Privacy Policy
Anvay is operated by Aryan Barsaiya, trading as “Anvay” (“Anvay”, “we”, “us”).
Contact for any privacy question or request
anvay2810@gmail.com
1. In short
Anvay is Japanese-language training software sold to training institutes, not to the public. You cannot sign up for it — your institute creates your account. We hold your learning progress so your teacher can see how your batch is doing, and we measure how the app is used so we can improve it. We do not sell your data, we do not advertise, and there are no advertising or tracking SDKs in the app.
2. Who is responsible for your data
Anvay is licensed to a training institute or sending organisation (“the Institute”), which enrols its own students and staff. That determines who is responsible for what:
- The Institute decides what data about its students goes into Anvay, and why. Under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) it acts as the Data Fiduciary, and it is responsible for giving each student notice and obtaining consent before enrolling them.
- Anvay processes that data on the Institute’s instructions, as a Data Processor, to run the service.
If you are a student: your Institute enrolled you and holds the record of who you are. It is your first point of contact for any question about your data — see section 8. You can also always write to us directly.
3. What we collect
How much we hold about you is set by your Institute, not by us. Every Institute chooses one of two settings when it is onboarded, and we apply it to that Institute’s whole account:
| Setting | What identifies you to us |
|---|---|
| Reference only (the data-minimising default) |
A roll number or similar reference chosen by your Institute. We are not given your name, email address or phone number, and we cannot tell which person a roll number belongs to — only your Institute holds that mapping. Your sign-in address is a placeholder that cannot receive mail. |
| Contact details allowed | Your name, email address and, if your Institute supplies it, your phone number, in addition to the reference. Your email address is your sign-in address, which is what lets you reset your own password instead of asking your Institute to do it. |
Your Institute can tell you which setting applies to you. Ask them, or ask us.
Under both settings we collect the following:
| Data | Why we hold it | Source |
|---|---|---|
| Account credentials — a sign-in address and a password, stored only as a cryptographic hash and never in readable form | To sign you in and control who may open the app. There is no public sign-up | Your Institute, or us |
| Your batch, your Institute, and your chosen learning language (Hindi, Malayalam or Telugu) | To give you the right course and show your teacher the right group | Your Institute |
| Device identifier — an identifier for the device you sign in from | To bind an account to one device, so a single login is not shared around a class | Generated on your device |
| Learning progress — lessons, exercises and cards opened and completed; the answers you give, including which option you chose when you get one wrong; mock-test scores and results | To show your progress, to build your Institute’s readiness dashboard, and to correct our own teaching material | Your use of the app |
| Usage data — which screens and exercises are opened, in what order, how long they take, where learners get stuck, and whether a feature is used at all | To improve the app and the teaching content | Your use of the app |
| Technical and diagnostic data — app version, device model, operating system version, language and region settings, crash reports, error logs and performance timings | To keep the app working, to diagnose faults, and to know which devices we must keep supporting | Your device |
| Connection records — IP address and timestamps in our server logs | Security, abuse prevention and fault diagnosis. We do not use your IP address to work out where you are, and the app never requests location permission | Your connection |
4. What we do not collect
- Identity documents, passport or visa data, financial or payment data, and health data. Nothing in the app asks for these, and our agreements state the Institute will not upload them.
- Location, contacts, calendar, photos, files, or microphone input. The app requests none of these permissions. Spoken Japanese is produced by your device’s own built-in text-to-speech — no audio is recorded and none is sent anywhere.
- Advertising identifiers. Anvay carries no advertising, no advertising SDKs, and no third-party trackers. We do not track you across other companies’ apps or websites.
- Payment data. There are no in-app purchases. Anvay is invoiced to your Institute, never to you.
We do not sell personal data, and we do not share it for advertising or for anyone else’s marketing.
5. How we use it
Only for these purposes:
- To operate the app and sign you in.
- To record and show your learning progress, and to produce your Institute’s batch-readiness dashboard.
- To control who may open the app, including binding an account to a device.
- To improve the app and the teaching content — including correcting the language material itself, which is why we look at wrong answers.
- To diagnose faults, keep the service secure, and prevent misuse.
- To produce anonymised, aggregate statistics — pass rates, average scores, engagement — describing how the product performs. These no longer identify any individual, and we do not attribute them to a named Institute or a named student without that Institute’s written consent.
We do not use your data to make any automated decision that has a legal or similarly significant effect on you, and we do not profile you. A dashboard telling a teacher that a learner is behind is information for that teacher; it is not a decision made by Anvay.
6. Who we share it with
We share data only with the service providers needed to run the app. Each processes it on our instructions, under confidentiality obligations, and none of them may use it for its own purposes:
Supabase · Google · Apple · Cloudflare
Beyond that, we disclose data only where the law requires it, or where your Institute instructs us to.
7. Where it is stored, and how long we keep it
Your data is stored in India. Some of the providers named above may process limited technical data, such as crash reports, outside India.
| While your Institute’s account is active | We keep your data for as long as the account is active |
| At the end of a free pilot | We disable the pilot accounts and delete the pilot data we hold |
| On your Institute’s written request | We return or delete the data we hold for it |
| Anonymised, aggregate data | Kept — it can no longer identify anyone, so it is not subject to return or deletion |
| Backups | Overwritten on a rolling cycle, so deleted data can persist in backups for a short period before being overwritten |
8. Your rights, and how to delete your data
Under the DPDP Act 2023 you have the right to access a summary of your personal data, to have it corrected or completed, to have it erased, to nominate another person to exercise these rights if you die or become incapacitated, and to complain about how your data is handled.
Deleting your account and your data
You did not create your Anvay account — your Institute did — so there are two routes, and both work:
- Ask your Institute. It manages your account and can have it removed. This is usually fastest.
- Write to us at anvay2810@gmail.com, from your registered email address if you have one, or with your Institute’s name and your roll number if you do not. We will delete your account and the personal data associated with it, and confirm when it is done.
Why we may have to involve your Institute. If your Institute uses the reference only setting, we genuinely cannot tell which person a roll number belongs to — that mapping exists only at your Institute. We will work with them to identify your records.
We respond within 30 days. Anonymised, aggregate statistics that no longer identify you are not deleted, because they cannot be traced back to you.
Full details, including exactly what is removed and what is kept, are on our data deletion page.
9. Security
Data is transmitted over encrypted connections (TLS) and stored on managed infrastructure with encryption at rest. Passwords are stored only as cryptographic hashes and cannot be read by us. Access to the production database is limited to the founder. Database-level access rules mean an account can read only its own records, and an Institute can read only its own batches — this is enforced by the database, not only by the app.
We are a small, founder-run product and we will not pretend to be more than that: no system is perfectly secure. If a personal data breach affects you, we will notify the affected Institute and the Data Protection Board of India as the law requires, and we will tell you what happened and what to do about it.
10. Children
Anvay is intended for adult learners aged 18 and over, and our agreements require Institutes to confirm that the students they enrol are adults. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child’s data has reached us, write to anvay2810@gmail.com and we will delete it.
11. Changes to this policy
We will update this page when the service changes and change the effective date at the top. Material changes are notified to Institutes in writing before they take effect.
12. Contact
Questions, requests and complaints about this policy or about how Anvay handles data:
Aryan Barsaiya — Anvay
anvay2810@gmail.com
If you are not satisfied with our response, you may complain to the Data Protection Board of India.