Privacy Policy

Last updated: 15th July 2026

This Privacy Policy (“Policy”) explains how Oncourselearning Technologies Private Limited (“Oncourse,” “Oncourse AI,” “we,” “our,” or “us”), acting as a Data Fiduciary, collects, uses, processes, stores, shares, and protects your personal data when you access or use our website at https://getoncourse.ai/, our mobile applications, and all associated AI-generated educational products and services (collectively, the “Services”).

This Policy applies to all individuals who access or use our Services, including but not limited to medical students, healthcare professionals, and academic administrators (collectively referred to as “Data Principals” or “you”).

Notice of Consent: By clicking "I Agree," registering an account, or otherwise accessing the Services, you acknowledge that you have read this Privacy Policy and give your unambiguous, specific, informed, and revocable consent to the processing of your personal data as described herein. Your use of the Services is also governed by our Terms of Service. If you do not agree with this Policy, please do not use or access the Services.

International Jurisdictions and Regional Privacy Rights

Because Oncourse AI is a global educational platform, the personal data we collect may be subject to different privacy laws depending on your country or state of residence. We are committed to honouring your local privacy rights.

  • Users in India: If you access our Services from India, your personal data is protected under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). Please see Section 12 for your rights as a Data Principal and details on our Grievance Officer.
  • Users in the EEA, UK, and Switzerland: If you are located in the European Economic Area, the United Kingdom, or Switzerland, your data is processed under the General Data Protection Regulation ("GDPR"). Please see Section 13 for your specific data subject rights and our lawful bases for processing.
  • Users in the United States: If you are a resident of the United States, your privacy rights may be governed by state-specific comprehensive privacy laws (such as the California Consumer Privacy Act/CPRA, Texas Data Privacy and Security Act, etc.). Please see Section 14 (U.S. State Privacy Rights) for disclosures regarding your right to opt out of the sale/sharing of data, targeted advertising, and how we handle financial or educational information.
  • Other International Users: If you access our Services from any other region (including Canada, Australia, Latin America, the Middle East, or Asia), your data will be processed in accordance with this general Privacy Policy. By using our Services, you acknowledge and consent to the transfer, storage, and processing of your information outside of your home country to our secure servers.

1. Definitions

Capitalised terms not defined in this Privacy Policy shall have the meanings ascribed to them in our Terms of Service.

  • “AI Output” means any text, diagrams, summaries, clinical case simulations, or other content generated by our artificial intelligence models and features in response to a User Prompt.
  • “Data Fiduciary” means Oncourselearning Technologies Private Limited, which determines the purpose and means of the processing of Personal Data under the Indian Digital Personal Data Protection Act, 2023 (DPDP Act).
  • “Data Principal” (or “Data Subject”) means the natural person to whom the Personal Data relates (including medical students, healthcare professionals, and academic users).
  • “Personal Data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or professional credentials.
  • “Processing” means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
  • “Service Provider” (or “Data Processor”) means any third party, cloud host, or technology partner engaged by Oncourse AI to process Personal Data on our behalf.
  • “User Prompt” means any text, voice, image, clinical notes, or other input submitted by you to an AI Feature within the Services.

2. Information We Collect

We collect different types of personal data to provide, improve, and secure our Services. We categorise this information as follows:

2.1 Information You Provide Directly

  • Account Identifiers: First and last name, email address, phone number, and profile photo.
  • Academic Profile Information: Your chosen examination track (e.g., NEET PG, INI-CET, USMLE, PLAB), year of medical study, and current institution or medical college.
  • Billing Details: Name, billing address, and partial payment-method information (such as the last four digits of a card). Note: We do not store full credit/debit card numbers or UPI credentials; all transactions are securely processed by authorised third-party payment gateways.
  • Communications: Support messages, feedback, and survey responses you voluntarily send us.

2.2 Information from Third-Party Sign-In

If you choose to log in using a third-party platform (eg., Google or Apple), these platforms share specific data with us based on your authorisation (typically your name, email address, and profile photo). We never receive or access your third-party account passwords.

2.3 Automated Usage and Learning Data

  • Device Information: IP address, unique device identifiers, operating system, browser type and version, mobile network information, and crash reports.
  • Activity Metrics: Pages or screens viewed, features utilised, time spent on the platform, and click-stream paths.
  • Medical Learning Metrics: Quiz attempts, selected answers, time spent per question, flashcard review history, lesson progress, Clinical Rounds gameplay data, study points, badges, and streaks.

