LAST UPDATED: September 10, 2026 • JURISDICTION: INDIA

Privacy Policy

Our Commitment: Consisto respects your privacy. Our platform relies on data minimization, symmetric AES-256-GCM field encryption, HMAC blind indexes, and Zero-Knowledge architecture wherever possible.

1. Information We Collect

We collect only information strictly necessary to provide our educational services:

  • Account Identification: Full name, email address, school affiliation (`school_code`), class, section, and hashed authentication credentials. Name and email fields are encrypted at rest using AES-256-GCM (`cipher:iv:tag`). Lookups use HMAC-SHA256 blind indexing (`email_bidx`).
  • Educational & Examination Data: Test attempts, DPP responses, attendance heartbeats, score records, and teacher-published notes.
  • Live Classroom Data: WebRTC connection metadata, join/leave timestamps, and 30-second presence pulse counts. Live video/audio streams are processed in real-time and not saved unless explicitly requested for institutional archiving.
  • AI Interaction Data: cAI prompts, doubt queries, and subjective evaluation context. AI prompts are processed strictly for real-time inference and are never used to train public LLM models.
  • Telemetry & Security Logs: Authentication logs, IP addresses, user agent strings, bot-check reCAPTCHA scores, and audit event logs (`user_sessions`, `meet_logs`, `cai_usage_logs`).

2. How We Use Information

Collected data is used strictly to:

  • Operate, maintain, and deliver the Consisto educational platform.
  • Authenticate accounts, maintain secure database sessions (`token_hash = sha256(token)`), and prevent unauthorized access.
  • Compute classroom attendance percentages and generate school analytical reports.
  • Process subscription billing via Razorpay payment gateways.
  • Enforce automated content moderation and prevent platform abuse.

3. Third-Party Subprocessors

We do not sell personal data. We share data only with trusted subprocessors required for platform operations:

  • Firebase (Google): Cloud infrastructure, hosting, and optional Firebase ID token authentication.
  • LiveKit Cloud: Infrastructure for real-time WebRTC live classrooms.
  • Google Gemini API: AI inference for cAI study assistance and doubt clearing.
  • Razorpay: Payment gateway for processing subscriptions and institutional orders.
  • Brevo: Transactional email delivery and OTP verification.
  • Google reCAPTCHA: Bot prevention and human verification (`bot-check.php`).

4. Data Retention & 48-Hour Cooldown Account Deletion

You may request account deletion at any time. Upon requesting deletion, your account enters a 48-hour cooldown period. During this window, login is restricted but data remains recoverable in case of an accidental request.

Once the 48 hours elapse, automated database purge jobs permanently delete all Personally Identifiable Information (PII), encrypted blobs, and user records. This action is irreversible.

5. Your Rights & Data Protection Officer

Under applicable regulations (such as India's DPDP Act), you have the right to access, update, export, or delete your personal data. To exercise your rights, contact our Data Protection Officer at privacy@consisto.in.