01The short version
- We collect what we need to run a learning account: name, email, mobile number, grade, and what the learner does on the platform.
- We do not sell data. Ever. Not to advertisers, not to coaching centres, not to anyone.
- There are no advertising or analytics trackers on Lably. No Google Analytics, no Meta pixel, no ad SDK. We do not build advertising profiles of children.
- An account for someone under 18 must be held by a parent or guardian, and that parent can see, correct or delete everything in it.
- Payment details never touch our servers — Razorpay handles them.
- Want it all gone? Email support@lably.in from your registered address and we will erase it within 30 days.
02Who we are
Lably is a learning platform for school students in India, operating at lably.in and in the Lably mobile apps. Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary for the accounts people create directly with us — we decide what is collected and why. You are the Data Principal.
There is one important exception. When a school gives a student an account through Klasroom, the school decides what student data goes in and we process it on the school’s instructions. In that case the school is the Data Fiduciary and we are its processor. Requests about a school-issued account should start with the school — write to hello@lably.in if you need our help.
Our registered entity details are available on request at hello@lably.in.
03What we collect
This is the full list. If a field is not here, we are not storing it.
| Category | What exactly | Where it comes from |
|---|---|---|
| Account | Name, email address, mobile number and country code, the grade chosen at signup, and a one-way encrypted hash of your password (we cannot read your password). If you use Sign in with Google, we store your Google account identifier instead of a password. | You, at signup |
| Learning activity | Which labs, journeys, chapters and storybooks you opened; quiz and practice attempts and scores; code you submit in the Dojo; XP, level, streaks, badges, collected cards, league placement; certificates earned; time spent learning. | Generated as you use Lably |
| Child profiles | On a Family+ plan: the name, avatar, grade and progress of each child profile a parent creates (up to 4). | The parent who holds the account |
| Payments | The Razorpay order and payment reference, the amount, which plan it was for, whether it succeeded, and your plan status and end date. Not your card number, UPI ID, CVV or bank details — those go straight to Razorpay and never reach us. | Razorpay, when you pay |
| Device and session | The IP address, browser/device description (user-agent), session identifier and timestamp of your current login. This exists for one reason: Lably allows one active device per account, so we have to know which device is the current one. | Your device, at login |
| School link | For school accounts: the school and classroom the student belongs to, plus whatever the school records in Klasroom. | Your school |
| Optional profile | A public profile is off by default. If it is switched on, a short tagline and a limited public view (first name, grade, level, XP, streak, badges, league) becomes visible. Email, phone and school are never made public. | You, only if you turn it on |
| Support | Whatever you write to us in an email, and our replies. | You, when you contact us |
We do not ask for and do not want: your address, your date of birth, your income, government ID numbers, health information, biometrics, or your child’s photograph.
04Why we use it
- To run your account — signing you in, verifying your email with a one-time code, keeping you signed in, enforcing the one-device rule.
- To make learning work — saving progress, resuming where you left off, showing the right grade’s content, awarding XP, streaks, badges and certificates, running leagues and lab battles.
- To answer questions — sending a doubt to an AI model and returning the explanation (see section 7).
- To take payments — creating the order, confirming it, unlocking the plan, and issuing a refund if you ask for one.
- To tell parents how it is going — progress reports for the parent who holds the account.
- To keep the platform safe — rate limiting, blocking abuse, investigating fraudulent payments, and acting on reports of bullying.
- To improve Lably — understanding, in aggregate, which labs are used and where learners get stuck. This work is done on grouped data, not by profiling an individual child.
- To meet legal obligations — mainly keeping financial records.
Under the DPDP Act we rely on your consent, given when an account is created and when a payment is made, and on the “certain legitimate uses” the Act allows — for example, keeping records the law requires us to keep. You can withdraw consent at any time (section 10), though that generally means closing the account, because Lably cannot run without the data in section 3.
05Children’s data and parental rights
The DPDP Act treats everyone under 18 as a child and sets specific obligations. Here is how we meet them, and what it means for you as a parent.
Consent
An account for a learner under 18 must be created and held by a parent or legal guardian, using the parent’s email address. Creating the account and verifying that email is how consent is given. When a school issues the account, the school is responsible for having the parental consent before enrolling the student.
Three things we deliberately do not do
- No behavioural tracking of children. There is no advertising or analytics tracker anywhere on Lably. We do not follow a child around the internet.
- No targeted advertising. Lably shows no third-party ads at all, so there is nothing to target.
- No public exposure by default. Public profiles are off unless someone deliberately turns them on, and even then a child’s email, phone number and school are never shown.
What a parent or guardian can ask for
- A copy of everything held about their child.
- Correction of anything wrong — a misspelled name, the wrong grade.
- Deletion of the account and the data in it.
- Withdrawal of consent, which ends the account.
- An explanation of anything on this page that is unclear. Ask us. We would rather answer a question than lose your trust.
Email support@lably.in from the address registered on the account and we will action it. See section 10 for timelines.
A note on honesty. We cannot technically verify that the person at the keyboard is an adult. What we can do is design so that a child’s data is not exposed, not monetised and not tracked, and so that a parent can reach in and remove it at any time. That is the promise we are willing to make and keep.
