This Privacy Policy explains how QuizCash ("we", "our", "us") collects, uses, shares and
protects information when you use Praveenya — our education application for Android and
iOS (package com.quizcash.live) and the related institution web portal (together, the
"Platform"). QuizCash is the name of the operating company; Praveenya is the name of the product.
Praveenya is an educational product. It provides practice quizzes and exam preparation, institution-hosted assessments, and a campus / college administration workspace where students, parents and teachers can see attendance, marks, timetables, assignments, notices, study material and school documents. By using the Platform you agree to this Policy.
Praveenya does not process payments and does not operate a wallet. The app never asks for, and we do not collect through it, bank account details, card numbers, UPI handles or any other payment-instrument or government identity document for financial purposes. There is no payment SDK embedded in the app.
This Policy is issued under the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Contents
- Who this Policy covers
- Students, children and your institution
- Information we collect and why
- Legal basis for processing
- Device permissions
- Identifiers, cookies and SDKs
- Advertising and how to opt out
- How we use information
- Who we share information with
- How long we keep data
- Security
- Your rights
- Deleting your account
- International transfers
- Changes to this Policy
- Grievance Officer and contact
1. Who this Policy covers
Praveenya is used by four kinds of people, and what we hold differs for each:
- Individual learners who install the app to practise quizzes and prepare for exams.
- Students who have joined an institution (school, college or polytechnic) inside the app and therefore see that institution's academic records about them.
- Parents and guardians linked to a student, who can see their ward's marks, report card and attendance alerts.
- Teachers and institution staff, who record attendance, set and grade homework, and publish notices and material.
2. Students, children and the role of your institution
Praveenya's educational features are open to learners of all ages. The app does not run age-restricted features and does not require a date of birth to create an account.
The institution is the owner of academic records
Where you use Praveenya as part of a school, college or polytechnic, that institution decides what academic data is recorded about you, who at the institution may see it, and how long it is kept. In DPDP terms the institution is the Data Fiduciary for those academic records; QuizCash acts as a Data Processor operating the software on the institution's instructions. We do not use institution-held student records for our own purposes, and we do not sell them.
Requests to correct academic data — a wrong attendance mark, a wrong grade, an incorrect name or admission detail — must be raised with your institution's office, because we are not permitted to change a school's record on a student's request. We will help your institution act on such a request.
Children
For a user we know to be a child (under 18) under the DPDP Act, the institution is responsible for obtaining and holding verifiable parental or guardian consent before enrolling the student on the Platform, and for confirming that it has done so. We do not knowingly create standalone accounts for children outside an institution relationship, and we do not build advertising or behavioural profiles of students from their academic records. If you believe a child has registered without the required consent, write to support@quizcash.in and we will remove the account.
3. Information we collect and why
3.1 Information you give us when you register
- Name — to identify you in the app, on class rosters and on leaderboards.
- Mobile number and/or email address — used as your login identity and to deliver the one-time password (OTP) that verifies it.
- Password — stored only in irreversible hashed form; we never see or store the plaintext.
- Sign in with Google or Apple (optional) — if you use it, the provider returns an identity token together with the name and email address on that account. We do not receive your Google or Apple password.
We do not ask for a date of birth, gender, address or identity document at registration.
3.2 Information you choose to add
- Profile photo — optional. Chosen from your photo library and uploaded to your profile; you can remove it at any time from the profile screen.
- Homework and leave attachments — files you attach to an assignment submission or a leave application are uploaded to your institution so a teacher can assess or approve them.
- Survey answers — responses to course-exit questionnaires and faculty feedback surveys your institution runs.
- Support messages — anything you send us by email or through a complaint form.
3.3 Aadhaar number (institution students only, optional)
Some institutions must print a student's Aadhaar number on statutory school documents, principally the Leaving Certificate. Where your institution has that requirement, the student profile screen offers a one-time field for you to enter your Aadhaar number yourself. This is optional — nothing else in the app depends on it. It is validated on your device for format and checksum before being sent, it can be entered only once, and thereafter the app can only ever display it masked (for example "XXXX XXXX 1234"); the full number is never sent back to the app. We do not use Aadhaar for authentication, verification or any financial purpose.
