How the Bodhya Learn learning app collects, uses, stores and protects information — with special care for children.
यह गोपनीयता नीति अंग्रेज़ी में है। किसी भी प्रश्न के लिए कृपया नीचे दिए गए ईमेल पर हमसे संपर्क करें। हम आपकी सहायता हिन्दी में करेंगे। (This policy is written in English. For any question, please contact us at the email below — we are happy to help you in Hindi.)
App: Bodhya Learn (Android package net.bodhya.learn)
Publisher / Data Fiduciary: Vishal Arya, an individual based in Patna, Bihar, India
Effective date: 11 August 2026 · Last updated: 11 August 2026
Privacy at a glance
- Built for learning, not for tracking. Bodhya Learn works fully offline. Most information stays on the learner's own device.
- No advertising. There are no ads and no advertising IDs in this app.
- No third-party analytics or trackers. We do not embed any third-party advertising or analytics SDKs.
- No sensitive device permissions. The app requests no location, camera, microphone, contacts, SMS, phone, or external-storage permissions.
- We never sell or rent data. Learner data is never sold, rented, or shared for anyone else's marketing.
- Made for children — with consent. Because our learners are children, we rely on a parent, legal guardian, or authorised facilitator to enrol and supervise the child.
- You can ask us to delete everything. Contact us any time to see, correct, or erase a learner's data.
1. Who we are
Bodhya Learn ("Bodhya Learn", "the app", "we", "us", "our") is published by Vishal Arya, an individual based in Patna, Bihar, India. This is an independent, personally-run project; it is not published by any company or organisation. For the purposes of India's Digital Personal Data Protection Act, 2023, Vishal Arya is the Data Fiduciary responsible for the learner information described here. Under COPPA and the GDPR we act, respectively, as the operator and the data controller.
Bodhya Learn is a free, offline-first, bilingual (English and Hindi) learning game that teaches English literacy, Mathematics, Science, and life skills for Class 1–10. It is designed especially for girls in Champaran, Bihar, India — many of whom are early readers or non-readers who navigate the app by listening, because every screen can be read aloud. Bodhya Learn is used both in facilitator-run campus classrooms and by individual learners studying at home.
2. Scope of this policy
This policy covers the Bodhya Learn Android app (package net.bodhya.learn) and the associated backend service that I operate at https://learn.bodhya.net. It explains what information the app handles when used offline on a device and what is synchronised to our backend when an internet connection is available.
The app is a self-contained web application (HTML, CSS and JavaScript) packaged for Android using Capacitor. It contains no external assets, no content delivery networks, and no third-party code libraries loaded over the network. Sounds are generated on the device, speech uses your device's built-in text-to-speech, and all learning content is bundled inside the app.
3. A note about children
Bodhya Learn is intended for children and is used by children under the age of 13. Because it is designed for a child audience, we build the app to comply with the requirements of Google Play's Families policy and to be safe for children. Because our learners are minors, the app should be set up and supervised by a parent, a legal guardian, or an authorised programme facilitator (for example, a teacher at a Bodhya Learn campus). By enrolling a child or letting a child use Bodhya Learn, that adult confirms they have the authority to consent on the child's behalf.
We practise data minimisation: the app is built to collect as little as possible from children, and only what is needed for the child to learn and for a facilitator to support them. We ask learners to choose a first name or a nickname rather than a full legal name, and we do not require an email address, phone number, photograph, precise location, or any government identifier from a child.
4. What we collect
The information below is everything Bodhya Learn handles. Most of it is created by the learner as they play and is stored on the device; some of it is synchronised to our backend when the device is online, so a facilitator can help and so progress is not lost if a device is replaced.
| Information | What it is | Stored on device | Synced to backend when online |
|---|---|---|---|
| Chosen name | A first name or nickname the learner picks to sign in and be greeted by. | Yes | Yes |
| Campus login password | For campus (classroom) accounts only. Never stored as plain text — see Security. | Yes (hashed) | Yes (hashed) |
| Learning progress | Lessons completed and in-game rewards: stars, coins, and gems. | Yes | Yes |
| Quiz & test attempts | Answers the learner gives to quizzes and tests, and whether they were correct. | Yes | Yes |
| Attendance / time spent | How much time the learner spends in the app, used to record classroom attendance and study time. | Yes | Yes |
| Doubts (questions) | Questions a learner chooses to send to their facilitator for help. | Yes (queued) | Yes |
When the device is offline, completed activities and doubts are held in a queue on the device and sent to the backend later, once a connection is available. Bodhya Learn remains fully usable offline; syncing only adds the ability for a facilitator to see progress and answer doubts.
