Last updated: 11 August 2026 · Effective: June 2026 · Notice version: v1
1. Introduction
Testogram is an educational technology platform operated by LearnCurve Systems Pvt Ltd, a company duly incorporated under the provisions of the Companies Act, 2013, with its registered office in Gurugram, Haryana, India (hereinafter referred to as the "Company", "We", "Us", or "Our").
This Privacy Policy (hereinafter referred to as the "Policy") describes the manner in which the Company collects, uses, processes, stores, shares, and protects the personal information of individuals (hereinafter referred to as "Users", "You", or "Your") who access or use the Testogram mobile application, web application, and related services, features, and functionality (collectively, the "Platform").
By accessing, registering on, or otherwise using the Platform, the User acknowledges this Policy and agrees to the Company's Terms of Service. Where the Digital Personal Data Protection Act, 2023 requires the User's consent for a particular purpose, that consent is sought separately within the Platform, is specific to the purpose, and may be withdrawn at any time as described in Section 9. Use of the Platform is not, and is not treated as, consent for any such purpose. If the User does not agree to the practices described herein, the User must immediately discontinue all use of the Platform.
2. Information We Collect
2.1 Information Provided Directly by the User
Account Registration Information: Full legal name, email address, telephone number, and password provided during the account creation process.
Profile Information: Examination preferences, target examination selection, educational background, and responses provided during the onboarding process.
Payment Information: Billing details processed securely through Razorpay, a PCI-DSS compliant third-party payment gateway. The Company does not directly store, process, or have access to complete payment card numbers, card verification values (CVV), or banking credentials. Such information is handled exclusively by Razorpay in accordance with its own privacy policy and security standards.
Support Communications: Messages, feedback, inquiries, and correspondence submitted by the User to the Company's support team through any channel.
2.2 Information Generated Through Platform Usage
Learning & Assessment Data: Quiz attempts, answers submitted, scores, accuracy rates, time spent on questions and sessions, difficulty level progression, and learning path advancement.
Performance Analytics: Subject-wise and chapter-wise performance metrics, identification of areas requiring improvement, improvement trends, and mastery level progression.
Engagement Data: Participation in rewards programmes, achievement records, leaderboard rankings, referral activity, and other gamification-related data.
Financial Data: Subscription status and history, virtual currency balances and transaction records, payment transaction history, and refund records.
2.3 Information Collected Automatically
Device Information: Device model, manufacturer, operating system type and version, unique device identifiers, the Android Advertising Identifier (AAID) — used solely for product analytics and install-source attribution and, where the User has consented to advertising measurement, for the purposes described in Section 2.5 — and Firebase Cloud Messaging (FCM) tokens necessary for the delivery of push notifications.
Usage Data: Application session duration and frequency, features accessed, navigation patterns, interaction events, and user interface engagement metrics.
Network Information: Internet Protocol (IP) address and general geographic region derived therefrom (not precise geolocation).
2.4 Analytics & Attribution Data
Product Analytics: The Platform uses Google Analytics for Firebase to collect usage, event, and engagement data — including screens viewed, features used, session frequency and duration, and key product events such as account sign-up, quiz completion, and purchase — in order to understand how the Platform is used and to improve its features, content, and reliability.
Install Attribution: Upon first launch, the Platform reads the Google Play Install Referrer and any associated campaign parameters (such as UTM source, medium, and campaign values) to attribute the installation to its acquisition source. This data is used in aggregate to measure the effectiveness of marketing and referral activity and is used to measure acquisition. Where the User has consented to advertising measurement, attribution data is also processed for the purposes described in Section 2.5.
2.5 Information Shared for Advertising Measurement
Where the User has given consent for advertising measurement, the Company shares a limited set of information with Meta Platforms, Inc. and Google LLC for the purpose of measuring the effectiveness of the Company's advertising:
A pseudonymous account identifier: The User's internal account identifier, irreversibly hashed using SHA-256. This identifier does not reveal the User's name, email address, or telephone number.
Conversion event names and timestamps: Specifically, that a registration was completed and that a first quiz was completed. No quiz content, score, or performance data is included.
