Legal · Brute Info Edutech Private Limited
Privacy Policy
What we collect, why we collect it, who processes it, how long we keep it and the rights you have over it — including the fact that your learning record currently never leaves your own browser.
Brute Info Edutech Private Limited is the data fiduciary for the personal data described here. This policy explains, in plain language, exactly what the Brute Info platform does with information about you. We have written it against the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
- Data fiduciary
- Brute Info Edutech Private Limited
- Learning record
- Stored in your browser, not on our servers
- Payment data
- None collected — no gateway is connected
- Grievance officer
- privacy@bruteinfo.in
1.Who we are and what this policy covers
“We”, “us” and “our” mean Brute Info Edutech Private Limited, a company incorporated in India with its registered office at Unit 402, 4th Floor, Vantage Business Hub, Balewadi High Street, Baner, Pune, Maharashtra 411045, India. We are the data fiduciary responsible for deciding how and why your personal data is processed on the Brute Info platform.
This policy covers the website at bruteinfo.in and every feature reached through it — browsing the catalogue, creating an account, enrolling, using the classroom, the cart and checkout, orders, certificates and support correspondence. It does not cover third-party sites we link to, which have their own policies.
It sits alongside the Terms of Use and the Cookie & Local Storage Policy. Where a term is defined in the Terms of Use, it has the same meaning here.
2.What we collect
We collect only what the product needs to work. In practice that is four categories.
a. Account data
- your full name, as you enter it at sign-up or edit it later;
- your email address, which is also your sign-in identifier;
- a password, which is never stored in readable form — see section 10;
- the initials derived from your name, used to draw your avatar; and
- the timestamps of account creation, sign-in and password reset.
b. Learning data
- which courses and tiers you are enrolled in;
- which lectures you have marked viewed, and when;
- the progress percentage computed per course, and your streak and weekly-goal counters;
- notes you write against a lecture; and
- certificates issued to you, with their serial numbers.
c. Commercial data
- the contents of your cart, including the tier selected for each course;
- every order you place, whether it succeeds, fails or is a complimentary preview, with its invoice number, itemised amounts, GST component and failure reason; and
- coupon codes you attempt to redeem.
We do not collect payment instrument data. No card number, UPI handle, bank account, CVV or OTP is captured, transmitted or stored anywhere on the Platform, because no payment gateway is connected. Every payment attempt fails before any instrument is requested.
d. Preferences and technical data
- your appearance and learning preferences — theme, accent colour, density, text size, playback speed, autoplay, captions, reduced motion, high contrast, language, keyboard shortcuts, notification choices and profile visibility;
- the technical information every web server necessarily receives in order to serve a page: your IP address, user-agent string, referring page and the time of the request. On our current static hosting these appear only in the host's transient server logs; we do not aggregate, profile or resell them.
We do not operate advertising networks, behavioural profiling, cross-site tracking pixels or third-party analytics on the Platform. We do not knowingly collect sensitive personal data such as caste, religion, health, biometric or financial information, and you should not send it to us.
3.How we use it
Each category of data is used for a specific, stated purpose, and for nothing else:
| What | Why | Basis |
|---|---|---|
| Name and email | To create and authenticate your account, address you correctly, print your name on a certificate and send transactional email such as password resets | Performance of the contract with you |
| Learning data | To show your progress, resume you at the right lecture, compute course completion and issue certificates | Performance of the contract with you |
| Cart and orders | To process purchases, raise a tax invoice, keep a payment history and meet our statutory record-keeping duties | Contract and legal obligation |
| Preferences | To render the interface the way you asked for it, on this device | Your consent, given by changing the setting |
| Marketing email | To tell you about new courses and offers | Your consent, withdrawable at any time |
| Server logs | To keep the service available and to investigate abuse and security incidents | Legitimate use for the security of the service |
We never sell your personal data, and we never rent, trade or share it with data brokers. We do not use your data or your notes to train machine-learning models.
We do not take automated decisions that produce legal or similarly significant effects about you.
4.Your learning record stays on your device
Everything you do on the Platform is written to your own browser
Your account record, enrolments, per-lecture ticks, progress
percentages, notes, cart, orders, certificates and preferences are stored in
local storage on the device you are using, under keys beginning
bruteinfo:v1. They are not uploaded to a Brute Info server, because the
Platform currently runs without a backend.
The practical consequences are worth spelling out:
- Only you and anyone with access to that browser profile can read it. We cannot see it, and neither can any other learner.
- It does not follow you. Signing in on a different browser, a different device or a private window gives you a fresh, empty record.
- Clearing site data erases it permanently. Browsers also evict local storage on their own in low-storage or privacy-hardened configurations.
- We cannot restore it. There is no server-side copy and therefore no backup to recover from. This is a genuine limitation, not a policy choice, and we would rather tell you now than after you lose a month of progress.
