← Back to home

Privacy Policy

Version 1.2Last updated 18 September 2026DPDP Act, 2023

What personal data the Target 720 app collects, why we collect it, how long we keep it, and what you can ask us to do with it.

This policy explains what personal data the Target 720 mobile app collects, why we collect it, how long we keep it, and what you can ask us to do with it. It is written for India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025.

Target 720 is operated by Vidyn.AI (“we”, “us”). We are the Data Fiduciary for the data described below. You are the Data Principal.

1. What we collect

1.1 Your account

You sign in with Google, or with Apple on iPhone. Sign-in is handled by Firebase Authentication (Google LLC), which receives your name, email address and profile picture from that account and gives us a sign-in token.

In our own database we store a Firebase user identifier, your display name, your profile picture URL, your email address, and whether that address has been verified.

We store your email address so that we can contact you about your own account — for example to confirm a purchase, to acknowledge a report you have sent us, or to confirm that a request to delete your account has been received. We do not use it for marketing, and we do not share it for anyone else's marketing. It is kept for as long as your account exists and is erased with the rest of your account data (see §5).

1.2 What you tell us about your preparation

DataWhy we need it
Date of birthTo confirm your age when you create your account
Class level (11, 12 or dropper)To decide which part of the syllabus to show you
Target exam yearTo pace your study plan
Subjects selectedTo build your plan and homework
Daily reminder timeTo time your study reminder

1.3 Your learning activity

1.4 Your subscription

If you buy a subscription, we store the plan tier, whether it is active, its expiry date, and the reference numbers of the subscription and its payments. A subscription bought in the app is paid for through Apple or Google in their own stores; one bought directly from us is paid for through Razorpay, our payment provider, under its own privacy policy. We never see or store your card, UPI or bank details.

1.5 What we do not do

1.6 App analytics and crash reports

To see which parts of the app students actually use, and to find out when it breaks, the app sends usage and crash information to Google Analytics for Firebase and Firebase Crashlytics (both Google LLC).

What is sentWhy
Screens you open, and actions such as starting a mock, opening a chapter, or completing a module — with your account identifier attachedTo understand which features help students and which are ignored
Your subscription tier, exam class and exam year; how much of the syllabus you had already covered when you joined; whether you have allowed notifications; and whether you are one of our test usersTo tell whether a feature works for the students it was built for, and to separate our own testing from real use
A device identifier, device model, operating system, app version, and an approximate city or region derived from your internet addressTo reproduce faults and tell one device's session from another
If the app crashes: the error, the code path, and the screen you were on — with your account identifier attachedTo fix the crash, and to tell whether it hit one student or thousands

This information is linked to your account. It is not used to advertise to you, is not combined with data from other companies' apps or websites, and is not sold.

Retention. Usage data is kept for 14 months and then deleted automatically. Crash reports are kept for 90 days.

If you object. Email support@target720.com from your registered address. Deleting your account (see §6) also erases the usage and crash data held against it, and stops any further collection.

Google processes this data on our instructions, which may involve processing outside India under their own terms and safeguards.

2. Why we process it, and on what basis

We process your data on the basis of your consent, given when you create your account and accept this policy, and only for these purposes:

  1. To run the service — sign you in, show you the syllabus, save your progress and attempts across devices.
  2. To personalise your preparation — build your daily plan and your mistake notebook from your own progress and attempt history. This is automated, but it only decides what study material to put in front of you; it makes no decision with legal consequences for you.
  3. To support you — answer your emails and investigate faults you report.
  4. To keep the service working and safe — diagnose errors, prevent abuse, and keep the content secure.
  5. To meet legal obligations — including responding to your rights requests under the DPDP Act.

You can withdraw your consent at any time by deleting your account (see §6). Withdrawing consent means we can no longer provide the service to you.

3. Who else touches your data

ProcessorWhat they do
Google LLC — Firebase AuthenticationVerifies your sign-in and holds your name, email and profile picture
Google LLC — Google Analytics for Firebase, Firebase CrashlyticsReceive app usage events and crash reports, linked to your account (§1.6)
Apple Inc. — Sign in with Apple (iPhone)Verifies your sign-in if you choose Apple
Apple Inc. / Google LLC — App Store, Google PlayDistribute the app and process any subscription payment
Razorpay Software Limited — web paymentsProcesses the payment for a subscription bought directly from us, and holds the payment and mandate details needed to take each yearly renewal
Our cloud hosting providerRuns our servers and database

These providers act on our instructions under contract. Beyond them, we disclose personal data only where the law requires it.

4. Where your data is stored

Your account and learning data are stored and processed in India. Firebase Authentication and the app stores are operated by Google and Apple on their own global infrastructure, which may involve processing outside India, under their own terms and safeguards.

5. How long we keep it

DataRetention
Account, profile, learning activity, mistake notebook, plansKept while your account exists. Erased at the end of the recovery window — up to 30 days after you delete your account.
Activity event recordsKept while your account exists; erased with the account at the end of the recovery window.
Subscription recordsErased with your account at the end of the recovery window, except where tax or accounting law requires us to retain a purchase record.
Support emailsKept up to 24 months after the issue is closed.

Deleting your account happens in two steps. The account closes immediately: you are signed out on every device and cannot sign in again. Your data is not erased at that moment — it is kept for a recovery window of up to 30 days so that an accidental deletion can be undone. At the end of that window it is erased permanently.

During the window, email support@vidyn.ai from the address on the account and ask us to restore it. Signing in again will not restore it. Once the erasure has run, nothing can be recovered. See §6 for the rest of your rights.

6. Your rights

Under the DPDP Act you can ask us to:

For anything you cannot do in the app, email support@vidyn.ai from the address on your account. We respond within 30 days. We may need to confirm it is really you before we act on a request.

7. Contact us about your data

For any question, request or complaint about your personal data:

8. Security

Data is encrypted in transit (HTTPS/TLS) and at rest on our servers. Access to production data is restricted to the people who need it. No system is perfect; if a breach affects your data we will notify you and the Data Protection Board as the law requires.

9. Changes to this policy

If we change how we handle your data, we will update this page, change the version and date at the top, and — for a significant change — notify you in the app before it takes effect.

Also worth reading