Privacy Policy
Last updated: 7 September 2026
Lipi collects the minimum data needed to run a learning platform, and treats children’s learning data with particular care.
What we collect
- Account: your email address, name (optional) and a hashed password. We never store card numbers — India payments are processed by Razorpay and international payments by Stripe.
- Learning activity: which chapters and practice sessions a profile completes, time spent, and quiz outcomes. This powers progress views and smart review.
- Child profiles: a display name, board, class and language chosen by the parent. We do not ask children for contact details.
- Site usage: which pages are opened and for how long, described in “On-site analytics” below.
- Invites: if you create your account after opening a friend’s invite link, we record that friend’s invite code against your new account so they can earn a free month when you buy a module; they see only your first name, never your email address.
How learning data is used
- Progress and mastery signals stay private to the learner; parents see privacy-safe aggregates and never ordinary quiz answers or private notes.
- For a child profile, Ask Lipi questions and a bounded answer record are saved for up to 90 days and are visible only to the verified household owner. The child is told beside the composer before using AI.
- AI study help runs on lesson content we host; questions are used to answer the learner, measure credits and keep the service safe—not to build advertising profiles.
- We do not sell personal data, and we show no third-party advertising.
On-site analytics
We measure how the site is used with our own code, on our own servers. Nothing in this section is shared with an advertising network, and none of it is used to rank, compare or diagnose a child.
What is recorded
- The pages you open and the order you open them in, with a random visitor id and session id (the cookies below) so we can count visits and returning visitors.
- How long a page was actually visible on your screen, so we know which lessons are read and which are abandoned.
- Device type — phone, tablet or desktop — and nothing more specific than that.
- Your pricing region: India or international.
- The website you came from (the site name only, never the full page), and any campaign or partner code on the link you clicked.
- Events such as opening a lesson, reaching a paywall, signing up, signing in, starting checkout and completing a purchase. Purchase events carry the order amount and currency, never card details.
What is not recorded
- Your IP address and browser details are read when an event arrives — to classify the device and to rate-limit abuse — and are then discarded. They are not stored with the event.
- No names, email addresses or profile names are attached to analytics events. Signed-in events carry only an internal account id, which is deleted with your account.
- No cross-site tracking, no fingerprinting, no advertising profiles, and no sale of data. The visitor id is a random number that identifies nothing outside lipi.study.
How it is used
- The Lipi team sees aggregate reports only: pages, boards, classes, subjects and chapters, sources and totals per day.
- Reports use minimum group sizes — a figure that would describe fewer than five sessions is shown as “<5” — so no individual child or family is ever shown.
- There is no screen anywhere in Lipi that shows one visitor’s or one child’s browsing history.
Retention
- Raw analytics events are deleted after 13 months. Visitor ids expire with the cookie (180 days). Partner-link and campaign visit records, which partners need for commission reconciliation, are deleted after 13 months as well.
- Aggregates that contain no identifiers (for example “how many lessons were opened in Class 6 Maths in August”) may be kept.
Google Analytics
- Google Analytics runs only on our public marketing pages (home, catalogue, pricing, blog and similar). It is switched off in every learning and signed-in area: the learning and reading pages, and the child, parent, self, account, profiles, progress, plans and reviews pages. If you open one of those areas from a marketing page, Google’s script is told to stop measuring until you return.
- Where it runs, Google’s advertising signals and ad-personalisation are switched off, and page views are sent from our own code so both systems count the same thing. Google receives the page path only — not the page title, the full address, search terms or share links.
- Purchases and checkouts are not reported to Google at all; those figures live only in our own first-party analytics.
- We never send Google your account id, email, profile role, or the Lipi visitor or session ids.
Your choices
- We honour the Global Privacy Control signal: if your browser sends it, the analytics visitor cookie is not set and your visits are not linked across sessions.
- You can clear cookies and site data for lipi.study in your browser’s settings at any time. Clearing them signs you out and starts you as a new visitor.
Cookies and browser storage
These are all first-party: set by lipi.study, readable only by lipi.study. We set no third-party advertising or cross-site tracking cookies. The sign-in cookie, the invite code (lipi_invite) and the analytics visitor id (lipi_v) are marked so page scripts cannot read them; the session id (lipi_sid), partner code (lipi_ref) and pricing region (lipi_region) are readable by our own page scripts by design, and each row below says so.
| Name | Purpose | Lifetime |
|---|---|---|
| authjs.session-token | Keeps you signed in. Marked so page scripts cannot read it. | Until you sign out, or the session expires |
| lipi_active_profile | Remembers which learner profile in your household is active. | 90 days |
| lipi_region | Remembers whether you see Indian (INR) or international pricing. Readable by page scripts so the price switch works without a reload. | 180 days |
| lipi_v | A random analytics visitor id, so we can tell new visitors from returning ones. It is not built from your address or device, is not readable by page scripts, and is never sent to Google. Not set at all when your browser sends the Global Privacy Control signal. | 180 days |
| lipi_sid and the browser storage key lipi_session | A random session id that groups the pages you open in one visit. The session renews after 30 minutes of inactivity or at the start of a new day (Indian time). Readable by page scripts by design: the page mints it and the server reads the copy. | 1 day (session id in storage renews itself) |
| lipi_utm | Campaign parameters (utm_source, utm_medium, utm_campaign, utm_content) and the page you arrived on, taken from the link you clicked to reach Lipi. | 30 days |
| lipi_campaign | The campaign code from a Lipi short link (lipi.study/go/...), so we can see which campaign a sign-up or purchase came from. | 30 days |
| lipi_ref | The partner code from a partner referral link, so the partner who recommended Lipi can be credited. Readable by page scripts by design, so the sign-in page can claim the referral. | 90 days |
| lipi_invite | The invite code from a friend's invite link (lipi.study/join/...), so the friend who invited you is credited when you create an account. Marked so page scripts cannot read it, and removed once you create an account or sign in. | until you create an account or sign in, at most 30 days |
| lipi_site_access | Only during a private preview: remembers that you entered the preview access code. | While the preview gate is switched on |
Earlier versions of the site used a per-tab identifier that died with the tab; it has been replaced by the session id above so that visits across several tabs count once.
Retention and deletion
A parent can export, delete or pause future child-profile AI activity directly in the Parent hub. You can request deletion of your account and all associated profiles and learning data by writing to care@lipi.study from your account email. We delete within 30 days, except records we must keep for tax and payment compliance.
Analytics events linked to an account lose that link when the account is deleted. Raw analytics events are deleted after 13 months regardless, visitor ids after 180 days, and aggregate figures without identifiers may be kept.
Security
Passwords are stored hashed, transport is encrypted (HTTPS), and paid media is served through signed, expiring links. Report a vulnerability to the same address — we read it.
Changes
If this policy changes materially we will note it on this page with a new date.