Privacy Policy
This Privacy Policy explains what data Padham Sathi collects, why, and how we protect it.
1. Information We Collect
- Account data: name, email and/or phone number, and a hashed password.
- Usage data: pages viewed, notes/questions accessed, device and browser information, IP address.
- Security data: login attempts, device fingerprints, and audit logs used to detect abuse.
2. How We Use Verification Codes
One-time codes (OTPs) sent by email or SMS are only ever delivered to a medium you have already verified as belonging to you — with the sole exception of the initial code used to verify a brand-new email or phone number at signup. We never send login or password-reset codes to an unverified contact.
3. How We Use Your Information
- To create and secure your account (authentication, fraud prevention, rate limiting).
- To send transactional messages: OTPs, password resets, and service notices.
- To personalize your dashboard (continue learning, bookmarks, recommendations).
- To improve the Service through aggregated, anonymized analytics.
4. reCAPTCHA
We use Google reCAPTCHA v3 to protect registration, login, password reset, and contact forms from automated abuse. reCAPTCHA may collect hardware and software information and send it to Google in accordance with the Google Privacy Policy.
5. Data Retention
Verification codes and password-reset tokens are deleted automatically after they expire or are used. Account data is retained until you request deletion, with the following automatic exceptions, run nightly:
- Session/device records (used for the "My Sessions" list on your account) older than 90 days are deleted automatically.
- Chapter-reading progress for a subscription that has lapsed and not been renewed is deleted after 90 days, so what you were reading isn't kept indefinitely once access has ended - renewing your subscription in that window keeps it intact.
- Raw, non-aggregated analytics/behavior events are deleted after 180 days; only aggregated, anonymized statistics are kept beyond that.
6. Data Sharing
We do not sell your personal data. We share data only with service providers strictly necessary to operate the Service (e.g. our SMS provider for OTP delivery, our email provider for transactional email), bound by confidentiality obligations.
7. Your Rights
You may request access to, correction of, or deletion of your personal data at any time via our Contact page.
8. Security
Passwords are hashed, never stored in plain text. Verification codes and reset tokens are stored as one-way hashes. All account changes are recorded in an audit log for your protection.
9. Children's Privacy
The Service is intended for students of school age and above under appropriate parental/guardian guidance where applicable local law requires it.
10. Changes to This Policy
We will post any changes to this page and update the "Last updated" date above.