Device advertising identifier: Where the Meta or Google software development kits are enabled in the Platform's mobile application, the device advertising identifier and basic device metadata, collected on the User's device and transmitted directly to the respective recipient.
The Company does not share the User's name, email address, telephone number, examination performance, quiz responses, or study activity for advertising measurement purposes.
Where the User has not given consent for advertising measurement, or has withdrawn it, none of the information described in this subsection is shared.
3. How We Use Your Information
The Company processes the information collected from Users for the following lawful purposes:
Provision and Personalisation of Services: To deliver, maintain, and personalise the Platform's features, including tailoring quiz content, difficulty levels, learning paths, and study recommendations based on the User's performance, preferences, and examination goals.
Performance Analytics and Insights: To generate and provide the User with insights regarding their strengths, areas requiring improvement, and overall progress to facilitate more effective study practices.
Communications and Notifications: To send study reminders, achievement notifications, performance-based recommendations, service announcements, and other communications through push notifications, in-app messages, or electronic mail. The User may manage notification preferences through the Platform's settings.
Payment Processing: To process subscription payments, manage virtual currency transactions, and handle refund requests through Razorpay.
Platform Improvement and Development: To analyse aggregate and anonymised usage patterns for the purposes of improving content quality, user experience, platform reliability, and developing new features and services.
Advertising Measurement: Where the User has consented, measuring the effectiveness of the Company's advertising as described in Section 2.5.
Fraud Prevention and Security: To detect, prevent, and address fraudulent activity, account abuse, unauthorised access, and other security threats through automated risk assessment and monitoring systems.
Customer Support: To respond to the User's inquiries, troubleshoot technical issues, and provide assistance.
Legal Compliance: To fulfil the Company's obligations under applicable laws, regulations, and legal processes, and to protect the Company's legal rights and interests.
4. Automated Decision-Making
The Platform employs automated systems and algorithms to process User data for certain purposes, including but not limited to:
Adaptive Learning: Automated analysis of User performance to adjust question difficulty, recommend study topics, and personalise learning paths.
Fraud Detection: Automated risk scoring of referral activities and account behaviour to identify and prevent potentially fraudulent activity.
Notifications and Recommendations: Automated generation of study nudges, streak reminders, and performance-based recommendations based on the User's activity patterns.
These automated processes are designed to enhance the User's experience and maintain the integrity of the Platform. No automated decision-making process employed by the Company produces legal effects or similarly significant effects on the User. The User may contact the Company at privacy@testogram.com to request human review of any automated decision or to obtain further information about the logic involved.
5. Data Storage & Security
The Company implements appropriate technical, administrative, and organisational measures to protect the User's personal information against unauthorised access, alteration, disclosure, or destruction:
Hosting Infrastructure: All User data stored by the Company is held on Microsoft Azure infrastructure located in the Central India region, within the territory of the Republic of India.
Encryption at Rest: All stored data is encrypted at rest using the Azure platform's default encryption mechanisms.
Encryption in Transit: All data transmitted between the User's device and the Company's servers is protected using Transport Layer Security (TLS) version 1.2 or higher.
Access Controls: Internal access to User data is restricted on a need-to-know basis through role-based access controls (RBAC) with comprehensive audit logging of all administrative actions.
Database Security: PostgreSQL databases are configured with parameterised queries to prevent SQL injection attacks, with regular automated backups and disaster recovery procedures.
While the Company implements industry-standard security measures and continuously works to enhance its security posture, no method of electronic storage, processing, or transmission is entirely secure. The Company cannot guarantee absolute security of the User's information but is committed to promptly identifying, investigating, and addressing any security incidents in accordance with applicable law.
6. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected Users, the Company shall:
Notify affected Users without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, via electronic mail to the User's registered email address and/or through an in-app notification.
Provide a description of the nature of the breach, the categories and approximate number of Users affected, the likely consequences of the breach, and the measures taken or proposed to be taken by the Company to address the breach and mitigate its effects.
Notify the relevant data protection authority or regulatory body as required under applicable law, including the Indian Computer Emergency Response Team (CERT-In) in accordance with the Information Technology Act, 2000, and associated rules.
Maintain a documented record of all personal data breaches, including the facts, effects, and remedial actions taken.
