Privacy Policy

Effective date: to be set on publication.

This policy explains what personal data SnapCard collects when you use our flashcard study app (the Service), how we use it, who we share it with, how long we keep it, and the rights you have over it. We have written this under India's Digital Personal Data Protection Act, 2023 (DPDPA) and the rules notified under it.

Plain-English summary, then the full notice.

At a glance

  • We collect your email and name (from your login), your date of birth (to confirm you can use SnapCard), the flashcards and study sessions you create, and — if you upgrade to Pro — your billing address and payment metadata.
  • We use it to run the Service, deliver study reminders, charge you, and improve the product. We do not sell your data and we do not show you third-party advertising.
  • We share the minimum needed with: Google for sign-in, Razorpay (India) for payments, Anthropic (United States) for the AI that generates flashcards from your photos, and AWS (Mumbai) for hosting. Two of these process limited data outside India — see §7 for what, where, and the safeguards in place.
  • We keep your data only as long as we need it. Tax-mandated records (invoices, payments) are kept for 7 years. Daily study session detail is pruned after 2 years. You can ask us to delete everything else anytime.
  • You can access, correct, or erase your data at any time. Email grievance@usesnapcard.com.
  • If you are under 18, we ask for your parent or guardian's email and only proceed once they confirm they agree. We do not run analytics or marketing on under-18 accounts.

1. Who we are

The data fiduciary under DPDPA is Snapcard Labs LLP, the company that operates SnapCard ("SnapCard", "we", "us", "our"). For all data-protection matters our point of contact is the Grievance Officer named in §11 below.

We operate from India and the Service is offered only to users in India.

2. The personal data we collect

We only collect what we need to give you the Service.

CategoryWhat it includesWhere it comes from
IdentityEmail address, name (optional)From you, via Sign in with Google
Age verificationDate of birth, derived adult/minor statusFrom you, on first use
Parental consent (under-18 only)Parent/guardian name, email, relationship, IP they confirmed fromFrom you (entered) and your parent (confirmation)
Account stateAccount status, role, last-login timestamp, IP of last loginGenerated by us
Study contentFlashcards you create or generate, the photos you upload to generate cards, your responses to cards, study session timestampsFrom your use of the app
Billing (Pro users only)Billing name, billing address (line 1, line 2, city, state, postal code, country), GST number (optional), emailFrom you, on checkout
Payment metadata (Pro users only)Payment method type (UPI / card last 4 / bank name), gateway transaction ID, amount, currency, statusFrom Razorpay's response
Device + technicalIP address, user-agent string, browser/OS, app versionCaptured on every request
Audit + consentTimestamps and IP for each consent change, login, and significant account actionGenerated by us

We do not collect: government IDs (Aadhaar, PAN), biometric data, health records, location data, contacts, microphone or camera data beyond photos you explicitly upload, or anything you don't deliberately enter.

3. Why we use your data

We process each category for a specific, named purpose. We rely on your consent (DPDPA §6) as the lawful basis, except where the law gives us a different basis (e.g. tax law obliges us to keep invoices).

PurposeCategories usedLawful basis
Authenticate you and keep your account secureIdentity, account state, deviceConsent + legitimate use (account security)
Confirm you can lawfully use SnapCardAge verification, parental consentDPDPA §9 obligation
Show you flashcards and run spaced-repetition reviewsStudy contentConsent (the core Service)
Process payments and issue tax-compliant invoicesBilling, payment metadataConsent + Indian tax law
Send transactional emails (login, parental confirmation, receipts, account changes)IdentityNecessary for the contract
Send product updates and marketing emailsIdentityConsent (you may opt out at any time)
Improve the product through aggregated analyticsStudy content, deviceConsent (you may opt out at any time)
Diagnose bugs and prevent abuseAudit + technicalLegitimate use
Comply with lawful requests from Indian authoritiesWhatever is requestedLegal obligation

We do not run any of the opt-in purposes (analytics, marketing) on accounts of users under 18. See §10.

