Skip to content

Legal

Privacy Policy

Last updated:

This policy is being finalised with our legal counsel. It describes how ZeroTheory works today; if the reviewed version changes anything material, we will update this page and tell affected users.

The short version: we collect what we need to teach you and verify your work. Nothing about you is public, or shared with a college or recruiter, unless you choose it. Learners under 18 are never shown publicly. We don't sell your data or train AI on it, and you can export or delete everything from Settings.

Who we are

ZeroTheory (zerotheoryai.com and zerotheory.live) is run by ZeroTheoryAI Private Limited (CIN U62090AP2026PTC125862), registered at Gundlappadoddi, Kalyandurg, Ananthapur, Andhra Pradesh 515761, India. For your personal data we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025.

Questions about this policy or your data go to our Grievance Officer, Kundan Kumar Khatri (Founder & CEO), at grievance@zerotheoryai.com.

What we collect

  • Account: your email address and, if you sign in with GitHub or Google, your name, profile photo and username from that account. With GitHub we also store your numeric GitHub ID and login, so we can prove that a project repository is yours. If you use a password, our sign-in service stores only a salted hash of it; nobody at ZeroTheory can see it.
  • Onboarding answers: your goal, stage, course, coding experience, interests, weekly hours, preferred language, main device, graduation year, state, city and date of birth. We use your date of birth only to apply the protections for learners under 18, and it can't be changed later without support.
  • Learning activity: lessons completed, quiz attempts and scores, XP, streaks and the days you were active.
  • Projects: the repository you link (its ID, name, URL and visibility), the commit that was evaluated, the scores and feedback, and code-similarity fingerprints. Fingerprints are one-way hashes. We never copy or store your source code. If you add a YouTube "explain your build" video, we store its video ID.
  • College details, only if you join a college with its code: your college, department and graduation year, plus any academic record (CGPA or percentage) you choose to add.
  • Payments for courses and programmes: order and invoice details (name, email, billing state and GSTIN if you give one) and Razorpay payment references. Card, UPI and bank details go straight to Razorpay; we never see or store them.
  • Enquiry forms (colleges, recruiters): the details you type in. To stop spam we also keep a one-way hash of your IP address for up to a day; we don't store the address itself.
  • Security records: sign-in events and a log of sensitive actions (for example a college exporting student records), kept for one year.

Why we use it

We use your data only for these purposes:

  • To run your account and your learning: personal plans, lessons, quizzes, project evaluation, XP, streaks and ZScore. You give consent for this when you create an account.
  • To keep the platform fair and secure: integrity checks, fraud and abuse prevention.
  • To meet legal duties: GST invoices, accounting records and responding to lawful orders.
  • For the optional uses below, only if you switch them on. We never use your data to train AI models, and we never sell it.

Separate choices you control

Each of these is a separate choice. Nothing is pre-ticked, and you can turn any of them off at any time in Settings. Turning one off doesn't affect the others or your learning.

  • Public profile: a portfolio page at zerotheoryai.com/u/your-username showing your verified projects and scores.
  • Leaderboards: your name on public boards. Visitors see percentile bands (such as "Top 5%"), never exact ranks, and never the bottom half of a board.
  • College sharing: joining a college with its code shares your learning record with that college's staff. The consent screen shows exactly what they will see. Leaving the college ends their access at once.
  • Recruiter discovery (opening in 2027): letting verified recruiters find your record. Your contact details are shared only when you accept a specific recruiter's request.
  • Marketing emails: news about cohorts and events.

Public profiles, leaderboards and recruiter discovery are for adults only; see the next section.

Learners under 18

Learners under 18 can learn with us, with extra protections:

  • They never get a public profile, never appear on public leaderboards and are never shown to recruiters, whatever settings they choose.
  • We don't track them for advertising or build behavioural profiles of them.
  • A parent or guardian must approve before they can join a college on ZeroTheory.

Before the DPDP Rules' obligations for children's data take effect, we will ask for verifiable consent from a parent or guardian before processing any learning data of a learner under 18. Parents and guardians can write to grievance@zerotheoryai.com at any time.

Who else sees your data

Besides the people you choose above, we use a small number of service providers ("Data Processors"). They act only on our instructions:

  • Supabase: our database and sign-in service. Your account and learning data are stored in its Sydney (Australia) region.
  • Vercel: hosts the website and delivers pages from servers close to you.
  • GitHub and Google: sign-in. Project evaluations run as GitHub Actions in your own repository.
  • Razorpay: payments for courses and programmes.
  • Cloudflare Turnstile: checks that enquiry forms are sent by people, not bots.
  • YouTube: lesson videos and explainer videos are hosted there.

Some of these providers may process data outside India, which the DPDP Act allows except for countries the Government restricts. We share data with authorities only when the law requires it.

Every time a college opens or exports your record, and later every time a recruiter unlocks your contact details, it is written to your Who has seen my data page.

How long we keep it

  • Your account and learning record: for as long as your account is open.
  • After you delete your account: a 7-day grace period (you can change your mind), then your personal data is permanently erased.
  • Invoices and payment records: for as long as tax law requires (currently about eight years under GST rules). These are kept even after account deletion.
  • Security and access logs: one year.
  • Enquiries: while we are in conversation with you, and deleted when you ask.

Your rights

Under the DPDP Act you can:

  • Access your data, including who we have shared it with. Use Export my data in Settings for a full copy.
  • Correct or complete it. Most fields can be edited in Settings.
  • Erase it by deleting your account in Settings.
  • Withdraw consent for any optional use at any time. Withdrawing is as easy as giving it.
  • Nominate someone to exercise these rights if you die or become unable to.
  • Complain to our Grievance Officer, and then to the Data Protection Board of India if you are not satisfied.

Email grievance@zerotheoryai.com for anything you can't do yourself in Settings. We acknowledge within 24 hours and respond within 15 days.

How we protect it

  • All traffic is encrypted (HTTPS), and data is encrypted at rest by our providers.
  • Database rules decide who can read each record, so a college can only ever see its own students.
  • Our staff and college administrators must use two-factor authentication for sensitive actions, and those actions are logged.
  • Sign-in cookies can't be read by scripts on the page.

If a breach affects your data, we will tell you and the Data Protection Board without delay, with a detailed report to the Board within 72 hours, and report to CERT-In as required.

Cookies

We use only the cookies needed to keep you signed in and to sign you in securely across zerotheoryai.com and zerotheory.live. We don't use advertising cookies or cross-site trackers. If we add privacy-friendly analytics later, we will update this section first.

Changes to this policy

When we change this policy, we update the date at the top. If a change affects what we do with your data, we tell you by email or in the app before it applies, and ask for your consent again where the law requires it.