Tapasya

Privacy policy

What Tapasya keeps, where it is kept, who can see it, and how to have it removed.

Effective date: 11-10-2026Last revised: 11-10-2026

This Privacy Policy describes how personal data is collected, used, stored, disclosed and otherwise processed in connection with Tapasya (the "App"), including its Windows application, its Android application and any related services, servers, web pages and communications (together, the "Service"). The Service is operated by Arth Laddha ("we", "us", "our" or the "Operator"), who acts as the data fiduciary for the purposes of the Digital Personal Data Protection Act, 2023 and the rules made under it ("DPDP Act"). In this Policy, "you" and "your" mean any individual who installs, accesses or uses the Service.

By creating an account, installing or using the Service, you acknowledge that you have read this Policy. Where consent is the basis for processing, you are asked for it in the App, and you may withdraw it as described in Section 11.

1. Scope

1.1 This Policy applies to personal data processed through the Service. It does not apply to third-party applications, websites or services that you choose to open, link to or use alongside the Service, including any application you allow during a strict session, which are governed by their own terms and policies.

1.2 Certain features described in this Policy (including the Android application, strict mode, phone usage data, push notifications and synchronisation between devices) may not be available in every version of the App. The provisions relating to a feature apply only when, and to the extent that, the feature is available in the version you use.

2. Definitions

2.1 "Account Data" means the data described in Section 3.1. "Device" means a computer, phone or tablet on which the App is installed. "Local Data" means data stored only on your Device. "Server" means the hosted database and authentication service used by the Service, described in Section 7. "Day Summary" means the summary described in Section 3.4. "Strict Session" means a focus session in which access to applications not permitted by you is restricted, as described in Section 3.6. "Administrator" means the Operator acting in the capacity of administrator of the Service.

3. Personal data we process

3.1 Account Data. When you create or use an account: your email address; the first name you provide; the identifier generated for you (the "TAP Code"); the date and time your account was created; whether your account is approved or blocked; the date and time of your App's most recent check with the Server; the version of the App you use; and the one-time sign-in codes and session tokens issued by the authentication service.

3.2 Device Data. For each Device on which you sign in: a randomly generated identifier created by the App for that Device; the Device's name as set in its operating system (for example, the computer name); the version of the App installed on it; and the dates and times the Device was first and last seen by the Server. On Android, where you permit notifications from the Server, a push notification token issued by Google for that Device.

3.3 Study Data (Local Data). The information you enter or generate in the App, including: your examination details, papers, chapters and sub-topics; study blocks and their times, papers, chapters, types, ratings and notes; time recorded as not studying; plans, plan items and their progress; revision records; tests, marks and mistakes; doubts; rest days; targets and settings; your stated reasons for studying; motivational lines you add; and records of focus sessions, including pauses. Study Data is stored on your Device. Except as stated in Sections 3.4 and 3.8, it is not transmitted to the Server.

3.4 Day Summary. Unless you switch off the setting "Share my day", the App transmits to the Server, at intervals and whenever the day changes, a Day Summary consisting of: the date; the number of seconds studied that day; your daily target in seconds; whether the day is a rest day; your current streak; the state of each of the last seven days; the time studied that day for each paper (by paper code and colour); the number of study entries made that day; whether the focus timer is paused; and, while the focus timer is running, the paper code and colour, the time the session started and a periodic signal that the session is still active. The Day Summary does not include chapter names, notes, the activity log, test marks, mistakes, doubts, strict-mode attempts or broken locks.

3.5 Daily History. For each day on which a Day Summary is received, the Server retains one record containing the date, the seconds studied, the daily target and the number of study entries, for up to 400 days (see Section 9).

3.6 Strict Session Data. During a Strict Session, the App processes: the list of applications (on Windows, programs) you have permitted, and any list of websites you have chosen to block or to allow; the identity of each application that has a window on the screen of your Device (on Android, its package name; on Windows, the program name and title of the window in front), when the windows change and about once a second, in order to determine whether it is permitted; where you have set a rule for websites, the web address shown in the address bar of a browser you have permitted while it is in front, in order to determine whether that website is permitted (the address is not stored; only the name of a website that was not permitted is recorded as an attempt); the number and times of attempts to open applications or websites that are not permitted, and their names; and any period within a Strict Session during which the restriction was not in effect, with its times and the apparent reason (a "broken lock"). To recognise such a period the App also notes, during a Strict Session only, whether the screen is on, how many times the Device has been started, whether its accessibility service is enabled (on Android), whether the Device's clock was moved forward (on Windows, using the time reported by the Server and the time since the Device was started), and whether the App was running. This information is Local Data. It is not included in the Day Summary, is not synchronised, is not shown to other users and is not shown to the Administrator through the Service.