4. AI-generated flashcards (Anthropic)

When you upload a photo to generate flashcards, we send the photo only (no email, no name, no user ID) to Anthropic, Inc. in the United States. Anthropic processes the photo to generate the cards and does not use the photo to train their models. We do not send any user-identifying data to Anthropic. See Anthropic's policy at https://www.anthropic.com/legal/privacy.

5. Who we share data with

We share the minimum data needed with the following service providers. None of them sell your data; all are bound by data-processing agreements.

RecipientWhat they getWhyWhere they process it
Google LLCEmail, nameVerify your identity at sign-in (Sign in with Google)United States — see §7
Razorpay Software Private LimitedEmail, phone (if you enter it), billing address, payment amount, payment methodProcess Pro payments + issue refundsIndia
Anthropic, Inc.Photo you upload for card generationGenerate flashcards (see §4)United States
Amazon Web Services, Inc.All Service data at restHosting (RDS, S3, ECS)India (Mumbai, ap-south-1)
Zoho Corporation (ZeptoMail)Recipient email, the email bodySend transactional + opted-in marketing emailIndia
Indian authoritiesWhatever is lawfully requestedWhen required by a valid court order or statuteIndia

We do not share your data with advertisers, data brokers, or any party not listed above.

6. Cookies and similar tech

We use a small number of cookies, only what is needed to run the Service:

  • Auth session cookie (essential) — our own first-party cookie that keeps you signed in after you sign in with Google.
  • Consent cookie (essential) — remembers what you selected on the consent screen so we don't ask every visit.
  • Analytics cookies (only if you opted into analytics) — we use Google Analytics 4 to understand which features get used. These set the _ga / _ga_* cookies. We load Google Analytics only after you opt in; if you don't consent (or you're under 18), the Google Analytics script is never loaded and no analytics cookies are set. We use IP anonymisation and do not enable Google Signals / ads personalisation.
  • Analytics-consent cookie (essential) — a small first-party flag (sc_analytics) that records your analytics choice so it applies across our site and the exam runner. It contains no personal data.

We do not use third-party advertising cookies, retargeting pixels, or session replay tools.

7. International data transfers (DPDPA §16)

Two service providers process limited data outside India:

  • Google (operated by Google LLC, United States) processes your email and name when you sign in with Google — the data Google needs to verify your identity. We keep you signed in with our own first-party session; we do not store a password.
  • Anthropic, Inc. (United States) processes the photo you upload for card generation — with no identifying data attached (see §4).
  • Google Analytics (Google LLC, United States) — only if you opt into analytics — processes usage and device data (pages viewed, approximate region, anonymised IP). We don't send your name or email to it, and it's never loaded for under-18 accounts. You can opt out any time on the privacy screen.

We rely on the following safeguards for both transfers:

  • DPDPA §16 status. As of the effective date of this policy, the Government of India has not notified any country as a restricted destination under §16. Both transfers are therefore permitted under current Indian law. We monitor the negative list and will revisit if either country is added.
  • Vendor security posture. Both Google and Anthropic maintain SOC 2 Type II certification; Google additionally maintains ISO 27001.
  • Contractual safeguards. Our processing agreements with both vendors include standard contractual clauses obliging them to protect your data to the standard required by Indian law.

We capture your specific informed consent to the Google transfer on the consent screen — see DPDPA Notice. You cannot use SnapCard without giving this consent, because we cannot authenticate you without Google.

All other personal data lives in India.

8. How long we keep your data

CategoryRetention
Account record (users row)While your account is active. On deletion, soft-deleted immediately, then hard-deleted/redacted within 30 days, except where law obliges us to keep specific fields longer (see below).
Invoices, payment records7 years (GST Act recordkeeping requirement) — we keep these even after your account is deleted, but unlink them from your user record
Failed payment attempts7 years (audit + fraud-prevention)
Audit logs7 years (security + statutory inquiries)
Study session detailLast 2 years; older session detail is pruned by a scheduled job. Your aggregate progress (which cards you know, when they're due) is kept while your account is active.
Parental consent recordsWhile your account is active, then redacted alongside the account
Consent recordsWhile your account is active, then redacted alongside the account
Photos you uploaded for card generation30 days after upload, then automatically deleted from S3
Server logs (Nginx, app logs)30 days

If a longer period is needed for a specific legal obligation, we keep only the fields that obligation requires and nothing else.

