Privacy Policy

Last updated: 30 July 2026

Your library is private to you. This policy explains what we collect and, importantly, that the text of your uploads is sent to third-party AI providers to power the learning features.

1. Overview

This Privacy Policy explains what information Examly collects, how we use it, and who we share it with. Examly is a personal learning tool: your library is private to you and we do not sell your data.

You are responsible for the material you import and for having the right to upload it. Examly does not review uploaded files and is not responsible for copyright issues arising from them; see our Terms of Service.

2. Information we collect

  • Account information: your email address, display name, and authentication data (such as passwords stored only as secure hashes, or a linked Google sign-in).
  • Documents you upload: the PDF files you add to your library, and the text and study content derived from them (concepts, links, summaries, questions, and solutions).
  • Usage information: basic telemetry about how you use the Service (pages viewed and interactions), used to operate and improve the product.
  • Cookies and tokens: we use a secure cookie and access tokens to keep you signed in. We do not use advertising trackers.

3. How we use your information

We use your information to provide and operate the Service: to process your documents into learning content, track your progress, keep your account secure, respond to your requests, and improve the product. We do not sell your personal information or your uploaded content, and we do not show your library to other users.

4. Third-party AI providers

To provide AI features, the text of your uploaded documents and the content derived from them may be sent to third-party AI model providers, which may include services such as MiniMax, OpenAI, Google, Anthropic, and DeepSeek, and may change over time.

Those providers process this data under their own terms and privacy policies, which we do not control. You may optionally supply your own provider API keys; when you do, they are stored encrypted and used only to make requests on your behalf.

We are not responsible for how third-party providers handle data beyond our choice to use them. Please do not upload content you are not comfortable having processed by such providers.

5. Shared processing cache (deduplication)

To avoid reprocessing the same file many times, the extracted and structured text of a document may be cached using a content fingerprint (a hash of the file's bytes). If anyone later uploads a byte-for-byte identical file, the Service may reuse that cached processing instead of running it again.

This cache is keyed to the file's content, not to your identity. Your account, your library, and your progress remain private to you and are not exposed to other users through this cache.

6. Storage and security

Uploaded files and derived content are held in object storage, and any provider API keys you supply are encrypted at rest. We take reasonable measures to protect your information, but no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Study rooms and community features

If you join a study room, what you post there is visible to the other members of that room. This includes your display name, your messages and any images you attach, your presence and study status, resources you choose to share, and your focus minutes on the room's leaderboard.

Messages are moved out of the live room into a separate retained store about ten days after they are posted. We keep that store so we can investigate abuse reports and enforce our community rules.

Messages are screened automatically before they post. The filter blocks explicit language and flags attempts to share contact details, which is intended to protect you and other members. Reports you file, and enforcement actions we take, are recorded.

8. Sharing and disclosure

We share information only as needed to run the Service. We do not sell it. The providers who process data on our behalf are:

  • Google Cloud (Cloud Run, Cloud SQL): hosting and the database that holds your account and content. United States.
  • Cloudflare (R2, CDN, DNS): storage for uploaded files and images, and delivery of the site. Global.
  • AI model providers: MiniMax, OpenAI, Google, Anthropic and DeepSeek, as described above. See that section for what is sent.
  • Google Document AI: optional OCR for scanned PDFs, which receives page images of the document.
  • Our email provider: receives your email address and the contents of the emails we send you.
  • Redis: short-lived counters and presence data, holding account identifiers only.

These providers are located outside India, so operating the Service involves transferring your personal data abroad. We may also disclose information if required by law, or to protect the rights, safety and security of our users and the Service.

9. Data retention and deletion

We keep your account information and content while your account is active. You can remove documents and subjects from your library at any time from within the app.

You can delete your account yourself from Account settings. When you do, your account is deactivated immediately, you are signed out everywhere, and the permanent deletion runs 14 days later. During those 14 days you can cancel using the link in the confirmation email we send you. After that it cannot be undone.

When the deletion runs, we delete your account, your library and its uploaded files, the concepts and questions derived from them, your notes, annotations, tasks, practice history, progress, spaced-repetition state, preferences, support conversations and usage history.

Some things are handled differently, and we would rather say so plainly:

  • Messages you posted in study rooms have their text and images removed and are shown as deleted, but the surrounding conversation stays for the other members.
  • Abuse reports and enforcement records are kept with your identity removed, for up to 24 months, so that a safety history is not erased by deleting an account.
  • We keep a minimal record that a deletion happened: the date and a one-way fingerprint of the email address, which cannot be used to contact you. It exists so we can confirm to you that we did what we said.
  • The shared processing cache described above is not deleted, because it is keyed to a file's contents and holds nothing that identifies you. If you were the only person who had ever uploaded a given file, that file and its cached processing are deleted with your account.
  • Encrypted backups of the database roll off on their own schedule, within 30 days. Deleted data can persist in a backup until then.

10. Your rights

You can exercise these rights yourself from Account settings, or by contacting us using the details below. We respond within 30 days.

  • Access and portability: request a copy of your data. We generate a ZIP of JSON files covering your profile, library, notes, practice history, progress and messages, and email you a download link.
  • Correction: change your display name and account settings in the app, or ask us to correct anything else.
  • Deletion: delete your account as described above.
  • Withdraw consent: you can withdraw your consent to our processing at any time by deleting your account. Doing so does not affect anything we did while your consent was in place.
  • Grievance redressal: if you are in India, you may raise a grievance with our Grievance Officer, whose details are below, and you may afterwards complain to the Data Protection Board of India.
  • Nomination: if you are in India, you may nominate another person to exercise your rights on your behalf in the event of your death or incapacity. Contact us to do this.
  • Complaint: if you are in the EEA or UK, you may complain to your local data protection authority.

11. If something goes wrong

If a security incident affects your personal data, we will notify you and the relevant authority (in India, the Data Protection Board) without undue delay, and tell you what happened, what it means for you, and what we are doing about it.

12. Children and younger users

Examly is a study tool, and we know a lot of exam preparation is done by school students. Indian law treats anyone under 18 as a child for data-protection purposes and requires a parent or guardian's consent before their personal data is processed. Other countries set lower ages.

If you are under 18, please use Examly with your parent or guardian's knowledge and agreement, and do not share personal details about yourself in study rooms. We do not show advertising and we do not use your activity to target or profile you.

If you are a parent or guardian and you want to see what we hold about your child, correct it, or have it deleted, contact us and we will act on it.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the date above. Please review it periodically.

14. Grievance Officer

If you are in India, the Digital Personal Data Protection Act gives you the right to a clear route for complaints about how we handle your personal data. You can reach our Grievance Officer here:

Grievance Officer, Examly · grievance@examly.ink · Visakhapatnam, Andhra Pradesh, India

We acknowledge grievances within 72 hours and aim to resolve them within 30 days. If you are not satisfied with how we have handled your complaint, you may escalate it to the Data Protection Board of India.

15. Contact

Questions about this Privacy Policy can be sent to support@examly.ink.

You can also reach us through the contact page, linked below. It goes to the same place and you don't need an account to use it.