PrepMojo

Legal

Privacy Policy

Last updated: September 10, 2026

Plain-English summary

PrepMojo is a study app for Indian olympiad aspirants Class 1-8. Parents create an account; children practice using it. We collect the minimum information needed to show your child the right questions and to keep your account secure. We don't sell your data. We don't serve advertising. You can delete your account and your child's practice history at any time.

The full policy below spells out the legal specifics under India's Digital Personal Data Protection Act, 2023 (DPDP).

Who we are

“PrepMojo”, “we”, “us” means VedaForge Labs Private Limited (CIN U62011HR2026PTC147688), an Indian company that operates prepmojo.in, app.prepmojo.in and api.prepmojo.in. We are the Data Fiduciary for the personal data described in this policy, in the sense the DPDP Act uses that term.

VedaForge Labs Private Limited
Flat No. B303, Tower B, Tulip Ivory, Sector 70, Gurugram, Haryana 122101, India

For data-protection questions, or to exercise any of the rights below, contact our Grievance Officer:

Ashok Kumar Bansal
Grievance Officer & Data Protection Contact
[email protected] · postal address as above

What we collect

Account information (parent / primary guardian)

  • Email address (used to sign in)
  • Your name, if you choose to provide one
  • A contact mobile number, if you choose to give one - optional, asked during onboarding, and used only so we can reach you about your account. It is stored separately from the number used for phone-OTP sign-in and is never used to log you in
  • Authentication tokens issued by Supabase, our auth provider

Child profile (provided by the parent)

  • The child's first name, as you type it - a first name or a nickname is enough, we never ask for a full legal name
  • Class level, 1 to 8
  • School name and city- both required. These are also what we use to suggest classmates your child might want to add as friends, so please read “Friends and what other children can see” below before filling them in
  • Section or class division (e.g. “A”), if you enter one - optional
  • Target olympiads, if any are picked during onboarding - this step can be skipped
  • A profile photo, only if you upload one- optional, and never asked for. You can instead pick one of our cartoon avatars, which is the default and involves no photograph at all. If you do upload a photo it is shown to other children on friend suggestions and the league leaderboard, exactly like your child's first name and class already are - so please read “Friends, leagues, and what other children can see” below before uploading one. The app asks you to tick a box confirming you understand this before it will accept a photo - uploading is a separate, explicit choice, not something covered by having signed up. You can remove it at any time, in one tap, and it is deleted from our database when you do

That is the whole list. We do not ask for your child's date of birth, board, roll number or address, and there is nowhere in the app to enter them.

Practice activity

  • Which questions were attempted, when, and the answer given
  • Whether the answer was correct, time spent per question
  • Bookmarks, mistakes queue, daily streaks, XP totals

Mojo AI tutor conversations (only if your child uses it)

  • The messages your child types to the tutor, and the tutor's replies, stored against the question they were working on
  • To generate a reply we send the question, its correct answer, your child's attempt, and the conversation so far to OpenAI(see “Who sees the data”). We do notsend your child's name, your email, or any account identifier with it

Purchase information (only if you buy Plus or a mock pack)

  • Order records - what you bought, the amount, currency, date, and the payment provider's transaction reference
  • For app-store purchases, the store country your account is registered in - we need it to apply the right tax treatment
  • We never receive or store your card number, UPI ID, CVV or bank credentials. Those go directly to the payment provider

Newsletter signup (optional, separate from your account)

  • Just your email address, if you subscribe on the marketing site - this is not tied to a PrepMojo account and doesn't require one
  • Used only to send you occasional PrepMojo updates. Not shared, not used for anything else. Reply to any email to be removed.

Technical telemetry

  • Server logs containing your IP address, request timestamp, user agent - kept for 30 days for security and abuse-prevention
  • Crash and error reports when something goes wrong in the app or API - the fault, the code path, and the app version. We configure our error reporter to collect no personal data and strip request and user details before sending
  • On the marketing site (prepmojo.in) only, Google Analytics - but only after you accept the cookie banner. See “Cookies & analytics” below. We do not use advertising cookies or pixels anywhere.