2.4 AI Feature and Conversation Data

When you interact with our AI medical tutors, Rezzy, or other AI features, we collect:

  • User Prompts: The text, voice recordings, or uploaded media you submit to the AI platform, chatbots, AI medical tutors, Rezzy, or other AI features.
  • AI Output: The educational summaries, answers, and case analyses generated in response to your prompts.
  • Voice Inputs: Audio recordings used for speech-to-text conversion or VIVA features.
  • Conversation Metadata: Timestamps, session durations, message counts, and AI model versions used.

⚠️ CRITICAL SECURITY RESTRICTION FOR MEDICAL DATA: You are strictly prohibited from inputting real-world, identifiable patient health records, hospital charts, or any confidential clinical data into the AI features. While we do not intentionally seek or collect health data, if you choose to include personal or patient details in your prompts, that data will be processed by our AI systems. Please safeguard patient privacy at all times.

2.5 Device Permissions (Camera, Photos, and Files)

With your explicit permission, we access your device’s camera, photo library, or file storage solely to let you upload a profile picture or submit medical diagrams/notes for AI analysis. We collect basic file metadata (file name, type, and size) only to execute the specific feature you request.

2.6 Cookies and Tracking Technologies

We utilise cookies, software development kits (SDKs), pixels, and similar tracking tools to authenticate your identity, remember your preferences, and track app performance. You can manage cookies via your browser settings, though disabling them may restrict your access to certain app features.

3. Sources of Information

We gather personal data from the following distinct sources:

  • Directly from You: Information you enter manually when creating an account, purchasing a subscription, or interacting with our AI features.
  • Automatically from Your Device: Data collected via your web browser or mobile application regarding your hardware, operating system, and platform usage metrics.
  • Third-Party Identity Providers: Platforms such as Google or Apple, if you choose to utilise their single sign-on features to log in.
  • Payment Gateways and App Stores: Authorised merchant partners (for example: Stripe, Razorpay, the Apple App Store, or Google Play Store) who confirm transaction success and subscription status.
  • Analytics and Attribution Partners: Third-party services (for example: Mixpanel and AppsFlyer) that provide aggregated data on how users discover, navigate, and engage with our educational content.

4. Cookies and Similar Technologies

We utilise cookies, software development kits (SDKs), tracking pixels, and related technologies to optimise your digital experience. These tools are categorised as follows:

  • Strictly Necessary: Essential for validating your identity, maintaining secure active sessions, and preventing fraudulent access to premium medical materials. These cannot be disabled.
  • Functionality: Used to remember your custom preferences, such as your user interface theme, language settings, and active examination track.
  • Analytics and Performance: Used to monitor anonymous traffic patterns, track app stability, and measure which AI features or clinical case studies are most effective.
  • Marketing and Attribution: Used to evaluate the reach of our promotional campaigns and display relevant educational offers based on your interest.

Managing Your Choices: We deploy a Cookie Management Banner for users accessing the Services from jurisdictions that mandate granular cookie consent (such as the UK, EEA, and specific US states). This banner allows you to accept, reject, or custom-configure non-essential cookies. You can also adjust your cookie preferences directly via your internet browser settings.

5. How We Use Your Information

We use your personal data strictly for specified, lawful purposes to deliver and optimise your learning experience. We process your information to:

  • Operate the Platform: Create, maintain, and secure your student account.
  • Deliver AI Functionality: Generate real-time educational responses, clinical case explanations, and flashcard summaries based on your prompts.
  • Personalise Your Learning: Adapt quiz difficulty, provide performance analytics, track your study streaks, and recommend lessons based on your exam track (e.g., NEET PG, USMLE).
  • Manage Subscriptions: Securely verify payments, handle billing inquiries, and prevent transactional fraud.
  • Communicate with You: Send system alerts, security notifications, customer support updates, and—where you have explicitly consented—relevant promotional materials.
  • Maintain App Stability: Troubleshoot code errors, debug system crashes, and monitor daily server performance.
  • Enhance Platform Capabilities: Evaluate and refine the accuracy, safety, and relevance of our internal software tools.
  • Ensure Security & Compliance: Protect our users from cyber threats, prevent system abuse, enforce our Terms of Service, and comply with binding statutory mandates.