3.4 Academic and campus information held by your institution
When you join an institution in the app, the app displays records that institution maintains about you. Depending on which modules your institution has switched on, these can include:
- Attendance — daily and subject-wise, including absences and the percentage calculated from them.
- Marks and results — internal assessment marks, exam-term summaries, the school-issued report card (delivered as a PDF rendered by the institution), and board results fetched from the examination board's portal on your behalf.
- Coursework — assignments and homework, your submissions and attachments, and the teacher's marks and written feedback.
- Scheduling — timetable, date sheets, academic calendar, holidays and events.
- Communications — notices, circulars and study material published to your class.
- Leave — leave applications you submit, with the reason and any attachment, and the approver's decision.
- Document locker — documents your institution has issued to you or filed about you: school records, certificates, the leaving certificate, scholarship and internship papers, and fee receipts issued by the institution.
- Student profile maintained by the institution office — which, depending on the institution, may include gender, blood group, admission category, religion, mother tongue, caste and sub-caste, nationality, place of birth, GR / PEN / APAAR identifiers, parents' names, home address, emergency contact name and number, admission date and previous school.
We display and store this information so the institution can run its academic administration and so you, and where applicable your parent or guardian, can see it. Some of these fields are sensitive personal data and are treated as such: access is limited to you, your linked guardian, and staff at your institution whose role permits it.
3.5 Information collected automatically
- Learning activity — quizzes you join, attempts, scores, time taken and leaderboard position. Correct answers and your selected answers are treated as confidential to the assessment and are deliberately excluded from all logs and diagnostics.
- Device information for notifications — device name, operating-system version, app version, device type and a stable per-installation identifier, so that a message is delivered once to the right device and an old device stops receiving your notifications.
- Push token — a Firebase Cloud Messaging token, which is what a notification is actually addressed to.
- Diagnostics and crash reports — when the app crashes or hits an error, Firebase Crashlytics receives the stack trace, device model, OS and app version, and your internal user ID. Crash reporting is disabled in development builds. Your name, email address and phone number are never sent to the crash service, and log breadcrumbs are automatically scrubbed of authentication tokens, one-time passwords, passwords and API keys before they leave the device.
- Advertising identifier — where ads are enabled, the Google Advertising ID (Android) or the Apple identifier for advertisers (iOS, only if you allow tracking when asked). See section 7.
- Server logs — IP address, timestamps and the request path, kept for security, abuse-prevention and debugging.
We do not collect your location, your contacts, your call or SMS logs, or the other apps on your device.
4. Legal basis for processing
- Consent — for optional items: your profile photo, your Aadhaar entry, marketing messages, notifications, and personalised advertising where consent is required. You may withdraw consent at any time; withdrawal does not undo processing already lawfully carried out.
- Performance of the service you asked for — creating and securing your account, delivering quizzes and results, and showing you your institution's records.
- Legitimate uses under the DPDP Act — security, fraud and abuse prevention, keeping the service working, and complying with law.
- The institution's instructions — for academic records, where we process on behalf of your school or college as described in section 2.
- Legal obligation — where a law, regulator or valid court order requires disclosure or retention.
5. Device permissions and why the app asks
- Internet and network state (Android, automatic) — required to reach our servers and to tell you when you are offline.
- Notifications (Android 13+ and iOS, on request) — to deliver class notices, homework reminders, attendance alerts and quiz announcements. You may decline, and you may turn notifications off later in your device settings; the rest of the app continues to work.
- Camera (on request, only when you tap "Scan") — to read a QR code that joins you to an institution or a class. Camera frames are decoded on your device only; no image, photo or video is recorded, stored or transmitted. You can always type the join code instead of scanning it.
- Photo library (on request) — only when you pick a profile picture or attach a file to homework. We receive only the file you select; the app does not browse or index your gallery.
- App tracking transparency (iOS, on request) — asked only where ads are enabled, to let you allow or refuse the use of the advertising identifier. Refusing is fully supported.
