Privacy Policy

Last updated: November 6, 2025

1. Introduction

At Evalyy, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered educational platform. By using Evalyy, you consent to the data practices described in this policy.

2. Information We Collect

We collect several types of information from and about users of our platform:

2.1 Account Information

  • Full name
  • Email address
  • Password (stored in encrypted/hashed format)
  • Email verification status

2.2 Authentication Information

  • Google OAuth data (if you sign in with Google): Google ID, email, and profile information
  • Authentication provider (local or Google)

2.3 API Keys and Credentials

  • Google API key (stored in encrypted format)
  • Note: API keys are encrypted and never displayed in full

2.4 Study Session Data

  • Study session content and preferences
  • Question sets and quiz submissions
  • Difficulty preferences and curriculum settings
  • Study progress and performance data

2.5 Payment Information

  • Stripe customer ID and Razorpay payment information
  • Token purchase transactions
  • Payment transaction records (processed by payment processors, not stored by us)

2.6 Usage Data

  • Token usage (evalyy_token balance)
  • Platform usage statistics
  • Device and browser information
  • IP address and location data

2.7 Analytics Data

  • Google Analytics data (only with your consent)
  • Page views, clicks, and user interactions
  • Session duration and navigation patterns

3. How We Use Your Information

We use the information we collect for various purposes:

  • To provide and maintain our AI-powered educational platform
  • To create personalized study sessions and quiz questions based on your curriculum
  • To process your token purchases
  • To send you email verification messages and account-related communications
  • To respond to your inquiries and provide customer support
  • To improve our platform, services, and user experience
  • To detect and prevent fraud, security issues, and abuse
  • To comply with legal obligations and enforce our Terms and Conditions
  • To analyze platform usage and trends (with your consent for analytics)

4. How We Store and Protect Your Information

We implement appropriate technical and organizational measures to protect your personal information:

  • Passwords are hashed using secure encryption algorithms
  • API keys are stored in encrypted format
  • Data is transmitted over secure HTTPS connections
  • Access to personal data is restricted to authorized personnel only
  • Regular security audits and updates to protect against vulnerabilities
  • Data is stored in secure databases with access controls

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

5. Third-Party Services

We use third-party services that may collect information:

5.1 Payment Processors

We use Stripe and Razorpay to process payments. When you make a purchase, your payment information is processed directly by these payment processors and is subject to their respective Privacy Policies. We only receive transaction confirmations and payment status updates.

5.2 Google Services

If you choose to sign in with Google OAuth, we receive your Google profile information in accordance with Google's Privacy Policy. We also use Google Analytics (with your consent) to understand how users interact with our platform.

5.3 AI Service Providers

When you use our AI-powered features, your Google API key is used to generate study content. API keys are encrypted and managed according to the respective service providers' terms.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies:

  • Essential Cookies: Required for platform functionality (authentication, session management)
  • Analytics Cookies: Used with your consent to analyze platform usage via Google Analytics
  • Preference Cookies: Remember your cookie preferences and settings

You can manage your cookie preferences at any time through our Cookie Preferences settings. Analytics cookies are only used with your explicit consent.

7. Data Retention

We retain your personal information for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations
  • Resolve disputes and enforce our agreements
  • Maintain security and prevent fraud

When you delete your account, we will delete or anonymize your personal information, except where we are required to retain it for legal purposes.

8. Your Rights and Choices

You have the following rights regarding your personal information:

  • Access: Request access to your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your account and associated data
  • Data Portability: Request a copy of your data in a portable format
  • Consent Withdrawal: Withdraw consent for analytics cookies at any time
  • Account Settings: Update your account information through your profile settings

To exercise these rights, please contact us at support@evalyy.com or update your preferences in your account settings.

9. Contact Us

If you have any questions about this Privacy Policy, your personal information, or wish to exercise your rights, please contact us:

  • Business Name: Evalyy
  • Email: support@evalyy.com

We will respond to your inquiry within a reasonable timeframe.