5. What we do not collect
To keep this app safe for children, Bodhya Learn does not collect, request, or transmit any of the following:
- No advertising identifiers (no Android Advertising ID / AAID), and no SIM serial or device build serial.
- No precise or coarse location data, and no GPS access.
- No contacts, call logs, SMS, photos, camera, microphone recordings, or files from the device. The app requests no microphone permission and contains no recording code.
- No email address or phone number from the learner.
- No government identifiers (such as Aadhaar), biometrics, or financial information.
- No behavioural advertising profiles, cross-app tracking, or fingerprinting of any kind.
- No third-party analytics, advertising, or social-media SDKs.
App permissions: the app requests no sensitive Android runtime permissions — it does not ask for location, camera, microphone, contacts, SMS, phone, or external-storage access. Speech is produced through your device's built-in text-to-speech, which does not require a permission.
About the AI tutor: the app's code contains an experimental AI voice tutor ("Roshni"). It is disabled and not active in this release; it processes no data and sends nothing anywhere. If we ever enable it, we will update this policy first and, where the law requires it, seek fresh consent before it is turned on.
6. Why we use this information and our legal basis
- To let the learner sign in and save progress — the chosen name and (for campus accounts) the login password.
- To teach and adapt — progress, stars/coins/gems, and quiz/test attempts let the app show the right next lesson and let the learner resume where they left off.
- To let a facilitator support the learner — attendance/time-spent and doubts help a teacher see who needs help, record classroom attendance, and answer questions.
- To keep the app working and secure — basic technical operation and preventing misuse.
Our primary lawful basis for processing a child's data is the verifiable consent of the child's parent, legal guardian, or authorised facilitator (India's DPDP Act 2023, Section 9; GDPR Article 6(1)(a) together with Article 8; and COPPA verifiable parental / school-authorised consent). Where relevant we also process data to perform the educational service the child was enrolled in. We do not use learner data for advertising, behavioural profiling, or any commercial purpose.
7. Where data is stored: on the device vs. our backend
On the device
By default and whenever the app is used offline, all of the information in Section 4 is stored locally on the learner's device (in the app's local storage). If the app is uninstalled, this on-device data is removed with it.
On our backend
When the device is online, the app synchronises the learner's data to a backend service that I operate myself, hosted at https://learn.bodhya.net using the open-source Frappe framework. This lets facilitators view progress and answer doubts, and lets a learner keep their progress across devices. This backend is controlled by me; the data on it is not handed to advertisers, data brokers, or other third parties (see Section 8).
8. Sharing, selling, and advertising
We do not sell, rent, or trade learner data. We do not share it for anyone's advertising or marketing. The app shows no advertisements.
Learner information is visible only to: (a) the learner; (b) the learner's authorised facilitator(s) and the volunteers who support the learner; and (c) the learner's parent or legal guardian on request. We may disclose information only if we are legally required to do so by a valid legal process, or where necessary to protect the safety of a child. We do not transfer learner data to third parties for their own purposes, and we do not use any third-party processor for advertising or analytics.
9. Children's data and the law
We handle children's data in line with the following frameworks:
India — Digital Personal Data Protection Act, 2023 (and the DPDP Rules, 2025)
Under India's DPDP Act, 2023 a "child" is anyone under 18 years of age. Processing a child's personal data requires verifiable consent from a parent or lawful guardian, and the law prohibits tracking, behavioural monitoring, and targeted advertising directed at children — none of which Bodhya Learn does. For campus learners, consent is obtained through the enrolling parent/guardian and the child's facilitator or institution at the time of enrolment; for home learners, the supervising adult provides this consent when setting up the app. Note: the Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025 and provide an approximately 18-month phased implementation period, so key obligations become fully enforceable during 2026–2027. We will keep our practices and this policy aligned with the DPDP framework as its provisions take effect.
United States — COPPA
For families in the United States, we comply with the Children's Online Privacy Protection Act (COPPA), which protects children under 13. We collect only the limited information described in Section 4, obtain verifiable parental consent (or, in a classroom, consent authorised by the school/facilitator acting on a parent's behalf for a purely educational purpose), do not condition a child's participation on disclosing more than is reasonably necessary, and give parents the right to review and delete their child's information. Our operator contact details required by COPPA are in Section 15.
European Union / EEA / UK — GDPR and GDPR-K
For users in the EU, EEA, or UK, we rely on the consent of the holder of parental responsibility for children below the applicable age of digital consent (Article 8 GDPR; between 13 and 16 depending on the country). We honour the GDPR rights described in Section 10, and we do not carry out profiling or automated decision-making that produces legal or similarly significant effects on a child.
