Privacy Policy
PrepDr (“we”, “us”, “our”) is operated by Bommalapurada Puneetha Reddy, an individual based in Bengaluru, Karnataka, India. This Privacy Policy explains what personal data we collect when you use PrepDr, why we collect it, how we use and share it, and the rights you have under the Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Who is the Data Fiduciary
For the purposes of the DPDP Act, the Data Fiduciary is Bommalapurada Puneetha Reddy, an individual operating under the trade name PrepDr. Our place of business is Bengaluru, Karnataka, India. Contact details are listed in Section 11 below and on our Contact page.
2. Personal data we collect
We only collect data that helps us provide and improve the service. The categories are:
Account data (collected at sign-up and sign-in)
- Email address, taken from your Google account when you sign up with “Continue with Google”. Google verifies that the address is yours; we never ask you to type it, and it is the address every receipt and account notice goes to.
- Phone number, verified by a one-time password (OTP) sent over SMS. Signing up requires both: the Google account proves who you are, the number keeps the account uniquely yours and reaches you about receipts and recovery. Never marketing.
- Your name and study details — the name you type for yourself, your board, specialty, college and year, collected in the last step of sign-up so we hand you the right papers.
- A session cookie that keeps you logged in across pages.
Profile data (collected during onboarding)
- Medical college or institution, year of study, specialty of interest.
- Optional preference responses (e.g., perceived value of the product) used to prioritize what we build.
Usage data (generated as you use the app)
- Pages you open, time spent on each page, search queries, click events, bookmarks, notes, drawings, and feedback you submit on answers.
- Daily reading-time totals and study-streak history that power your personal Stats page.
Device and connection data
- Browser user-agent string, online/offline status, and approximate location (city / country level) inferred from your IP address.
- Theme preference (light / dark), stored locally in your browser via
localStorage. - A persistent device identifier (an opaque random UUID under the key
prepdr_device_uuid) stored in your browser’slocalStorage. We use it only to distinguish browsers on a paid subscription so we can detect unauthorized account sharing. It is not a person identifier, is never combined with third-party data, and is reset if you clear browser storage. - A device fingerprint consisting of screen dimensions, device pixel ratio, browser timezone, language preference, and the platform string reported by your browser. We use it only to corroborate the device identifier above for the same anti-sharing purpose; we do not use it for advertising or cross-site tracking.
Payment data (only if you make a payment)
- We do not store your card number, UPI ID, or banking credentials. All payments are processed directly by our payment processor (Razorpay), and we receive only a transaction reference, the amount, and the payment status.
3. Why we collect it
We use your personal data only for the following specific, lawful purposes:
- To provide the service: create and maintain your account, render personalized pages, save your bookmarks/notes, sync data across your devices.
- To improve the service: understand which content is helpful, find bugs, prioritize new features, and measure engagement quality.
- To communicate with you: service notifications, replies to your support emails, and occasional product updates.
- To process payments when you choose to subscribe to a paid tier.
- To protect paid subscriptions from unauthorized account sharing, by detecting concurrent sessions and unusual device counts on a single account using the device identifier and device fingerprint described in §2.
- To comply with applicable law and respond to lawful requests from authorities.
We do not sell your personal data, and we do not use it to build advertising profiles for third parties.
4. Who we share it with
We share data only with Data Processors who help us operate the service, and only the data each one needs:
- Google LLC (Firebase Authentication) — Google sign-in, phone-OTP delivery, SMS verification, and reCAPTCHA bot protection at sign-up and sign-in.
- Google LLC (Cloud Run, Cloud Build, Secret Manager) — hosting infrastructure for the application and operational secrets.
- Google LLC (Google Identity) — the Google account you sign in with, which is how we recognise you and how your account keeps its verified email address.
- Neon Inc. — managed PostgreSQL database for your account, profile, and usage data.
- Razorpay Software Pvt. Ltd. — payment processing (order creation, card / UPI / netbanking acceptance, webhooks). We share only your name, email, phone, and order details with Razorpay; Razorpay handles card/UPI credentials directly.
- Analytics providers — if and when we add product analytics, we will list them here and request your consent where required.
Each processor is bound by its own privacy commitments and processes your data only on our instructions. We may disclose data to law-enforcement or other authorities when we are legally required to do so.
5. Cross-border data transfers
Some of our processors store data outside India. In particular, our database and hosting infrastructure are operated from data centers in the United States. By using PrepDr, you understand that your personal data may be processed and stored outside India, subject to safeguards required under the DPDP Act.
6. How long we keep it
We retain your account and usage data for as long as your account is active. If you ask us to delete your account, we will delete or irreversibly anonymize your personal data within 30 days.
Exception — payment and tax records. Records related to payments (order IDs, payment IDs, amounts, dates, refund history) are retained for up to 8 years to comply with the Indian Income Tax Act and tax-audit requirements. These records are stored separately from your active user data; they survive account deletion but are accessible only for tax / audit / refund purposes and are not used to re-identify you for any other reason.
7. Your rights under the DPDP Act
You have the following rights with respect to your personal data:
- Right to access — request a copy of the personal data we hold about you.
- Right to correction — ask us to correct inaccurate or incomplete data.
- Right to erasure — ask us to delete your personal data, subject to legal-retention exceptions.
- Right to grievance redressal — raise a complaint about how we handle your data.
- Right to nominate — nominate another person to exercise your rights in case of your death or incapacity.
- Right to withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email us at support@prepdr.in from the email address registered with your account. We will respond within 30 days.
8. Cookies and local storage
We use the minimum amount of cookies and local storage needed to make the app work:
- A session cookie that keeps you signed in. It is essential and cannot be turned off without signing out.
- A theme preference stored in your browser’s
localStorageso we remember your light / dark choice. - A device identifier (
prepdr_device_uuid) stored inlocalStoragefor account-sharing detection on paid subscriptions, as described in §2 above. Clearing your browser storage resets it; your next session will then appear to us as a new device. - An offline cache (Service Worker) that lets the app work when you are offline. You can clear it any time from your browser settings.
We do not use third-party advertising or tracking cookies.
9. Children’s data
PrepDr is intended for medical students and professionals. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.
10. Security
We use industry-standard safeguards: HTTPS in transit, encrypted storage at rest, access controls on production systems, and regular reviews of our processors. No system is perfectly secure, and we cannot guarantee absolute security, but we will notify affected users and the Data Protection Board of any personal-data breach as required by the DPDP Act.
11. Grievance Officer and contact
If you have a complaint about how we handle your personal data, please contact our Grievance Officer:
- Grievance Officer: Bommalapurada Puneetha Reddy, operator — PrepDr
- Email: grievance@prepdr.in
- Address: Bengaluru, Karnataka, India
We will acknowledge your complaint within 7 days and resolve it within 30 days. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India under the DPDP Act, 2023.
12. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the current version. For material changes that affect your rights, we will notify you in-app or by email at least 30 days before the change takes effect.