3.7 Activity Data (Local Data).

(a) On Windows. To detect periods of study and inactivity, the App reads: the time since the keyboard or mouse was last used; whether audio is playing; whether the window in front is in full-screen mode; whether the computer is locked; and, once a minute (and, during a Strict Session, once a second), the program name and title of the window in front. During a Strict Session with a rule for websites, the App also reads the address bar of a browser you have permitted, as described in Section 3.6. The App does not take screenshots, does not record keystrokes and does not record the content of windows. Private or incognito browser windows and applications you exclude are not recorded in the window log.

(b) On Android. Where you grant usage access, the App reads from the operating system how long each application was in the foreground on each day (not what the application showed), and keeps one figure per application and day, to show your screen time and the time spent in applications you mark as distractions. To enforce Strict Sessions, the App uses the Android Accessibility Service solely to identify the application in the foreground and, where you have set a rule for websites, the web address in the address bar of a browser you have permitted, as described in Section 3.6; it does not read any other content of the screen, text you type or the contents of other applications, and it does nothing outside a Strict Session. The App asks you to enable that service only after describing this use to you in the App and obtaining your agreement there. To list the applications you may permit, the App reads the list of launchable applications installed on your Device. Where you enable "uninstall protection", the App is registered as a device administrator application without any administrator policy, solely so that it cannot be removed or force-stopped during a Strict Session; it does not use that status to erase, lock or change anything on your Device, and you can disable it in the App or in the Device's settings. Where you grant the permission and switch the setting on, the App switches Do Not Disturb on at the start of a Strict Session (if it was off) and back off at its end. To show the notifications described in Section 6.1, the App asks the operating system to start it in the background about every half hour and works out on your Device, from your own Study Data, whether a notification is due.

Activity Data is Local Data, except to the extent it is included in synchronised data under Section 3.8.

3.8 Synchronised Data. Where synchronisation between your Devices is available and you are signed in, copies of your Study Data are transmitted to and stored on the Server, associated with your account, so that they are available on each of your Devices. The following are not synchronised and remain Local Data on the Device on which they were made, unless you are told otherwise in the App before it is enabled: Strict Session Data; Android usage data (screen time); the Windows activity log; and settings that describe a Device rather than you (for example the applications you allow in Strict Sessions, notification settings and the applications you mark as distractions).

3.9 Social Data. Friend requests you send and receive, the TAP Codes involved, whether a request was accepted, and the dates and times of these actions.

3.10 Administrator Notes. The Administrator may record a private note about your account. The note is visible only to the Administrator.

3.11 Communications. If you write to us, your email address and the contents of your message, and any reply.

3.12 Diagnostic Data (Local Data). Log files recording the App's operation and errors, stored on your Device. They are transmitted to us only if you choose to send them.

4. Purposes of processing

4.1 We process personal data to: create and maintain your account and verify your identity at sign-in; control access to the Service, including approval, blocking, the number of Devices per account and minimum supported versions; provide the App's functions, including recording, analysing and planning your study; enforce Strict Sessions you start; show your Day Summary to the persons described in Section 5; send notifications you have enabled; synchronise your data between your Devices where available; inform you of new versions; respond to your communications; maintain the security, integrity and proper functioning of the Service, diagnose faults and prevent misuse; administer the Service, including understanding how and by whom it is used; and comply with applicable law.

4.2 We process personal data on the basis of your consent, given in the App, and for the legitimate uses permitted by the DPDP Act, including where you have voluntarily provided the data for a specified purpose and have not indicated that you do not consent to its use.

4.3 We do not sell personal data. We do not use personal data for advertising. We do not use personal data for automated decisions producing legal or similarly significant effects on you.

5. Who can see your data

5.1 You. You can see your own data in the App.

5.2 Friends. A user whose friend request you have accepted, or who has accepted yours, can see your first name, your TAP Code and, while "Share my day" is on, your Day Summary. If "Share my day" is off, they see that you are not sharing your day.

5.3 The Administrator. In administering the Service, the Administrator can see, for every account: the Account Data; the Device Data (other than push tokens); the number of friends; the private note, if any; and, while "Share my day" is on, the Day Summary and the Daily History, including rankings of users by hours studied, days studied and number of entries over periods of up to 30 days. The Administrator can export this information. The Administrator can approve, block and delete accounts. The Administrator's view of the Day Summary and Daily History is subject to the same "Share my day" setting as that of friends. In addition, as the operator of the Server, the Administrator has technical access to all data stored on the Server, including Synchronised Data, but does not access Synchronised Data except where necessary to operate, secure, maintain or repair the Service, to respond to a request from you, or to comply with law.

5.4 Service providers. The persons listed in Section 7, to the extent necessary for them to provide their services.

5.5 Legal disclosures. We may disclose personal data where required by law, court order or a lawful request of a government authority, or where reasonably necessary to protect the rights, safety or property of any person.

5.6 Transfer of the Service. If the Service, or its operation, is transferred to another person, personal data may be transferred to that person, who will be bound by this Policy or will give you notice of any change.