Why we collect it (legal basis)

  • Consent (DPDP §6) - you consent at sign-up; consent is freely revocable
  • Performance of service - to actually deliver personalized practice and reports your child needs
  • Legitimate uses (DPDP §7) - security, fraud prevention, fixing bugs, complying with legal obligations

Children's data - special handling

PrepMojo is designed for school-going children (typically ages 6-18). Per DPDP §9, we treat all child data with extra care:

  • The child's profile is created only by a parent or guardian
  • We do not target advertising at children. We do not run any ads.
  • We do not track child data outside the practice surface (no cross-site tracking)
  • A parent can delete their account (self-service, immediate) or email [email protected] to request deletion

Who sees the data

Practice and account data is stored in our database on Amazon Web Services, region ap-south-1 (Mumbai, India), under our exclusive control. The following processors see narrow slices of it:

  • Amazon Web Services (database and application hosting, ap-south-1 / Mumbai)
  • Cloudflare (network routing and TLS termination for our domains - sees traffic metadata, not your account data)
  • Supabase (sign-in - issues your login tokens; does not store practice data)
  • Google(only if you choose “Continue with Google” sign-in)
  • Apple(only if you choose “Sign in with Apple” in the iOS app)
  • MSG91 (would deliver an SMS one-time passcode). Sign-in by phone number is not currently offered, so no SMS is sent and MSG91 receives nothing today. We list it because the capability exists and we would rather tell you now than quietly add a processor later
  • Google Analytics (marketing site only, only if you accept the cookie banner - see below)
  • Amazon Rekognition (checks a profile photo you upload for unsuitable content before we store it - it sees the image and nothing else, no name and no account identifier). It runs in ap-south-1 / Mumbai, is used only for that check, and only on a photo you chose to upload. We have instructed AWS not to retain or use these images to improve their services, through an account-wide opt-out that covers every AWS AI service. As with MSG91 above, we list it because the capability exists rather than adding a processor quietly later
  • Amazon SES (sends the emails we send you - receipts, newsletter - on our behalf; does not use your email for anything else)
  • Razorpay (processes web payments - sees your name, email, phone and payment instrument; only if you buy something on the web)
  • Apple and Google Play (bill and process in-app purchases under their own privacy policies; only if you buy inside the mobile app)
  • RevenueCat(reconciles app-store purchases with your account - sees an anonymised account identifier and the store's receipt, not your practice data)
  • OpenAI (runs the Mojo AI tutor; only if your child uses it - see the cross-border note below)
  • Sentry(crash and error reports from the app and API). We run it with personal data reporting switched off and strip request and user details before anything is sent, so these reports carry the technical fault only, not your child's data

We do not sell, rent, or trade personal data with third parties. We do not share data with advertisers. In particular, we never share children's data with any third party for advertising, profiling, or behavioural tracking - DPDP §9 prohibits it, and we would not do it anyway.

Friends, leagues, and what other children can see

PrepMojo has friends and leagues, and these are the places where something about your child is shown to someone outside your family. You should know exactly how they work.

To a child your family has not accepted, your child is a first name, a class, and a picture. Nothing else. Not the school, not the city, not the section - even though the school is what the suggestion was matched on. That is true of friend suggestions, the league leaderboard, and a random challenge opponent alike.

  • We suggest possible friends in three tiers, and every one of them requires the same classfirst: children in the same class at the same school and in the same section, then the same class at the same school, then the same class in the same city. The row says which of the three it was - “same school” - without naming the school back to you
  • Suggestions are not offered at all until your child has answered at least one question. A brand-new account cannot be used to read through a school
  • A photo is optional and is never the default. If you upload nothing, your child appears as a cartoon avatar and no photograph of them exists on PrepMojo at all. If you do upload one, it is visible to the other children described here, and the way to withdraw it is to remove the photo - one tap, and it is deleted from our database
  • It never shows your email, your phone number, your child's answers, scores, reports, or anything they typed to the Mojo AI tutor
  • Nobody is added as a friend automatically - a suggestion is only a suggestion until someone acts on it

The league leaderboard ranks your child against other children in the same class- not only their friends, and not against a mixed field of every age. It shows the same three things: first name, class, and avatar or photo, with the week's XP. Never scores on individual questions, reports, or anything typed to the Mojo AI tutor.

School, city and section are shown in one case only: when a relationship already exists or is being offered. An accepted friend sees them, and so does a parent looking at an incoming friend request - because someone who has chosen to introduce themselves has disclosed that about their own child, and the parent deciding whether to accept needs enough to recognise who is asking. A child your family has merely been suggested, or is outranking on a board, is not that, and is not shown them.

