Security and privacy

What we collect, how long we keep it, and who can see it.

Most of what NYGTLYF holds is a record of a student being wrong about things. That is sensitive in a way a shopping history is not, so the handling of it is written out here in specifics rather than in reassurance.

The short version

  • TLS in transit, encrypted at rest
  • Doubt text reduced to a signal after 90 days
  • Parent accounts see progress, never session contents
  • Not sold to institutes, advertisers or data brokers
  • Export and deletion available on every plan
What we collect

Six categories, each with a stated retention period.

If a category is not on this list, we are not collecting it. There is no location tracking, no contact list access and no microphone or camera requirement.

Data categories collected by NYGTLYF and their retention periods
CategoryWhat it is and whyRetention
Account detailsName, email address, class, board and the subjects selected. Used to match explanations to your syllabus and to sign you in.While the account is open
Ladder and mastery stateWhich concepts are mastered, flagged or locked, difficulty level reached, and the history of those changes.While the account is open
Doubt text and explanationsWhat you typed and what the tutor returned. Needed to hold the thread, answer follow ups and locate the sub skill that broke.90 days, then reduced to the sub skill signal
Practice attempts and workingAnswers submitted, working where shown, error classification and time on question.12 months, then aggregated to mastery figures
Study timeActive minutes on questions and explanations. Idle time is discarded rather than recorded.While the account is open
Technical logsSign in events, device and browser type, and error traces. Used for security and for fixing faults.30 days

What we do not do with it

We do not sell student data, and we do not share it with advertisers or data brokers.
We do not sell or licence student accounts to schools or coaching institutes.
We do not build advertising profiles from what a student is weak at.
We do not use a student account to market a different product to their parent.
We do not read session contents for any purpose other than running the engine and investigating a fault you report.
Technical controls

Four controls that actually change what is possible.

Encryption in transit and at rest

All traffic to and from the platform runs over TLS. Stored account data, ladder state and session records are encrypted at rest by the managed database and object storage services we run on.

Access limited to what the job needs

Internal access to production data is role based, granted to the smallest number of people needed to operate the service, and logged. Nobody on the team browses student sessions casually.

The parent boundary is structural

Session contents are not exposed to a parent view at the data layer, so there is no setting, escalation or support request that reveals them. It is not a permission we could flip.

Retention is bounded and stated

Every category of data above has a stated retention period. Doubt text reduces to a sub skill signal after ninety days, so the useful part of the record survives and the transcript does not.

The parent boundary

Stated once more, because it is the most important line on this page.

A linked parent account can see concepts mastered, concepts flagged for review, difficulty level reached, active study time, streaks and diagnostic outcomes. It cannot see the text of a doubt, the explanation given, an individual wrong answer, the working behind it, or how long any single question took.

This is enforced where the data is read, not by a checkbox in a settings page. Support cannot retrieve session contents for a parent, an upgrade does not unlock them, and there is no plan on which they become visible.

  • Students see the link. A parent view is visible on the student side for as long as it exists.
  • Students see everything parents see. There is no asymmetry in the other direction.
  • Links can be removed. Removal is visible to both sides.
The full visible and private lists

Why this is not a settings toggle

A privacy promise that depends on a preference is a promise that gets renegotiated. A student would have to trust that nobody with access to the account will change it, that support will refuse a reasonable sounding request, and that a future release will not quietly flip the default.

Removing the capability removes all three of those conversations. It also costs us a feature that some parents would genuinely like, and we think that trade is correct.

The practical consequenceA student can ask something they are embarrassed about without weighing who might read it later. That is the condition the engine needs to work at all.
Your controls

Five things you can do with your own data, on any plan.

None of these are restricted to paid plans, and none of them require a reason.

See everything on your account

A student can view every figure held about them, including everything a linked parent account can see. There is no view of a student that is hidden from that student.

Export your data

Request a machine readable export of account details, ladder state and mastery history. Available on every plan including the free tier.

Correct what is wrong

Class, board, subject list and profile details can be corrected at any time from the account. A corrected class triggers a fresh diagnostic rather than reusing the old placement.

Delete the account

Deletion removes account details, ladder state, session records and practice history. Aggregate figures that cannot identify a student may remain. Technical logs age out on their own thirty day cycle.

Unlink a parent account

A linked parent view can be removed. The student always sees that the link exists while it is active, and sees when it is removed.

How to make a request

Export, correction, deletion and unlinking can all be raised from the account, or in writing through the contact form. Requests are acknowledged and actioned within thirty days.

Raise a data request
Compliance posture

Where we actually stand today.

We would rather state this plainly than imply certifications we do not hold. NYGTLYF is operated by Nygtlyf Private Limited, incorporated in India, and processes personal data in that capacity.

  • Indian data protection law. We operate under the Digital Personal Data Protection Act, 2023 framework, including its provisions on the processing of children's data and verifiable parental consent.
  • Managed infrastructure. We run on established cloud infrastructure providers and rely on their certified physical and platform controls rather than operating our own hardware.
  • No independent certification yet. We do not hold an ISO 27001 certificate or a SOC 2 report at this time, and we will not describe our providers' certifications as our own.
  • No third party penetration test published. When that changes, it will be stated on this page with a date, not in a press release.

If you have found a security issue, please report it through the contact form and mark it as a security report. We will acknowledge it and will not pursue action against good faith research.

Report a security issue
Read before you sign up

If any of this is a problem for your household, it is better to know now.

The privacy policy sets out the same ground in legal terms, and the terms of service cover the account relationship. Both are linked in the footer, and neither is written to be unreadable.

Data requests are acknowledged and actioned within thirty days.

One evening, start to finishNo class scheduled, no one to askLive
CollectedAccount details, ladder state, session records, study time
90 daysDoubt text reduces to a sub skill signal
12 monthsPractice attempts aggregate to mastery figures
On requestFull export, correction, or deletion of the account