MyGyan Icon
Login

MyGyan

Your shortcut to new skills.

Owned & operated by GenSutra AI Technologies Pvt Ltd.

Privacy Policy

MyGyan — owned and operated by GenSutra AI Technologies Pvt Ltd

Effective Date: 28 July 2026 Last Updated: 24 August 2026


1. Introduction

This Privacy Policy explains how GenSutra AI Technologies Pvt Ltd ("GenSutra", "we", "our", "us") collects, uses, shares and protects personal data when you use MyGyan, our AI-powered learning platform at mygyan.ai, our mobile applications, and related services (together, the "Platform").

We are based in Bengaluru, Karnataka, India. This Policy is written to comply with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and with the Information Technology Act, 2000 and rules made under it.

Terms used here have the meanings given in our Terms of Service.

Summary of the things people most often want to know:

  • We do not train our AI models on your content, and our AI providers do not train theirs on it either. See clause 6.
  • We measure what our AI requests cost, but send no content to do it — not your prompts, not your documents, not what we generate for you. See clause 6.1 for the one exception, on error reports.
  • We do not sell or rent your personal data, and we show no advertising on the Platform. We do measure whether our own advertising elsewhere reaches the right people, as described in clause 10. See clause 8.
  • If you use MyGyan through your employer, your manager can see your learning progress. See clause 7.
  • You can access, correct and delete your data, and withdraw consent. See clause 11.

2. Who is responsible for your data

2.1 Individual accounts

Where you register and pay for MyGyan yourself, GenSutra is the Data Fiduciary for your personal data. We decide why and how it is processed, and we are accountable to you for it.

2.2 Organisation Seats

Where an organisation — typically your employer — provides you with a Seat:

  • The Organisation is a Data Fiduciary in respect of the data it decides to process about you, including its decision to enrol you, the courses it assigns to you, and the progress reporting it receives about you. Its own privacy notice governs that.
  • GenSutra acts as a Data Processor for the Organisation in respect of that Organisation-directed processing, and processes it on the Organisation's documented instructions.
  • GenSutra remains a Data Fiduciary in respect of the account and platform data we need to operate MyGyan for you, to secure it, and to meet our own legal obligations.

If you want to know why your Organisation enrolled you or what it does with your progress data, please ask your Organisation first. We will help where we can.


3. Personal data we collect

3.1 Data you give us

  • Account and identity data — name, email address, mobile number, password credentials, profile photo, country and time zone.
  • Professional profile data — your stated role, industry, experience, skills, learning goals and preferences.
  • Documents you upload — including your résumé or CV, which typically contains your employment history, education, qualifications and contact details.
  • Prompts and instructions — what you type or say to the Platform when asking for a course, an explanation or a change.
  • Learning inputs — your responses to exercises, quizzes, assessments and free-text questions, and any notes you save.
  • Payment data — billing name, address and tax identifiers. Full card and bank details are collected and stored by our payment provider, not by us. We hold only a token, the last four digits, the instrument type, and transaction records.
  • Support and communications — messages you send us, and records of support interactions.

3.2 Data we collect automatically

  • Device and connection data — IP address, device type, operating system, browser, language settings.
  • Usage data — pages and screens viewed, features used, session times, slides and modules opened, time spent, completion events.
  • AI request measurements — technical information about requests made to our AI systems, such as model used, tokens consumed and duration, with the content removed. This is described in clause 6.1.
  • Cookies and similar technologies — see clause 10.
  • Security and diagnostic logs — authentication events, errors, and access records.

3.3 Data we derive

  • Learning profile — a model of your background, current knowledge and skill gaps, built from the data in clause 3.1 and used to personalise what we serve you.
  • Progress and competency data — modules completed, slides progressed, assessment outcomes, activity recency.
  • Recommendations — suggested courses and next steps.

3.4 Data from others

  • From your Organisation, where it enrols you — your name, work email, mobile number, role, tier, and reporting line.
  • From authentication providers, if you sign in with Google or a similar service — your name, email address and profile picture, in accordance with your settings with that provider.
  • From our payment provider — payment status, mandate status and refund records.

We do not collect or ask for any special category of data, such as health data, biometric data, caste, religion, or political affiliation. Please do not put such information into prompts, uploaded documents or free-text answers.


