PRODUCTION SERVICE
Privacy and data use
Effective 5 August 2026 · Notice privacy-2026-08-05.v6Bhasha Boost is operated by Ankit Upadhyay. This notice explains how the current service handles account, PDF, classroom, and support data.
Who can create an account
Account creation is public after email verification and automated-abuse protection. There is no invitation or manual account unlock; protected study activity is admitted automatically while service capacity remains. The current service does not perform age verification or collect parent or guardian consent.
Information the product handles
Account and choices
Email address, display name, authentication records, service admission status, accessibility settings, consent history, and personalization choices.
PDFs and derived study material
Uploaded PDFs, file hashes and metadata, converted text/layout/images, source coordinates, document embeddings, headings, and sections needed to display and teach the source.
Classroom and learning records
Final learner transcripts, teacher output confirmed as played, checkpoints, assessment evidence, canvas actions, progress, notes, reviews, and approved memories.
Operations and support
Stable error codes, timings, token and usage counts, one-way hashed identifiers, ordinary request metadata handled by infrastructure, and anything sent in a support email.
Live microphone audio
The browser streams live microphone audio through the classroom service to Sarvam AI for speech recognition. The service also sends teacher text to Sarvam AI to synthesize the teacher voice. Bhasha Boost does not store raw microphone audio in its database or file storage. It stores final transcripts and committed learning events so lessons can continue across sessions.
Sarvam AI processes live audio in India in real time and states that it does not store the audio unless storage is explicitly requested. Bhasha Boost does not request raw-audio storage. The raw-audio choice in Settings records consent for a possible future feature; changing it does not enable raw-audio retention in the current service.
Why the data is used
- Authenticate the learner and keep each account's study spaces separate.
- Convert, index, display, and retrieve evidence from the learner's PDF.
- Recognize speech, generate a source-grounded response, and synthesize the teacher voice.
- Resume lessons, show notes and progress, run checkpoints, and apply permitted personalization.
- Limit abuse and spending, diagnose failures, secure the service, and respond to support requests.
Services that process release data
The following service providers process data for the listed purposes in the current service.
Supabase
Account authentication, the application database, and private PDF/object storage.
Cloudflare
Web and classroom hosting, Turnstile bot protection, DNS, and inbound support-email routing.
Resend
Delivery of account-verification and password-recovery emails sent by Supabase Auth.
Datalab
Converting uploaded PDFs into structured text, layout, images, and source coordinates.
Sarvam AI
Live speech-to-text for learner audio and text-to-speech for the teacher voice.
OpenAI
Grounded teacher responses, session-note generation, and document/query embeddings.
Trigger.dev
Running background document-conversion and indexing jobs with bounded job metadata.
Upstash
Short-lived classroom admission, rate-limit, ticket, and connection-coordination state.
Grafana Cloud
Receiving filtered operational traces, identifiers represented as one-way hashes, and stable error codes.
Retention and deletion boundaries
Bhasha Boost keeps account records, original and derived PDF content, final transcripts, classroom events, notes, and progress while the account remains active so the learner can return to lessons. Short-lived Upstash coordination data expires according to application-set time limits.
Account deletion in Settings removes owner-scoped files from live Supabase Storage, then deletes the authentication account and cascading live database rows. Provider logs, temporary processing copies, and backups may remain for the periods applied by each provider's production account and security policies. Deletion from the live application does not mean immediate deletion from those separate provider systems. Contact support@bhashaboost.com for deletion help.
Learner controls
- Export: Settings can prepare a bounded JSON archive of the learning record and an inventory of private PDF objects. It does not put PDF binaries or signed download links in the archive.
- Delete: Settings provides a deliberate account-deletion flow with identity, phrase, and permanent-deletion confirmation.
- Personalization: Settings exposes separate controls for preferences, mastery and misconceptions, and relationship continuity, with a visible consent history.
Signed-in learners can use Settings & privacy. For an assisted export, deletion problem, correction, or privacy question, use the contact below.
Privacy, security, and support contact
Email support@bhashaboost.com to report a privacy or security incident, ask a data-use question, or request help with export or deletion.
Include any short incident reference shown by the app, but do not email a password, API key, full PDF, or raw classroom audio.