Koshish collects only what is needed to support study planning, account access, practice, revision, and learner progress.
Last updated: 23 September 2026
Your mobile number, email if you connect one, your chosen exam and profile details, and analytics on the questions you attempt. For account security we also record the device label, browser and IP address you sign in with, plus your consent choices and any grievance you file. That is all the plan needs to work.
We never sell your personal data. Mobile number, identity, account data and learning history stay private and are not used as public marketing proof.
An HttpOnly session cookie keeps you signed in, a CSRF token protects state-changing requests, and a cookie mirrors your analytics choice. Once you're signed in, consent is kept on our servers as a versioned, append-only record — the cookie is only a local copy. Analytics needs your consent in the EEA and UK, where we ask before anything loads. Elsewhere — including India — analytics run by default because no consent is required there, and you can switch them off at any time from Cookie settings in the footer or Profile → Security; a choice you make always wins over that default. If your browser sends the Global Privacy Control signal, we treat analytics as off until you say otherwise, whatever the default would have been. Analytics means Google Analytics (through Google Tag Manager), Cloudflare Web Analytics, PostHog, and Sentry error reports — that is the complete list of what receives data with your consent on.
Your data is kept until you delete your account. Deletion is a 30-day process: your account is deactivated immediately (you can't sign in and your active sessions end), then a nightly job permanently removes your profile and learning records across our services. It can't be cancelled during that window. A few records are kept on purpose — your consent history (proof of what you authorised), security and audit events, and any grievance you filed. Audit rows hold no learning content such as answers or notes, and once your account is purged the deletion is recorded against a one-way hash of your ID rather than the ID itself.
Access, a copy of, correct, or delete your personal data any time from Profile → Security (Download your data / Delete account). Endpoints: GET /api/v1/users/me/export and POST /api/v1/users/me/delete. Your export bundles your profile, consents, sessions, notifications and learning records from each service. You may also change or withdraw analytics consent yourself from Cookie settings in the footer or Profile → Security → Manage consent — withdrawing is as easy as allowing, takes effect immediately, and is recorded server-side with its version and date, so it holds on every device you sign in from. Each choice is kept in your consent history.
Koshish is built for exam aspirants. At sign-up everyone confirms an age band — 'I am 18 or older', or 'I am under 18; a parent or guardian will review setup with me' — and accepts the current Terms version. This is a self-attestation, not a verified date of birth. Under-18 users should use Koshish with a parent or guardian's guidance, and a guardian may ask us to delete a minor's account through the grievance contact below.
Koshish runs on cloud infrastructure we manage, and by default we do not commit to keeping your account and learning data in any particular country. Our analytics and error-reporting providers process that data outside India — currently in the United States and EU — under their own data-processing terms, which is why those transfers are listed here rather than left implied. What we do commit: we never sell your personal data or use it for advertising, and analytics run on consent in the EEA/UK and by default elsewhere, switchable off from Cookie settings or Profile → Security. If your institute needs data kept in a specific region, that can be agreed in writing as part of an institutional plan.
Grievance Officer: not yet appointed. When an officer is on file their name and contact are published on our Grievance Officer page (/grievance-officer); until then we won't print unverified details. The quickest route is the in-app grievance form (/grievance): it records your complaint immediately and returns a reference number and a resolution due date 30 days out. The officer email is published on that page when appointed; until then we do not print an unverified address. We don't send automated status emails yet, so your reference number is your tracking handle inside the app.
Koshish asks for learning details only when they support setup, planning, practice, revision, or account safety.
Student progress should be shown to the student, not converted into unsupported public counters or social proof.
Account access, OTP flows, and sign-out actions stay inside the authenticated app experience.
Learning activity powers daily recommendations, weak-topic repair, and revision reminders — and nothing else.
These terms and this policy are governed by the laws of India, including the Digital Personal Data Protection Act, 2023.