Privacy notice
The short version: we don’t ask who you are. No account, no login, no upload, no AI chatbot reading your child’s work. Here is exactly what that means, and your rights under India’s Digital Personal Data Protection Act 2023.
Version 2.0 · 2026-07-14
1. Data fiduciary 2. What we collect 3. How we use it 4. Legal basis 5. Children 6. Sharing 7. Cross-border 8. Security 9. Retention 10. Your rights 11. Grievance officer 12. Changes
1. Who is the data fiduciary
Vaaani is operated as a sole proprietorship by Neil Shankar Ray, an independent EdTech builder based in Kolkata, West Bengal, India — the controller of any personal data processed through this service. Contact details for the named grievance officer are in §11.
2. What we collect
We deliberately collect no accounts and nothing that identifies a person. Concretely:
On your device (in the browser)
- A random, anonymous learner id (e.g.
guest_a1b2c3) held in your browser’s local storage. It is not linked to any name, email, or phone. - Your chosen home language (e.g. Bengali), so the app can bridge from it.
Clearing your browser storage removes this id and detaches you from the learning progress it points to.
On our engine (to run the learning twin)
- That anonymous id and your learning interactions — which lessons you were shown, your self-marked outcomes ("I did it" / "tricky" / "not yet"), and tap answers.
- The per-skill belief state ("cognitive twin") the engine builds from those interactions, so lessons continue where you left off.
Voice — only if you use the microphone
- When a learner taps "Say it", the short recording is sent to our engine to measure which sounds were produced. We use it for that measurement only — not to identify anyone, not to build a voice profile, and not to train any model.
Automatically
- Standard server request logs (IP address, timestamp, path), kept briefly for security and reliability.
- No advertising or analytics trackers. No third-party analytics scripts run on this site, and we set no tracking cookies.
We do not collect: names, email addresses, passwords, phone numbers, dates of birth, uploaded documents, or chatbot conversations — because the product does not use any of those.
3. How we use it
- To build and run each learner’s private cognitive twin — to choose the next lesson and show you the reason for the choice.
- To measure pronunciation from a voice clip, when the microphone is used, and turn it into per-sound feedback.
- To keep the service healthy and prevent abuse (server logs).
We do not use your data to train any AI model, we do not sell it, and we do not share it with advertisers or analytics brokers. There is no large language model in the teaching decision — the engine is a transparent, symbolic model whose reasoning it can show you.
4. Legal basis (DPDP §6, §7)
- Consent (§6) — for processing the anonymous learning interactions and any voice clip you choose to record. You give it by choosing to use the feature; you can stop at any time.
- Data minimisation — our primary safeguard is collecting no identifying data in the first place.
5. Children’s data (DPDP §9)
Vaaani is built for children, and we treat that seriously:
- We create no account and collect no identifying data about a child — the learner id is random and anonymous, so we hold nothing that names or locates a specific child.
- We do not profile children for advertising or track behaviour across sites. The only per-child model is the learning twin intrinsic to teaching, and it lives against an anonymous id.
- The one potentially personal input is a voice recording, and only if the child chooses to use the microphone. Schools and guardians should obtain appropriate consent before a child uses the microphone feature; the rest of the app works fully without it.
Caveat: the final DPDP Rules (yet to be notified by MeitY as of this version’s date) may set specific verifiable-consent mechanisms for children. Because we collect no identifying data or accounts, much of that machinery is not triggered; we will adapt promptly if the Rules require more, and will update this notice.
6. Who processes data for us
- Google Cloud Platform — runs the Vaaani engine and stores the learning-twin database, in the asia-south1 (Mumbai), India region.
- Vercel — serves the website and securely routes app requests to the engine. Vercel is a US company with a global edge network; traffic passes through it encrypted (TLS) in transit.
- Google (Gmail) — only relevant if you email us (for example a pilot enquiry via the Contact link); that message lands in our Gmail inbox. There is no contact form that stores data on a server.
We do not send data to any large-language-model provider, and we do not share data with advertising or analytics services.
7. Cross-border transfer (DPDP §16)
The learning-twin data and voice processing happen and are stored in India (Google Cloud, Mumbai). The website and request routing use Vercel, a US provider whose global network may carry encrypted traffic through servers outside India while in transit. No learner data is sent to any AI/LLM provider, and none is sent to China. India’s DPDP framework permits cross-border transfer to countries not on a Negative List notified by the Central Government.
8. Security
- HTTPS everywhere (TLS 1.2+).
- No passwords are collected or stored — there are no accounts.
- Database access is restricted to the application process on the India server.
- A backup is taken before each production deploy.
No system is perfectly secure. If you suspect a problem, please email the grievance officer (§11) immediately.
9. Retention
- Learning twin (anonymous): kept so lessons stay continuous. You can clear your browser storage to detach from it, or ask us to delete a twin by emailing the grievance officer with your device id.
- Voice clips: used to compute per-sound outcomes; we do not build or keep a voice profile.
- Server logs: kept briefly for security and reliability, then discarded.
10. Your rights (DPDP §11–§14)
Because we hold no account, you exercise your rights by emailing the grievance officer (§11) and quoting your anonymous device id:
- Access (§11) — ask what the twin holds against your id.
- Correction & erasure (§12) — ask us to delete the twin tied to your id; clearing your browser storage also detaches you immediately.
- Nominate (§14) — nominate a successor data principal in case of death or incapacity.
- Grievance redressal (§13) — email the grievance officer; we respond within seven working days.
- Withdraw consent (§6(4)) — stop using the feature, clear your storage, or email us.
Neil Shankar Ray
Email: iamanushka32@gmail.com
Postal: C/o Mrs. Chinu Ray, 55/1, Jubilee Park, Tollygunge, Kolkata-33, West Bengal, India
Response SLA: seven working days. If unresolved, you may approach the Data Protection Board of India once it is operational under DPDP §18.
12. Changes to this notice
We will update this notice when our processing changes, when DPDP Rules are notified, or when the lawyer review completes. The version number and date at the top of this page change whenever we publish revisions.