1. Who we are
Eduera AI is a learning service for school students (Classes 5–9), entrance-exam aspirants (NEET, JEE) and competitive-exam candidates (Bank PO, RRB, SSC and similar).
- Data Fiduciary (the company responsible for your information): Lumeward Technologies Private Limited
- Registered address: 1-172E, New Street, SKLM- 532218
- Website: eduera.ai
- CIN / registration number: Owner to supply — CIN or company registration number
- GSTIN: Owner to supply — GST registration number
How to reach us about your information
- Grievance Officer: Owner to supply — Name of the Grievance Officer
- Email: Owner to supply — Monitored grievance mailbox
- Postal address: Owner to supply — Postal address for written requests
- Response time: we aim to acknowledge within Owner to supply — Time within which a request is acknowledged and to resolve within Owner to supply — Time within which a request is resolved.
You can also raise a request from inside the app, under Questions & Feedback, once you are signed in. If you cannot sign in — for example because you never created an account — use the email address above.
2. Which parts of this policy apply to you
Eduera AI has three separate areas, and who agrees to what is different in each.
- School (Classes 5–9). The account is held by a parent or lawful guardian. The learner is a child, usually under 18. The parent agrees, for themselves and for the child.
- Entrance (NEET, JEE). The account is held either by the learner themselves or by a parent who adds a child. The learner is an adult, or a child added by a parent. Whoever holds the account agrees; a parent also agrees on the child's behalf.
- Career (Bank PO, RRB, SSC and similar). The account is always held by the learner themselves, who is an adult and agrees for themselves.
In School, and in Entrance when a parent adds a child, the person who agrees and the person the information is about are two different people. Section 8 explains what that means in practice.
3. What we collect
3.1 Account information (everyone)
- Your mobile number. This is how you sign in. We store it in the international format (+91 and ten digits) and verify it with a one-time code sent by SMS.
- Your name.
- Your password, stored only as a bcrypt hash — we never hold the password itself and cannot show it to you.
- Your email address, if you choose to give one. Email is optional and is not a way to sign in. If you add one, we use it to send your GST invoice.
- Your account status, which area of Eduera AI you use by default, and the date and version of the Privacy Policy and Terms you accepted.
- One-time codes for signing up and for resetting a password, held only as a hash and only until they expire (ten minutes).
3.2 Learner profile
For each learner (whether that is you or your child):
- Name
- Board or exam, and class or stage
- School name — optional, offered only for School learners
- Date of birth — optional
Only the name, and the board or exam and class or stage, are required. The school name and date of birth are fields you may fill in if you want to; nothing in Eduera AI asks for them and nothing stops working if you leave them blank.
We do not need a date of birth to know that a learner is a child. The class tells us: a learner in Class 5 is about ten years old. Every learner in the School area is treated as a child and given the protections in Section 8, whether or not a date of birth was ever entered.
3.3 Learning records
Every time a learner practises or takes a test, we keep:
- Which assignment or test it was, and which board, class, subject, chapter and difficulty level it covered
- Every question that was served
- The answer the learner chose or typed
- Whether it was right, wrong, partly right or left blank
- The score
- How many seconds were spent on each individual question
- When it was started and finished
From those records we work out, and store:
- Chapter and concept mastery, and which levels have been unlocked (School only)
- Chapter assessment results and remediation plans
- Scheduled practice and weakness-recovery sessions
3.4 The learning profile (“Learning DNA”)
From the learning records above, Eduera AI builds a picture of how the learner works. This is profiling, and for School learners it is profiling of a child, so we describe it plainly rather than calling it “personalisation”.
It includes:
- Accuracy — how often answers are right
- Speed — how the time spent on each question compares with the time the question is expected to take
- Challenge — accuracy weighted by the difficulty of the questions
- Consistency — how steady performance is from one session to the next
- Strong and weak topics, named chapter by chapter and concept by concept
- Behavioural patterns, currently four: a repeated mistake on one topic, a gap between knowing a concept and applying it, and “possible rushing” — raised when three or more wrong answers were each given in under three quarters of the time the question was expected to take
The profile is worked out fresh each time it is displayed, from the learning records in Section 3.3. We do not keep a separate stored profile. So if the underlying attempts are deleted, the profile disappears with them.
What we do not do with it. We do not use it to advertise anything to a learner, we do not sell it, we do not share it with schools or other families, and we do not use it to make any decision with a legal or similarly significant effect. It is used to choose what to practise next and to show progress.
3.5 Subscription and payment information
- Which plan was bought, for which learner and which board or exam
- The price, the promo discount if any, the GST amount, and the total
- Payment status, refund status, and the reference numbers our payment gateway gives us
- The invoice number and the date the invoice was emailed
We never see or store your card number, UPI ID, bank details, CVV or PIN. Those are entered on the payment gateway's own page and stay with the gateway. What we keep is the gateway's reference for the transaction. (Earlier wording said Eduera AI “does not need to store” complete payment credentials. It does not store them.)
