This policy explains what the MindTree app and website collect, why, and what you can do about it. It covers the MindTree apps for iPhone and Android and the MindTree web platform.
Who we are
MindTree Academy is operated by Olivet Management Private Limited, 081/787, Olivet, Panavely, Kottarakkara, Kollam, Kerala 691532, India.
- General and privacy enquiries: [email protected]
- Support: [email protected]
- Grievance Officer (Digital Personal Data Protection Act, 2023): Nandan, [email protected], +91 974415878
We answer privacy requests within 30 days.
What we collect
When you create an account
- Email address and a password. We never store your password itself, only a salted hash of it, so nobody at MindTree can read it.
- A six-digit verification code sent to your email to confirm it is yours, and again when you sign in or reset your password. Codes are short-lived and single-use.
Your profile
Your name, the country you are in, your state (India only), your qualification level, the exam you are studying towards, and an optional short bio. You enter these yourself and can change them at any time in the app.
What you do while learning
- Which lessons you open, how much of a video you watched, how far you scrolled through a document and how long you spent reading it, and which items you have completed.
- Practice answers, scores and the questions you got wrong.
- Mock-test attempts, answers, timings and results.
- Your bookmarks, revision list and wishlist.
- Certificates issued to you, including the name printed on them and their verification code.
We use this to show you your progress, to decide when a module or certificate is complete, and to give your faculty an accurate picture of how their students are doing.
Questions you ask ("doubts")
The text of your question and any file you attach. MindTree faculty can read these in order to answer them. Please do not include anything in a doubt that you would not want your teacher to see.
During a proctored mock test
While a proctored test is open — and only then — the app:
- adds"(this applies throughout the app, to protect the course material, not only during a test)".
- This now contradicts the sentence just above it, which says "While a proctored test is open — and only then — the app:". I'd move screenshot blocking out of this list into its own line, for example: "The app prevents screenshots and screen recording on all screens, to protect course material. While a proctored test is open, it also records…"
- records three kinds of event and sends them to your faculty: that a screenshot was attempted, that you left the app, and that your network dropped.
These events are information for your faculty, not a verdict: none of them fails your attempt automatically, and a phone call that interrupts you counts as leaving the app. The app does not use your camera, microphone or location at any time, for proctoring or anything else, and never asks for permission to.
Your device
- A random identifier created when you install the app. It is not your phone's serial number, advertising identifier or anything Apple or Google assigns; it is a number we generate, it tells us nothing about you, and it is replaced if you reinstall the app.
- Your device model, operating system version and app version.
These let us show you the list of devices your account is signed in on, let you sign a device out remotely, enforce the limit on how many devices one account may use, and work out whether a bug affects a particular phone or app version.
Automatically, on our servers
Your IP address, the time of each request and basic technical details of it, kept in server logs so we can investigate faults and abuse.
Payments
Courses are bought on the MindTree website and in the Android app only. The iPhone app sells nothing and processes no payments.
Where you do pay, payment is handled by Razorpay, our payment gateway. Your card, UPI or netbanking details go to Razorpay, not to MindTree — we never see or store them. We keep the order itself: what was bought, when, how much, and the invoice.
What we do not do
- We use no analytics service and no crash-reporting service. There is no Google Analytics, Firebase, Crashlytics, Facebook SDK or equivalent in our apps.
- We use no advertising identifiers and show no adverts.
- We do not track you across other companies' apps or websites, and the app therefore never shows Apple's tracking-permission prompt.
- We do not sell your personal data, and we do not share it with data brokers.
Why we use your data, and on what basis
| What | Why | Basis |
|---|---|---|
| Account and profile | To give you an account, personalise your learning and print your certificates | Performance of our contract with you |
| Learning activity | To track progress, unlock exams and certificates, and report to your faculty | Performance of our contract |
| Doubts | To let faculty answer you | Performance of our contract |
| Proctoring events | To keep exams fair | Our legitimate interest in exam integrity |
| Device details | Device list, device limit, security and debugging | Our legitimate interest in securing accounts |
| Orders and invoices | To sell you a course and meet tax law | Contract, and legal obligation |
| Verification codes | To confirm it is really you | Performance of our contract, and security |
If you are in a country whose law requires consent for any of the above, we rely on the consent you give when you create your account, and you may withdraw it by deleting your account.
Who else sees it
We share personal data only with the companies that help us run the service, and only as much as they need:
- our hosting provider, which runs the MindTree servers;
- our media delivery network, which streams videos and serves documents;
- our transactional email provider, which delivers verification codes, receipts and notices;
- Razorpay, for payments on the website and Android app;
- Expo (EAS Update), which delivers app updates. It receives the app version and platform, not your personal data.
- adds a YouTube (Google) bullet covering privacy-enhanced embeds, no cookies until play, and Google receiving IP address and similar details once a video plays.
- Also change the full stop after the Expo bullet to a semicolon.
- If YouTube embeds are new in the iOS app, check that your App Store privacy label still matches.
Your faculty and MindTree administrators see your learning activity, your doubts and your proctoring events, because that is the point of the service. We also disclose data where the law requires it, or to protect our rights or someone's safety.
Our servers and providers may be located outside your country, including in India. Where we transfer data internationally, we do so under the protections that apply to those transfers.
How long we keep it
- Your account, profile and learning history: until you delete your account.
- Orders and invoices: retained after deletion, stripped of your personal details, because Indian tax law requires us to keep records of sales.
- Server logs: 90 days.
- Verification codes: minutes.
Deleting your account, and your other rights
You can delete your account yourself, from inside the app:
Profile → Settings → Account → Delete my account
Deletion is immediate and permanent. Your account, profile and learning history are erased, you are signed out on every device, and you cannot sign back in or recover the account. Invoices survive without your personal details, as described above. If you would rather we did it for you, write to [email protected].
You may also ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong or out of date;
- erase your data, or restrict or object to how we use it;
- withdraw consent where we relied on it;
- nominate someone to exercise these rights for you if you die or become incapable (India's DPDP Act); and
- complain to your data protection authority, or to our Grievance Officer above.
Write to [email protected] and we will reply within 30 days. Most of these you can do yourself in the app, which is faster.
Security
Everything travels over HTTPS with TLS. Your sign-in tokens are held in the iOS Keychain or the Android Keystore, not in ordinary app storage. Passwords are stored only as salted hashes. Access to production data inside MindTree is limited to the people who need it. No system is perfectly secure, and we will tell you and the authorities if a breach affects you and the law requires it.
Children
MindTree is for nursing students and nursing professionals. You must be at least 18 years old to hold an account, and the service is not directed at children. If you believe a child has created an account, write to [email protected] and we will delete it.
Changes
If we change this policy we will update the date at the top, and we will tell you in the app or by email if the change is significant.