Privacy Policy

Last updated: 13 July 2026

This Policy explains what personal data we collect, why, and your rights under the Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Who is responsible for your data

The data fiduciary is Nitin Mathuria ("we", "us"), an individual based in Sawai Madhopur, Rajasthan, India, operating Sarkari Exam Typing. Contact and Grievance Officer: Nitin Mathuria, [email protected].

2. What we collect and why

DataWhyLegal basis
Account identifier (email or Google sign-in, or an anonymous ID)To create your account, hold your licence, and let you sign in on your devicePerformance of contract / your consent
Entitlement records (plan, start, expiry, device count, abuse flags)To give you access to paid content, show current device presence, and prevent account sharingPerformance of contract / legitimate security interest
Typing attempt summaries (exam, speed, accuracy, mistakes, pass/fail, time)To show your results and progressPerformance of contract
Payment records (order id, amount, status — via Cosmofeed)To confirm payment and prevent fraudLegal obligation / contract
Signed browser key and basic technical logs (browser, platform, language, timezone, last seen)To show signed-in browsers, support remote sign-out, secure paid access, and prevent account sharingLegitimate use / security
Pseudonymous site-presence heartbeat and current pageTo count unique active accounts/browsers and understand which pages are currently usefulLegitimate use / service operations

The actual keystrokes you type during a test are processed in your own browser to calculate your score. We do not upload your raw keystrokes; at most, a compact result summary is stored.

3. Payments

Payments are handled by Cosmofeed (SuperProfile). When you pay, your card, UPI, or bank details are collected and processed by Cosmofeed under its own privacy policy. We receive only a payment status and reference (including the email you enter at checkout, used to activate your plan), not your full financial details.

4. Cookies, analytics and advertising

We do not use third-party analytics, advertising, or tracking cookies. We do use a first-party operational presence counter: a random browser identifier is sent with a heartbeat and stored only as a server-side digest. Signed-in accounts are counted by a pseudonymous account digest. This tells us unique active accounts/browsers and active pages, but does not record raw IP addresses, keystrokes, or a page-view history. Presence records are automatically removed after the short monitoring window; aggregate hourly summaries are kept for up to 30 days for operational comparison.

We use only the storage that is necessary to run the app — for example, keeping you signed in and remembering your light/dark theme. If we add third-party analytics in future, we will update this page and obtain consent where required.

Our pages do load web fonts (Google Fonts) and the Firebase software kit from Google's content delivery network (fonts.googleapis.com, fonts.gstatic.com, www.gstatic.com). Loading these files transfers your IP address to Google so it can serve them. No cookies are set for this, and it is not used for advertising or profiling. See Section 5.

5. How we share data

6. Where data is stored

Data is stored on Google Firebase / Google Cloud infrastructure, primarily in the asia-south1 (Mumbai, India) region. Some processing by Google or Cosmofeed may occur on their infrastructure outside India, under their own safeguards.

7. How long we keep it

We keep account, entitlement, and result data while your account is active and for a reasonable period afterwards. Payment records are kept for the period required by law. You can ask us to delete your data (see below), subject to records we must retain.

8. Your rights (DPDP Act)

To exercise any right, email [email protected] from your registered email. We aim to respond within a reasonable time as required by law.

9. Children

We do not knowingly process the data of a child (under 18) without verifiable parental consent. If you believe a child has provided data without consent, contact us to remove it.

10. Security

We use access controls, deny-by-default database rules, server-side payment verification, and secret management so that sensitive keys never reach your browser. No system is perfectly secure; we cannot guarantee absolute security, and text delivered to your browser can be copied by a determined user.

11. Changes

We may update this Policy and will post changes here with a new "last updated" date.

This document reflects our actual data practices. It is provided for transparency and is not a substitute for independent legal advice.

Terms & Conditions · Refund & Cancellation · Disclaimer · Home