10. Rights of parents, guardians, and facilitators
Because our learners are children, these rights are exercised by the child's parent, legal guardian, or authorised facilitator (and, where appropriate, by the learner). You may:
- Access — ask us for a copy of the information we hold about a learner.
- Correct — ask us to fix information that is wrong or incomplete.
- Delete / erase — ask us to delete a learner's account and data from our backend, and stop any further collection. (On-device data can also be cleared by uninstalling the app or clearing its storage.)
- Withdraw consent — withdraw consent for future processing at any time; this does not affect processing already carried out.
- Portability — where applicable, receive the learner's data in a structured, machine-readable format.
- Object / restrict — object to or ask us to restrict certain processing, where the law provides for it.
- Refuse further collection — parents may review the learner's information and refuse to permit its further collection or use.
To exercise any of these rights, contact us using the details in Section 15. We will verify that the request comes from an authorised adult before acting, and we will respond within the timeframes required by applicable law (and in any case without undue delay).
11. Data retention and deletion
We keep a learner's data on our backend only for as long as it is needed to provide the learning service — typically while the learner is actively enrolled in the programme — and to meet any legal obligation. When data is no longer needed, or when consent is withdrawn or deletion is requested, we delete it from our backend within a reasonable period. We do not retain children's personal data longer than is reasonably necessary to fulfil the educational purpose for which it was collected.
How to delete a learner's data: Full instructions are on our dedicated page, bodhya.net/data-deletion, which is publicly reachable and needs no app, account or login. In short: email us at [email protected] with the learner's chosen name and her campus/class (see Section 15). We acknowledge within 7 days and complete the deletion within 30 days of confirming the account. On-device data stays only on the device and is removed when the app is uninstalled or its storage is cleared, or — for the browser version at learn.bodhya.net/play — when the site's stored data is cleared in that browser. A learner who only ever played as an offline guest has no backend account, so there is nothing for us to delete.
12. Security
We take practical steps to protect learner information:
- Passwords are never stored as plain text. Campus login passwords are protected on the device using PBKDF2 (a slow, salted password-hashing function). We store only the hash, never the password itself.
- Encryption in transit. All synchronisation with our backend happens over HTTPS, so data is encrypted while it travels over the network.
- Data minimisation. The app is designed to collect as little as possible, which reduces risk (see Sections 3 and 5).
- Self-hosted backend. Synced data lives on infrastructure I operate myself, not on third-party advertising or analytics platforms.
No method of storage or transmission is ever completely secure, but we work to protect learner data using measures appropriate to its sensitivity, and we will notify affected users and the relevant authorities (including the Data Protection Board of India, where applicable) of any personal-data breach as required by law.
13. International use
I and the backend are based in India, and learner data synced to our backend is processed in India. If you use Bodhya Learn from outside India (for example, families in the Indian diaspora), you understand that your information will be processed in India in accordance with this policy and applicable data-protection law, including the safeguards described in Section 9. Regardless of where you are, we apply the child-protection commitments in this policy.
14. Changes to this policy
We may update this policy from time to time — for example, if a feature changes or the law changes. When we do, we will revise the "Last updated" date at the top and, for material changes affecting children's data, seek fresh consent where the law requires it. The current version is always available at the public URL where this policy is hosted. Continued use of the app after an update means the responsible adult accepts the revised policy.
15. Contact and grievance redressal
If you have any question, request, or complaint about privacy — including to access, correct, or delete a learner's data — please contact us. For DPDP Act purposes, this is also our grievance-redressal contact, and it is the operator contact required under COPPA.
Vishal Arya (Data Fiduciary / COPPA operator / GDPR data controller)
Grievance & privacy contact: Vishal Arya (publisher)
Email: [email protected]
Telephone: +91 89862 89083
Postal address: Mansarovar Garden, SK Sinha Library Road, Patna, Bihar 800001, India
App: Bodhya Learn (net.bodhya.learn)
Backend: https://learn.bodhya.net
We will acknowledge and respond to privacy requests within the time required by applicable law. If you are in the EU/EEA/UK, you also have the right to lodge a complaint with your local data-protection authority; if you are in India, you may raise a grievance with the Data Protection Board of India after contacting us.
© Vishal Arya. Bodhya Learn. This Privacy Policy is effective as of 11 August 2026.
Bodhya Learn is free and offline-first software built for children's education. We do not show ads, we do not track, and we do not sell data.