Two controls, on every screen that shows another child. Beside any child from another family there is a menu that lets you report them - a photo that is wrong, a name that is wrong, someone pretending to be a child. Reporting also blocks them: the two children stop appearing to each other on leaderboards, in suggestions and in random challenges, and neither family can send the other a friend request. A person reads every report. Blocks are listed under Settings and can be lifted there at any time.

What there is no setting for is being listed at all. Being visible to other children in the same class is how friends and leagues work, so it comes with using them - you can block an individual child, but you cannot make your child invisible to everyone. If that is what you want, the way to do it today is to delete the account, which is self-service and immediate. We would rather say that plainly than offer an opt-out we do not actually have.

The Mojo AI tutor and data leaving India

Everything else in this policy stays on Indian infrastructure. The one exception is the Mojo AI tutor, which is powered by a model from OpenAI and processed outside India.

  • It runs only when a child actively opens the tutor on a question. Nothing is sent if the tutor is never used
  • What we send: the question text, its correct answer, your child's attempt, and the messages in that conversation
  • What we do not send: your child's name, class, school, email, phone number, or any identifier that links the conversation back to them
  • OpenAI processes the request to return a reply. Under its API terms the content is not used to train its models
  • If you would rather no part of your child's work leave India, simply don't use the tutor - the rest of PrepMojo works without it

Cookies & analytics

Our practice app (app.prepmojo.in) does not use cookies or third-party analytics. Our marketing site (prepmojo.in) uses Google Analytics to understand traffic - page views, referrers, rough location by country/city - only after you accept the cookie banner shown on your first visit. Nothing from Google Analytics loads, and no analytics cookie is set, before you accept.

  • We turn on IP anonymization in Google Analytics.
  • We do not use Google Analytics for advertising or remarketing.
  • You can decline the banner, or withdraw consent at any time via “Cookie preferences” in the site footer - this clears your choice and asks again on your next visit.

Data retention

  • Account data - kept while your account is active; deleted within 30 days of account closure
  • Practice activity - same lifecycle as the child profile
  • Mojo AI tutor conversations - same lifecycle as the child profile; deleted when the account is
  • Server logs - 30 days
  • Crash and error reports - 90 days
  • Purchase and invoice records - retained for 8 yearsafter the transaction, because the Companies Act, 2013 and GST law require us to keep them. This is the one thing account deletion does not erase: we keep the order amount, date, transaction reference, and the name and email address of the parent who paid, so the record stays a complete one an auditor can read. Your child's name, photo, answers and practice history are deleted with the account and form no part of it. DPDP §17 permits this retention for compliance with the law
  • Backups containing your data - rotated out within 90 days of source deletion
  • Newsletter email - kept until you ask to be removed; we don't expire it automatically since it's not tied to activity

Your rights under DPDP

  • Access - get a copy of the personal data we hold about you
  • Correction- fix anything that's inaccurate
  • Erasure - ask us to delete your account and child profiles
  • Withdraw consent - revoke consent at any time; doing so terminates the service
  • Grievance redressal - escalate complaints to our Grievance Officer, Ashok Kumar Bansal, named at the top of this policy
  • Nominate - name someone to exercise these rights on your behalf if you die or become incapacitated (DPDP §14). Email us to record a nominee

To exercise any of these, email [email protected]. We acknowledge within 24 hours and resolve within 15 days. For erasure you don't need to wait for us at all - use self-service deletion, which takes effect immediately. If you are unsatisfied with how we handle a grievance you may approach the Data Protection Board of India.

Security

Data is encrypted in transit (TLS via Cloudflare). The database is not exposed to the public internet - it's reachable only from our application server, over a private network connection with no open inbound ports. Authentication uses signed JWTs with short expiration. Sign-in is via email + password or Google on every platform, and additionally “Sign in with Apple” in the iOS app; where a password is used, we never see or store it in plain text - it's hashed by our authentication provider.

Changes to this policy

We'll update the “Last updated” date at the top of this page when material changes happen, and notify signed-in users by email if the change affects how their data is used.

Contact

Questions, deletion requests, grievances: [email protected], or by post:

Ashok Kumar Bansal, Grievance Officer & Data Protection Contact
VedaForge Labs Private Limited
Flat No. B303, Tower B, Tulip Ivory, Sector 70, Gurugram, Haryana 122101, India

See also: Terms of Service.