6. No AI Training and Development

6.1 Data Exclusions: What We Never Use for Training

We are committed to protecting your privacy and the confidentiality of your data. We explicitly guarantee that we do not use, sell, rent, or distribute any of your personal data, uploaded content, prompts, inputs, or outputs (collectively, "User Content") to train, retrain, fine-tune, or otherwise improve any artificial intelligence, machine learning, large language models (LLMs), or similar algorithmic systems—whether owned by us or by third-party service providers. All processing of your data is strictly transient and limited to the real-time delivery of our services.

6.2 Third-Party AI Models & Data Selling

  • We Do Not Sell Your Data: Your data is never sold, traded, or monetised to third parties.
  • Strict External Vendor Contracts: When we route a prompt through third-party infrastructure (such as OpenAI or Microsoft Azure) to return a response to you, we use enterprise-grade secure application programming interfaces (APIs). We contractually bind these providers to:
    • Process your inputs solely to deliver the service to you;
    • Prohibit the use of your data (including prompts, inputs, and outputs) to train, tune, or improve their own commercial models; and
    • Delete your data as soon as their standard administrative, compliance, and abuse-monitoring retention windows close, without persisting it.

7. How We Share Your Information

We do not sell your personal data for monetary value, nor do we disclose it to third parties for their independent marketing initiatives without your explicit consent.

We only share your information in the following limited and highly secure circumstances:

7.1 Service Providers (Sub-Processors)

We share personal data with external vendor partners—known as Sub-Processors—who perform operational tasks on our behalf. These third parties are bound by strict data protection agreements and are legally prohibited from using any of your data (including personal data and raw inputs/prompts) to train their own artificial intelligence or commercial models. They may only handle your data to fulfil specific functions, including:

  • Cloud Infrastructure and Hosting: Secure data storage and platform maintenance (e.g., Supabase, Amazon Web Services).
  • Artificial Intelligence Infrastructure: Enterprise API providers of Large Language Models (LLMs) that power our core AI modules (eg., Rezzy).
  • Product Analytics and Telemetry: Platform diagnostic tools used to improve software performance (e.g., Mixpanel, PostHog).
  • Attribution and Marketing Performance: Services used to track user sign-up origin and promotional campaign reach (e.g., AppsFlyer).
  • Payment Processing: Secure financial gateways that process premium subscriptions (e.g., Razorpay, Apple App Store, Google Play Store).
  • Subscription and Paywall Management: Systems that verify account access levels and trial statuses (e.g., Superwall, RevenueCat).
  • Customer Communications: Email networks, customer relationship management (CRM) platforms, and notification systems used to send updates or support tickets.

Transparency Notice: To maintain absolute accountability, we publish and continually maintain a comprehensive list of all current operational sub-processors at https://getoncourse.ai/subprocessors.

7.2 Corporate Affiliates

We may share information with our parent company, corporate subsidiaries, or joint ventures. Any such corporate affiliate is contractually bound to treat your data with the similar level of security and compliance outlined in this Privacy Policy.

7.3 Strategic Business Partners

If we partner with external medical institutions, universities, or co-branded educational services, we will never disclose your personal data unless you have given us your explicit, opt-in consent to do so for that specific promotion or joint program.

7.4 Legal Mandates and Safety Disclosures

We reserve the right to access, preserve, and disclose your data if we believe in good faith that such action is legally required to:

  • Comply with a binding court order, regulatory demand, search warrant, or administrative legal process under Indian or applicable international laws.
  • Investigate, prevent, or address systemic platform abuse, financial fraud, security vulnerabilities, or critical technical errors.
  • Protect the safety, property, and physical well-being of our engineering team, our user community, medical students, or the general public.
  • Enforce our active Terms of Service and protect our intellectual property.

7.5 Corporate Restructuring and Transfers

In the event that Oncourselearning Technologies Pvt. Ltd. undergoes a significant business transition—such as a merger, corporate acquisition, debt financing, structural reorganisation, asset sale, or bankruptcy—your personal data may be shared or transferred as part of our business assets to the successor entity. If this occurs, we will notify you prominently via email or the app interface prior to the transfer.

7.6 Explicit Consent Operations

We may share your information for any alternative, specific purpose not explicitly covered in this policy, provided we present you with a clear notice beforehand and secure your direct, affirmative consent.

