SSC CGL CHSL GK 2026
Privacy Policy
Table of Contents
- Information We Collect
- How We Use Your Information
- Data Storage & Security
- Third-Party Services & Integrations
- Cookies & Tracking Technologies
- Your Rights & Choices
- Children’s Privacy
- Data Retention
- Changes to This Policy
- Third-Party Links & Disclaimers
- Grievance Redressal & Contact
- Legal Compliance & Disclaimer
1Information We Collect
We collect and process the following categories of personal data to provide the App services and improve user experience:
A. Account & Authentication Data
- Email Address: Required for user registration, password reset, and account communication.
- Password: Securely hashed and stored; never transmitted in plain text.
- Device ID: Unique identifier for tracking app installations and offline progress synchronization.
- Display Name: Optional; used for leaderboard display and profile identification.
B. Academic & Usage Data
- Exam Progress: Sections completed, questions attempted, scores, time spent per section.
- Quiz History: Previous year papers (PYP) solved, full-length tests taken, sectional tests results.
- Bookmarks & Notes: Questions bookmarked for revision, personal notes created in-app.
- Leaderboard Data: Aggregate rankings, performance metrics for competitive display.
C. Device & Technical Data
- Device Information: Device type, OS version, app version, screen resolution, language preference.
- IP Address & Location: Approximate location inferred from IP (not GPS-based).
- Analytics & Crash Reports: App usage patterns, feature interaction data, crash logs for debugging.
D. Billing & Transaction Data
- In-App Purchase Records: Subscription purchases, premium feature access, transaction dates, and amounts.
- Payment Processor Data: Handled by Google Play Billing (Google) and not directly stored by us.
E. Communication Data
- Support Messages: Email/in-app support inquiries, attachments, feedback submitted.
- Push Notifications: Notification preferences and engagement data.
2How We Use Your Information
We use collected information for the following legitimate purposes:
Primary Uses
- Service Delivery: Create and manage user accounts, deliver exam preparation content, track progress, and enable leaderboard functionality.
- Personalization: Recommend practice sets based on weak areas, adjust difficulty levels, and tailor daily quiz content to exam patterns (SSC CGL / SSC CHSL).
- Performance Analytics: Understand user behavior, identify bottlenecks in content delivery, and optimize quiz difficulty.
- Communication: Send transactional emails (password reset, subscription confirmation, exam updates), push notifications, and periodic newsletters about new content or feature releases.
- Billing & Subscription Management: Process in-app purchases, manage subscription renewals, and issue invoices or receipts.
Secondary Uses
- Fraud Prevention: Detect and prevent unauthorized access, duplicate accounts, or suspicious activity.
- Legal & Compliance: Respond to legal requests, enforce terms of service, and comply with law enforcement inquiries.
- Content Improvement: Analyze user feedback, crash reports, and usage patterns to improve content accuracy and feature functionality.
- Research & Development: Conduct anonymized research on exam preparation trends and user learning patterns.
3Data Storage & Security
Where We Store Your Data
- Primary Database: Google Firebase (Firestore & Realtime Database), hosted on Google Cloud servers in India or neighboring regions, encrypted at rest.
- Backup & Sync: Encrypted local storage on your device; cloud backup via Firebase for offline-to-online synchronization.
- Analytics & Logs: Google Analytics & Firebase Crashlytics (anonymized and aggregated).
Security Measures
- Encryption in Transit: All data transmitted between your device and our servers uses industry-standard TLS 1.2+ encryption (HTTPS).
- Encryption at Rest: Firebase encrypts data at rest using AES-256-GCM.
- Authentication: Passwords are hashed using bcrypt with strong salt; Firebase Auth provides two-factor authentication (optional).
- Access Control: Only authorized personnel with genuine business need access personal data; all access is logged and monitored.
- Regular Audits: Security assessments conducted quarterly; vulnerability scanning performed on all systems.
- Incident Response: Breach detection mechanisms in place; users will be notified within 72 hours of any confirmed data breach.
4Third-Party Services & Integrations
A. Google Services
| Service | Purpose | Data Shared |
|---|---|---|
| Google Firebase Authentication | User account creation, login, password reset | Email, Display Name, Device ID |
| Google Firestore & Realtime DB | Store user progress, quiz history, bookmarks | All user-generated academic data |
| Google Analytics for Firebase | Understand user behavior, feature usage patterns | Anonymized usage analytics (no PII) |
| Firebase Crashlytics | Detect and log app crashes for debugging | Crash logs, stack traces (no PII) |
| Google Cloud Storage | Store quiz content, PDFs, media assets | Educational content (not personal data) |
B. Google Play Billing
- Payment Processing: In-app purchases (premium subscriptions, unlock all tests) are processed by Google Play Billing.
- Data Handled by Google: Payment method details, transaction records, billing address — NOT stored by us.
- Our Access: We receive only order confirmation (receipt ID, purchase date, subscription status) for service delivery.
- Google’s Privacy Policy: https://policies.google.com/privacy
C. AdMob (Advertising)
- Ad Serving: We use Google AdMob to display non-personalized & personalized ads (with user consent).
- Data Shared: Advertising ID, approximate location, app usage patterns (for ad targeting).
- User Consent: On first app launch, users are prompted to opt-in to personalized ads; users can disable personalized ads in device settings.
- Opt-Out Option: Users can reset their Advertising ID in device settings to reset ad targeting.
- AdMob Privacy: https://policies.google.com/technologies/ads
D. Email & Communication
- SendGrid / Firebase Email: Transactional emails (password reset, subscription confirmation, support replies) are sent via Firebase or third-party email services.
- Data Shared: Email address, name, transactional context only.
5Cookies & Tracking Technologies
What We Track
- Google Analytics Cookies: Track user sessions, page views, feature interactions, and click-through paths.