3.6 Support messages
If you write to us through Questions & Feedback, we keep your message, the learner it is about, your email if you gave one, and one optional screenshot (JPEG or PNG, up to 3 MB) if you attach one. Our support staff read these.
3.7 Uploaded answer images
Where a question is answered on paper, the app can accept a photo of the handwritten answer (JPEG or PNG, up to 2 MB). The image is stored with our cloud storage provider and a record of it is kept against the attempt. A photo of a child's written work may show their handwriting and their name.
3.8 Referral invitations — information about people who are not our users
If you invite someone to Eduera AI, we store their mobile number, the invitation code, who invited them, and whether they have joined.
That person has not signed up and has not agreed to anything. We hold their number so that, if they do sign up with it, the invitation is recognised and credited to you.
- Invitations are shared by you, through WhatsApp, from your own device.
- Eduera AI does not currently send any SMS to an invited number. The SMS channel is built but switched off in every environment.
- Only a Super Admin can see a list of invited people who have not joined. Every single viewing of that list is recorded in our audit log, and there is no way to download or export it in bulk.
- We do not use these numbers for marketing.
3.9 Technical and security information
- Server logs recording that a request happened, its outcome, and identifiers for the account — used to run the service and to investigate problems
- Your IP address is used briefly, in memory and in a short-lived cache, to limit how many sign-in attempts, one-time codes and AI requests can come from one place. It is not written to our database for this purpose.
- Records of administrative actions taken by our staff
3.10 Visitors who have not signed in
You can ask the assistant on our home page a question before you have an account. When you do:
- Your message and the conversation so far are sent to our AI provider to be answered (see Section 5).
- We do not store your message, your reply, your IP address, a session identifier, or anything that could tie two questions to the same person.
- We increase a daily counter — a number like “the home-page assistant was asked 42 questions today”. The table it lives in has no column an identifier could be put in.
- Your IP address is used briefly to rate-limit abuse, as in Section 3.9.
Website analytics. Eduera AI has a first-party analytics feature that, when switched on, sets a cookie named eduera_visitor_id lasting up to 12 months and keeps a 30-minute session identifier, in order to count visits to public pages, how many end in a registration and, once you are signed in, which screens of the app are used and where a flow such as choosing a plan or starting an assignment is left unfinished. It records the page path, the referring site, UTM campaign tags, and a keyed hash of the IP address and browser string — never the raw IP address, never precise location, and never a learner's answers or results. If you then register, the visits recorded under that visitor identifier are linked to your account.
This feature is switched off in our production service as deployed today. If we turn it on, we will say so here before we do.
Google Analytics, on public pages only. The public pages of our website (the home page, the curriculum pages, the sign-in and sign-up pages, and these two legal pages) load Google Analytics 4, a service of Google LLC, to count visits and see which pages are read. It is never loaded on any page you reach after signing in, so nothing a learner does in Eduera AI is sent to Google. It runs with advertising features switched off and with IP addresses anonymised; we do not use it for advertising, remarketing or cross-site tracking. Google may process this data outside India. No advertising pixel, session-recording tool or other third-party tag is loaded anywhere.
4. Why we use your information, and on what basis
- Create and secure your account; verify your mobile number. Why: you cannot use the service otherwise. Basis: your consent at signup, and necessity for the service you asked for.
- Serve assignments, mark answers, show results. Why: this is the service. Basis: your consent; performance of our agreement with you.
- Build the learning profile in Section 3.4 and recommend what to practise next. Why: to make practice useful instead of random. Basis: your consent, given at signup. For a child in School, the parent's consent.
- Answer questions through Eduera AI's assistants. Why: you asked a question. Basis: your consent.
- Take payment, raise a GST invoice, handle refunds. Why: to sell you a subscription and meet tax law. Basis: performance of our agreement; legal obligation.
- Reply to support messages. Why: you wrote to us. Basis: your consent.
- Recognise a referral. Why: to credit the person who invited you. Basis: your consent, as the inviter.
- Limit abuse, investigate security incidents, keep the service running. Why: to keep the service safe and available. Basis: our legitimate interest in running a secure service, and legal obligation.
- Count usage so we can size capacity and cost. Why: to run the business. Basis: legitimate interest; the figures are aggregated.
We do not use your information or your child's to advertise, we do not sell it, we do not share it with data brokers, and we do not profile a learner for any purpose other than their own learning.
5. Eduera AI's use of an AI provider
Parts of Eduera AI are answered by a large language model run by a third-party provider. You should know exactly what is sent.
