Privacy Policy

We are committed to protecting your personal data. This policy explains what we collect, how we use it, and your rights as a Kushora platform user.

Last Updated: June 2026

1. Overview

Welcome to Kushora ("we", "our", "us"), an Engineering Placement Preparation Platform. This Privacy Policy governs the collection, processing, storage, and use of personal information when you access or use Kushora at kushorra.web.app and any associated mobile or desktop interfaces.

Kushora is operated by Kushora Technologies, registered in India. Our platform serves three categories of users: Students, Staff (faculty / placement coordinators), and Institutional Administrators.

By registering on or using Kushora, you confirm that you have read and understood this Privacy Policy, and that you consent to the processing activities described herein. If you do not agree, please do not use the platform.

This Privacy Policy should be read alongside our Terms of Service. Both documents together govern your use of Kushora.

2. Data We Collect

We collect the following categories of data depending on your role on the platform:

2.1 Student Data

Data Type Examples Purpose
Identity Data Full name, enrollment/roll number, email address, mobile number Account creation & authentication
Academic Data Branch, semester, year of study, institution name Performance grouping & analytics
Assessment Data Aptitude test scores, coding submission code & outputs, interview responses, time taken, attempt history Progress tracking & AI evaluation
Proctoring Sensory Data Temporary browser camera/webcam stream, microphone audio decibels, active browser tab visibility state Active test proctoring & academic integrity auditing. (Note: Video and audio feeds are processed strictly client-side in your browser; no recordings are uploaded or saved.)
Profile Data Profile photo (optional), bio, skill tags Dashboard personalisation
Usage Data Pages visited, test start/end times, sessions, device/browser type Platform analytics & UX improvement

2.2 Staff Data

  • Full name, staff ID, designation, department, email address
  • Institution affiliation and assigned student cohorts
  • Activity logs (students accessed, reports generated)

2.3 Institutional Administrator Data

  • Institution name, address, AICTE/UGC affiliation code
  • Admin contact name, official email, and phone number
  • Subscription tier, billing contact, and access request details

3. How Data is Collected

We collect your data through the following channels:

  • Registration Forms: When a student, staff member, or institution submits a registration or access request form.
  • OTP Verification: Email-based OTP verification (via Google Apps Script) during account signup and login processes.
  • Test Submissions: Answers, code, time logs, and scores captured automatically when you submit Aptitude, Coding, or Interview practice assessments.
  • Firebase Authentication: Login events, session tokens, and UID assignment are handled and recorded by Firebase Authentication (Google).
  • Browser Cookies & Local Storage: Session persistence tokens and preferences stored in your browser's localStorage.
  • Usage Analytics: Page navigation, feature interactions, and error events captured via browser telemetry.

4. Use of Your Data

We use the data we collect for the following purposes:

  • Account Management: To create, authenticate, and manage your Kushora account securely.
  • Assessment Delivery: To serve aptitude questions, coding problems, and mock interview prompts tailored to your academic level.
  • Performance Analytics: To compute scores, generate progress reports, identify skill gaps, and display leaderboards visible to authorised staff.
  • AI-Based Evaluation: To submit your coding solutions and interview responses to AI evaluation models that generate automated feedback, scoring, and improvement suggestions.
  • Staff Reporting: To provide placement coordinators and faculty with aggregated and individual student performance dashboards.
  • Notifications: To send OTP emails, test result alerts, and important platform announcements via email.
  • Platform Improvement: To analyse usage patterns, fix bugs, and improve platform performance and user experience.
  • Legal Compliance: To fulfil obligations under applicable Indian laws, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDPA).

We do not use your personal data for targeted advertising, sell your data to third-party marketers, or use your data for any purpose unrelated to educational placement preparation.

5. Firebase & Cloud Storage

Kushora uses Google Firebase (a Google LLC product) as its primary cloud backend. By using Kushora, you acknowledge that your data is processed and stored on Firebase infrastructure, which may involve servers in multiple geographic regions.

Firebase Services Used

  • Firebase Authentication: Manages your account login, session tokens, and identity verification.
  • Firebase Realtime Database: Stores student profiles, test records, scores, staff data, and institution configurations in real-time.
  • Firebase Hosting: Serves the Kushora web application files globally via Google's CDN.

Firebase's data handling is governed by Google's Privacy Policy and the Firebase Data Processing and Security Terms. We recommend reviewing these documents at firebase.google.com/support/privacy.

Firebase Realtime Database data is secured using Firebase Security Rules. Only authenticated users with the correct role (student, staff, or admin) can access their designated data nodes. Unauthorised cross-role data access is blocked at the database rule level.

6. AI & Automated Processing

Kushora employs AI-based automated evaluation for the following platform features:

  • Coding Assessment Evaluation: Your submitted source code and output are processed by an AI model that assesses correctness, time complexity, code quality, and edge-case handling. Feedback is generated automatically.
  • Mock Interview Evaluation: Text-based interview responses submitted through the platform are analysed by a language model for communication clarity, technical accuracy, and structured thinking. AI-generated scores and improvement tips are returned.
  • Automated Proctoring Audits: If required by the test coordinator, the platform uses client-side face-detection algorithms (via face-api.js) and sound frequency monitors (via browser Web Audio analyser) to detect academic dishonesty patterns. These checks run entirely inside the user's web browser locally. No audio, photo, or video recordings are saved, stored, or transmitted outside your local machine. Only resulting numerical security violation counts (e.g. warning tallies) are saved to your test profile database node.

