This Privacy Policy explains what personal information TG EXAM HUB collects, how we use it, and what choices you have. It applies to the Platform described in our Terms & Conditions.
1. Information we collect
- Account details. Name, email, phone (if provided), password (stored only as a bcrypt hash), and your role on the platform.
- Preferences. Onboarding choices such as your primary exam target, preferred language and preparation goal.
- Usage data. Test attempts, answers you selected, timestamps, subject-wise scores, IP address of the request, and basic device/browser metadata associated with each session.
- Content you submit. Referral codes you enter, feedback, and any documents an admin user uploads through the admin workflow.
- Communications. Support emails you send, and password-reset messages we send you.
2. What we do not collect
- We do not store your full payment card number, CVV, UPI PIN, or net-banking credentials. Payment flows are handled by third-party payment providers.
- We do not sell your personal data.
3. How we use your information
- To create and secure your account, and to authenticate you on each visit.
- To operate the CBT engine, generate your response sheet, and compute performance analytics.
- To send transactional email — for example, password reset links, receipts, referral notifications, and important service messages.
- To detect, investigate and prevent abuse: brute-force attempts on login, fake or self-referrals, unauthorised admin access, credential stuffing, and platform scraping.
- To improve the Platform, fix bugs, and prioritise new features. Analytics we run for this purpose are aggregated and do not identify individual users in reports.
4. Third-party processors
We rely on a small number of vendors to run the Platform. Each of them only sees the minimum information needed for their function:
- MongoDB hosting — stores the operational database.
- Transactional email provider — sends password reset messages, referral notifications, and receipts.
- Large-language-model providers — process the text of your Junia / Jovin chat messages when you use those AI features. Do not enter sensitive personal data into these chats.
- Payment provider — will handle checkout once real payments go live.
5. Cookies & local storage
We use local storage in your browser to keep you signed in (a JSON Web Token issued at login), to preserve in-progress CBT state so a refresh doesn't lose your answers, and to remember lightweight UI preferences. We do not use third-party advertising cookies.
6. Retention
We retain your account, attempts, and coin history for as long as your account is active. If you request deletion, we remove or anonymise identifiable data within a reasonable period, except where we are required to retain records — for example, tax/accounting records for completed transactions, or fraud/abuse evidence for the duration reasonably necessary.
7. Your choices & rights
- You may request a copy of the personal data we hold about you.
- You may correct inaccurate account details by editing your profile or contacting us.
- You may request deletion of your account. Contact us via the Contact page — see the wording below about what remains after deletion.
- You may opt out of non-essential emails. Transactional emails required to run your account (security alerts, password resets) cannot be opted out of while your account exists.
8. Security
We store passwords only as bcrypt hashes, use bearer JSON Web Tokens for session authentication, gate admin/super-admin endpoints with server-side role checks, rate-limit high-risk public endpoints, and enforce input and upload validation on the server. No online service can be 100 % secure, so please use a unique strong password and enable device-level protections on your side.
9. Children
The Platform is intended for aspirants preparing for competitive exams and is not directed to children under 13. If we learn we have inadvertently collected data from a child under 13, we will delete it.
10. Cross-border transfers
Our vendors may process your data in servers located outside India. We take reasonable steps to ensure they meet security standards comparable to the ones we follow.
11. Changes to this Policy
We may update this Policy from time to time. The "last updated" date at the top will change to reflect this. Material updates will additionally be flagged inside the Platform.
12. Contact
Questions about this Policy? Use the address listed on the Contact page.
The registered legal entity, Data Protection Officer contact, and postal address will be added here once the operating entity is finalised. Until then, please use the support email on the Contact page.