Effective Date: September 5, 2026 |
Last Updated: September 5, 2026 |
Entity: Acadmiyum Technologies OPC Private Limited
Google User Data & YouTube API Services Compliance Notice
AcadmyAI connects with Google APIs (Google Sign-In / OAuth 2.0) and YouTube API Services to deliver educational course video lectures and personalized Socratic tutoring. In full adherence to the Google API Services User Data Policy and YouTube API Services Developer Policies:
No Sale & No Unauthorized Sharing: We do NOT sell Google user data, share it with advertising brokers, or transfer it to unauthorized third parties (Section 5).
No AI Model Training on User Data: Google user data is NEVER used to train, retrain, or fine-tune generalized AI/ML models (Section 4).
Strong Security Safeguards: Sensitive data is protected using industry-standard TLS 1.2/1.3 transit encryption, AES-256 rest encryption, role-based access controls, and administrative multi-factor authentication (Section 6).
Clear Retention & 30-Day Deletion: Data is retained strictly during account activity. Users can request total deletion at any time via acadmyaiorg@gmail.com with a guaranteed 30-day purge SLA (Section 7).
This Privacy Policy governs the collection, processing, storage, and transfer of personal data by Acadmiyum Technologies OPC Private Limited ("Company", "we", "us", or "our"), incorporated under the laws of India.
This policy applies to all websites, web applications, mobile applications (Android / Google Play Store), and associated subdomains operated by us, including:
System & Device Metadata: IP address, browser type and version, operating system, device screen resolution, access timestamps, and referring URLs collected for security, error diagnostics, and session stability.
C. Information from Third-Party Identity Providers
When you sign in using Google Sign-In (OAuth 2.0), we receive basic identity information authorized by you via the Google consent screen, as detailed in Section 3 below.
03. Google User Data & YouTube API Services Data
AcadmyAI integrates with Google APIs and YouTube API Services to provide seamless authentication and enriched educational experiences (such as embedding curated lecture videos into course modules).
A. Google OAuth User Data
When you choose to authenticate via Google Sign-In, we access and receive the following data:
Google Unique Identifier (Google sub ID): To uniquely identify and bind your user account across sessions.
Primary Email Address: To verify your account, send transaction receipts, and enable account recovery.
Full Name & Profile Picture: To personalize your in-app profile, teacher dashboard, and student avatar.
B. YouTube API Services Data
AcadmyAI utilizes YouTube API Services to allow educators and students to reference, embed, search, and view relevant educational lecture videos within course modules.
Data Accessed: YouTube public video IDs, video titles, descriptions, video duration, channel names, and thumbnail URLs.
User Viewing State: In-app lesson completion checkpoints (stored in AcadmyAI databases to resume lecture progress).
No Channel Modification: AcadmyAI does not access private YouTube channel settings, upload videos to your YouTube account, or modify your YouTube subscriptions or playlists.
04. How We Use Data & Google Limited Use Compliance
We process collected information solely for the following legitimate purposes:
To authenticate and maintain secure user sessions.
To power conversational Socratic oral examinations and generate context-aware remedial study notes.
To display recommended educational lecture videos inside course outlines.
To compute Knowledge Radar proficiency scores and deliver personalized learning feedback.
To process subscription payments and Cram Pass purchases securely through Razorpay.
To protect the integrity of our systems, prevent fraud, and comply with statutory legal requirements.
Google API Limited Use Disclosure:
AcadmyAI's use and transfer to any other app of information received from Google APIs will adhere to the
Google API Services User Data Policy, including the Limited Use requirements.
Strict Prohibition on AI Model Training
We DO NOT use Google user data to train, fine-tune, or improve generalized Artificial Intelligence (AI) or Machine Learning (ML) models. Any AI processing performed (e.g., generating Socratic questions via large language models) operates strictly in an isolated inference context without retaining user personal identifiable information (PII) or Google user data in model weights or training corpuses.
05. Data Sharing, Transfer, and Disclosure
Acadmiyum Technologies OPC Private Limited maintains a strict Zero-Data-Monetization policy. We do NOT sell, rent, lease, or trade personal data or Google user data to third parties, data brokers, or advertising networks under any circumstances.
With Whom We Share, Transfer, or Disclose Google User Data:
We share, transfer, or disclose Google user data strictly with the following categories of trusted recipients, and only to the extent necessary to deliver the AcadmyAI services:
Recipient / Processor Category
Purpose of Disclosure
Data Categories Disclosed
Security & Contractual Safeguards
Cloud Hosting & Infrastructure Providers (Firebase, Google Cloud Platform, Supabase)
Secure server hosting, database persistence, and user session management.
User ID, email, profile name, avatar URL, session tokens.
Bound by Data Processing Agreements (DPAs), SOC 2 Type II certified, TLS transit & AES-256 rest encryption.
Processing Pro subscriptions and Cram Pass payments.
Billing name, email, transaction identifiers. (Payment card numbers are processed directly by Razorpay under PCI-DSS Level 1 compliance; AcadmyAI never handles raw card data).
Generating real-time oral Socratic questions and transcribing spoken viva answers.
Anonymized audio transcriptions and curriculum prompts. No Google user credentials or profile tokens are transmitted.
Stateless API inference with zero data retention for training.
Legal & Regulatory Authorities (Only upon valid legal compulsion)
Compliance with statutory laws, court orders, subpoenas, or to prevent imminent fraud and security threats.
Only the specific data points legally mandated by court order or law.
Reviewed by legal counsel prior to disclosure; affected users notified where legally permissible.
Additional Sharing Restrictions:
No Third-Party Advertising: Google user data is NEVER disclosed or transferred to advertising networks, re-targeting providers, or data aggregators.