9. Your rights under DPDPA

You may at any time:

  • Access (DPDPA §11) — request a copy of all personal data we hold about you, in a machine-readable format. We will respond within 30 days.
  • Correct (DPDPA §12) — ask us to correct anything that is wrong, inaccurate, or out of date.
  • Erase (DPDPA §12) — ask us to delete your account and all personal data we hold, except the categories §8 says we must keep for legal reasons.
  • Withdraw consent (DPDPA §6) — change any of your opt-in choices from the Privacy screen in the app at any time. Withdrawal does not affect processing we did before you withdrew.
  • Nominate (DPDPA §14) — name another person to exercise these rights on your behalf if you become unable to.
  • Complain — first to our Grievance Officer (§11), and if not satisfied, to the Data Protection Board of India.

We provide automated tools for access and erasure inside the Privacy screen in the app. For correction and nomination, email the Grievance Officer.

10. Users under 18

Many of our users are NEET aspirants in Classes 11 and 12, who may be under 18. Under DPDPA §9, we treat anyone we know to be under 18 as a child, and we apply these additional protections:

  • We collect your date of birth on first use. If you are under 18 we cannot create an account for you without your parent or guardian's verifiable consent.
  • We email your parent or guardian a one-time confirmation link. Your account stays inactive until they click it. The link expires in 72 hours. You can re-send to a different email if needed.
  • We do not run product analytics on children's accounts. The consent screen still asks, but the answer is recorded as "not applicable" server-side and no analytics events are sent.
  • We do not send marketing email to children's accounts. Transactional email (sign-in, parental confirmation, payment receipts, account changes) continues to send.
  • We do not show ads of any kind. If we ever introduce advertising to SnapCard, children's accounts will be excluded.
  • We do not allow features that track behaviour for purposes unrelated to your studies.

If you are a parent or guardian who confirmed consent and you want to withdraw it, email the Grievance Officer. Withdrawal does not affect the lawfulness of processing before the withdrawal.

We do not knowingly process the data of children under 13. If we become aware that we have, we will delete the account.

11. Grievance Officer

Operated by: Snapcard Labs LLP Grievance Officer: Suman Saurav Email: grievance@usesnapcard.com Address: Bhagalpur, Bihar - 812002, India Response time: within 30 days of receipt, as required by DPDPA §13.

If you are not satisfied with our response, you may complain to the Data Protection Board of India when it becomes operational. We will publish updated contact details for the Board on the /grievance page of this site as soon as they are announced.

12. Security

We encrypt your data in transit (TLS 1.2+) and at rest (AES-256 on S3, encrypted RDS volumes). Access to the production database is limited to named individuals via short-lived OIDC tokens; long-lived credentials are not used. We do not use or store passwords at all — you sign in with Google, and we keep you signed in with an opaque first-party session token (stored only as a SHA-256 hash). Payment card numbers are never stored on our servers; Razorpay holds them.

We will notify the Data Protection Board within statutory timelines of any personal-data breach that risks harm to users, and we will notify affected users directly when a breach affects them specifically.

13. Changes to this policy

When we change anything material in this policy, we bump the POLICY_VERSION shown at the top, send a notice to your account email, and require you to review and re-consent on your next visit. We keep prior versions of this document in the project's git history so you can compare what changed.

Minor edits (typos, clarifying wording that doesn't change what we do) may be made without a re-consent prompt.

14. Governing law

This policy and the Service are governed by the laws of India. Any dispute arising under this policy is subject to the exclusive jurisdiction of the courts at Bhagalpur, Bihar.

15. How to reach us

For anything about your privacy:

Operated by: Snapcard Labs LLP Grievance Officer: Suman Saurav Email: grievance@usesnapcard.com Address: Bhagalpur, Bihar - 812002, India

For service support, write to the same email.