Privacy Policy

What Pravaha collects, why, who can see it, and how to get it removed.

Last updated

Who we are

Pravaha (pravaha.academy) is a learning platform operated by Samagra Tech, India. In this policy “we” and “us” mean Samagra Tech, and “Pravaha” means the platform itself.

For anything in this policy, write to hello@samagra.xyz.

Two different relationships

Pravaha is sold to organisations, and that changes who is answerable for your data.

If you use Pravaha because your employer or institution runs it. Your organisation decides what programs you take, who can see your progress, and how long your account lives. Under India’s Digital Personal Data Protection Act, 2023, your organisation is the Data Fiduciary and we act as its Data Processor: we handle your data on their instructions and for no purpose of our own. If you want your learning data corrected or removed, ask your organisation first. We will act on their instruction, and we will help you reach the right person if you write to us instead.

If you visit this website or fill in the contact form. There is no organisation in between, so we are the Data Fiduciary for that data and this policy is the whole story.

What Pravaha collects

Account details

Your name, work email address, the organisation you belong to, and your role in it (learner, trainer, manager). Passwords are stored only as a salted hash, never as text we can read. If you sign up yourself, we send a one time code to your email to confirm the address belongs to you.

Learning activity

The programs you enrol in, the units you complete, your answers in the AI reinforcement chat and the questions that prompted them, grades, the number of attempts, time taken, completion dates, and any certificate issued to you. Trainer notes written about your work are stored alongside it.

Assessment integrity signals

Pravaha’s assessments are unsupervised, so the platform records how an answer was produced in order to tell composed work from pasted work. While you are answering a question in the reinforcement chat, we record:

Signal What it means
Tab switches That you left the page, and for how long. Not where you went.
Copy events That text was copied from the assistant’s message
Pastes That text was pasted, and whether its content came from the conversation itself
Typing and revision bands The start and end times of bursts of typing and of deleting. Not the keys pressed.
Injected text That text appeared in the answer box with no typing or allowed paste behind it
Time on question From the question appearing to your submission

From these we compute an estimated probability that outside assistance was used, and store it with the answer. Your trainer sees this number.

Two things this is not. It is not a keystroke log: we keep the timing and shape of typing, not a record of every character you type on the way to an answer. And there is no camera, microphone, screen recording, or software installed on your machine. Everything above is measured by the web page you are already on, and only while an assessment is open.

GitHub activity, if your organisation turns it on

The GitHub integration is off unless your organisation enables it, and it needs two separate consents: an administrator installs our GitHub App on your GitHub organisation and chooses which repositories it may read, and you separately connect your own GitHub identity from your settings page.

Once both exist, we read the pull requests you authored in those repositories that have since been merged or closed, and store the pull request title and description, the code changes in it, the review conversation on it including comments written by your reviewers and by bots, and the timestamps around it. An AI analysis of that material produces observations about your work, each one anchored to a specific comment, commit, or file that a trainer can click through and read for themselves.

Two limits are built in. We store no GitHub access token for you: your token is used once to read your username, then discarded. And we never look further back than the later of the day the app was installed and the day you connected, so nothing that happened before both consents existed is ever fetched. You can disconnect at any time from your settings.

Technical data

Server logs holding IP address, browser and device information, and the requests made. These exist for security and debugging and are not used to build a profile of you.

Enquiries to us

If you fill in the contact form on this site we receive the name, role, and work email you typed, so that we can reply.

Cookies and local storage

This marketing site sets no cookies and runs no analytics. There is no Google Analytics, no advertising pixel, and no third party tracker on pravaha.academy.

Inside the application, your browser holds your sign in token in local storage so that you stay signed in, and a small cookie remembers whether you left the sidebar open. Both are functional. Neither follows you anywhere else.

Why we process this

We do not sell personal data. We do not use it for advertising, and we do not profile you for any purpose outside the service.

AI processing

Parts of Pravaha are built on large language models, which means some of your content is sent to a model provider to be processed and a response returned. Specifically:

We currently use Anthropic (United States) and DeepSeek (China) as model providers. Data is sent to them to produce a response for you and is governed additionally by their own terms. If your organisation needs model processing confined to a particular provider or region, contact us before you deploy.

Who else touches your data

We use a small number of service providers, and only for the purpose named:

Provider Purpose Where
Cloud infrastructure provider Application, database, and backup hosting Europe or India
Anthropic Assessment conversation and grading, certificate summaries United States
DeepSeek Question grading, pull request analysis China
Resend Transactional email delivery United States
GitHub Source of pull request data, only if enabled United States
Formspree Contact form on this website only United States

Inside your own organisation, trainers and managers can see your enrolments, progress, assessment answers, grades, integrity signals, and any GitHub observations. That is the point of the product, and it is worth knowing plainly.

Beyond this, we disclose personal data only where the law requires it, or to protect the rights and safety of users.

Where data is stored and for how long

Pravaha runs on cloud infrastructure hosted in Europe or India. We may move between providers or between those two regions as the service grows, and will tell customer organisations before we do. The database is backed up daily, in the same region as the data it came from, and backups are kept for 30 days before being deleted automatically.

If your organisation needs its data pinned to one region, tell us before you deploy and we will confirm in writing.

Your learning data is retained while your organisation’s account is active and your account exists within it. When an account is deleted or an organisation ends its subscription, we delete the data on request and it drops out of the backups within 30 days. Contact form submissions are kept while the conversation is live and for as long as needed to answer it.

Security

Traffic is encrypted in transit with TLS. Passwords are stored as salted hashes. Every query in the application is scoped to a single organisation, so one customer’s data cannot be reached from another’s account. Database access is not exposed to the public internet. Backups run daily on the same infrastructure.

No system is perfectly secure. If you believe you have found a vulnerability, write to hello@samagra.xyz and we will respond.

Your rights

Under the Digital Personal Data Protection Act, 2023, you may ask for access to the personal data we hold about you, correction of anything inaccurate, erasure of data no longer needed, and you may nominate someone to exercise these rights if you die or become incapacitated. You may withdraw a consent you gave, for example by disconnecting GitHub.

If you use Pravaha through an employer or institution, send these requests to them first: they decide what happens to learning records they commissioned. For everything else, write to hello@samagra.xyz and we will respond within 30 days.

If you are unhappy with how a request was handled, our grievance contact is the same address. You may escalate to the Data Protection Board of India.

If you are in the European Union or United Kingdom, we will honour equivalent rights of access, rectification, erasure, restriction, and portability on request.

Children

Pravaha is built for workplace and professional training and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child’s data has reached us, write to us and we will remove it.

Changes

If this policy changes materially, we will update the date at the top of the page and tell customer organisations directly. Continued use after a change means the updated policy applies.

Contact

Samagra Tech hello@samagra.xyz

Questions about this page? Write to hello@samagra.xyz.