- Firebase Persistent IDs: Device-level identifiers to track app usage across sessions and enable offline-to-online sync.
- Advertising Cookies (via AdMob): Track ad impressions, click-throughs, and conversion data for ad performance measurement.
Disabling Tracking
- Google Analytics Opt-Out: Users can disable analytics by opting out of data collection in app settings.
- Advertising ID Reset: Users can reset their Advertising ID in Android Settings → Google → Manage Your Account → Data & Privacy → Ad Settings.
- Do Not Track (DNT): We respect browser-based DNT signals where applicable.
6Your Rights & Choices
DPDPA 2023 Rights
Under the DPDPA 2023, users have the following rights:
- Right to Access: Request a copy of all personal data we hold about you. Submit a request to support@gkquestionsguru.com with subject “Data Access Request.”
- Right to Correction: Request correction of inaccurate personal data (e.g., incorrect name, email).
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data, subject to legal exceptions. Note: Erasure may prevent access to your account and historical data.
- Right to Withdraw Consent: Withdraw consent for specific data processing (e.g., marketing emails, personalized ads) at any time.
- Right to Data Portability: Request your data in a machine-readable format for transfer to another service.
- Right to Object: Object to specific processing of your data (e.g., declining personalized recommendations).
How to Exercise Your Rights
To exercise any of the above rights, contact us at:
- Email: support@gkquestionsguru.com
- Subject Line: [Your Right] e.g., “Data Access Request,” “Erasure Request,” “Consent Withdrawal”
- Include: Full name, email, account details, and specific request.
- Response Time: We aim to respond within 30 days of receipt. Complex requests may take up to 60 days.
7Children’s Privacy
The App is designed for users aged 13 years and above preparing for SSC CGL / SSC CHSL exams.
Special Protections for Minors
- Age Verification: Users under 18 should obtain parental/guardian consent before registering.
- Limited Data Collection: We do not collect data beyond what is necessary for exam preparation.
- No Behavioral Profiling: We do not use children’s data to build detailed behavioral profiles.
- Parental Controls: Parents/guardians can request account information or request data deletion by contacting support.
- No Sale of Data: We strictly prohibit selling data of users under 18.
8Data Retention
We retain personal data for the following periods:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account & Authentication Data | For duration of account + 6 months after deletion | Legal & compliance (tax records, disputes) |
| Quiz History & Progress | For duration of account | Provide personalized learning experience |
| Billing & Transaction Records | 7 years | GST compliance, audit trail, dispute resolution |
| Analytics & Usage Data | 26 months (anonymized after 12 months) | Product improvement, usage analysis |
| Support / Communication Data | 2 years from last contact | Respond to follow-up queries, maintain records |
| Crash Logs & Error Reports | 90 days | Bug fixing & performance optimization |
| Marketing & Newsletter Data | Until opt-out or account deletion | Deliver newsletters, respect user preferences |
Deletion Upon Request
- You can request immediate deletion of your account and associated data anytime.
- Some data (e.g., billing records) may be retained longer due to legal obligations.
- Anonymized, aggregated data may be retained for analytics indefinitely.
9Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our practices. Material changes will be communicated via:
- Email notification to registered users (at least 30 days before change takes effect).
- In-app notification or pop-up message.
- Updated version published on our website and within the app.
Continued use of the App after changes confirms your acceptance of the updated policy. If you disagree with changes, you may delete your account and stop using the service.
10Third-Party Links & Disclaimers
External Links
The App may contain links to external websites (e.g., SSC official website, exam notifications). We are not responsible for the privacy practices of these third-party sites. Please review their privacy policies before sharing personal information.
Official Exam Content Disclaimer
SSC CGL CHSL GK 2026 is an independent educational app and is NOT affiliated with, endorsed by, or officially associated with the Staff Selection Commission (SSC), Government of India, or any government agency.
- Exam notifications, syllabus, and official patterns are sourced from publicly available official SSC websites (ssc.gov.in).
- Content is curated for educational purposes and may be updated based on annual exam pattern changes.
- SSC, CGL, CHSL, and related trademarks belong to the Government of India and SSC.
- Users are advised to cross-reference official SSC notifications before registering for exams.
11Grievance Redressal & Contact
Data Protection Officer (DPO) / Grievance Contact
- Name: Manmeet Kumar
- Business Name: Study Virus (Authorized Trade Name)
- Legal Entity: MANMEET KUMAR
- GST: 07EYEPK4090N1ZX
- Email: support@gkquestionsguru.com
- Response Time: We aim to acknowledge all grievances within 5 business days and resolve within 30 days.
Escalation
If you are unsatisfied with our response, you can file a complaint with the Central Authority under DPDPA 2023 (when established) or relevant data protection authorities.
12Legal Compliance & Disclaimer
Governing Law
This Privacy Policy is governed by the laws of India, specifically:
- Information Technology Act, 2000 (IT Act)
- Digital Personal Data Protection Act, 2023 (DPDPA)
- Indian Penal Code, 1860 (where applicable)
- Applicable state and central laws.
Jurisdiction
Users agree that any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of courts in Delhi, India.
Data Protection Certifications
- Google Cloud (Firebase): ISO 27001, SOC 2 Type II certified
- Google AdMob: GDPR compliant
Limitation of Liability
- While we implement industry-standard security measures, no system is 100% secure. We cannot guarantee absolute data security.
- We are not liable for unauthorized access due to user negligence (e.g., sharing passwords, weak device security).
- In the event of a data breach beyond our reasonable control, we will notify affected users within 72 hours as required by law.
Severability
If any provision of this Privacy Policy is found invalid or unenforceable, the remaining provisions shall remain in full force and effect.