Most people preparing for JEE, NEET, CLAT or NDA are 15 to 18 years old. Under the Digital Personal Data Protection Act 2023, anyone under 18 is a child, and their data carries stricter protection. We would rather over-explain this than bury it in the main privacy policy.
This page is written for parents and guardians as much as for students.
01Who this applies to
Anyone under 18. We ask for date of birth at sign-up to identify these accounts — not as a formality, but because it determines how the account is treated. Please give it accurately.
02Parental consent
Where a user is under 18, we are required to obtain verifiable consent from a parent or legal guardian before processing their personal data.
Rule 10 of the DPDP Rules permits verifying that the consenting adult is genuinely an adult using a virtual token issued by an authorised entity — and names DigiLocker as one. We already use DigiLocker for identity verification, so the same rail can confirm a parent’s age without us collecting or storing identity documents.
The consent flow works like this: when an account is created for someone under 18, the student adds a parent or guardian’s email and mobile number. The guardian receives a request describing exactly what data will be processed and why, and confirms their own adulthood through the DigiLocker age token — we never see or store their identity documents. Only after that confirmation is the child’s account activated, and we record the consent (who consented, for what, and when) so it can be reviewed or withdrawn later.
This flow is designed and documented, but not yet live in production. Until it is, we do not knowingly onboard users under 18 without a guardian present.
03What we will never do with a child's data
Section 9(3) of the DPDP Act prohibits these outright, and we would not do them regardless:
- No behavioural tracking for advertising or profiling.
- No targeted advertising. We do not run third-party ad networks anywhere on the service.
- No selling or sharing a child’s data with data brokers or marketers.
- No detrimental processing — nothing likely to have a harmful effect on the child’s wellbeing.
To be clear about one thing that might look similar: the adaptive engine adjusts question difficulty from answers within the service, to teach. That is the educational function the student came for. It is not advertising profiling and the data does not leave us.
04Your child's public handle
Every account on EByAi carries a username — a handle like @swift_falcon_a3f9that other students see. We generate it when the account is created, from two neutral words and a few characters derived from the account’s internal id — neverfrom your child’s name, date of birth, school or city. It is the identity shown on the leaderboard, on their profile and on everything they post.
There is no anonymous posting, and we want you to know that before your child asks their first doubt rather than after. A question posted into a community feature carries the handle. That is deliberate: it is what lets us act on harassment, and what stops one person running several accounts to distort the ranking.
Measured against the no detrimental processing standard above, what matters is that the handle cannot follow a child off the platform, or become a label for having found something hard. So a handle is never used in an email or SMS we send, never printed on a payment receipt, never attached to identity verification, and never usable to sign in. Classmates can see it — that is what a leaderboard is — so if the handle your child has chosen would identify them offline, change it.
05What a parent or guardian can do
- See what we hold about your child.
- Correct anything inaccurate.
- Change the username — if the handle identifies your child, or is being used to needle them, write to us and we will change it. We will not make you wait out the 30-day limit that normally applies to a change.
- Delete the account and its data.
- Withdraw consent at any time — withdrawal is as easy as giving it, and processing stops.
- Ask questions about anything on this page.
06Payments made by a minor
A paid plan should be bought by a parent or guardian, who is responsible for the payment. If a payment was made from an under-18 account without a guardian’s knowledge, contact us and we will look at it sympathetically — notwithstanding the general no-refund-after-activation rule in the refund policy.
07Contact us about a child's account
- Email: hr@aashita.ai — mark it “Child account”
- Grievance officer: Sunny Dhalia, cto@aashita.ai
- Phone: +91 92160 63146
Acknowledged within 48 hours, resolved within one month.
08Compliance status — stated plainly
The DPDP Rules were notified on 13 November 2025, with full compliance required by 13 May 2027. We are building toward that date rather than waiting for it.
Where a control is not yet live, this page says so rather than implying otherwise. The parental-consent verification flow described above is designed but not yet in production, and we say so there.