Legal
Privacy Policy
Last updated:
The short version: we collect what we need to teach you and verify your work. Nothing about you is public, or shared with a college or recruiter, unless you choose it. Learners under 18 are never shown publicly. We don't sell your data or train AI on it, and you can export or delete everything from Settings.
Who we are
ZeroTheory (zerotheoryai.com and zerotheory.live) is run by ZeroTheoryAI Private Limited (CIN U62090AP2026PTC125862), registered at Gundlappadoddi, Kalyandurg, Ananthapur, Andhra Pradesh 515761, India. For your personal data we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025.
Questions about this policy or your data go to our Grievance Officer, Kundan Kumar Khatri (Founder & CEO), at grievance@zerotheoryai.com.
What we collect
- Account: your email address and, if you sign in with GitHub or Google, your name, profile photo and username from that account. With GitHub we also store your numeric GitHub ID and login, so we can prove that a project repository is yours. If you use a password, our sign-in service stores only a salted hash of it; nobody at ZeroTheory can see it.
- Onboarding answers: your goal, stage, course, coding experience, interests, weekly hours, preferred language, main device, graduation year, state, city and date of birth. We use your date of birth only to apply the protections for learners under 18, and it can't be changed later without support.
- Learning activity: lessons completed, quiz attempts and scores, XP, streaks and the days you were active.
- Projects: the repository you link (its ID, name, URL and visibility), the commit that was evaluated, the scores and feedback, and code-similarity fingerprints. Fingerprints are one-way hashes. We never copy or store your source code. If you add a YouTube "explain your build" video, we store its video ID.
- College details, only if you join a college with its code: your college, department and graduation year, plus any academic record (CGPA or percentage) you choose to add.
- Payments for courses and programmes: order and invoice details (name, email, billing state and GSTIN if you give one) and Razorpay payment references. Card, UPI and bank details go straight to Razorpay; we never see or store them.
- Enquiry forms (colleges, recruiters): the details you type in. To stop spam we also keep a one-way hash of your IP address for up to a day; we don't store the address itself.
- Security records: sign-in events and a log of sensitive actions (for example a college exporting student records), kept for one year.
Why we use it
We use your data only for these purposes:
- To run your account and your learning: personal plans, lessons, quizzes, project evaluation, XP, streaks and ZScore. You give consent for this when you create an account.
- To keep the platform fair and secure: integrity checks, fraud and abuse prevention.
- To meet legal duties: GST invoices, accounting records and responding to lawful orders.
- For the optional uses below, only if you switch them on. We never use your data to train AI models, and we never sell it.
Separate choices you control
Each of these is a separate choice. Nothing is pre-ticked, and you can turn any of them off at any time in Settings. Turning one off doesn't affect the others or your learning.
- Public profile: a portfolio page at zerotheoryai.com/u/your-username showing your verified projects and scores.
- Leaderboards: your name on public boards. Visitors see percentile bands (such as "Top 5%"), never exact ranks, and never the bottom half of a board.
- College sharing: joining a college with its code shares your learning record with that college's staff. The consent screen shows exactly what they will see. Leaving the college ends their access at once.
- Recruiter discovery (opening in 2027): letting verified recruiters find your record. Your contact details are shared only when you accept a specific recruiter's request.
- Marketing emails: news about cohorts and events.
Public profiles, leaderboards and recruiter discovery are for adults only; see the next section.
Learners under 18
Learners under 18 can learn with us, with extra protections:
- They never get a public profile, never appear on public leaderboards and are never shown to recruiters, whatever settings they choose.
- We don't track them for advertising or build behavioural profiles of them.
- A parent or guardian must approve before they can join a college on ZeroTheory.
Before the DPDP Rules' obligations for children's data take effect, we will ask for verifiable consent from a parent or guardian before processing any learning data of a learner under 18. Parents and guardians can write to grievance@zerotheoryai.com at any time.
How long we keep it
- Your account and learning record: for as long as your account is open.
- After you delete your account: a 7-day grace period (you can change your mind), then your personal data is permanently erased.
- Invoices and payment records: for as long as tax law requires (currently about eight years under GST rules). These are kept even after account deletion.
- Security and access logs: one year.
- Enquiries: while we are in conversation with you, and deleted when you ask.
Your rights
Under the DPDP Act you can:
- Access your data, including who we have shared it with. Use Export my data in Settings for a full copy.
- Correct or complete it. Most fields can be edited in Settings.
- Erase it by deleting your account in Settings.
- Withdraw consent for any optional use at any time. Withdrawing is as easy as giving it.
- Nominate someone to exercise these rights if you die or become unable to.
- Complain to our Grievance Officer, and then to the Data Protection Board of India if you are not satisfied.
Email grievance@zerotheoryai.com for anything you can't do yourself in Settings. We acknowledge within 24 hours and respond within 15 days.
How we protect it
- All traffic is encrypted (HTTPS), and data is encrypted at rest by our providers.
- Database rules decide who can read each record, so a college can only ever see its own students.
- Our staff and college administrators must use two-factor authentication for sensitive actions, and those actions are logged.
- Sign-in cookies can't be read by scripts on the page.
If a breach affects your data, we will tell you and the Data Protection Board without delay, with a detailed report to the Board within 72 hours, and report to CERT-In as required.
Changes to this policy
When we change this policy, we update the date at the top. If a change affects what we do with your data, we tell you by email or in the app before it applies, and ask for your consent again where the law requires it.