7. Third-Party Services
The Company engages the following third parties in connection with the Platform. Where a third party processes personal data solely on the Company's instructions, it acts as a Data Processor. Where a third party determines the purposes and means of its own processing, it is a separate Data Fiduciary receiving a disclosure, and its own privacy policy governs that processing.
Razorpay Software Private Limited — payment processing: Razorpay handles payment information under its own privacy policy and its own regulatory obligations as a payment service provider. The Company receives only transaction confirmations, order identifiers, and payment status information, and does not store, process, or have access to complete payment card numbers, card verification values, or banking credentials.
Google LLC (Firebase) — notifications, product analytics, hosting, and advertising measurement: Firebase Cloud Messaging delivers push notifications; device tokens are stored by the Company to route notifications to the User's devices. Google Analytics for Firebase processes usage and engagement data for product analytics. Firebase Hosting serves the Company's web properties. Firebase services are governed by Google's privacy policy. Where the User has consented to advertising measurement, Google also receives the information described in Section 2.5 for that purpose.
Meta Platforms, Inc. — advertising measurement: Where the User has consented to advertising measurement, Meta receives the information described in Section 2.5. Meta is a recipient of that information rather than a processor acting on the Company's instructions: Meta determines the purposes and means of its own subsequent processing, including identity matching and the optimisation of its advertising systems, and that processing is governed by Meta's own privacy policy.
Azure Communication Services (Microsoft Corporation): Delivery of transactional electronic mail, including one-time password (OTP) verification codes, password-reset codes, and account-related notifications. Microsoft processes the User's email address and the contents of such messages solely to deliver them on the Company's behalf, in accordance with Microsoft's privacy statement. The Azure Communication Services resource is provisioned with its data location set to India, such that data stored by the service resides within the territory of the Republic of India.
Sentry: Application error tracking and monitoring. Sentry may receive anonymised crash reports, diagnostic data, and technical error information to assist the Company in identifying and resolving technical issues. No personally identifiable information is intentionally transmitted to Sentry.
Microsoft Azure (Microsoft Corporation): Cloud infrastructure, application hosting, database services, and file and media storage. The Company's compute, PostgreSQL database, and file and media storage resources are provisioned in the Central India region, and data processed through these services remains within the territory of the Republic of India unless otherwise specified.
The Company does not sell, rent, or lease the User's personal information. Disclosures to the recipients named in this Section are made only for the purposes stated, and where consent is required, only where the User has given it.
7.1 Withdrawal of Consent for Advertising Measurement
Where the User withdraws consent for advertising measurement, the Company ceases all further disclosure to Meta and Google for that purpose immediately, and records the withdrawal.
The Company has established that Meta does not make available to advertisers any mechanism — application programming interface, support process, or documented workflow — by which information previously received through its Conversions API may be deleted in respect of an identified individual. The Company therefore cannot cause the deletion of information already disclosed.
The Company's implementation ceases all future disclosures on withdrawal, records the withdrawal, and provides the User with Meta's available privacy controls. Whether this fully satisfies the erasure obligation under Sections 6(6) and 8(7)(b) of the Digital Personal Data Protection Act, 2023, in the absence of an advertiser-side deletion mechanism, is a matter on which the Company has sought and continues to seek legal confirmation.
Users who wish to manage or clear information held by Meta about their activity with businesses may do so through Meta's own privacy controls, available in the Facebook and Instagram account settings under "Off-Facebook Activity" or the equivalent control in force from time to time.
8. Cross-Border Data Transfers
The Company primarily stores and processes User data within the territory of the Republic of India. However, certain third-party service providers engaged by the Company may process limited data outside of India in the course of providing their services (for example, Sentry for error monitoring, and Meta Platforms, Inc. and Google LLC for advertising measurement). In such cases, the Company shall ensure that:
Appropriate safeguards are in place, including contractual obligations requiring the third-party provider to maintain adequate data protection standards consistent with applicable Indian law.
Data transfers are limited to what is strictly necessary for the provision of the relevant service.
The User's rights under applicable data protection laws are not diminished by reason of any such transfer.
The User's data may be processed outside India by the recipients named in Section 7. Where consent is required for a particular disclosure, it is sought separately within the Platform as described in Section 9. Use of the Platform is not treated as consent to any such disclosure.
