Last updated: September 2026
This policy applies to anyone who creates an account on Eklavya, whether you access it directly or through a school/institution that has adopted the underlying learning platform Eklavya is built on top of. If you are under 18, this policy is written for your parent or guardian to read together with you.
Every fact in your career profile is tagged with a source so its origin is never ambiguous:
| Source tag | What it means | Examples |
|---|---|---|
| manual | You typed or selected it yourself | Age, education level, location, interests, skills, achievements, journal entries |
| llm_extracted | Our AI pulled it out of a conversation you had with it during onboarding | Academic records, interests, and skills mentioned in a chat |
| lms_sync | Derived automatically from your activity on the learning platform | Course completions, quiz scores, mock-interview performance |
| social | Inferred from your activity in Eklavya's community features | Group memberships based on declared interests |
We also collect standard account information (name, email, login method) and, if you sign up with Google, the basic profile information Google shares with us during sign-in.
Before we build out anything beyond a bare account, we ask you to declare your age. If you are under 18:
Where this is still a work in progress: our current consent mechanism records that consent was given, but does not yet independently verify that the person giving it is actually the account holder's parent or guardian (for example, via a confirmation link emailed to the parent). Treat this section as describing our intent and design direction, not a completed, audited compliance guarantee.
We do not sell your personal data. We do not use your journal entries or AI conversation transcripts for anything other than building your own profile — they are not shared with other users, teachers, or administrators under any circumstance, including platform administrators.
When you use Eklavya's conversational onboarding, your messages are sent to a third-party AI provider (OpenAI or Anthropic, depending on configuration) to extract structured profile information. We instruct the AI to treat your messages strictly as information to extract from, never as instructions to follow, as a safeguard against manipulation of the assistant.
Raw conversation transcripts are retained for a limited period (currently 30 days) after which they are automatically deleted — only the structured facts extracted from them (tagged llm_extracted) remain in your profile after that.
If your institution has not yet provided AI access, or you've used your monthly allowance, you may be asked to provide your own API key for a third-party AI provider to continue using AI features. Keys you provide are encrypted before storage and are never visible to teachers, administrators, or other students.
We keep your profile data for as long as your account is active. Raw AI conversation transcripts are deleted automatically after 30 days.
Students can delete their account themselves from the Account tab in the app. This permanently removes your login and everything linked to it — profile, career records, journal, progress, and messages you sent — and cannot be undone. Teacher and administrator accounts own shared content (courses, exams, audit history) and are deleted by the platform administrator on request instead. Some records may be kept where the law requires it.
Data is stored using row-level access controls so that, even at the database layer, most tables can only be read by their owning user. Sensitive credentials (encryption keys, institutional AI provider keys) are never hardcoded in our code or written to logs.
Eklavya relies on the following third parties to operate. Each processes data on our behalf only as needed to provide the service:
| Provider | What it does for Eklavya |
|---|---|
| Supabase | Hosts the database and handles sign-in. Your account, profile, and all stored records live here (Asia-Pacific region). |
| Render | Runs Eklavya's application server (Singapore region). Requests pass through it to reach the database. |
| Signs you in ("Continue with Google"). We receive your name, email address, and profile picture as Google provides them. | |
| OpenAI or Anthropic | Processes messages you send to AI features so they can respond, as described in Section 5. |
This means your data is processed outside India. We do not sell it to any of these providers or anyone else.
You (or, for a minor, their parent/guardian) can:
We'll update the "Last updated" date at the top of this page whenever this policy changes, and, for material changes, make a reasonable effort to notify active users directly.