Privacy Policy
Effective date: to be set on publication.
This policy explains what personal data SnapCard collects when you use our flashcard study app (the Service), how we use it, who we share it with, how long we keep it, and the rights you have over it. We have written this under India's Digital Personal Data Protection Act, 2023 (DPDPA) and the rules notified under it.
Plain-English summary, then the full notice.
At a glance
- We collect your email and name (from your login), your date of birth (to confirm you can use SnapCard), the flashcards and study sessions you create, and — if you upgrade to Pro — your billing address and payment metadata.
- We use it to run the Service, deliver study reminders, charge you, and improve the product. We do not sell your data and we do not show you third-party advertising.
- We share the minimum needed with: Google for sign-in, Razorpay (India) for payments, Anthropic (United States) for the AI that generates flashcards from your photos, and AWS (Mumbai) for hosting. Two of these process limited data outside India — see §7 for what, where, and the safeguards in place.
- We keep your data only as long as we need it. Tax-mandated records (invoices, payments) are kept for 7 years. Daily study session detail is pruned after 2 years. You can ask us to delete everything else anytime.
- You can access, correct, or erase your data at any time. Email grievance@usesnapcard.com.
- If you are under 18, we ask for your parent or guardian's email and only proceed once they confirm they agree. We do not run analytics or marketing on under-18 accounts.
1. Who we are
The data fiduciary under DPDPA is Snapcard Labs LLP, the company that operates SnapCard ("SnapCard", "we", "us", "our"). For all data-protection matters our point of contact is the Grievance Officer named in §11 below.
We operate from India and the Service is offered only to users in India.
2. The personal data we collect
We only collect what we need to give you the Service.
| Category | What it includes | Where it comes from |
|---|---|---|
| Identity | Email address, name (optional) | From you, via Sign in with Google |
| Age verification | Date of birth, derived adult/minor status | From you, on first use |
| Parental consent (under-18 only) | Parent/guardian name, email, relationship, IP they confirmed from | From you (entered) and your parent (confirmation) |
| Account state | Account status, role, last-login timestamp, IP of last login | Generated by us |
| Study content | Flashcards you create or generate, the photos you upload to generate cards, your responses to cards, study session timestamps | From your use of the app |
| Billing (Pro users only) | Billing name, billing address (line 1, line 2, city, state, postal code, country), GST number (optional), email | From you, on checkout |
| Payment metadata (Pro users only) | Payment method type (UPI / card last 4 / bank name), gateway transaction ID, amount, currency, status | From Razorpay's response |
| Device + technical | IP address, user-agent string, browser/OS, app version | Captured on every request |
| Audit + consent | Timestamps and IP for each consent change, login, and significant account action | Generated by us |
We do not collect: government IDs (Aadhaar, PAN), biometric data, health records, location data, contacts, microphone or camera data beyond photos you explicitly upload, or anything you don't deliberately enter.
3. Why we use your data
We process each category for a specific, named purpose. We rely on your consent (DPDPA §6) as the lawful basis, except where the law gives us a different basis (e.g. tax law obliges us to keep invoices).
| Purpose | Categories used | Lawful basis |
|---|---|---|
| Authenticate you and keep your account secure | Identity, account state, device | Consent + legitimate use (account security) |
| Confirm you can lawfully use SnapCard | Age verification, parental consent | DPDPA §9 obligation |
| Show you flashcards and run spaced-repetition reviews | Study content | Consent (the core Service) |
| Process payments and issue tax-compliant invoices | Billing, payment metadata | Consent + Indian tax law |
| Send transactional emails (login, parental confirmation, receipts, account changes) | Identity | Necessary for the contract |
| Send product updates and marketing emails | Identity | Consent (you may opt out at any time) |
| Improve the product through aggregated analytics | Study content, device | Consent (you may opt out at any time) |
| Diagnose bugs and prevent abuse | Audit + technical | Legitimate use |
| Comply with lawful requests from Indian authorities | Whatever is requested | Legal obligation |
We do not run any of the opt-in purposes (analytics, marketing) on accounts of users under 18. See §10.