4. Why we use your personal data

PurposeWhat this involves
Providing the PlatformCreating and running your account, authenticating you, delivering courses and features
PersonalisationBuilding your learning profile from your prompts, résumé, progress and assessment responses, so the content we generate reflects your actual background and level
Generating AI contentSending your inputs to our AI providers so that learning material and audio narration can be generated for you
Organisation reportingMaking your progress visible to your Organisation Administrator and manager, where you use an Organisation Seat (clause 7)
PaymentsProcessing subscriptions, renewals, mandates, invoices, refunds and tax records
SupportResponding to your questions and complaints
Security and integrityDetecting and preventing fraud, abuse, unauthorised access and misuse
Cost measurementRecording how much each AI request consumed, so we can attribute cost to the right course (clause 6.1)
Service improvementUnderstanding, in aggregate, which features work — see clause 6 for what we do not do
Legal complianceMeeting tax, accounting, and regulatory obligations, and responding to lawful requests
MarketingSending you product news and offers, only if you have opted in
Advertising measurementMeasuring whether our advertising reaches the right people, as described in clause 10

5. Our lawful basis for processing

Under the Digital Personal Data Protection Act, 2023 we process personal data on the following bases:

Consent (section 6). For processing that requires it, including marketing communications, non-essential cookies and any optional integration you enable. Where we rely on consent, we ask for it through a clear notice describing what data we process and for what purpose, and you may withdraw it at any time (clause 11). Withdrawing consent does not affect processing already carried out, and may mean we can no longer provide some features.

Product analytics and advertising. These run when you use the Platform, so we can understand which features are used and whether our advertising reaches the right people. See clause 10. You can block non-essential cookies in your browser.

Certain legitimate uses (section 7). Specifically:

  • Section 7(a) — where you have voluntarily provided your personal data to us for a specified purpose and have not indicated that you object to its use for that purpose. This covers the core operation of your account and the delivery of the learning service you asked for.
  • Section 7(c) — where processing is necessary for us to comply with a legal obligation in India, including tax, accounting and company-law record-keeping.
  • Section 7(d) — where processing is necessary to comply with a judgment, decree or order.

Where the EU or UK GDPR applies to you because of where you are located, we will additionally comply with it and will identify the applicable Article 6 basis on request.


6. We do not train our AI models on your data

We do not use your prompts, uploaded documents, résumé, assessment responses, learning activity or any other content you provide to train, fine-tune, or otherwise develop artificial-intelligence models.

We use third-party AI providers to generate learning content and audio for you. We use those providers under commercial terms which prohibit them from using your content to train their models.

Some of those providers retain inputs and outputs for a short period for security and abuse-monitoring purposes only — for example, our primary model provider may retain prompts and generated content for up to 30 days for that purpose. This is not training, and the content is not used to improve any model.

Your content is used to personalise the Platform for you — that is, to build your individual learning profile so that what we generate matches your background and level — and, where you use an Organisation Seat, to provide the reporting described in clause 7. It is not pooled with other users' data to generate their content.

We do use aggregated and de-identified statistics — for example, how many users complete a module, or where users commonly drop off — to understand and improve the product. This information cannot reasonably be used to identify you or to reconstruct your content.

6.1 What we record about AI requests

Building a course involves many separate calls to AI models. We need to know what each one cost, so that we can attribute cost correctly and keep the service sustainable. We therefore send technical information about each request to a monitoring service.

What is recorded: which model was used, how many tokens the request and the response consumed, how long it took, whether it succeeded or failed, and internal references identifying the course, chapter and account the request relates to.

What is not recorded: we do not send the content of your prompts, of documents you upload such as your résumé, or of the learning material generated for you. Text is stripped out automatically before a record leaves our systems, so what the monitoring service receives is the shape of a request and its measurements, not what it said.

One exception. When a request fails, a short description of the failure is recorded so that we can diagnose it. Descriptions we write ourselves contain no content. A fault reported back to us by one of our AI providers may quote a fragment of the text that caused it — for example where a provider rejects a passage for being too long. These records are held for the same period as the rest and are used only to fix the fault.

How it is linked to you. The internal references include an account identifier — a randomly generated internal value. It does not carry your name, email address or mobile number.

Where it is held and for how long. This service is operated by Langfuse and processes data outside India, in the European Union. Records are retained for 30 days and then deleted. See clauses 9, 13 and 14.


7. If you use MyGyan through your employer

This clause describes something you should know before you start using an Organisation Seat.

7.1 What your Organisation can see

Where an Organisation provides your Seat, the following is visible to your Organisation Administrator, and to the person recorded as your manager within the Organisation:

  • your name, work email address and mobile number, as provided to us by the Organisation;
  • your assigned tier and Seat status;
  • the courses assigned to you, and when they were assigned;
  • your progress in those courses — modules and slides completed, progress made, and the date of your most recent activity.

7.2 What your Organisation cannot see

Your Organisation Administrator and manager cannot see:

  • the text of your prompts, questions or free-text answers;
  • your uploaded résumé or CV;
  • your assessment answers;
  • your password or payment data;
  • your activity on any personal MyGyan account held separately from your Seat.

