Privacy
Your data, on your terms.
TrueGYDE is built in India and complies with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable rules. This policy explains what we collect, why we collect it, how long we keep it, and the rights you have as a Data Principal.
Last updated · 27 June 2026
Who we are (the Data Fiduciary)
"TrueGYDE" (operated by TrueGYDE Technologies) is the Data Fiduciary that determines the purpose and means of processing your personal data. You can reach our Grievance Officer / Data Protection contact at privacy@truegyde.app.
The personal data we collect
- Account data: name, email, phone (optional), password hash, role (student, parent, institution, employer).
- Profile data: age band, school / college / employer, stream or department, interests, passions, current domain.
- Assessment data: answers to the TrueGYDE assessment, derived signals, archetype outcomes, candidate paths.
- Activity data: tasks completed, reflections, mentor feedback, evidence uploaded, referral codes used.
- Device & log data: IP address, browser, device type, pages visited, timestamps — used for security and product analytics.
- Communications: messages you send us, support requests, parent / child linking requests.
We do not knowingly collect Aadhaar, biometric data, financial account details, health records, caste or religion. Please do not share these with us.
Purposes — why we process your data
- To create and operate your TrueGYDE account.
- To generate your archetype, candidate paths, and personalised roadmap.
- To deliver tasks, feedback, reflections and progress tracking.
- To allow parents / institutions / employers (only with your consent) to view relevant evidence.
- To send transactional emails (verification, password reset, weekly summary).
- To improve our models, in aggregated and de-identified form.
- To meet legal, audit and security obligations.
Lawful basis & consent (DPDP §6 and §7)
We rely primarily on your free, specific, informed, unconditional and unambiguous consent, given through a clear affirmative action (ticking the consent box at sign-up). For limited purposes — such as fulfilling a service you requested, complying with law, or responding to a medical emergency — we may rely on the "certain legitimate uses" basis under §7 of the DPDP Act.
You can withdraw consent at any time from Settings → Privacy or by writing to privacy@truegyde.app. Withdrawal does not affect processing already carried out lawfully.
Children & verifiable parental consent
For Data Principals under 18, TrueGYDE obtains verifiable consent from a parent or lawful guardian before processing any personal data, as required by §9 of the DPDP Act. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children, and we do not process children's data in a way likely to cause detrimental effect on their well-being.
Parents can review, correct or delete their child's data at any time from the Parent workspace, or by emailing privacy@truegyde.app.
Your rights as a Data Principal (DPDP Chapter III)
- Right to information about personal data being processed.
- Right to correction, completion, updating and erasure of your data.
- Right of grievance redressal — we will respond within 30 days.
- Right to nominate another individual to exercise your rights in case of death or incapacity.
- Right to withdraw consent at any time, as easily as it was given.
To exercise any right, email privacy@truegyde.app from your registered email. If we cannot resolve a complaint, you may approach the Data Protection Board of India.
Sharing & disclosure
We share personal data only with:
- Data Processors who act on our documented instructions — cloud infrastructure (Cloudflare, Supabase), email delivery (Resend), and AI reasoning providers used to generate archetypes and roadmaps. They are bound by contract to confidentiality and DPDP-aligned safeguards.
- Linked parties you choose to share with — your parent, institution, or an employer you apply to. You control this from Settings → Sharing.
- Authorities, when required by Indian law, a court order, or to protect vital interests.
We do not sell personal data, and we do not use it for third-party advertising.
Cross-border transfers
Some processors operate outside India. We transfer personal data only to jurisdictions not restricted by the Central Government under §16 of the DPDP Act, and under contractual safeguards equivalent to those we apply within India.
Retention
We retain personal data only as long as needed for the purpose collected, or while you maintain an account with us. When the purpose is served and there is no legal duty to retain, we erase or de-identify the data. Backups are rotated on a 30-day cycle.
Security
We use industry-standard safeguards — encryption in transit (TLS 1.2+), encryption at rest, row-level access control, principle-of-least-privilege access, audit logs, and periodic security reviews. No system is perfectly secure; in the event of a personal data breach, we will notify the Data Protection Board and affected Data Principals as required.
Cookies & analytics
We use strictly necessary cookies to keep you signed in, and privacy-preserving product analytics to understand how features are used. We do not use third-party advertising cookies.
Changes to this policy
We may update this policy from time to time. Material changes will be notified by email and via an in-app banner at least 7 days before they take effect.
Contact & Grievance Officer
Grievance Officer · TrueGYDE Technologies
Email: privacy@truegyde.app
We respond to all DPDP requests within 30 days.