Skip to content
Privacy

What we collect, and what we don't

This describes what actually happens in the product, not what a template says. If you find something here that does not match how Raysheo behaves, that is a bug and we want to know.

Last updated 22 August 2026.

What we collect

Very little, and all of it is either something you typed or something a web server records to work at all.

When you create an account we store your email address, a display name, and your password — the password as a one-way hash, never as text anyone can read, including us.

If you sign in with Google or Apple, they send us your email address and name. Those are the only things we ask for. We do not request access to your Google Drive, contacts, calendar or anything else, and could not read them if we wanted to. Apple lets you hide your real email address; if you do, we only ever see the relay address.

If you pay for Raysheo Plus, see “Who processes data for us” below for what we receive — it is never your card or bank details.

Our web server keeps ordinary access logs: IP address, time, the page requested, and your browser's user-agent string. Every web server does this, and it is how we notice an outage or an attack.

As you study, we store your progress — which cards you have seen, how you rated them, your answers to practice questions, your bookmarks and your own notes. That is the point of an account: so it is still there on your phone tomorrow.

What we do not do

These are worth stating plainly, because they are the questions people actually have.

  • We do not sell your personal data. Not to anyone, at any price.
  • We do not share it with advertisers, data brokers or "partners".
  • We run no advertising.
  • We have no third-party analytics — no Google Analytics, no Meta pixel, no session recording. There is no such code in the product.
  • We do not build a profile of you for anything other than showing you your own study progress.
  • We set no tracking cookies.

If that ever changes, this page changes first, and we will say so rather than quietly editing a paragraph.

Who processes data for us

A handful of companies touch some part of this. Here is exactly what each one does.

  • Supabase hosts our database and handles sign-in. Your account and your study progress live there. The database is in the Mumbai region, so this data is stored in India.
  • Cloudflare Turnstile checks that a sign-in attempt is a person rather than a script. Cloudflare state that it sets no tracking cookie and shows no puzzle, which is why we use it instead of the alternatives.
  • Google Fonts serves the two typefaces this site uses. That means Google receives your IP address when a page loads. We would rather it did not, and self-hosting the fonts is on the list.
  • Resend sends account email — confirmations, password resets and payment receipts. It sees your email address and the message.
  • Apple and Google Play bill the subscriptions bought in the iPhone and Android apps, under their own privacy terms. They handle your payment details; we receive confirmation that a subscription is active, never your card.
  • UPI payments on the web go from your UPI app straight to our bank. The bank’s credit notification gives us the transaction reference (UTR), the amount, the payer name and bank, and the last digits of the paying account. We keep these to match the payment to your account and as the tax record of the sale. No payment gateway sits in between, and we never see a card number.

Signing in with Google or Apple means that company knows you have an account with us. That is inherent to using it, and email sign-up avoids it entirely.

What is stored on your device

The app is built to work without a signal, which means it keeps things locally.

  • Downloaded subject packs — the cards, questions and notes — so a session works on a train with no connection.
  • Your sign-in token, so you are not asked to sign in every time.
  • Your study progress, until it syncs.

On the web this uses your browser's local storage; in the mobile apps it is the app's own private storage. Signing out clears the token. Clearing your browser data or deleting the app removes the rest.

How long we keep it

Your account and progress stay until you delete the account. When you do, we delete them.

Server access logs are kept for 14 days and then discarded.

If you ever paid for Raysheo, the record of that payment is kept for as long as Indian tax and accounting law requires, even after the account is deleted. That is a legal obligation, and it is an invoice, not study data.

Your rights

Under India's Digital Personal Data Protection Act 2023 you can ask us to show you what we hold about you, correct it if it is wrong, delete it, or give you a copy to take elsewhere. If you are outside India you may have similar rights under your own law, and we will not argue about which applies — ask, and we will do it.

Write to hello@raysheo.com. We will respond within 30 days.

The Act also requires us to name a person who handles these requests: Amitsingh Rajput (hello@raysheo.com).

Security

Passwords are hashed, never stored in a readable form. Traffic to and from the site uses HTTPS. Database access is restricted per-account, so one student's rows are not reachable by another.

No system is perfect, and anyone claiming otherwise is selling something. If you find a problem, tell us at hello@raysheo.com and we will take it seriously.

Children

Raysheo is built for students on a law degree, and is not directed at children under 18. We do not knowingly collect data from them. If you believe a child has created an account, tell us and we will remove it.

Changes

If this policy changes in a way that affects you, we will say so in the app rather than relying on you noticing a new date at the top of a page.

Who we are

Raysheo is operated by Frontier Digital, Pune, Maharashtra (frontierdigital.in). Contact: hello@raysheo.com.