ClassVaultBack to site
Legal

Privacy Policy

Last updated 25 August 2026

This explains what ClassVault collects about you, why, who else touches it, how long we keep it, and what you can ask us to do with it. It covers the ClassVault website and application operated by Priyanshu Singh.

1. What we collect

When you create an account. Your email address, or your phone number if you sign in by SMS, or your name and email from Google or GitHub if you use those. Passwords are stored only as a hash by our authentication provider — we never see or hold your password.

When you complete onboarding. Your display name, your university, your degree, your expected graduation year, and your study preferences. If you verify with an academic email address, we store that address and the university it belongs to.

When you upload a note. The file itself, its title, description, subject, tags, file type and size, and a SHA-256 checksum of the contents. For PDFs we also extract the text so the note can be searched. Files are stored privately; they are never public objects.

When you use the product. Ratings you leave on notes, reports you file, rooms you join and messages you send in them, study roadmaps generated for you, and your progress through their tasks. If you upload a profile photo it is stored in a public bucket, so treat it as publicly visible.

Automatically. Standard server logs from our host, including IP address and request metadata, and a bot-detection signal from Cloudflare Turnstile on sign-up, password reset, and phone sign-in.

We do not run per-user behavioural analytics, advertising trackers, or third-party analytics scripts. Operational metrics we look at are aggregate counts only.

2. Why we use it

  • To run your account and keep you signed in.
  • To decide what you are allowed to see. University scoping and note access are enforced from your verified membership.
  • To make notes findable, including by text extracted from PDFs you uploaded.
  • To generate study roadmaps from notes you are entitled to use.
  • To keep the platform safe — handling reports, moderating content, and limiting abuse and automated sign-ups.
  • To respond when you contact us.

We process this data to provide a service you asked for, to meet legal obligations that apply to us as an intermediary, and — for safety and abuse prevention — because we have a legitimate interest in the platform not being harmful to the students using it.

3. What other students can see

Your display name, profile photo, degree, and graduation year are visible to other students. Contributor information on a note is shown pseudonymously.

Ratings are anonymous and shown only as aggregates. If you report a note, the person who uploaded it is never told who reported it. Study-room membership and chat are visible to others in that room while it exists.

Your email address, phone number, and password are never shown to other students.

4. Who else processes your data

We do not sell your data and we do not share it for advertising. We rely on these providers to operate:

  • Supabase — authentication, database, file storage, and realtime updates.
  • Vercel — application hosting and server logs.
  • Cloudflare — Turnstile bot detection on authentication forms.
  • Twilio — delivery of SMS one-time codes, if you sign in by phone.
  • Google and GitHub — only if you choose to sign in with them.

These providers operate outside India, so your data is transferred and stored abroad. We may also disclose data where the law requires it, or to respond to a valid legal request.

5. How long we keep it

  • Account and profile data — while your account exists.
  • Deleted notes — recoverable by you for 30 days, then the file, its record, its ratings, and any derived roadmap data are permanently removed.
  • Study rooms and their chat — destroyed when the room ends, when the last member leaves, or when it expires. They are not archived.
  • Ratings — kept even after you lose access to the note they were left on, because they were valid when made and removing them would distort that note’s history.
  • Moderation records — kept as an audit trail of actions taken.

6. If you delete your account

We remove your account and profile data. We do not delete the notes, ratings, or shared roadmaps you contributed — they stay available under their existing scope so that other students’ libraries and shared links do not break. Those contributions are no longer connected to a live profile.

If you want a specific note removed rather than kept, delete it yourself before closing your account, or ask us and we will remove it.

7. Your rights

Under the Digital Personal Data Protection Act, 2023, you can ask us to:

  • tell you what personal data of yours we hold and who we shared it with;
  • correct or complete anything inaccurate;
  • erase data we no longer need, subject to section 6 and our legal obligations;
  • nominate someone to exercise these rights if you die or become incapacitated.

Much of this you can do yourself: edit your identity and study preferences at Settings, and manage or delete your uploads in My Vault. For anything else, write to us using section 9.

You may withdraw consent at any time by closing your account. That does not undo processing we already carried out lawfully.

8. Security and children

Access to notes is enforced in the database itself, not just hidden in the interface. Uploaded files are stored privately and served through short-lived signed links. Passwords are hashed by our authentication provider. No system is perfectly secure, so please use a password you do not reuse elsewhere.

ClassVault is for students aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will remove it.

9. Contact and complaints

For any privacy question or request, write to Priyanshu Singh at hello@priyanshu.co, or by post at Greater Noida, Uttar Pradesh 201310, India. We aim to acknowledge within 24 hours and resolve within 15 days.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

10. Changes

If we change how we use your data in a way that materially affects you, we will give you notice through the service before it takes effect.

See also our Terms of Use and our content report and takedown process.

© 2026 ClassVault
TermsPrivacyReport content