoices, refunds, gift redemptions, and transactional email (receipts, gift codes, renewal/expiry notices — not marketing).
- Consent: processing a minor's data (guardian consent), optional cookies, and any future marketing communications (none are sent today; if introduced they will be strictly opt-in with one-click unsubscribe).
- Legitimate interests: security monitoring, fraud and abuse prevention (including the single-device enforcement and detecting abuse of the free-trial offer — see below), and aggregate platform improvement using de-identified data.
- Legal obligation: tax and accounting records (invoices, orders) retained as required by Indian law; responding to lawful requests from authorities.
6. AI and LLM Data Handling
No raw PII in AI traces: when you use the AI Assistant, your query is processed by a language model to generate an educational reply. Observability traces are scrubbed before storage — they carry categories and metadata, never raw personal data; the assistant is identified by a pseudonymous ID, never your email.
Providers: generation is routed across LLM providers (Google Gemini, DeepSeek, OpenAI, Anthropic, Groq) based on cost and capability. We send only the minimal content needed to produce a reply — never your account identity or raw PII — and we rely on each provider's API terms, which for standard API usage do not use submitted inputs to train their general models. The current provider list is shown in the sub-processor table and may change as we add or remove providers.
Published content: the learning content itself is generated from curriculum facts, not from user data.
6A. Advertising and Third-Party Ad Networks
Where ads appear: the free and trial tiers of the platform display advertisements, which help us keep that content free to use. Paid subscribers get an ad-free experience — no ads are shown to them at all.
Who serves them: ads are delivered by Google (Google Ad Manager and AdSense) and may include other advertising partners. To show and measure ads, these partners may set or read cookies and similar identifiers on your device and process technical data such as your approximate (coarse) location, device and browser information, and interaction with the ad. This happens subject to your consent: in the EU, UK and Switzerland advertising cookies stay off until you opt in; elsewhere they are on by default and you can opt out any time via Cookie settings. We also enable Google's consent-signal and data-redaction controls.
What we don't do: we do not give ad partners your name, email, or account identity, and we do not sell or rent your personal data. Ads shown to anyone we know or reasonably believe to be a child arecontextual only and never personalised (Section 2).
Your controls: manage advertising/marketing cookies any time from Cookie settings in the footer; subscribing removes ads entirely; and you can review Google's own ad controls at your Google account's ad settings. See the Cookie Policy for the specific cookies involved.
7. Third-Party Sub-processors
We share data only with processors that help us operate, each bound to process it on our instructions:
| Processor | Purpose | Data location |
|---|---|---|
| Clerk | Authentication and identity (email / Google sign-in) | US |
| Razorpay | Payment processing (cards, UPI, net banking) | India |
| Resend | Transactional email delivery (receipts, gift codes, notices) | US |
| Railway | Backend application hosting and database | US |
| Cloudflare | Frontend hosting, CDN, DNS, DDoS protection | Global |
| LLM providers (Google, DeepSeek, OpenAI, Anthropic, Groq) | Generating learning content and AI Assistant replies | US / Global |
| Langfuse | AI observability (PII-scrubbed traces only) | EU / US |
| Sentry | Error tracking | US |
| Google Analytics (via Google Tag Manager) | Product analytics — region-based default (see Cookie Policy) | US |
| Google Ads (via Google Tag Manager) | Conversion tracking and remarketing for our own ad campaigns — region-based default (see Cookie Policy) | US |
| Google Ad Manager / AdSense (and other ad partners) | Serving and measuring ads on the free and trial tiers — never for paid subscribers; subject to consent (see Cookie Policy) | US / Global |
We may disclose data where required by law or to protect the platform and its users from fraud or attack. There are no other recipients.
8. International Transfers
We operate from India; some processors above store data in other countries (primarily the US and EU). Where transfers occur we take steps to ensure your data is protected to a standard consistent with this policy and applicable law, including contractual safeguards with each processor.
9. Data Retention
- Active accounts: retained while your account is active.
- Account deletion: on request we delete your personal data after a short grace period (so accidental requests can be reversed), with confirmation when it completes. Notes, bookmarks, progress and assistant threads are deleted with the account.
- Financial records: orders, invoices, and credit notes are retained for the period required by Indian tax and accounting law, even after account deletion.
- Support messages: retained for a reasonable period after resolution, then deleted.
- AI observability traces: PII-scrubbed by construction and retained only for a limited operational window.
- De-identified aggregates: may be kept indefinitely — they cannot be linked to you.
10. Security
We apply technical and organisational safeguards: HTTPS everywhere, authentication delegated to a specialist provider (Clerk), payment data handled entirely by Razorpay, access controls on personal data, separation of secrets from code, PII-scrubbing before observability, and the single-active-device control against credential sharing. No system is perfectly secure, but minimising what we collect (Section 4) is itself our biggest safeguard — data we never hold cannot leak.
11. Data Breach Notification
If a personal data breach poses a risk to you, we will notify the relevant authority (in India, the Data Protection Board, as required under the DPDP Act) and affected users without undue delay, describing the nature of the breach, the data involved, and the steps we are taking.
12. Your Rights
Subject to applicable law (India DPDP Act and others), you may:
- Access a copy of the data we hold about you, and correct inaccurate data.
- Delete your account and data (Section 9), and withdraw consent at any time without affecting the lawfulness of prior processing.
- Nominate a representative to exercise your rights (a DPDP right), and — for minors — have these rights exercised by the parent/guardian.
- Grieve / complain: raise a grievance with us first (below); if unresolved, you may approach the Data Protection Board of India or the consumer forum with jurisdiction.
To make a request, email hello@conceptfirst.ai (subject: "Privacy request") or use the contact page (category: Privacy & legal). We respond within 30 days.
13. Marketing Communications
We currently send no marketing email at all — only transactional messages essential to the service (receipts and invoices, gift codes, refund updates, renewal and expiry notices, security alerts). If we ever introduce marketing email, it will be strictly opt-in, with an unsubscribe link in every message, and never directed at children.
14. Cookies
We use essential cookies, locally-stored preferences, Google Analytics + Google Ads (via Google Tag Manager, for our own product measurement and ad campaigns), and — on the free and trial tiers — advertising cookies from Google (Google Ad Manager / AdSense) and other ad partners that serve and measure ads (paid subscribers get none). Analytics and advertising cookies follow a region-based default: off in the EU/UK/Switzerland until you opt in, on elsewhere until you opt out. A consent banner records your choices on first visit, changeable anytime via "Cookie settings" in the footer. Full details, including what each cookie does, are in the Cookie Policy.
15. Grievance Officer and Contact
Privacy questions, data requests, and grievances may be sent to our Grievance Officer, Pennam Ramesh (Pennam Ventures), at hello@conceptfirst.ai (subject line: “Grievance”), or by post (address at the bottom of this page). We acknowledge grievances and respond within the timelines required by the DPDP Act, 2023 and its rules.
16. Changes to This Policy
We may update this policy and will notify you of material changes by email or prominent notice on the platform; continued use after the effective date constitutes acceptance. The "last updated" date at the top reflects the current version.
Operated by: Pennam Ventures (“ConceptFirst”) · Registered office: No 32/2, 34/1, Prestige Tech Platina, 11th Floor, Kadabisanahalli, Bengaluru, Karnataka, 560087, India
Contact: hello@conceptfirst.ai · Governing law: India · Last updated: 26 August 2026