This page is the written notice required under section 29(3) of the Aadhaar Act, which obliges us to inform you at the time of collection exactly how identity information will be used. It describes what happens if you verify your identity through DigiLocker.
Identity verification is currently switched off in production. Nothing described here is running today. The page is published in advance so it can be reviewed before the feature is enabled.
01Why we verify identity at all
One person, one account. Verification exists to stop a single person creating many accounts to farm free-tier limits, trial allowances or leaderboard position — which would make the ranking meaningless for everyone else.
It is required only before certain paid purchases. You never need to verify your identity to use the free trial or practise past-year questions.
02How it works
We use DigiLocker, the Government of India’s document wallet. The flow is:
- You choose to verify, and are sent to DigiLocker’s own site to sign in.
- You authenticate there. We never see your DigiLocker password or your Aadhaar OTP.
- DigiLocker asks you to consent to sharing specific details with us.
- If you consent, DigiLocker returns those details and you come back to EByAi.
You can stop at any point. If you decline, nothing is shared and nothing is stored.
03What we receive
- Your name as held by DigiLocker
- A stable identifier for your DigiLocker account
- Confirmation that verification succeeded
04What we store — and what we do not
We store:
- A flag that your account is verified, and the date
- An irreversible keyed hash of the identifier, used only to detect that the same person has already registered
We do not store:
- Your Aadhaar number. Not in any form we can read back.
- Any image or scan of an Aadhaar card or other document
- Your DigiLocker credentials
- Your biometrics — we never receive them, and could not
The hash is one-way: it lets us answer “has this person registered before?” without being able to recover the underlying number.
05What we use it for
Only this:
- To confirm one account per person before a paid purchase
- To display a verified badge on your profile
We do not use identity data for advertising, profiling, credit assessment, or any purpose beyond those stated. We do not sell or share it. Section 29(3) of the Aadhaar Act restricts use to purposes disclosed in writing at collection — this page is that disclosure.
Your verified name is never shown to other students. The name DigiLocker returns is your legal name. It is displayed back to you on your own profile screen, and is available to the few staff who handle verification problems. It is not on the leaderboard, not on your posts or answers, not on a profile another student can open, and not in a mention. The identity other people on EByAi see is your username — a handle you choose and can change — and never the name on your Aadhaar. The badge, wherever it is shown, says only that verification succeeded; it never carries the name.
06The one-account rule
If verification shows an identity already linked to another EByAi account, the new verification is refused. You may still use the free trial. If you believe this is a mistake — a shared device, or a family member — contact us and a person will look at it.
07Deleting your verification
Email hr@aashita.ai and we will remove the verification flag and the stored hash. Your account stays; the verified badge and any verification-gated purchases will not be available until you verify again. See also your rights under the privacy policy.
08If you are under 18
Identity verification and paid purchases should be handled by a parent or guardian. DigiLocker verification may also be used to confirm that a consenting adult is an adult, as permitted by Rule 10 of the DPDP Rules — see Children’s Privacy.
09Status and review
Identity verification is enabled only where a purchase or feature legally requires it. The identifier-hashing design described here — storing a keyed hash rather than the raw identifier — is documented publicly and is subject to legal review before it is relied on for any new verification-gated feature.
We have deliberately designed this to hold as little as possible, and we are stating the design publicly so it can be checked. If you believe something here is wrong, please tell us: hr@aashita.ai.