6. Notifications and communications

6.1 The App may display notifications on your Device, including reminders to record study, focus timer status, the end of a focus round, revisions due, targets, evening notes, milestones and notices of new versions. These are worked out on your Device from your own data; except where push notifications are described in Section 3.2, they are not sent from the Server. You can disable each of them in the App (on Android, under Notifications) or all of them in your Device's settings.

6.2 Sign-in codes are sent to your email address. We do not send marketing emails.

7. Service providers and international transfer

7.1 The Service uses the following service providers, each of which processes personal data on our behalf or as an independent controller under its own terms:

(a) Supabase, Inc. — hosting of the Server database and authentication; (b) Google LLC and its affiliates — sending of sign-in emails (Gmail), distribution of the Android application (Google Play), push notifications (Firebase Cloud Messaging), and the Android operating system services the App relies on; (c) GitHub, Inc. — storage of the App's source code and building of the App, and, where used, hosting of download pages and this Policy; (d) any provider used to host the download files for the App, as named on the download page.

7.2 Servers of these providers may be located outside India. By using the Service you acknowledge that your personal data may be transferred to and processed in such countries, subject to any restrictions notified by the Government of India under the DPDP Act.

8. Security

8.1 We take reasonable security safeguards to protect personal data, including: restricting the Server's tables so that they can be read and written only through functions that check the identity and permissions of the person asking; encrypting your stored sign-in on Windows using the operating system's data protection; restricting the App's local web server to your own Device, with a secret that changes at each start; keeping Local Data on your Device; and not transmitting Strict Session Data, screen time or web addresses read during a Strict Session.

8.2 No method of transmission or storage is completely secure. Local Data is as secure as your Device. In the event of a personal data breach, we will notify the Data Protection Board of India and affected users as required by the DPDP Act.

9. Retention

9.1 Account Data, Device Data, Social Data and Administrator Notes are retained while your account exists. A Device's record is removed when you sign out on it, when it is replaced by another Device, or when your account is deleted.

9.2 Only the most recent Day Summary is retained. It is deleted when you switch off "Share my day".

9.3 Daily History records are deleted after 400 days, and all your Daily History records are deleted when you switch off "Share my day".

9.4 Synchronised Data is retained while your account exists.

9.5 Upon deletion of your account, the data described in Sections 9.1 to 9.4 is deleted from the Server, except as required to be retained by law. Backups maintained by our service providers may persist for the period of their own backup cycles.

9.6 Local Data remains on your Device until you delete it or uninstall the App. On Windows, uninstalling the App does not delete Local Data or the App's daily backups, which remain in your user data folder until you delete them.

9.7 Communications are retained for as long as reasonably necessary to deal with them.

10. Children

The Service is not intended for persons under the age of 18. We do not knowingly process the personal data of a child. If you are under 18, do not create an account. If we learn that an account belongs to a person under 18, we will delete it unless verifiable consent of a parent or lawful guardian has been obtained in the manner required by law.

11. Your rights and choices

11.1 Subject to the DPDP Act, you have the right to: obtain a summary of the personal data we process about you and the processing activities; obtain the identities of the persons with whom it has been shared and a description of the data shared; have inaccurate or incomplete data corrected, completed or updated; have your personal data erased, unless retention is necessary for a specified purpose or required by law; withdraw consent at any time, without affecting processing that took place before withdrawal; nominate another individual to exercise these rights in the event of your death or incapacity; and have readily available means of grievance redressal.

11.2 You can exercise some of these rights directly in the App, including: switching "Share my day" off; removing friends; signing out of a Device; disabling notifications; withdrawing the permissions described in Section 3.7(b) in your Device's settings (which disables the related features); marking or unmarking applications as distractions; and deleting your account (in Settings, Account), which deletes from the Server the data described in Section 9.5. Withdrawing consent to processing that is necessary for the Service may mean that the Service, or parts of it, can no longer be provided to you.

11.3 To exercise any other right, or to request deletion of your account where this is not available in the App, write to the address in Section 14 from the email address associated with your account. We may need to verify your identity. We will respond within the period required by law.

11.4 If you are not satisfied with our response to a grievance, you may approach the Data Protection Board of India after exhausting the grievance procedure described above.

12. Third-party applications during Strict Sessions

Applications you permit during a Strict Session continue to operate under their own terms and privacy policies. The App does not collect data from within those applications.

13. Changes to this Policy

We may revise this Policy from time to time. The revised Policy takes effect on the date stated at its top. Where a revision materially changes how we process personal data, we will give notice in the App before it takes effect and, where required, seek your consent again. Your continued use of the Service after a revision takes effect constitutes acknowledgement of the revised Policy.

14. Contact

For any question, request or grievance concerning this Policy or your personal data:

Arth Laddha Email: tapasyastudyapp@gmail.com

15. Governing law

This Policy is governed by the laws of India.