4. AI-generated flashcards (Anthropic)
When you upload a photo to generate flashcards, we send the photo only (no email, no name, no user ID) to Anthropic, Inc. in the United States. Anthropic processes the photo to generate the cards and does not use the photo to train their models. We do not send any user-identifying data to Anthropic. See Anthropic's policy at https://www.anthropic.com/legal/privacy.
5. Who we share data with
We share the minimum data needed with the following service providers. None of them sell your data; all are bound by data-processing agreements.
| Recipient | What they get | Why | Where they process it |
|---|---|---|---|
| Google LLC | Email, name | Verify your identity at sign-in (Sign in with Google) | United States — see §7 |
| Razorpay Software Private Limited | Email, phone (if you enter it), billing address, payment amount, payment method | Process Pro payments + issue refunds | India |
| Anthropic, Inc. | Photo you upload for card generation | Generate flashcards (see §4) | United States |
| Amazon Web Services, Inc. | All Service data at rest | Hosting (RDS, S3, ECS) | India (Mumbai, ap-south-1) |
| Zoho Corporation (ZeptoMail) | Recipient email, the email body | Send transactional + opted-in marketing email | India |
| Indian authorities | Whatever is lawfully requested | When required by a valid court order or statute | India |
We do not share your data with advertisers, data brokers, or any party not listed above.
6. Cookies and similar tech
We use a small number of cookies, only what is needed to run the Service:
- Auth session cookie (essential) — our own first-party cookie that keeps you signed in after you sign in with Google.
- Consent cookie (essential) — remembers what you selected on the consent screen so we don't ask every visit.
- Analytics cookies (only if you opted into analytics) — we use
Google Analytics 4 to understand which features get used. These set the
_ga/_ga_*cookies. We load Google Analytics only after you opt in; if you don't consent (or you're under 18), the Google Analytics script is never loaded and no analytics cookies are set. We use IP anonymisation and do not enable Google Signals / ads personalisation. - Analytics-consent cookie (essential) — a small first-party flag
(
sc_analytics) that records your analytics choice so it applies across our site and the exam runner. It contains no personal data.
We do not use third-party advertising cookies, retargeting pixels, or session replay tools.
7. International data transfers (DPDPA §16)
Two service providers process limited data outside India:
- Google (operated by Google LLC, United States) processes your email and name when you sign in with Google — the data Google needs to verify your identity. We keep you signed in with our own first-party session; we do not store a password.
- Anthropic, Inc. (United States) processes the photo you upload for card generation — with no identifying data attached (see §4).
- Google Analytics (Google LLC, United States) — only if you opt into analytics — processes usage and device data (pages viewed, approximate region, anonymised IP). We don't send your name or email to it, and it's never loaded for under-18 accounts. You can opt out any time on the privacy screen.
We rely on the following safeguards for both transfers:
- DPDPA §16 status. As of the effective date of this policy, the Government of India has not notified any country as a restricted destination under §16. Both transfers are therefore permitted under current Indian law. We monitor the negative list and will revisit if either country is added.
- Vendor security posture. Both Google and Anthropic maintain SOC 2 Type II certification; Google additionally maintains ISO 27001.
- Contractual safeguards. Our processing agreements with both vendors include standard contractual clauses obliging them to protect your data to the standard required by Indian law.
We capture your specific informed consent to the Google transfer on the consent screen — see DPDPA Notice. You cannot use SnapCard without giving this consent, because we cannot authenticate you without Google.
All other personal data lives in India.
8. How long we keep your data
| Category | Retention |
|---|---|
Account record (users row) | While your account is active. On deletion, soft-deleted immediately, then hard-deleted/redacted within 30 days, except where law obliges us to keep specific fields longer (see below). |
| Invoices, payment records | 7 years (GST Act recordkeeping requirement) — we keep these even after your account is deleted, but unlink them from your user record |
| Failed payment attempts | 7 years (audit + fraud-prevention) |
| Audit logs | 7 years (security + statutory inquiries) |
| Study session detail | Last 2 years; older session detail is pruned by a scheduled job. Your aggregate progress (which cards you know, when they're due) is kept while your account is active. |
| Parental consent records | While your account is active, then redacted alongside the account |
| Consent records | While your account is active, then redacted alongside the account |
| Photos you uploaded for card generation | 30 days after upload, then automatically deleted from S3 |
| Server logs (Nginx, app logs) | 30 days |
If a longer period is needed for a specific legal obligation, we keep only the fields that obligation requires and nothing else.