07Who else sees your data
We use a small number of specialist services to run Lably. Each one sees only what it needs to do its job. This is the complete list.
| Service | What it does | What it receives |
|---|---|---|
| Razorpay | Takes payments and processes refunds | Your name, email, phone, the amount, and the card/UPI/bank details you enter into their checkout |
| Resend | Delivers our transactional email | Your email address and the contents of the message — sign-up verification codes, password resets, account notices |
| OpenAI and Google (Gemini) | Power the AI doubt-solver, the step-by-step Maths solver and AI-assisted grading | The question you asked and the context needed to answer it. We do not send your name, email or phone number. |
| Google (Sign in with Google) | Optional sign-in method | Only used if you choose it. Google confirms your identity and gives us your name, email and account identifier. |
| Google Fonts | Serves the typefaces the site is set in | Your IP address and browser, as with any file loaded from another domain. No account data. |
| Vercel | Hosts the website and stores media files (Vercel Blob) | Standard server request logs, including IP address. Lab images, audio and other media are served from their storage. |
| Sandboxed code runner | Compiles and runs code you write in the Dojo | The code you submitted and its input. Nothing that identifies you. |
We also share data where the law requires it — a valid order from a court or authority — and, if Lably is ever acquired or merged, with the acquirer, who would be bound by this policy. We would tell you before that happened.
08What we never do
- We never sell your data, or a child’s data, to anybody.
- We never pass your details to coaching institutes, publishers, lead brokers or advertisers.
- We never run third-party advertising on Lably, and we do not embed advertising SDKs or pixels.
- We never use a child’s learning data to build an advertising or behavioural profile.
- We never publish a learner’s identity without a deliberate opt-in.
If any of that ever changes, this page changes in the same release, and we email you first.
09How long we keep it
| Data | Kept for |
|---|---|
| Account and learning data | As long as the account is open. If an account sits completely unused for 3 years, we may delete it after emailing you first. |
| Email verification codes | Minutes. They expire and are discarded. |
| Session and device details | Overwritten each time you log in on a new device, cleared when you log out. |
| Payment records | Retained after account deletion, because Indian tax and company law requires financial records to be kept. Reduced to the minimum: amount, date, plan and payment reference. |
| Support emails | Up to 2 years, so we have context if you write again. |
| Certificates you have earned | Kept while the account is open. Deleting the account invalidates the public verification link — download anything you want to keep first. |
10Your rights, and how to use them
The DPDP Act gives you these rights. We honour all of them.
- Access — ask for a copy of what we hold about you or your child, and a list of who we have shared it with.
- Correction and completion — have anything wrong or out of date fixed.
- Erasure — have it deleted, unless the law requires us to keep a specific record (see section 9).
- Withdraw consent — at any time, as easily as you gave it.
- Grievance redressal — complain to us and get a response. If you are not satisfied, you may escalate to the Data Protection Board of India.
- Nominate — name someone to exercise these rights on your behalf if you die or become incapacitated.
How to ask
Email support@lably.in from the address registered on the account, and tell us what you want. Using the registered address is how we confirm it is really you — if you cannot, we will ask you a few questions to verify before we act.
Our commitment: we acknowledge every request within 2 working days, and complete access and correction requests within 30 days. Deletion is covered in the next section.
11Deleting your account
Being straight with you: there is no self-serve “delete my account” button in the app yet. Deletion today is handled by a person, on request. We would rather tell you that than put a button in this policy that does not exist. Building it is on our list.
Until then, here is the process, and we hold ourselves to it:
- Email support@lably.in from your registered address with the subject “Delete my account”.
- We confirm within 2 working days that we have received it.
- We erase the account and its learning data within 30 days of that confirmation.
- Payment records are kept in the reduced form described in section 9, because we are legally required to keep them.
- Deletion is permanent. Progress, streaks, cards and certificate verification links cannot be restored, so download any certificates you want to keep before asking.
- If you have an active paid plan and are within the 7-day window, ask for the refund at the same time — see the Refund Policy.
If your account was issued by a school, the school controls it. Ask the school to remove the student; we will act on their instruction.
12Security
- Everything travels over encrypted HTTPS connections.
- Passwords are stored as one-way hashes. Nobody at Lably — and nobody who steals our database — can read your password.
- Card, UPI and bank details never reach our servers; Razorpay handles them.
- Sign-in is rate limited, and one active session per account limits the damage a stolen password can do.
- Access to production data is limited to the people who need it.
No system is perfectly secure. If a breach ever affects your personal data, we will notify you and the Data Protection Board of India as the DPDP Act requires — promptly and with what we actually know, not a sanitised note weeks later.
If you find a security problem, please report it to support@lably.in. We will not pursue anyone who reports a genuine vulnerability responsibly and does not exploit it.
13Where data is stored
Lably is built and run in India. Some of the services in section 7 operate globally, so certain processing — hosting, email delivery, AI responses — may happen on servers outside India. Where that is the case, we use established providers with their own contractual data-protection commitments, and transfers are made in line with the DPDP Act and any restrictions the Government of India notifies.
14Changes to this policy
We will update this page when the product changes — a new feature, a new service provider. The “last updated” date at the top tells you which version you are reading.
For a change that materially affects how we use your data, we will email the address on your account before it takes effect.
15Contact and grievances
For anything about your data — a copy, a correction, a deletion, a complaint — write to support@lably.in. For anything else, hello@lably.in reaches us too.
We acknowledge within 2 working days and resolve grievances within 30 days. If we have not resolved yours to your satisfaction, you have the right to complain to the Data Protection Board of India.
More ways to reach us are on the contact page. The rules for using Lably are in the Terms of Service.
