Encryption in transit and at rest
All traffic to and from the platform runs over TLS. Stored account data, ladder state and session records are encrypted at rest by the managed database and object storage services we run on.
Most of what NYGTLYF holds is a record of a student being wrong about things. That is sensitive in a way a shopping history is not, so the handling of it is written out here in specifics rather than in reassurance.
If a category is not on this list, we are not collecting it. There is no location tracking, no contact list access and no microphone or camera requirement.
| Category | What it is and why | Retention |
|---|---|---|
| Account details | Name, email address, class, board and the subjects selected. Used to match explanations to your syllabus and to sign you in. | While the account is open |
| Ladder and mastery state | Which concepts are mastered, flagged or locked, difficulty level reached, and the history of those changes. | While the account is open |
| Doubt text and explanations | What you typed and what the tutor returned. Needed to hold the thread, answer follow ups and locate the sub skill that broke. | 90 days, then reduced to the sub skill signal |
| Practice attempts and working | Answers submitted, working where shown, error classification and time on question. | 12 months, then aggregated to mastery figures |
| Study time | Active minutes on questions and explanations. Idle time is discarded rather than recorded. | While the account is open |
| Technical logs | Sign in events, device and browser type, and error traces. Used for security and for fixing faults. | 30 days |
All traffic to and from the platform runs over TLS. Stored account data, ladder state and session records are encrypted at rest by the managed database and object storage services we run on.
Internal access to production data is role based, granted to the smallest number of people needed to operate the service, and logged. Nobody on the team browses student sessions casually.
Session contents are not exposed to a parent view at the data layer, so there is no setting, escalation or support request that reveals them. It is not a permission we could flip.
Every category of data above has a stated retention period. Doubt text reduces to a sub skill signal after ninety days, so the useful part of the record survives and the transcript does not.
A linked parent account can see concepts mastered, concepts flagged for review, difficulty level reached, active study time, streaks and diagnostic outcomes. It cannot see the text of a doubt, the explanation given, an individual wrong answer, the working behind it, or how long any single question took.
This is enforced where the data is read, not by a checkbox in a settings page. Support cannot retrieve session contents for a parent, an upgrade does not unlock them, and there is no plan on which they become visible.
A privacy promise that depends on a preference is a promise that gets renegotiated. A student would have to trust that nobody with access to the account will change it, that support will refuse a reasonable sounding request, and that a future release will not quietly flip the default.
Removing the capability removes all three of those conversations. It also costs us a feature that some parents would genuinely like, and we think that trade is correct.
None of these are restricted to paid plans, and none of them require a reason.
A student can view every figure held about them, including everything a linked parent account can see. There is no view of a student that is hidden from that student.
Request a machine readable export of account details, ladder state and mastery history. Available on every plan including the free tier.
Class, board, subject list and profile details can be corrected at any time from the account. A corrected class triggers a fresh diagnostic rather than reusing the old placement.
Deletion removes account details, ladder state, session records and practice history. Aggregate figures that cannot identify a student may remain. Technical logs age out on their own thirty day cycle.
A linked parent view can be removed. The student always sees that the link exists while it is active, and sees when it is removed.
Export, correction, deletion and unlinking can all be raised from the account, or in writing through the contact form. Requests are acknowledged and actioned within thirty days.
Raise a data requestWe would rather state this plainly than imply certifications we do not hold. NYGTLYF is operated by Nygtlyf Private Limited, incorporated in India, and processes personal data in that capacity.
If you have found a security issue, please report it through the contact form and mark it as a security report. We will acknowledge it and will not pursue action against good faith research.
Report a security issueThe privacy policy sets out the same ground in legal terms, and the terms of service cover the account relationship. Both are linked in the footer, and neither is written to be unreadable.
Data requests are acknowledged and actioned within thirty days.