9. Your rights under DPDPA
You may at any time:
- Access (DPDPA §11) — request a copy of all personal data we hold about you, in a machine-readable format. We will respond within 30 days.
- Correct (DPDPA §12) — ask us to correct anything that is wrong, inaccurate, or out of date.
- Erase (DPDPA §12) — ask us to delete your account and all personal data we hold, except the categories §8 says we must keep for legal reasons.
- Withdraw consent (DPDPA §6) — change any of your opt-in choices from the Privacy screen in the app at any time. Withdrawal does not affect processing we did before you withdrew.
- Nominate (DPDPA §14) — name another person to exercise these rights on your behalf if you become unable to.
- Complain — first to our Grievance Officer (§11), and if not satisfied, to the Data Protection Board of India.
We provide automated tools for access and erasure inside the Privacy screen in the app. For correction and nomination, email the Grievance Officer.
10. Users under 18
Many of our users are NEET aspirants in Classes 11 and 12, who may be under 18. Under DPDPA §9, we treat anyone we know to be under 18 as a child, and we apply these additional protections:
- We collect your date of birth on first use. If you are under 18 we cannot create an account for you without your parent or guardian's verifiable consent.
- We email your parent or guardian a one-time confirmation link. Your account stays inactive until they click it. The link expires in 72 hours. You can re-send to a different email if needed.
- We do not run product analytics on children's accounts. The consent screen still asks, but the answer is recorded as "not applicable" server-side and no analytics events are sent.
- We do not send marketing email to children's accounts. Transactional email (sign-in, parental confirmation, payment receipts, account changes) continues to send.
- We do not show ads of any kind. If we ever introduce advertising to SnapCard, children's accounts will be excluded.
- We do not allow features that track behaviour for purposes unrelated to your studies.
If you are a parent or guardian who confirmed consent and you want to withdraw it, email the Grievance Officer. Withdrawal does not affect the lawfulness of processing before the withdrawal.
We do not knowingly process the data of children under 13. If we become aware that we have, we will delete the account.
11. Grievance Officer
Operated by: Snapcard Labs LLP Grievance Officer: Suman Saurav Email: grievance@usesnapcard.com Address: Bhagalpur, Bihar - 812002, India Response time: within 30 days of receipt, as required by DPDPA §13.
If you are not satisfied with our response, you may complain to the
Data Protection Board of India when it becomes operational. We
will publish updated contact details for the Board on the /grievance
page of this site as soon as they are announced.
12. Security
We encrypt your data in transit (TLS 1.2+) and at rest (AES-256 on S3, encrypted RDS volumes). Access to the production database is limited to named individuals via short-lived OIDC tokens; long-lived credentials are not used. We do not use or store passwords at all — you sign in with Google, and we keep you signed in with an opaque first-party session token (stored only as a SHA-256 hash). Payment card numbers are never stored on our servers; Razorpay holds them.
We will notify the Data Protection Board within statutory timelines of any personal-data breach that risks harm to users, and we will notify affected users directly when a breach affects them specifically.
13. Changes to this policy
When we change anything material in this policy, we bump the
POLICY_VERSION shown at the top, send a notice to your account email,
and require you to review and re-consent on your next visit. We keep
prior versions of this document in the project's git history so you
can compare what changed.
Minor edits (typos, clarifying wording that doesn't change what we do) may be made without a re-consent prompt.
14. Governing law
This policy and the Service are governed by the laws of India. Any dispute arising under this policy is subject to the exclusive jurisdiction of the courts at Bhagalpur, Bihar.
15. How to reach us
For anything about your privacy:
Operated by: Snapcard Labs LLP Grievance Officer: Suman Saurav Email: grievance@usesnapcard.com Address: Bhagalpur, Bihar - 812002, India
For service support, write to the same email.