9. Your Rights
Subject to applicable law, the User has the following rights with respect to their personal data:
Right to Access: The User may request a copy of the personal data the Company holds about them, along with information regarding the purposes of processing and the categories of data concerned.
Right to Correction: The User may request the correction or updating of inaccurate or incomplete personal data held by the Company.
Right to Deletion: The User may request the deletion or anonymisation of their personal data, subject to the data retention requirements described in Section 11 and any overriding legal obligations of the Company.
Right to Data Portability: The User may request that their personal data be provided in a structured, commonly used, and machine-readable format, where technically feasible.
Right to Withdraw Consent: The User may withdraw consent for any purpose for which consent was given, at any time. Withdrawal is available in the Platform's mobile application under Settings → Privacy, and requires the same single action as giving consent. Withdrawal does not affect the lawfulness of processing carried out before it, and does not affect the User's access to any feature of the Platform.
Right to Restrict Processing: The User may request the restriction of processing of their personal data in certain circumstances as provided under applicable law.
Right to Lodge a Complaint: The User may file a complaint with the relevant data protection authority or regulatory body if the User believes that their data protection rights have been violated.
To exercise any of the foregoing rights, the User may contact the Company at privacy@testogram.com. The Company shall respond to all legitimate requests within thirty (30) days of receipt. In exceptional circumstances requiring an extension, the Company shall inform the User of the extension and the reasons therefor within the initial thirty (30) day period.
9.1 Grievance Redressal
The Company has appointed a Grievance Officer to address questions and complaints concerning the User's personal data and this Policy.
Grievance Officer
LearnCurve Systems Private Limited
Flat 703, Teamcowork, Palm Court, Gurugram–Mehrauli Road,
Sector 16, Gurugram, Haryana 122007, India privacy@testogram.com
The Company will acknowledge a grievance on receipt and will respond within thirty (30) days.
9.2 Complaint to the Data Protection Board of India
Where the User is not satisfied with the Company's response to a grievance, or where the Company has failed to respond, the User may make a complaint to the Data Protection Board of India in the manner provided under the Digital Personal Data Protection Act, 2023 and the rules made thereunder.
The Company encourages Users to raise a grievance with the Grievance Officer first, but nothing in this Policy requires a User to do so before approaching the Board.
10. Account Deletion
The User may request deletion of their Testogram account at any time through the following methods:
The account deletion functionality available within the Platform's settings (Profile → Delete Account).
Submitting a written request via electronic mail to privacy@testogram.com from the User's registered email address.
Upon receipt of a valid deletion request, the following process shall apply:
A grace period shall commence during which the User's account is deactivated but their data is preserved, allowing the User to reconsider and cancel the deletion request.
The User may cancel the deletion request within the grace period by logging back in to their account or by contacting the Company's support team.
Upon expiration of the grace period, the User's personally identifiable information (including name, email address, telephone number, and profile details) shall be permanently and irreversibly anonymised.
Anonymised quiz performance, learning, and analytics data shall be retained for aggregate platform analytics, content improvement, and research purposes.
Active subscriptions shall be cancelled. All unused Virtual Currency balances shall be permanently forfeited upon account deletion.
For complete details regarding the account deletion process, please refer to the Company's Account Deletion page.
11. Data Retention
The Company retains User data in accordance with the following retention schedule:
Active Accounts: Personal data is retained for as long as the User's account remains active and in use.
Deleted Accounts: Personally identifiable information is permanently anonymised following the expiration of the applicable grace period.
Product Analytics: Usage and engagement data processed for product analytics, which is associated with a device or account identifier, is retained for twenty-six (26) months from collection, after which it is deleted or irreversibly aggregated.
Anonymised and Aggregate Data: Data from which all identifiers have been removed, and which cannot be related to any individual whether alone or in combination with other information held by the Company, is not personal data and may be retained without limit for aggregate analytics, research, and content improvement.
Advertising Measurement Data: Information disclosed for advertising measurement is retained by the Company only for so long as the User's consent for that purpose remains in force. Where consent is withdrawn, the Company ceases further disclosure immediately and deletes its own records of what was disclosed, subject to Section 7.1 in respect of information already received by a recipient.