7.3 Why

We provide this reporting because the Organisation has purchased Seats in order to manage training for its personnel, and because it is a Data Fiduciary in its own right for that purpose. Your Organisation is responsible for telling you why it enrolled you and how it uses this information, and for having its own lawful basis for doing so.

7.4 If your Seat ends

If your Organisation removes your Seat, or its subscription or trial ends, your access at that tier ends and your account reverts to the free tier. Your learning history remains on your account.


8. When we share personal data

We do not sell or rent personal data, and we do not share it for third-party advertising. We show no advertising on the Platform. We do measure the effectiveness of our own advertising on other sites, which is covered by clause 10 and by the providers listed in clause 9.

We share personal data only:

  • With service providers who process it on our behalf, under contract, for the purposes in clause 4 (see clause 9);
  • With your Organisation, where you use an Organisation Seat, as described in clause 7;
  • With our AI providers, to generate learning content and audio for you, on terms prohibiting training;
  • Where you ask us to, including when you enable an integration;
  • For legal reasons — where required by law, by a court or by a competent authority, or where necessary to establish, exercise or defend legal claims, prevent fraud, or protect the rights, property or safety of any person;
  • In a corporate transaction — in connection with a merger, acquisition, restructuring or sale of assets, subject to the acquirer being bound by protections no less protective than this Policy. We will tell you if this happens and it materially affects you.

We may share aggregated or de-identified information that cannot reasonably identify you.


9. Our service providers

We use the following providers to process personal data. Each processes it on our instructions, under contract, and is required to maintain appropriate security.

ProviderPurposeWhere it processes data
Amazon Web Services (AWS)Cloud hosting, databases, file storageIndia (Mumbai, ap-south-1)
AWS Simple Email ServiceTransactional and notification emailIndia
AWS CloudWatchApplication and infrastructure loggingIndia
Microsoft Azure OpenAI ServiceGenerating learning contentUnited States (East US 2)
GoogleGenerating learning content and audio narrationIndia or United States
AnthropicGenerating learning contentUnited States
ElevenLabsAudio narration of lessonsUnited States
LangfuseMeasuring the cost and performance of AI requests (clause 6.1)European Union
RazorpayPayments, subscriptions, mandates, refundsIndia
PostHogProduct analyticsUnited States or European Union
Google AdsMeasuring the effectiveness of our advertising (clause 10)United States
Microsoft ClaritySession analytics — how you interact with a page (clause 10)United States

We keep this list current, and we update this Policy when we add or change a provider that processes personal data.


10. Cookies and similar technologies

We use cookies, local storage and similar technologies for two purposes.

Strictly necessary. Keeping you signed in, securing your session, remembering your preferences such as language and time zone. These are required for the Platform to work and cannot be disabled.

Analytics and advertising. Understanding which features are used and where people get stuck, and measuring whether our advertising reaches the right people. These run when you use the Platform. This covers product analytics (PostHog), advertising measurement (Google Ads) and session analytics (Microsoft Clarity), which may record how you interact with a page. They are listed in clause 9.

You can block cookies in your browser, though strictly necessary cookies are required for the Platform to work.

We do not sell your personal data, and we permit no advertising or session-analytics tracker outside those listed in clause 9.


11. Your rights

Under the Digital Personal Data Protection Act, 2023 you have the following rights:

  • Right to access information (section 11) — to obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors with whom it has been shared.
  • Right to correction, completion, updating and erasure (section 12) — to have inaccurate or misleading data corrected, incomplete data completed, and your data erased where it is no longer needed for the purpose it was collected for and we are not required by law to keep it.
  • Right to grievance redressal (section 13) — to complain to us about how we handle your data, using the contact details in clause 15. You must use this before approaching the Data Protection Board.
  • Right to nominate (section 14) — to nominate another person to exercise your rights on your behalf if you die or become incapable of doing so.
  • Right to withdraw consent (section 6) — at any time, as easily as you gave it.

How to exercise them

You can update much of your profile information directly in your account settings.

For access, erasure, or deletion of your account, email [email protected] from the address registered on your account. We handle these requests manually. We will:

  • acknowledge within 72 hours;
  • complete the request within 30 days;
  • confirm in writing when it is done.

We may need to verify your identity first. We do not charge for this.

Note that some records must be retained even after an erasure request — see clause 13.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

Where the EU or UK GDPR applies to you, you have the additional rights it confers, including data portability and the right to object to processing.

Your responsibilities. Section 15 of the Act asks you not to impersonate anyone, not to suppress material information, not to register a false or frivolous grievance, and to provide authentic information when seeking correction or erasure.