What leaves our systems
When a learner uses the assistant on a results page or a dashboard, we send:
- The assignment's title, and the board or exam, class or stage, subject, chapter and difficulty level
- The score, and how many answers were right, wrong and unanswered
- The learner's weakest topics
- Each question in the attempt, the learner's own answer, the correct answer, the time they spent on it, and the stored explanation
- The learner's typed message and the conversation so far
When a visitor uses the home-page assistant, we send their message, the conversation so far, and material drawn from our published course catalogue.
What does not leave
We do not send the learner's name, the parent's name, the mobile number, the email address, the school name, the date of birth, the account identifier or the payment details. The provider receives learning content, not an identity.
We do not permit the provider to use what we send to train its models. Owner to supply — Confirmation that the provider may not train on what we send
Which provider, and where
The provider, the model and the server address they are reached at are settings our administrators control, so they can change without a new release of the app.
- Provider used today: Owner to supply — AI provider and model in use
- Where processing happens: Owner to supply — Region where AI processing happens Confirm whether this is inside India or outside it.
Processing may take place outside India. If it does, we do it under Owner to supply — Safeguard relied on for processing outside India. We will name the provider and the region here and keep it current.
The output may be wrong
Answers, explanations, generated practice questions, estimated mastery and recommendations are produced automatically and may be incomplete or incorrect. They are learning aids. They are not official grades, not a professional educational assessment and not a guarantee of results. Check anything important against the current syllabus, the textbook, the school or a teacher.
6. Who else we share information with
We share only what is necessary, and only with these kinds of organisation:
- Payment gateway (Owner to supply — Name of the payment gateway) takes the payment. It receives your payment instrument, which goes to them and not to us, and the order amount and reference.
- AI provider (Owner to supply — AI provider and model in use) answers questions and generates explanations. It receives the learning content in Section 5. No names, no contact details.
- Email provider (Owner to supply — Name of the email provider) delivers your GST invoice. It receives your email address, your name and the invoice.
- SMS provider (Owner to supply — Name of the SMS provider) would deliver one-time codes, receiving your mobile number and the code. No SMS provider is connected today.
- Cloud hosting and database (Owner to supply — Name of the hosting provider) runs the servers and stores the database. It holds everything in this policy, as the place it is kept.
- Cloud file storage (Owner to supply — Name of the file-storage provider) stores uploaded answer photos, if that feature is kept. It receives the image.
We may also disclose information where the law requires it, to protect people or the service, or in connection with a sale or reorganisation of the business — in which case the same protections would have to follow the information.
We do not sell personal data.
Inside Eduera AI, our own staff hold different levels of access, recorded against named accounts. Some staff roles can see and export the list of registered parents and learners, including names. Every such export is written to an audit log.
7. How long we keep things
These are the periods the software actually applies.
- Account, learner profile, and all learning records — attempts, answers, per-question timing, scores, mastery: kept for as long as the account exists, and not deleted automatically. Deleted only if you ask us to (Section 9).
- Records of AI requests (which feature, when, how many tokens — not the content): 90 days, then deleted.
- Daily counters for the home-page assistant (no identity at all): 730 days (2 years), then deleted.
- Website analytics events (when the feature is on; it is off today): 395 days (13 months), then deleted.
- Google Analytics (public pages only): kept by Google for the retention period set on our Google Analytics property, at most 14 months, then deleted.
- Referral invitations, including an invited non-user's mobile number: kept indefinitely, with no automatic deletion.
- Subscription and payment records, and invoices: kept indefinitely as financial records. Owner to supply — Retention period for financial records
- Support messages and attached screenshots: kept indefinitely.
- Administrative audit logs: kept indefinitely, so that access to personal data stays accountable.
- One-time codes: 10 minutes, then they expire.
- Cached AI conversations: 1 hour, in a store that is wiped when the service restarts. Not a saved transcript.
Where something says “kept indefinitely” above, that is a statement of what the software does today, not a claim that it should be so.
8. Children
Every learner in the School area is treated as a child. Classes 5 to 9 means learners of roughly ten to fifteen, so we do not ask for proof of age and do not rely on a date of birth being present — the class the learner is enrolled in establishes it. Almost everything in this section is about them.
A learner in the Entrance area who was added by a parent is treated the same way. A learner who manages their own account is treated as an adult.
How and when a parent consents
Consent is given once, when you register, and it covers the learners you add afterwards.
To create an account you give your own mobile number and verify it with a one-time code, so we know the number is real and reachable by you. You then tick a box confirming that you have read and agree to this Privacy Policy and to the Terms & Conditions. The box must be ticked; the account cannot be created otherwise.
When you tick it we do not just store a yes. We record four things against your account:
- the date and time you accepted this Privacy Policy;
- the version of this Privacy Policy you accepted;
- the date and time you accepted the Terms & Conditions;
- the version of the Terms & Conditions you accepted.