If we later introduce server-side synchronisation, we will update this policy, tell you before it starts and give you the choice of whether your existing local record is uploaded.
The complete list of keys, and what each one holds, is published in the Cookie & Local Storage Policy. You can inspect every value yourself in your browser's developer tools, and erase all of them from Settings.
5.Children's data
The Platform is intended for adults and for senior students preparing for university and placement examinations. It is not directed at children.
- You must be 18 or older to open an account in your own name.
- A person aged 13 to 17 may learn on the Platform only through an account opened and operated by a parent or legal guardian, who is the account holder for all purposes.
- We do not knowingly collect personal data from anyone under 13, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children — activities that are in any case prohibited under section 9 of the Digital Personal Data Protection Act, 2023.
If you believe a child has given us personal data, write to privacy@bruteinfo.in. We will verify the request and delete the data within 7 working days.
6.Cookies and local storage
Brute Info sets no advertising cookies, no analytics cookies and no cross-site tracking cookies. We use the browser's local storage instead of cookies for almost everything, which means the data stays on your device and is never attached to a network request.
A single value — your resolved light or dark theme — is read before the page paints so that you never see a flash of the wrong colour scheme. Everything else is read after the page has loaded.
The full category-by-category breakdown, the key names, their purpose, their lifetime and a panel where you can change your choices is in the Cookie & Local Storage Policy.
7.Third-party processors
We keep the number of third parties deliberately small. These are all of them.
| Processor | Purpose | Data it can see |
|---|---|---|
| Google LLC — Firebase Authentication | Optional identity provider for email/password and Google sign-in. It is switched off
by default; when it is switched on, the Firebase JavaScript SDK is loaded from
www.gstatic.com |
Email address, display name, password verifier, sign-in timestamps and IP address |
| Google LLC — Google Fonts | Serves the two typefaces used across the site | IP address and user-agent of the request for the font file |
| GitHub, Inc. — GitHub Pages | Static hosting for the Platform | IP address, user-agent and requested URL, in transient server logs |
Authentication. The Platform ships with authentication running entirely in your own browser: accounts, password verifiers and sessions are held in local storage and no credential is transmitted anywhere. When Firebase Authentication is enabled by us instead, your email address and display name are processed by Google LLC under its own terms and Brute Info receives only the identifier, email address, display name and sign-in timestamps that Firebase returns. We will state clearly on the sign-in page which mode is active.
We have no advertising, analytics, tag-manager, chat-widget, heat-map, A/B-testing or session-replay provider. There is no fourth item on that list, and we will amend this policy before adding one.
8.When we share data
Beyond the processors listed above, we disclose personal data only in these circumstances:
- Where you ask us to — for example, when you make your learner profile public, or ask us to verify your certificate to an employer.
- Where the law requires it — in response to a valid, written order from a court, tribunal or authorised government agency in India. We satisfy ourselves that the request is lawful and proportionate, and we tell you unless we are legally barred from doing so.
- To protect people — where disclosure is strictly necessary to prevent serious harm, fraud, or a threat to the security of the Platform.
- On a business transfer — if the company is merged, acquired or restructured, data may transfer to the successor entity under the same commitments. You will be notified before your data becomes subject to a different policy.
We do not share your data with employers, colleges, recruiters or other learners without your explicit instruction.
9.How long we keep it
| Data | Kept for | Then |
|---|---|---|
| Account record and learning data | For as long as your account exists, on your device | Erased when you delete your account or clear site data |
| Preferences | Until you change or erase them | Reset to defaults |
| Orders, invoices and tax records | 8 financial years, as required under the Companies Act, 2013 and the Central Goods and Services Tax Act, 2017 | Deleted or irreversibly anonymised |
| Certificates and their serial numbers | Indefinitely, so that a certificate presented to an employer stays verifiable | Retained in a minimal, verification-only form |
| Support correspondence | 24 months from the last message | Deleted |
| Host server logs | As retained by our hosting provider, typically under 30 days | Rotated and discarded by the provider |
Where a statutory retention period applies, we keep the record for that period even if you ask us to erase it, and we tell you which obligation we are relying on.
10.Security
We take reasonable security safeguards proportionate to the data we hold:
- the Platform is served over HTTPS, and all third-party resources are loaded over HTTPS from a short, explicit list of hosts;
- passwords are never stored in readable form — a salted, irreversible verifier is stored instead, and password comparison is done against that verifier;
- no payment instrument data exists anywhere in the system, so it cannot be breached;
- because the learning record is held only in your browser, there is no central store of learner progress to compromise;
- access to any administrative tooling is limited to the small number of staff who need it, and is reviewed periodically.
No system is perfectly secure. If a personal data breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as required under section 8(6) of the Digital Personal Data Protection Act, 2023, without undue delay.
Protect your own account too: use a unique password, sign out on shared machines, and remember that anyone who can use your browser profile can read your learning record.