12. Security

We protect personal data using measures appropriate to the risk, including:

  • encryption of data in transit and at rest;
  • role-based access controls and least-privilege access for our personnel;
  • authentication controls and session management;
  • credentials and secrets held in a managed secrets store rather than in code;
  • audit logging of access to personal data, retained for at least one year in accordance with Rule 6 of the DPDP Rules, 2025;
  • review of a provider's security posture before we begin using it.

No system is completely secure. We cannot guarantee absolute security, and you are responsible for keeping your credentials confidential.

12.1 If there is a personal data breach

If a personal data breach affects your personal data, we will notify you without undue delay, describing the nature and extent of the breach, its likely consequences, the measures we have taken, and what you can do to protect yourself. We will also notify the Data Protection Board of India within the timelines prescribed by the DPDP Rules, 2025.


13. How long we keep data

DataRetention
Account, profile and learning dataFor as long as your account exists. If you ask us to delete your account, we action it within 30 days
Uploaded documents including résumésFor as long as your account exists, or until you ask us to delete them
Progress and assessment dataFor as long as your account exists
AI request measurements (clause 6.1)30 days
Aggregated usage metricsUp to 13 months
Access and security logsAt least 1 year, as required by Rule 6 of the DPDP Rules, 2025
Support correspondence24 months
Payment, invoice and tax records8 years, as required by section 128 of the Companies Act, 2013 and applicable tax law
Marketing consent recordsUntil withdrawn, and for 3 years afterwards as evidence of consent

Payment, invoice and tax records are retained even after you ask us to delete your account, because we are legally required to keep them. Everything else is deleted or irreversibly anonymised. Data held in backups is removed on the backup rotation cycle.

If you use an Organisation Seat, the Organisation may instruct us to retain or delete Organisation-directed data. Where we act as its Processor, we follow those instructions, subject to our own legal obligations.


14. Transfers outside India

We host the Platform and store your account, learning and payment data in India, in the AWS Mumbai region. Documents you upload, including your résumé, are stored in India and are not sent outside it.

Some of our providers process data outside India — see the table in clause 9 for which, and where. In particular:

  • AI content and audio generation sends your prompts and the material generated from them to model and speech providers, which may process outside India;
  • AI request measurement (clause 6.1) sends technical information about each request, together with internal references, to Langfuse, which processes outside India. It does not send your prompts or the content generated for you;
  • Product analytics may process outside India.

Section 16 of the DPDP Act permits transfer of personal data outside India except to a country or territory restricted by notification of the Central Government. We do not transfer personal data to any restricted country. We monitor notifications under section 16 and Rule 15 of the DPDP Rules, 2025, and will change our arrangements if a country we use becomes restricted.

Where we transfer data internationally, we put contractual safeguards in place with the recipient, including obligations of confidentiality, purpose limitation, security, and — for AI providers — a prohibition on training.


15. Contact us and how to complain

Grievance Officer Vinay Gupta GenSutra AI Technologies Pvt Ltd GK Co-Works, 72/12, Nallurhalli Main Road, HAL Old Airport Road, Brookefield, Bengaluru 560066, Karnataka, India Email: [email protected]

CIN: U63119KA2025PTC203416 · GSTIN: 29AAMCG0883E1ZD

The Grievance Officer is our contact point for questions about this Policy, for exercising your rights under clause 11, and for complaints, in accordance with the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Our response times:

  • We acknowledge every request or complaint within 72 hours.
  • We resolve it within 30 days of receipt.

If we cannot resolve something within 30 days we will tell you why and give you a revised timeline. The DPDP Rules set an outer limit of 90 days.

If you remain dissatisfied, you may complain to the Data Protection Board of India.


16. Children

The Platform is for adults. You must be at least 18 to use it.

We do not knowingly collect personal data from anyone under 18. We do not carry out behavioural monitoring or tracking of children, and we do not direct advertising at children.

If we become aware that we hold personal data of someone under 18, we will delete it and close the account. If you believe a child has provided us with personal data, please contact the Grievance Officer.

Organisations that purchase Seats warrant to us that every person they enrol is at least 18 years old.


17. Changes to this Policy

We may update this Policy. Where a change is material, we will give you at least 30 days' notice by email or prominent in-Platform notice before it takes effect, and where the change requires your consent, we will ask for it.

The current version is always at mygyan.ai/privacy-policy, with the "Last Updated" date at the top.


GenSutra AI Technologies Pvt Ltd CIN: U63119KA2025PTC203416 · GSTIN: 29AAMCG0883E1ZD GK Co-Works, 72/12, Nallurhalli Main Road, HAL Old Airport Road, Brookefield, Bengaluru 560066, Karnataka, India