Privacy Policy
Privacy Policy — 24/7 Education (E247)
Last updated: 30 June 2026
This Privacy Policy explains how Nakshatra Jain
(“we”, “us”) collects, uses, stores, and shares personal data when you use the
24/7 Education mobile and web application (the “App”). We comply
with the Digital Personal Data Protection Act, 2023 (DPDP Act)
of India, and where applicable, the GDPR.
1. Who is the data fiduciary?
The data fiduciary is Nakshatra Jain, operating from
Ajmer, Rajasthan, India.
For privacy queries or to exercise your rights, contact:
hustlecreates@gmail.com.
2. What data we collect
- Account data: an anonymous user ID generated by our auth
provider, a display name you choose, and an auto-generated friend code
(e.g.
EDU-XXXXX).
- Plan data: the study goal text you submit, the AI-generated
plan, and your progress on it (XP, streaks, days completed).
- Shared-plan data: when you join a plan with friends, your
display name and progress are visible to other members of that plan.
- Notes you write: if you use the Notes tab, the date, title,
text, mood and colour of each note are stored in your account so they sync
across your devices. Notes are private to you, are never shared with other
users, and are never sent to the AI.
- Locked notes are end-to-end encrypted. When you lock a
note it is encrypted on your own device with a key derived from your
4-digit PIN. Only the scrambled text ever reaches our servers.
We cannot read your locked notes, and neither can
anyone who obtained a copy of our database. We do not store your PIN
itself — only a one-way hash of it — so we cannot recover
or reset it. If you forget your PIN, those notes cannot be opened
again by anyone, including us.
- Unlocked notes are stored in readable form on our
database provider (Supabase), protected by transport encryption,
encryption at rest, and row-level security so that no other user can
access them. Our staff do not read them, and we never use them for
advertising, profiling or AI training — but we are technically
able to access them, in the same way as most major notes apps. If you
want a note to be readable only by you, lock it.
- Payment data: we do not see or store your card
details. Payments are processed entirely by Apple App Store or Google Play.
We only receive a record that a credit pack was purchased.
- Technical data: your IP address (used briefly for rate
limiting and abuse prevention) and basic device/browser info.
3. What we do NOT collect
- We do not ask for your phone number or your real name.
- If you sign in with Google, we receive the email address of that Google
account so we can identify you across devices. We do not use it for
marketing and we do not share it.
- We do not track you across other apps or websites.
- We do not sell your data to advertisers. We do not show ads.
4. Why we collect it (purposes)
- To create and save your study plans (contract).
- To enable shared plans with friends (consent — by joining a plan).
- To generate AI plans via Google Gemini (contract).
- To prevent abuse and protect the service (legitimate interest).
- To process in-app purchases (contract).
5. Third-party data processors
We use the following services to operate the App. We do not share your data with
them beyond what is necessary to run the service:
- Supabase (database + auth) — servers in Singapore (ap-southeast-1).
privacy policy.
- Vercel (backend hosting) — servers in the US/EU.
privacy policy.
- Netlify (web hosting) — servers globally.
privacy policy.
- AI provider such as Google Gemini API (AI plan generation) — your goal text is sent
to the provider to generate a plan. The provider's terms apply.
privacy policy.
- Apple App Store / Google Play — payment processing.
6. Cross-border transfers
Some of our processors are located outside India (Singapore, US, EU). By using the
App, you consent to this transfer. We choose providers with industry-standard
security and contractual data-protection commitments.
6A. AI prompt safety and masking
Before goal text is sent to our AI provider, we try to mask obvious sensitive
identifiers such as email addresses, phone numbers, invite codes, and links.
This masking is a safety measure, not a guarantee. Please do not enter highly
sensitive personal, financial, medical, legal, or identity information into
your goals.
7. How long we keep your data
- Account + plan data: as long as your account exists.
- If you delete your account: erased within 30 days, except where retention is
required by law (e.g. tax records of purchases — 8 years under Indian law).
- Rate-limit records: short-lived abuse-prevention records, usually under 24 hours.
8. Your rights under the DPDP Act
You have the right to:
- Access the personal data we hold about you.
- Correct or update it.
- Erase it (request account deletion).
- Withdraw consent at any time.
- Nominate another person to exercise your rights in case of death or incapacity.
- File a grievance with us. If unresolved within 30 days, escalate to the Data
Protection Board of India.
To exercise any right, email hustlecreates@gmail.com. We respond within
7 working days, and resolve within 30 days.
9. Children's data
The App is intended for users aged 13 and above. Under the DPDP
Act, users under 18 in India require verifiable consent from a parent or legal
guardian. By creating an account, you confirm you meet this requirement, or have
parental consent. We do not knowingly process children's data for behavioural
monitoring or targeted advertising.
10. Security
We use HTTPS everywhere, server-side API keys, row-level security on our database,
prompt filtering, basic output validation, and per-IP rate limiting on our AI
endpoint. No system is perfectly secure — if you discover a vulnerability,
please email hustlecreates@gmail.com.
Locked notes use end-to-end encryption (AES-256-GCM). The key is
derived from your PIN on your own device using PBKDF2; it is never transmitted and
never stored. This means a locked note is unreadable to us, to our hosting provider,
and to anyone who obtains a copy of our data. Your PIN is stored only as a salted
SHA-256 hash, so it cannot be recovered from our systems.
11. Changes to this policy
If we change this policy materially, we will update the “Last updated” date and
notify you in the App on next launch. Continued use means you accept the updated
policy.
11A. Reporting a bug or security issue
E247 is built and run by one person. If you find a bug, a privacy problem, or any
way to see data you should not be able to see, please tell us first
at hustlecreates@gmail.com. Security and privacy reports are read
before anything else and answered within 72 hours.
We will not pursue legal action against anyone who reports a genuine issue in good
faith, who does not access or alter other people's data beyond what is needed to
demonstrate the problem, and who gives us a reasonable chance to fix it before
making it public. We would much rather hear from you than read about it later.
12. Grievance Officer
Under the DPDP Act and the IT Rules 2011:
Grievance Officer: Nakshatra Jain
Email: hustlecreates@gmail.com
Address: E-247 Shastri Nagar, Ajmer, Rajasthan 305001, India
Response within 30 days.
← Back to app