Some further permissions are declared by the Google and advertising libraries the app includes rather than by us — vibration, Wi-Fi state, wake lock, and the Android advertising-ID and Privacy Sandbox permissions. They are used by those libraries for notification delivery and ad measurement, and the app does not use them to collect anything else.
6. Identifiers, cookies and SDKs
The mobile app does not use browser cookies. It uses the following identifiers and third-party components:
- Session tokens stored securely on your device to keep you signed in.
- A per-installation device identifier used solely to keep one active notification registration per device.
- Firebase Cloud Messaging (Google) — push notifications.
- Firebase Crashlytics (Google) — crash and error reporting.
- Firebase Analytics (Google) — in Praveenya this records advertising events only (an ad was shown, clicked, failed to load, or a rewarded ad was completed or dismissed), together with the automatic measurement the SDK performs, such as app opens and app version.
- Firebase Remote Config (Google) — lets us change configuration, such as how often an ad may appear, without shipping an app update. It reads configuration; it does not report your personal data.
- Google Mobile Ads (AdMob) and, through AdMob mediation, AppLovin — ad delivery and measurement, where ads are enabled.
- Google User Messaging Platform — shows the consent form described in section 7.
- ZXing — the QR decoder that runs entirely on your device and sends nothing anywhere.
Our institution web portal uses only the cookies and local storage needed to keep a signed-in administrator's session and preferences. It does not run third-party advertising or tracking cookies.
7. Advertising and how to opt out
Praveenya may show advertisements — banners, native placements, occasional full-screen ads, and rewarded ads. A rewarded ad unlocks a feature of the app, such as viewing the full public leaderboard for a quiz you attempted. Ads never award money or anything of monetary value.
Advertising is controlled by a server-side setting and can be switched off entirely, per platform. Ads are never shown on assessment screens while a quiz is in progress, and the number and spacing of ads is capped.
Advertising partners may use the device advertising identifier and coarse technical signals to select and measure ads. To limit that:
- Android — Settings → Google → Ads: "Delete advertising ID" or "Opt out of Ads Personalisation".
- iOS — Settings → Privacy & Security → Tracking: refuse tracking for Praveenya, or decline the prompt when the app asks.
- EEA, UK and other consent regions — on first launch the app shows Google's User Messaging Platform consent form before the ads SDK is started at all. Your choice there governs whether personalised ads may be served, and you can change it later from the app's privacy options.
Google's own handling of advertising data is described at policies.google.com/privacy.
8. How we use information
- Create, authenticate and secure your account, including OTP verification and sign-in from a single device.
- Deliver quizzes and practice tests, score attempts and compile leaderboards.
- Show you, and where linked your parent or guardian, the academic records your institution maintains about you, and let teachers record attendance, homework and marks.
- Deliver notifications you have asked for or that your institution sends — notices, homework, results and attendance alerts.
- Diagnose crashes, fix defects and monitor performance and availability.
- Detect and prevent fraud, cheating, duplicate accounts and abuse of the Platform.
- Show and measure advertisements, where advertising is enabled.
- Respond to your support requests and grievances.
- Comply with law and respond to valid legal process.
We do not sell personal data, and we do not use student academic records to target advertising.
9. Who we share information with
We share only what is necessary, and only with the following categories. The named third parties below are those actually integrated in the app:
- Your institution — staff at the school or college you have joined, according to their role, see the academic data described in section 3.4. A parent or guardian you or the institution has linked can see their ward's marks, report card and attendance.
- Google LLC / Google Ireland Ltd (Firebase) — Cloud Messaging (notification delivery), Crashlytics (crash reports), Analytics (advertising events) and Remote Config.
- Google Mobile Ads / AdMob — advertising delivery and measurement, where ads are enabled.
- AppLovin — an advertising network that serves ads through AdMob mediation, where ads are enabled.
- Google and Apple — only if you choose "Sign in with Google" or "Sign in with Apple", to verify the identity token you present.
- Examination boards — where you ask the app to fetch your published board result, we submit only the identifiers needed for that lookup to the board's own portal.
- Infrastructure and support providers — cloud hosting, email and SMS delivery for OTPs and notices, bound by confidentiality and data-processing terms.
- Law-enforcement, courts and regulators — when compelled by valid legal process.
- A successor entity — if our business is merged or acquired, subject to this Policy continuing to apply.
10. How long we keep data
- Account data — for as long as your account exists. On deletion it is removed or irreversibly anonymised as described in section 13.
- Academic records held for an institution — for as long as the institution's own retention rules and applicable education regulations require; the institution, not QuizCash, sets that period. Statutory records such as a leaving certificate are ordinarily retained permanently by the institution.
- Quiz attempts and scores — while your account is active, so you can review your own history.
- Crash reports and diagnostics — up to 90 days.
- Server and security logs — up to 12 months.
- Support correspondence — up to 24 months after the matter is closed.
- Records we are legally required to keep — for the period the relevant law prescribes.
11. Security
We protect data in transit with HTTPS/TLS and reject cleartext connections from the app. Passwords are stored only as irreversible hashes. Access to production data is role-based, authenticated and logged, and sessions can be revoked centrally. Sensitive values — tokens, one-time passwords, passwords and API keys — are stripped from logs and diagnostics before they leave your device, and quiz answer keys are excluded from logging so an assessment cannot be compromised through diagnostics. Aadhaar numbers, where collected, are returned to the app only in masked form.
No system is perfectly secure. If a personal-data breach affecting you occurs, we will notify you and the Data Protection Board of India as the DPDP Act requires.
12. Your rights
Under the DPDP Act, 2023 you have the right to:
- Access — obtain a summary of the personal data we hold about you and how it is processed.
- Correction and completion — have inaccurate or incomplete data corrected. For academic records, raise this with your institution (see section 2).
- Erasure — have your data deleted where we are not required to keep it (see section 13).
- Withdraw consent — for anything you consented to, including notifications, marketing and personalised advertising.
- Grievance redressal — a first response from our Grievance Officer (section 16) before approaching the Data Protection Board of India.
- Nominate — appoint another person to exercise these rights on your behalf in the event of your death or incapacity.
Send any request to support@quizcash.in from the email address or phone number on your account. We respond within 30 days.
13. Deleting your account
You can delete your Praveenya account and the personal data attached to it at any time. There are two routes:
- In the app — open Profile, scroll to Delete Account, and confirm at the two-step prompt. The request is sent to our servers immediately and you are signed out.
- By email — write to support@quizcash.in from your registered email address or phone number with the subject "Delete my account". We complete the deletion within 30 days and confirm when it is done.
What deletion does: your profile, login credentials, profile photo, device and notification registrations, quiz attempts and personal scores are deleted or irreversibly anonymised, and your account can no longer be used to sign in.
What deletion does not do: it does not erase the academic record your institution keeps about you. Attendance registers, marks, examination results and issued certificates belong to the institution's official record and are governed by its retention rules and by education regulations — deleting your app account removes your access to them, not the institution's copy. To have those records changed or removed, contact your institution. We also retain the minimum data needed to meet a legal obligation or to resolve a dispute, and aggregated statistics that cannot identify you.
14. International data transfers
Our application servers and database are hosted in India. Google's services — Cloud Messaging, Crashlytics, Analytics, Remote Config and AdMob — and the AppLovin advertising network may process data on servers outside India. Those transfers are governed by the providers' data-processing terms and standard contractual clauses, and are made only to countries not restricted by the Central Government under the DPDP Act. We do not transfer institution academic records outside India.
15. Changes to this Policy
We may update this Policy as the product changes or the law does. The "Last Updated" date at the top always reflects the current version. Material changes will be notified in the app or by email before they take effect; continued use after that date constitutes acceptance.
16. Grievance Officer and contact
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023:
Grievance Officer: Ajit Kanse
Email: support@quizcash.in
Response time: acknowledgement within 24 hours, resolution within 30 days of receipt.
For any question about this Policy, about what we hold, or to exercise any right above, contact support@quizcash.in. If you are a student, your institution's office is also a valid first point of contact for anything concerning your academic record.
Praveenya is an educational quiz and campus-administration application. It does not offer real-money gaming, prizes, wagering or any feature of monetary value.