11.International transfer of data
Brute Info is an Indian company and processes personal data in India. However, some of the processors listed in section 7 operate globally distributed infrastructure, so limited data may be processed outside India:
- GitHub Pages serves the Platform from a content delivery network with points of presence worldwide; the request logs are held by GitHub, Inc. in the United States.
- Google Fonts serves font files from Google's global network.
- Firebase Authentication, where enabled, processes authentication data on Google infrastructure that may be located outside India.
Such transfers are made in accordance with section 16 of the Digital Personal Data Protection Act, 2023, and only to countries that the Central Government has not restricted. We rely on the contractual commitments in each provider's data processing terms to keep the protection travelling with the data.
Your learning record is not transferred anywhere at all — it never leaves your device.
12.Your rights
Under the Digital Personal Data Protection Act, 2023 you have the following rights over your personal data. Most of them you can exercise yourself, immediately, without asking us.
- Right to access
- Obtain a summary of the personal data we process about you and the processors it has been shared with. Your learning record can be read directly in your browser; write to us for anything held outside it.
- Right to correction
- Correct inaccurate or incomplete data. Your name and profile details are editable on the profile page.
- Right to erasure
- Ask us to delete your personal data where it is no longer needed for the purpose it was collected. You can erase your account and its entire local record from Settings. Statutory retention periods in section 9 are the only exception.
- Right to withdraw consent
- Where processing rests on your consent — marketing email, profile visibility, stored preferences — you can withdraw it at any time in Settings or on the cookie preferences panel. Withdrawal does not affect processing already carried out.
- Right to grievance redressal
- Have a complaint about our handling of your data considered by our grievance officer. See section 13.
- Right to nominate
- Nominate another individual to exercise your rights in the event of your death or incapacity. Write to us with the nominee's name and contact details.
To exercise a right that you cannot exercise from inside the product, write to privacy@bruteinfo.in from the email address on your account. We may ask a question or two to confirm it is really you. We respond within 30 days, and there is no charge unless a request is manifestly excessive or repetitive.
You also have duties under section 15 of the Act: do not impersonate anyone, do not suppress material information, and do not file a false or frivolous grievance.
13.Grievance officer
As required under the Digital Personal Data Protection Act, 2023, rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the following officer may be contacted about any grievance relating to the processing of your personal data.
Grievance Officer & Data Protection Contact
- Designation
- Grievance Officer, Brute Info Edutech Private Limited
- privacy@bruteinfo.in
- Telephone
- +91 20 6971 4400
Monday – Saturday, 10:00 – 19:00 IST - Postal address
- The Grievance Officer
Brute Info Edutech Private Limited
Unit 402, 4th Floor, Vantage Business Hub
Balewadi High Street, Baner
Pune, Maharashtra 411045, India
The officer acknowledges every grievance within 48 hours and disposes of it within 30 days of receipt, giving reasons for the decision reached.
14.How to complain
If you are unhappy with how your personal data has been handled, use this escalation path.
- Tell our support team first. Email support@bruteinfo.in or call +91 20 6971 4400 during support hours. Most issues are simply a misunderstanding about where data is stored, and are settled the same day.
- Escalate to the grievance officer. Email privacy@bruteinfo.in with the subject line “Grievance”, describing what happened, when, and what outcome you want. Include the email address on your account so we can locate the record. You will receive an acknowledgement within 48 hours and a reasoned decision within 30 days.
- Approach the Data Protection Board of India. If our decision does not satisfy you, you may complain to the Board established under the Digital Personal Data Protection Act, 2023, using the procedure it publishes.
- Consumer forums. Nothing here limits your right to approach the consumer redressal machinery under the Consumer Protection Act, 2019.
15.Changes to this policy
We revise this policy when the product changes or the law does. The “last updated” date at the top of this page always reflects the version currently in force.
Where a change materially affects your rights — a new processor, a new category of data, or the introduction of server-side storage of your learning record — we will notify you by email to the address on your account, or by a prominent notice on the Platform, at least 15 days before the change takes effect.
Superseded versions are retained internally so that we can tell you which policy applied on a given date. Ask privacy@bruteinfo.in if you need one.
Brute Info Edutech Private Limited
- Registered office
- Unit 402, 4th Floor, Vantage Business Hub
Balewadi High Street, Baner
Pune, Maharashtra 411045
India - Corporate Identity Number (CIN)
- CIN: pending — to be issued
- GST Identification Number (GSTIN)
- GSTIN: pending — to be issued
- Privacy contact
- privacy@bruteinfo.in
+91 20 6971 4400
Monday – Saturday, 10:00 – 19:00 IST
CIN and GSTIN are shown as labelled placeholders because the registrations are not yet issued. They will be published here in full before the Platform begins collecting payments — we will not display a number we do not hold.
Brute Info Edutech Private Limited — Privacy Policy, last updated 18 August 2026. Retrieved from bruteinfo.in/privacy.html