Consent Records: Records of consent given and consent withdrawn — comprising the purpose, the action taken, the version of this Policy in force at the time, and the date — are retained separately from the data to which they relate, and are not deleted when an account is deleted. These records exist to demonstrate the lawfulness of processing carried out at the time it occurred, which is the Company's obligation under the Digital Personal Data Protection Act, 2023. They contain no name, email address, telephone number, or other directly identifying information.
Payment and Financial Records: Transaction records, invoices, and related financial documentation are retained for a minimum period of seven (7) years as required under the Indian Income Tax Act, 1961, the Goods and Services Tax Act, 2017, and other applicable fiscal and regulatory provisions.
Audit Logs: Administrative audit logs and security logs are retained for a period of three (3) years for security monitoring, incident investigation, and regulatory compliance purposes.
Legal and Regulatory Holds: Notwithstanding the foregoing, the Company may retain User data for such longer period as may be required by applicable law, regulation, legal process, or governmental request.
12. Children's Privacy
The Digital Personal Data Protection Act, 2023 defines a child as an individual who has not completed eighteen (18) years of age.
The Platform is directed at candidates for competitive examinations which require, as a condition of eligibility, the completion of an undergraduate degree and a minimum age of twenty-one (21) years. The Platform is not directed at, designed for, or intended to be used by children.
The Company does not knowingly collect personal data from a child without the verifiable consent of a parent or lawful guardian. Where the Company becomes aware that personal data has been collected from a child without such consent, it will delete that data promptly.
The Company does not undertake tracking or behavioural monitoring of children, and does not direct targeted advertising at children. The advertising measurement described in Section 2.5 is not operated in respect of any User known or reasonably believed to be a child.
13. Cookies & Tracking Technologies
The Platform employs the following tracking technologies:
Session Cookies: Essential cookies used solely to maintain the User's authenticated session. These are strictly necessary for the operation of the Platform and expire when the session ends or after a defined timeout.
Product Analytics: Google Analytics for Firebase collects usage and engagement data, and the Google Play Install Referrer attributes installations, for the purposes described in Section 2.4.
Advertising Measurement — consent required: Where, and only where, the User has given consent for advertising measurement, the Company operates the Meta Pixel on the Company's web properties; the Meta and Google software development kits within the Platform's mobile application; and server-side transmission of the conversion events described in Section 2.5. Where consent has not been given, or has been withdrawn, none of the above operates and no information is transmitted to Meta or Google for advertising purposes.
No Sale of Personal Data: The Company does not sell personal data, does not participate in data broker programmes, and does not disclose personal data to third parties for their own independent marketing purposes.
14. Changes to This Policy
The Company may amend this Policy from time to time. The current version is always available at testogram.com/privacy-policy, and the "Last updated" date and notice version at the head of this Policy indicate when it was last revised. Users are encouraged to review this Policy periodically.
Where a change materially affects processing for which the User's consent is required, the Company will seek fresh consent within the Platform before that processing begins. Continued use of the Platform following any other revision constitutes acknowledgement of the revised Policy.
15. Contact Us
For any question, concern, request, or complaint regarding this Policy, the User's personal data, or the Company's data processing practices, the User may contact the Company as follows:
Grievance Officer — for data protection matters, including access, correction, deletion, withdrawal of consent, and grievances:privacy@testogram.com
Company: LearnCurve Systems Private Limited
Flat 703, Teamcowork, Palm Court, Gurugram–Mehrauli Road,
Sector 16, Gurugram, Haryana 122007, India
Language: This Policy is published in English. A User who requires this Policy in another language specified in the Eighth Schedule to the Constitution of India may request it at privacy@testogram.com.
16. Applicable Law
This Policy is governed by and shall be construed in accordance with the laws of the Republic of India, including but not limited to the following legislative and regulatory instruments:
The Information Technology Act, 2000, and the rules and regulations promulgated thereunder.
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
The Digital Personal Data Protection Act, 2023, which applies to the Company's processing of personal data.
Any disputes arising from or relating to this Policy shall be subject to the exclusive jurisdiction of the competent courts located in Gurugram, Haryana, India, subject to the dispute resolution provisions set forth in the Company's Terms of Service.