Version 2026-07-15 · Compliant with the DPDP Act 2023, the IT Act 2000 (as amended 2008), and the SPDI Rules 2011
Short version. We collect the minimum data needed to run an account-based learning platform. We do not sell your data, run behavioural ads, or profile you. You can export or delete everything from your account settings at any time. The long version below is written to satisfy India's privacy law in detail.
Under the DPDP Act 2023, Neuraedge.AI (Proprietorship) is the Data Fiduciary for personal data collected via pyrun.in. Our principal place of business is Mumbai, Maharashtra, India. The proprietor is Nitesh Sharma. Contact for privacy matters: grievance@pyrun.in (fallback hello@pyrun.in).
We do not knowingly collect sensitive personal data (as defined in Rule 3 of the SPDI Rules) beyond password hashes and financial identifiers strictly needed to run the Service.
We process personal data for the following specific, lawful, and proportionate purposes, primarily on the basis of your consent (DPDP Act §6) and, where applicable, contractual necessity to deliver the Service you have paid for:
We do not process your data for advertising, profiling, automated decision-making with legal effect, or resale to third parties.
| Category | Retention |
|---|---|
| Account data (email, progress, snippets) | Until you delete your account (30-day soft-delete window, then permanent purge) |
| Consent records | Retained for the life of the account plus 3 years thereafter (DPDP audit trail) |
| Server & access logs | 30 days, then rotated |
| Payment records & invoices | 8 years, as required by Indian tax and accounting law |
| Support correspondence | 2 years from last message |
| Grievance intake records | 5 years from resolution |
We do not sell your data. We do not share it with third parties for marketing. The following processors handle personal data on our behalf under contractual obligations that require confidentiality, reasonable security practices consistent with the SPDI Rules, and use limited to running the Service:
Some processors listed above operate outside India (Singapore, the United States, and the European Economic Area). Personal data transferred to these regions is protected by the processor's data-processing agreements with us, which include Standard Contractual Clauses where required. The Central Government has not, as of the version date of this Policy, notified any country as restricted under DPDP Act §16. If it does, we will update the processor stack accordingly and notify affected users.
Under the DPDP Act you have the following rights, which you can exercise free of charge:
/api/account/export./api/account/export is a structured, machine-readable JSON dump.Full details are on our Cookie Policy page. In summary we use a single first-party session cookie to keep you signed in, and a short-lived first-party referral cookie (30 days) only when you arrive via a referral link. We do not use third-party advertising or profiling cookies. Vercel Analytics is configured in cookie-less mode.
In compliance with DPDP Act §8(9) and Rule 5(9) of the SPDI Rules, we have appointed a Grievance Officer:
To file a grievance use /grievance. If our response is unsatisfactory, you may escalate to the Data Protection Board of India at https://www.dpdp.gov.in once it becomes operational.
If we discover a personal data breach that is likely to result in harm, we will notify each affected user by email and notify the Data Protection Board of India without undue delay and in any case within 72 hours of becoming aware. Details of what happened, what data was affected, what we have done, and what you can do will be published at /security.
The Service is not directed at children under 18. Under-18s may use the Service only with verifiable parental / guardian consent, who accepts our Terms on their behalf. Consistent with DPDP Act §9, we do not track, monitor, or profile children, and we do not serve them targeted advertising (we do not serve targeted advertising to anyone). If we become aware that we have collected personal data from a child without the required consent, we will delete it.
We follow reasonable security practices consistent with Rule 8 of the SPDI Rules — encryption at rest (Neon Postgres), TLS in transit, bcrypt password hashing, session cookies with HttpOnly, Secure, and SameSite=Lax flags, magic-link expiration, and rate limiting on sensitive endpoints. Detail is on our Security page, along with our coordinated-disclosure contact.
Some features (code explainer, project reviewer) call Anthropic's Claude API. This uses your own Anthropic API key, stored only in your browser's localStorage. The key is never transmitted to our servers. Requests go directly from your browser to Anthropic. We do not cache your code, your prompts, or the model's responses on our servers. Use of Claude is governed by Anthropic's terms, which you accept by using the feature.
We do not send marketing emails. The only messages you will receive from us are transactional (sign-in links, receipts, service-critical notices, and — if you opt in — occasional product updates you can unsubscribe from in one click).
If we materially change this Policy, we will email registered users and show a banner on the site at least 14 days before the change takes effect. Prior versions are available on request from the Grievance Officer. The current version and effective date appears at the top of this page.
Privacy questions or data requests? Email the Grievance Officer at grievance@pyrun.in (fallback hello@pyrun.in). General support goes to hello@pyrun.in.