So there is a dated, versioned record of exactly which text you agreed to. If we change either document we change its version, and Section 12 explains what happens then.
Under the Terms you agree to at that moment, you confirm that you are a parent or lawful guardian and that you are authorised to create and manage every learner profile on your account, and to provide their information. That agreement covers each learner you add later — you are not asked to agree again each time, and adding a learner is treated as you exercising the authority you confirmed at registration.
The child never signs in
A child added by a parent does not get login credentials. The account we create for them carries an internal placeholder address (…@eduera.local) that receives no mail and cannot be used to sign in. The parent signs in and acts on the child's behalf.
What a parent can see and do
A parent signed in to their account can see, for each child on it:
- The child's profile — name, board, class, school name, date of birth — and can change any of it
- Every assignment and test, every question and the child's answer
- Every score and result
- The full learning profile described in Section 3.4, including the behavioural patterns
- Subscriptions and payments
A parent can delete a scheduled practice. There is no button today that deletes a child's profile, a child's learning records, or the whole account. To have any of that erased, write to the Grievance Officer in Section 1 and we will do it. Section 9 explains what happens.
Tracking, monitoring and advertising
- We do not show advertising to anyone, and we show no advertising to children.
- We do not use any third-party advertising or tracking technology anywhere on the service.
- We do not track a child across other websites or apps.
- We do analyse a child's own learning behaviour inside Eduera AI — their accuracy, their speed on each question, their consistency and the patterns in Section 3.4 — in order to choose what they should practise next and to show their parent how they are doing. We consider this to be in the child's interest and it is not used for any other purpose.
9. Your rights
Subject to the law, you can ask us to:
- Tell you what we hold about you and about a learner on your account, and who we have shared it with
- Correct or complete anything that is wrong
- Erase your information when it is no longer needed
- Withdraw your consent, at any time and as easily as you gave it
- Nominate someone to exercise these rights if you die or become unable to act
- Complain, to us first and then to the Data Protection Board of India
How to exercise them, honestly
In the app. You can see and correct a learner's profile yourself, at any time, from the parent dashboard. You can see every result and every payment.
By writing to us. For anything else — a copy of everything we hold, erasure, or withdrawing consent — email the Grievance Officer in Section 1.
We handle these requests by hand. There is no self-service “delete my account” button in Eduera AI today, and there is no automated export. A request is carried out by our staff against the database. We will confirm to you when it is done.
What withdrawing consent means. Most of what Eduera AI does needs the information described here. If you withdraw consent, we will stop the processing you have withdrawn it for, and the features that depend on it will stop working. We may still keep what the law requires us to keep — in particular, invoices and payment records for the period tax law demands.
What erasure would leave behind. If you ask us to erase a learner's records, we remove the profile, attempts, answers, timings, mastery, recommendations, explanations, scheduled practice and support messages. We would retain:
- Invoices and payment records, for as long as tax law requires
- Audit logs of administrative actions, so that access to personal data remains accountable
- Aggregate counts that name nobody
10. How we protect information
Plainly, and without overstating it:
- Your password is stored as a bcrypt hash. We cannot read it or recover it.
- One-time codes are stored as hashes and expire in ten minutes. The number of attempts is capped.
- Traffic between your device and Eduera AI is encrypted in transit (HTTPS).
- Signing in gives you a token that expires. Changing your password, or us revoking your sessions, invalidates every token already issued.
- Our AI provider's API keys are encrypted before they are stored, with a master key held outside the database.
- Staff access to the admin tools is limited by role, tied to a named account, and administrative actions are written to an audit log. Viewing the list of invited non-users is logged every single time.
- The service enforces a content security policy and runs its containers as a non-privileged user.
No internet service can promise perfect security, and we do not.
11. Your device's storage
Eduera AI keeps a few things in your browser's or app's own storage so the service works:
- Your sign-in token
- Which area of Eduera AI you are using
- Your chosen language
- A note of a checkout you started, so it can be resumed
If the website-analytics feature is switched on, the items in Section 3.10 are added. Google Analytics on the public pages is described in Section 3.10 too. None of this is used for advertising and none of it is fingerprinting.
12. Changes to this policy
We may update this policy as the service or the law changes. When we do, we will change the effective date at the top. If the change is significant, we will ask you to accept the new version before you continue using Eduera AI. The version you accepted, and the date you accepted it, are recorded against your account.
13. Languages
Eduera AI is offered in English, Hindi, Marathi, Tamil, Kannada and Telugu.
This policy is published in English, and the English text governs. A short plain-language summary of what this policy says is shown in all six languages at the point where you are asked to agree to it, so that the decision itself is made in the language you read. The summary is a summary: where it and this English text differ, this text is the one that applies.
