Learn with direction.
An optional account saves your reading progress and your place in the course. Every lesson is also open to guests. Certificates are not available.
Effective 10 October 2026 · Version aabha-privacy-20261010-v4
Privacy notice
Who is responsible
Anand Pai V, an individual in Bangalore, operates AabhaAI Academy and is the contact for privacy requests and grievances: aabhaaiacademy@gmail.com. We acknowledge requests and aim to resolve verified account deletion within 30 days. Never send us your password.
Information and purposes
Required registration information is your email address, password, an 18-plus self-attestation, terms acceptance and privacy-notice acknowledgement. Passwords are stored as one-way hashes. Verification and reset messages contain account-action links. We record policy versions and decision times. Registration is for adults 18 or older; we do not collect a date of birth. Contact us if an underage person has registered.
An optional account stores lesson IDs read, the last lesson visited, course version and account activity times so you can resume reading. Profile preferences may include a display name, timezone, text size, contrast and motion preferences. Account data exports also include any existing enrolments, reflections and assessment history linked to your account. Authorised operations personnel can access records for support and maintenance. Guest reading needs no account.
Support correspondence contains the email, message and attachments you send. Send only what is needed. Server and delivery logs can include timestamps, request paths, IP addresses, browser information, delivery status and errors for security and troubleshooting. Account-action links should be treated as private.
Cookies and browser storage
The learner service uses an essential session cookie for sign-in and a CSRF cookie to protect forms. Sessions expire after 12 hours. The CSRF cookie may remain for up to one year. When you mark public lessons read as a guest, the course stores lesson IDs and your place in local browser storage on that device. This remains until you clear site data; signing in lets you save account progress separately. The separate browser lab uses local browser storage to keep your editor text and selected exercise until you reset it or clear site data. Its code runs in your browser; saving this editor text does not save account learning progress. Cloudflare may set security cookies when serving the site. You can clear browser cookies and storage; doing so signs you out or removes local editor text.
Retention and deletion
Unverified registrations are closed after seven days. Active accounts and progress remain while used. After 24 months without authenticated activity, we send a notice and allow 30 days to sign in before closing the account. You can request deletion with your current password from your profile. The daily retention process removes eligible live identity and learning records within 30 days of a verified request; processing may happen sooner. Cancellation is available until processing starts.
After closure we retain limited consent and request records, linked to an inactive account reference without email, name or usable password, for 12 months. These records then expire. Support correspondence follows a 12-month policy after resolution and is reviewed separately by the operator; deletion from the mailbox and its recovery history is not handled by the account timer. Aabha account security and access logs are date-rotated and expire within 180 days, except where a specific legal requirement or documented dispute requires longer retention. Provider recovery copies follow separate policies.
Copies may remain in restricted operational backups and provider recovery systems. Backup expiry is not currently enforced, so we cannot promise a fixed final-erasure date for all backup copies. We keep a minimal erasure record without email or learner work to reapply deletions before allowing access after a database restore. This record remains while an older recoverable backup could otherwise restore an erased account. Backups are used for recovery, not ordinary account access.
Providers and locations
MilesWeb hosts the website, learner application and database. Resend delivers account messages using the recipient address, message and action link. Our current account uses standard-plan limits; Resend publishes 30-day email-data retention for standard plans. Email sending region does not determine all account-data locations: Resend states that email metadata, logs and API records are stored in the United States. Resend retention information and region information.
Google Gmail handles messages sent to the Academy mailbox. Operational backups are kept on the VPS and in Dropbox when the configured external backup runs; copies and recovery history can persist separately. Cloudflare provides DNS, proxy delivery and security. Providers may process data in other countries under their service terms. We do not sell learner data or use saved reading progress for advertising. Current public course reading does not send learner work to an external AI grading service. We may disclose information where required by applicable law or valid legal process.
Your choices and security
You can continue reading without an account, edit profile preferences, export your account data, reset your password or request account deletion. Contact us to correct information, withdraw an applicable consent or raise a grievance; some requests require proportionate identity verification. Withdrawal may prevent features that depend on the information. HTTPS, password hashing, access restrictions and account-session controls reduce risk, but no online service guarantees absolute security.
Changes
We will update this notice when practices change and show a new effective date. We will notify account holders of material changes and take any required consent or other legal step before a new use begins.