Business Transfers: In the event that Acadmiyum Technologies undergoes a merger, acquisition, reorganization, or sale of assets, user data will continue to be governed by this Privacy Policy, and users will be notified via email before any transfer occurs.
06. Data Protection Mechanisms & Security for Sensitive Data
We implement industry-standard technical, organizational, and physical security measures to protect sensitive personal data and Google user data against unauthorized access, alteration, disclosure, or destruction.
A. Encryption Standards
Encryption in Transit: 100% of network traffic between user browsers/clients and AcadmyAI servers, as well as server-to-server communications with Google and external APIs, is encrypted using modern Transport Layer Security (TLS 1.2 and TLS 1.3) over HTTPS with strict HTTP Strict Transport Security (HSTS).
Encryption at Rest: All database records, user authentication credentials, Google OAuth tokens, and server backups are encrypted at rest using industry-standard AES-256 (Advanced Encryption Standard with 256-bit keys).
B. Access Governance & Least Privilege
Principle of Least Privilege: Internal access to production databases and cloud infrastructure containing Google user data is restricted strictly to authorized engineering personnel who have a documented business requirement.
Multi-Factor Authentication (MFA): All administrative, operational, and database access points mandate hardware-backed or authenticator-based MFA.
Audit Logging: All administrative access and data modification operations are logged in immutable, tamper-evident audit logs monitored for anomalies.
C. Network & Infrastructure Defense
Firewalls & DDoS Mitigation: Our systems reside behind enterprise Web Application Firewalls (WAF) and automated Distributed Denial of Service (DDoS) protection layers to mitigate network-level attacks.
Vulnerability Assessments: Automated dependency scanning and continuous code analysis are integrated into our deployment pipelines to detect and patch security vulnerabilities promptly.
D. Incident Response & Breach Notification
In the unlikely event of a security incident affecting user personal data, we maintain a documented incident response procedure. We will notify affected users and relevant supervisory authorities within 72 hours of becoming aware of a confirmed breach, in accordance with applicable data protection laws.
07. Data Retention and Deletion Policy for Google User Data
We retain personal data and Google user data only for as long as necessary to fulfill the educational purposes for which it was collected, or to comply with statutory legal and accounting obligations.
A. Retention Timeframes
Active Account Data: Google user profile data (Google ID, email, name, avatar) and learning records are retained while your AcadmyAI account remains active.
YouTube API Data Caching: Any cached metadata retrieved via YouTube API Services (e.g., video titles, durations, or thumbnails) is cached locally strictly for performance optimization and is refreshed or purged within 30 calendar days, in full compliance with YouTube API Developer Policies.
Inactive Accounts: Accounts inactive for more than 24 consecutive months are flagged for scheduled archival and subsequent deletion following advance email notification.
B. User Data Deletion Process & SLA
You have the absolute right to request the permanent deletion of your AcadmyAI account and all associated personal and Google user data at any time.
Use the subject line: Data Deletion Request - AcadmyAI
Specify your account email and confirm your intention to delete your profile and all associated data.
Deletion Timeline: Upon identity confirmation, all your personal data, Google account identifiers, viva transcripts, and examination records will be permanently purged from active production databases within thirty (30) calendar days. Data contained in rotating backup archives will be permanently overwritten according to our standard backup lifecycle (within 30 to 90 days).
C. Revoking AcadmyAI Permissions Directly via Google
You do not need our permission or intervention to disconnect AcadmyAI from your Google Account. You can view, manage, and immediately revoke AcadmyAI's access to your Google account at any time by visiting Google's official security portal:
Revoking access via the Google Security page immediately terminates our API authorization and prevents AcadmyAI from obtaining any subsequent data from your Google Account.
08. YouTube API Services Specific Disclosures
AcadmyAI utilizes YouTube API Services to provide educational lecture video recommendations, structured video modules, and lecture embeds. By accessing or using YouTube-enabled features within AcadmyAI, you acknowledge and agree that:
YouTube videos embedded within AcadmyAI utilize YouTube's official iframe player API, which may place cookies or gather technical playback metrics according to Google's standard privacy policies.
We use essential cookies and browser local storage strictly for functional application performance:
Authentication Tokens: Secure HTTP-only cookies or encrypted local storage keys to maintain login sessions across page navigations.
User Interface Preferences: Remembering audio volume, microphone preferences, dark mode toggles, and study deck filters.
No Third-Party Advertising Cookies: We do not employ third-party tracking cookies or cross-site ad retargeting pixels on AcadmyAI.
10. Children's Privacy
AcadmyAI is designed for students aged 13 and older (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect or solicit personal data from children under the age of 13 without verified parental or institutional consent. If we learn that we have inadvertently collected personal data from a child under 13 without appropriate authorization, we will expeditiously delete that information. Parents or guardians who believe their child has provided data may contact us at acadmyaiorg@gmail.com.
11. Your Legal Rights (GDPR, DPDP Act India, CCPA)
Depending on your location, you hold statutory data protection rights, including:
Right of Access: Request a copy of all personal data we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your data as outlined in Section 7.
Right to Restrict or Object to Processing: Object to specific data processing operations under legitimate interest grounds.
Right to Data Portability: Receive your learning records and account profile in a structured, machine-readable format (e.g., JSON/CSV).
Right to Withdraw Consent: Withdraw previously granted consent at any time without affecting the lawfulness of processing prior to withdrawal.
To exercise any of these rights, email your request to acadmyaiorg@gmail.com. We respond to all verified requests within thirty (30) days without charge.
12. Contact Us & Grievance Redressal
If you have any questions, concerns, feedback, or grievance regarding this Privacy Policy or our data handling practices, please contact our designated Privacy and Grievance Officer: