Privacy Policy

Last updated: 2 July 2026

1. Who we are

IAS Neuron ("we", "us", "our") is an AI-powered UPSC Civil Services exam preparation platform operated by Chintan Panchal, accessible at iasneuron.com. We are an Indian entity and this policy is governed by the Information Technology Act 2000, the SPDI Rules 2011, and the Digital Personal Data Protection Act 2023 (DPDP Act).

Grievance Officer / Data Fiduciary Contact:
Chintan Panchal
Email: chintanpanchal1990@gmail.com
Response time: within 30 days of receipt of grievance.

2. What data we collect

DataWhy we collect itLegal basis
Name, email addressAccount creation and authenticationConsent (signup)
Password (hashed with bcrypt)Secure loginContract performance
Subscription plan and payment statusAccess control and billingContract performance
Article content, URLs, PDFs you analyseRunning the AI analysis you requestedConsent / contract
Analysis history (results stored)Showing you past analysesLegitimate interest
IP address, request logsSecurity, rate-limiting, abuse preventionLegitimate interest

We do not collect: Aadhaar numbers, PAN, financial card numbers, biometrics, caste, religion, sexual orientation, health data, or any Sensitive Personal Data as defined under SPDI Rules 2011 beyond what is listed above.

3. How we use your data

  • Provide and improve the IAS Neuron service
  • Authenticate your account and manage subscriptions
  • Send transactional emails (password reset, subscription receipts) — no marketing without explicit opt-in
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with Indian law (CERT-In Directions, IT Act, DPDP Act)

We do not sell your personal data to third parties. We do not use your content to train our own AI models.

4. Third-party processors

Content you submit for analysis is sent to these AI providers for processing:

  • Anthropic (text/PDF analysis) — processes in the USA; governed by Anthropic's privacy policy
  • Groq (image analysis) — processes in the USA; governed by Groq's privacy policy
  • DeepSeek (admin/social processing) — governed by DeepSeek's privacy policy

Other processors:

  • Razorpay — payment processing (India) — PCI DSS compliant
  • Neon (database) — US-East; SOC 2 compliant
  • Railway (hosting) — US; SOC 2 compliant
  • Resend (transactional email) — US

5. Data retention

  • Account data (name, email): retained for the lifetime of your account, then 90 days after deletion
  • Analysis history: retained for the lifetime of your account
  • Payment records: 8 years (as required under applicable financial record-keeping laws)
  • Server logs: 180 days (as required by CERT-In Directions 2022)
  • Password reset tokens: 1 hour (auto-expired)

6. Your rights (DPDP Act 2023)

  • Right to access: Request a copy of your personal data we hold
  • Right to correction: Request correction of inaccurate data
  • Right to erasure: Request deletion of your account and personal data (payment records excluded — legal retention requirement)
  • Right to grievance redress: Lodge a complaint with our Grievance Officer; escalate to the Data Protection Board of India once established
  • Right to withdraw consent: You may withdraw consent by deleting your account; withdrawal does not affect lawfulness of prior processing

To exercise these rights, email chintanpanchal1990@gmail.com with subject line "DPDP Data Request". We will respond within 30 days.

7. Children and age restriction

IAS Neuron is intended for users who are 18 years of age or older. We do not knowingly collect personal data from persons under 18. If you believe a minor has registered, contact us immediately and we will delete the account.

8. Security

We implement industry-standard security measures: TLS/HTTPS for all traffic, bcrypt password hashing (cost factor 12), parameterised database queries, rate limiting on all public APIs, security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options), and access controls on sensitive admin endpoints. Despite these measures, no system is 100% secure.

9. Cookies

We use only essential session cookies (NextAuth.js session token) necessary for authentication. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. No cookie consent banner is required as we use only strictly necessary cookies.

10. Changes to this policy

We may update this Privacy Policy. Material changes will be communicated by email to all registered users at least 7 days before they take effect. Continued use after the effective date constitutes acceptance of the revised policy.

11. Contact and grievances

Grievance Officer: Chintan Panchal
Email: chintanpanchal1990@gmail.com
Response: We acknowledge grievances within 48 hours and resolve within 30 days.
Escalation: Data Protection Board of India (once operational under DPDP Act 2023)