Privacy Policy
Last updated: June 30, 2026
This Privacy Policy explains how GNEPAL (operated by Gnepal, “we”, “us”) collects, uses, shares, and protects your information when you use our mobile app and website (the “Service”). By using the Service you agree to this policy.
Information we collect
- Account information you provide: first and last name, email address, and optionally a phone number. Your password is stored only as a salted hash — never in plain text.
- Google sign-in (optional): if you sign in with Google, we receive a verification token and your basic Google profile (name, email, profile picture) to create or match your account. We do not access your Google contacts, files, or other Google data.
- Learning data: your answers, time spent per question, mock-test and practice results, mastery and spaced-repetition (review) progress, study streaks, and the study goals and preferences you set (target score, exam date, daily study time).
- Device & notification data: a push-notification token, your platform (Android/iOS/web), and the app version, used to deliver notifications and required updates.
- Security & sign-in records: when you log in we record the IP address, device/browser (user-agent) and timestamps, and we log security events (e.g. failed logins) to protect your account and detect abuse.
- Usage analytics: first-party events about how you use the Service (e.g. screens opened, features used) to understand and improve it. These are our own records — we do not use third-party advertising or cross-app tracking SDKs.
- Purchases: if you buy premium access, we record which plan you purchased and its validity. Card/payment details are handled by the payment provider, not stored by us.
- Support communications you send us (e.g. via the contact form or email).
Information we do NOT collect
- We do not use third-party advertising or analytics SDKs, do not sell your data, and do not use your device’s advertising ID.
- Biometrics (fingerprint/face) are used only to unlock the app on your device, entirely by your device’s operating system — your biometric data never leaves your device and is never sent to us.
- We do not collect precise location.
How we use your information
- To provide, personalize, and improve your learning experience.
- To authenticate you, secure your account, and detect fraud or abuse.
- To send messages you’ve enabled — push notifications, email, and/or WhatsApp (e.g. one-time codes, your results, reminders). You can turn these off in Settings, and every marketing email carries an unsubscribe link.
- To respond to your support requests and for legal/compliance purposes.
Service providers we share data with
We do not sell your personal data. We share the minimum necessary with providers that operate the Service on our behalf, under confidentiality obligations:
- Cloud hosting — stores the Service’s data.
- Google — verifies your identity when you choose Google sign-in.
- Expo — delivers push notifications to your device.
- Email provider — sends transactional and notification email to your address (and reports bounces/complaints so we stop emailing invalid addresses).
- WhatsApp — when you opt in, we send your phone number and the message text (e.g. codes, results, reminders) to deliver WhatsApp messages.
- Cloudflare Turnstile — an anti-bot check on sign-up and password reset that receives your IP address and a challenge token (no learning data).
- Error monitoring (Sentry) — receives diagnostic crash/error reports (not your content).
- With a partner institution only when you explicitly opt in — e.g. tapping “I’m Interested” on a partner promotion shares your name and contact with that partner so they can reach you. If you don’t tap it, nothing is shared.
- When required by law, or to protect the rights and safety of our users.
Data security & storage
All data is encrypted in transit using HTTPS. Authentication tokens are kept in your device’s secure storage (Keychain/Keystore). Two-factor (authenticator) secrets for staff accounts are encrypted at rest. We apply access controls and retain data only as long as needed for the purposes above.
How long we keep your data
- Account and learning data: for as long as your account is active.
- Message delivery logs: automatically purged after 90 days.
- After you request deletion: personal data is anonymized after a 30-day grace period (see below).
Export your data
You can download a copy of the personal data we hold for you at any time from Profile → Account → Export data (web) or Profile & settings → Account → Export my data (mobile). The export is a JSON file containing your account details, profile, study preferences, a summary of your activity (tests taken, practice sets completed, questions reviewed, topics covered), and recent sign-ins.
Deleting your account & data
You can delete your account at any time from Profile → Danger zone → Delete account in the mobile app, or Profile → Account → Delete account on the web. Your account is deactivated immediately, push tokens are removed right away, and your personal information is permanently anonymized after a 30-day grace period. Anonymized, non-identifying statistics may be retained. See our account deletion page for details, or email privacy@gnepal.org if you cannot access your account.
Your rights
You can access and update your profile in Settings, export your data, and delete your account, all from within the app. For any other request, contact privacy@gnepal.org.
Children’s privacy
The Service is intended for entrance-exam aspirants and is not directed to children under 13. If you are a minor, you may use the Service only with the involvement and consent of a parent or guardian.
Data Safety summary
For quick reference (and to mirror the Google Play Data Safety form), here is what we collect and why. We do not sell data and do not use it for third-party advertising.
- Personal info (name, email, phone) — collected; shared only with the providers above; for account, sign-in, and communications.
- Learning & app activity (answers, results, progress, usage events) — collected; not shared; to provide and improve the Service.
- App info & performance (crash/diagnostic logs) — collected; shared with our error-monitoring provider; for stability.
- Device identifiers (push token) — collected; shared with Expo; to send notifications.
- Security data (IP address, user-agent, sign-in events) — collected; not shared; for account security and fraud prevention.
- Purchases (plan purchased) — collected; not shared; to grant premium access. Encrypted in transit. You can request deletion.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, an in-app notice.
Contact us
Questions about this policy, or to make a data request? Email privacy@gnepal.org.