Privacy

Last updated 27 September 2026

Short version: your academic data is yours, only you can see it, and we don't sell anything to anyone.

What we store

  • Your name and email, from the account you sign in with
  • Your university, course, semester, and section — as you typed them
  • Your subjects, timetable, and attendance marks
  • Assignments and any files you upload
  • Your conversations with the AI assistant
  • Messages you send to support, including the support chat, and whether you rated an answer helpful
  • Your settings, including theme and notification preferences

Who can see it

No other student can. Every record is tied to your account, and every request checks that the data belongs to you before returning it. There is no shared feed, no class leaderboard, and no way for another student to look up your attendance.

The yvendr team can access account and usage data internally — for support, debugging, and understanding how the product is actually used. This is a small team, not a public dashboard, and we don't read your uploaded notes or files unless you specifically ask us to for support.

We do not sell your data, and we do not run ads.

Who processes it for us

  • Clerk — sign-in and account security
  • Neon and, from October 2026, Supabase — the database your records live in
  • Vercel — hosting and file storage
  • Groq, Google (Gemini), Anthropic (Claude), DeepSeek, OpenRouter, and TokenRouter — the AI assistant, timetable reading, and image generation. We route between these depending on availability; a given message may go to any one of them.
  • Razorpay — payment processing for Premium; we never see or store your card or UPI details ourselves
  • Google Classroom — only if you connect it yourself from Profile; we read your active courses and coursework to build your Assignments list

When you ask the assistant something, the relevant parts of your data are sent to the AI provider to produce an answer. When you upload a timetable, that file is sent to be read. We only send what the request needs.

Your files

Uploads are stored with unguessable addresses and are only served after we confirm the file belongs to your account. Text is extracted from documents so the assistant can answer questions about your own notes.

Cookies

We don't use tracking or advertising cookies — there is no analytics, no ad pixel, and nothing that follows you across sites. Sign-in uses a small number of strictly-necessary cookies set by Clerk, our authentication provider, to keep you signed in. See our Cookies Policy for the full list.

Your rights, and deleting your data

You can see and correct most of your data directly in the app — your profile, subjects, timetable, and files are editable wherever they appear. Delete a subject, file, or assignment and it goes. Delete your account and everything tied to it is removed. You can also email hello@pocketprojects.org to ask us to access, correct, or delete your data, or to export a copy of it — we'll respond within 30 days.

Grievance Officer

As required under India's IT Rules, our Grievance Officer for privacy complaints is Rehan Hussain, reachable at hello@pocketprojects.org. We aim to acknowledge complaints within a few days and resolve them within 30 days.

Notifications

Push notifications are off until you turn them on, and you can turn them off again in Profile at any time.

How we protect it

Data is encrypted in transit (HTTPS everywhere, with HSTS) and at rest by our database and hosting providers. Every request is checked against your signed-in account before any data is returned, secrets and keys are kept out of our code, payments are handled entirely by Razorpay, and our backups are encrypted. Access inside yvendr is limited to the people who need it to run and support PocketUni. No system is perfectly secure; if a breach ever affects your data, we will tell you and the relevant authorities as the law requires.

How long we keep it

We keep your data while your account is open. When your account is deleted, your records are removed from our live database straight away and age out of our encrypted backups within 14 days. Support messages are kept for up to 12 months so we can follow up.

Your rights under Indian law

Under the Digital Personal Data Protection Act, 2023 you can ask to access, correct, update or erase your personal data, withdraw consent, and nominate someone to exercise these rights for you. Email hello@pocketprojects.org and we'll respond within 30 days. You can also raise a complaint with our Grievance Officer above, and with the Data Protection Board of India.

Students under 18

PocketUni is meant for university students. If you are under 18, you should use it only with a parent or guardian's consent.

Changes to this policy

If we change how we use your data in a meaningful way, we'll tell you in the app or by email before it takes effect.