This constitutes automated decision-making as defined under data protection regulations. The AI-generated scores may be reviewed by your institution's staff and used for placement readiness assessment.

AI evaluations are advisory and not final. You may contact your institution's placement coordinator to request a human review of any AI-generated score you believe to be inaccurate.

Submitted content (code, interview answers) may be temporarily processed by third-party AI APIs (such as Google Gemini). We do not permit these APIs to retain or train on your data beyond the scope of a single evaluation request, in accordance with their enterprise data use policies.

7. Data Sharing

We do not sell, rent, or trade your personal data. We may share limited data in the following circumstances only:

  • Within Your Institution: Your performance data (scores, test history, skill gap analysis) is visible to authorised staff and institutional administrators at your registered institution. This is the core purpose of the platform.
  • Service Providers: We share data with Google (Firebase, Gemini AI) and Google Apps Script (email delivery) strictly to operate the platform. These providers are bound by data processing agreements.
  • Legal Obligations: We may disclose personal data if required by a court order, government authority, or applicable law — including the Information Technology Act, 2000 and the DPDPA 2023.
  • Business Transfer: In the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity, provided they commit to this Privacy Policy or an equivalent standard.

Student data is never shared with placement companies, recruiters, or any external third parties without explicit, informed, opt-in consent from both the student and their institution.

8. Data Retention

We retain your personal data for as long as is necessary to fulfil the purposes described in this policy, or as required by applicable law:

Data Category Retention Period
Student account & profile data Until account deletion request or 1 year post-graduation (whichever is earlier)
Assessment scores & attempt history Duration of active institutional subscription + 6 months
Staff & admin account data Until role deactivation or institutional contract expiry + 3 months
OTP and authentication logs 30 days from generation
Usage analytics & error logs 90 days (rolling window)
AI evaluation inputs (code, interview text) Processed in real-time only; not persistently stored beyond the test result

After the applicable retention period, data is either permanently deleted from Firebase or anonymised so that it can no longer be associated with any individual.

9. Your Rights

Under the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian law, you have the following rights with respect to your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Correction: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your account and associated personal data, subject to retention obligations.
  • Right to Grievance Redressal: File a complaint with our Data Protection Officer if you believe your rights have been violated.
  • Right to Nominate: Nominate another individual to exercise rights on your behalf in the event of death or incapacity.
  • Right to Withdraw Consent: Withdraw consent to processing where consent is the legal basis; note that withdrawal may limit platform functionality.

To exercise any of these rights, contact us at privacy.kushora@9teeninitiative.com. We will respond within 30 days of receiving your verified request.

Minors under the age of 18 must have parental or guardian consent to use Kushora. If we discover that data from a minor has been collected without appropriate consent, we will delete it promptly.

10. Cookies & Tracking

Kushora uses a limited set of cookies and browser storage technologies:

Type Purpose Duration
Session Cookies Maintain your login session after authentication Until browser is closed
LocalStorage Tokens Store Firebase auth tokens for persistent login Until logout or token expiry
Preference Storage Remember UI preferences (theme, language) Until cleared manually
Firebase SDK Cookies Firebase Analytics and Authentication internal state Managed by Firebase SDK

We do not use third-party advertising cookies, cross-site tracking pixels, or social media tracking widgets on Kushora. You may clear browser cookies and localStorage at any time; this will log you out of the platform.

11. Data Security

We implement industry-standard security measures to protect your data from unauthorised access, disclosure, alteration, and destruction:

  • HTTPS / TLS Encryption: All data transmitted between your browser and Kushora servers is encrypted in transit using TLS 1.2 or higher.
  • Firebase Security Rules: Role-based access control is enforced at the Firebase Realtime Database level, ensuring students can only access their own records and staff can only access authorised cohorts.
  • OTP-Based Verification: Account registration and sensitive actions require OTP email verification, reducing the risk of unauthorised account creation.
  • Authentication Tokens: Firebase Authentication issues short-lived ID tokens that are automatically refreshed and expire on logout.
  • No Plain-text Passwords: Kushora does not store plain-text passwords. Authentication is managed entirely by Firebase Authentication (which uses industry-standard hashing).
  • Data Isolation: Each institution's data is scoped to their institutional node in the Firebase database, preventing cross-institution data leakage.

While we take all reasonable precautions, no system is completely immune to security risks. In the event of a data breach affecting your personal data, we will notify you as required by the DPDPA 2023 within the prescribed timeframe.

12. Contact Us

If you have any questions, concerns, or requests related to this Privacy Policy or the handling of your personal data, please contact our Data Protection Officer:

We reserve the right to update this Privacy Policy from time to time. Significant changes will be notified via email and a prominent notice on the platform. Continued use of Kushora after such notification constitutes acceptance of the revised policy.

This Privacy Policy is governed by and construed in accordance with the laws of India. Disputes shall be subject to the exclusive jurisdiction of the courts located in Gondia, Maharashtra, India.

No sections found

Try a different keyword to search the Privacy Policy.