Privacy Policy
We built claratto to help you learn — not to harvest your data. Here's exactly what we collect, why, and how we protect it.
Information We Collect
Account Information
We use Google OAuth via Firebase Authentication for sign-in. When you connect, we receive and store your name, email address, and profile photo URL. We never see your Google password.
Learning Activity (Your Brain)
To build and display your personal brain graph, we record:
- Topics you learn and the canonical AI-generated name for each.
- MCQ test scores and the resulting node strength (solid ≥75%, faint 45–74%, not stored <45%).
- Brain node connections — the relationships between topics, AI-reasoned at test time.
- Saved lesson notes — the AI's explanation stored after each initial teach session.
- Syllabus documents — if uploaded, the parsed course structure (subjects + topics) stored in your account.
Conversation Context (App Memory)
To give the AI continuity within and across sessions, we store a rolling conversation summary per topic — recent messages verbatim, older messages compressed into a summary. This is capped and never grows unboundedly. It is separate from your brain graph.
Voice Interview Data
During voice interviews, your spoken answers are temporarily recorded and sent to Sarvam AI (Speech-to-Text). We do not retain the raw audio. We store only the resulting text transcript and structured feedback report inside your account on Firestore.
Payment Information
Payments are processed by Razorpay. We never see or store your card number, CVV, UPI PIN, or banking credentials — Razorpay handles all sensitive payment data under PCI-DSS compliance. We receive only the payment status, transaction ID, and order amount from Razorpay's webhook to credit your account.
Usage and Technical Data
We log API call metadata (model used, token counts, credit debits) server-side for billing accuracy and abuse detection. We do not use third-party analytics trackers or advertising pixels.
How We Use Your Information
- Personalise AI tutoring — the model reads your existing brain nodes so it never re-teaches what you've already proven.
- Score tests server-side and write passing results to your brain graph — never trusting the client.
- Generate and deliver voice interview feedback reports.
- Manage your plan tier, recurring credit grants, top-up pack balances, and interview limits.
- Detect and prevent abuse of the test-gate system, credit system, and API quota.
- Send billing receipts and important service notices to your account email.
We do not sell your data, use it for advertising, or share it with third parties beyond the service providers listed in Section 04.
Data Storage and Retention
Your profile, brain nodes, lesson notes, interview transcripts, and chat context are stored in Google Cloud Firestore, hosted in Google's secure cloud infrastructure with encryption at rest and in transit.
Data is retained for as long as your account is active. You can request full deletion at any time (see Section 05). If your account is inactive for 24 consecutive months, we may delete it and all associated data after providing 30 days' notice by email.
Third-Party Services
We share only what is strictly necessary with the following trusted providers:
Your Rights and Choices
You have the right to:
- Access — request a copy of all personal data we hold on your account.
- Correction — request correction of inaccurate data.
- Deletion — request complete erasure of your profile, brain nodes, lesson notes, and interview history.
- Portability — request your brain node data in a machine-readable format.
- Withdrawal — stop using the service at any time; your data remains available for deletion on request.
To exercise any of these rights, email us at support@devstudiolabs.in with the subject line "Data Request — [your email]". We will process your request within 14 business days.
Cookies and Tracking
claratto uses only functional cookies — specifically the Firebase Authentication session token stored in your browser's local storage to keep you signed in across sessions. We do not use advertising cookies, cross-site trackers, or third-party analytics scripts.
Security
We take the following measures to protect your data:
- All AI calls and Firestore writes happen server-side behind Firebase ID token verification — the browser never writes directly to the database.
- Test scores and brain state are computed and written server-side, making them unforgeable from the client.
- AI API keys are server-only environment variables — never exposed to the browser.
- Razorpay webhook signatures are verified with HMAC-SHA256 before any credit grant.
- Firestore security rules deny all client writes; reads are owner-only.
Governing Law
This Privacy Policy is governed by the laws of India, including the Information Technology Act, 2000, and applicable rules thereunder. Disputes are subject to the exclusive jurisdiction of courts in Mumbai, Maharashtra, India.
Contact Us
For privacy questions, data requests, or concerns:
claratto — Privacy
Email: support@devstudiolabs.in
Location: Maharashtra, India
Response time: within 14 business days for data requests
claratto is a product of DevStudioLabs (Sole Proprietorship), registered in Ratnagiri, Maharashtra, India.