8. Data Retention

We store your personal data only for the duration necessary to fulfil the educational and operational purposes outlined in this Policy. Once data is no longer required, we either permanently delete it or irreversibly anonymise it.

Our specific retention periods include:

  • Account Profile Data: Retained for the active lifecycle of your Account, and for up to 24 months following account deletion or total inactivity to assist with security audits and dispute resolution.
  • Subscription & Transaction Records: Retained for up to 8 years post-transaction to meet strict statutory Indian tax, corporate accounting, and financial reporting laws.
  • AI Conversation Data & User Prompts: Retained in an identifiable format for up to 24 months, after which the text is permanently deleted or anonymised.
  • Uploaded Study Materials: Source uploads (such as textbook photographs, scanned notes, or medical diagrams uploaded for summary generation) are processed transiently and permanently deleted within 30 days, unless you explicitly choose to save the generated AI output to your active account profile.
  • Voice & Audio Recordings: Retained for up to 90 days to verify speech-to-text accuracy and platform safety, unless required longer for an active security review.
  • Platform Usage Analytics: Kept in an identifiable form for up to 24 months to optimise app features, then aggregated or anonymised.
  • Anonymised Datasets: Retained indefinitely for long-term product research, as this data contains no identifiable traits and is no longer classified as personal data.

9. International Data Transfers

Oncourse AI is operated by an Indian entity. However, because our application architecture and AI cloud infrastructure leverage a distributed global network, your personal data will be transferred to, stored in, and processed in countries outside your home jurisdiction. This includes secure data centres located in the United States, the European Union, the United Kingdom, and any other region where our authorised sub-processors maintain server hubs.

To safeguard your data across borders, we implement strict legal mechanisms:

  • Contractual Frameworks: We bind all international service providers to strict data protection agreements—such as the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum—ensuring your information receives the same high level of protection regardless of its physical location.
  • DPDP Act Alignment: For our users in India, we ensure that all international transfers comply fully with the cross-border data transfer rules and restriction lists published by the Government of India under the DPDP Act 2023.
  • Consent to Transfer: By registering for an account and utilizing our global AI platform, you acknowledge and agree to these secure international data transfers.

10. Data Security

We implement robust administrative, technical, and physical safeguards to secure your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include industry-standard encryption for data in transit and at rest, strict internal access controls, comprehensive audit logging, routine vulnerability assessments, and least-privilege engineering workflows.

While we take extensive precautions, no digital storage mechanism or internet transmission is completely flawless. Consequently, we cannot guarantee absolute security, and you access our Services at your own risk. You are solely responsible for protecting your account login credentials. If you suspect your account has been compromised, notify us immediately at hello@getoncourse.ai.

11. Data Breach Notification

In the event of a personal data breach that poses a risk to your security, rights, or interests, we will notify you and the appropriate regulatory authorities without undue delay.

  • Indian Jurisdiction: In accordance with the DPDP Act 2023 and mandates from the Indian Computer Emergency Response Team (CERT-In), data breaches will be reported to the Data Protection Board of India (DPBI) and affected individuals immediately upon verification.
  • Global Jurisdictions: For users protected under the GDPR or similar frameworks, we aim to notify relevant supervisory authorities within 72 hours of becoming aware of the breach, where feasible.
  • Notification Details: Our alerts will outline the nature of the breach, the specific categories of data compromised, potential consequences, and the immediate remedial actions we are taking.

12. Your Rights in India (DPDP Act, 2023)

If you are an Indian citizen or access our Services within India, you are classified as a Data Principal under the Digital Personal Data Protection Act, 2023. You can exercise the following statutory rights by contacting us at hello@getoncourse.ai:

  • Right to Summary (Access): Request a concise summary of the personal data we hold about you, the specific processing operations we perform, and the identities of any third-party sub-processors with whom your data has been shared.
  • Right to Correction, Completion, and Erasure: Request that we correct inaccurate records, complete missing profile information, update outdated details, or permanently delete personal data that is no longer necessary for your active educational usage.
  • Right to Grievance Redressal: File a formal complaint regarding any data handling issue directly with our designated Grievance Officer (see contact details in Section 17).
  • Right to Nominate: Authorise a specific individual to manage or exercise your data rights on your behalf in the event of your death or medical incapacity.
  • Right to Withdraw Consent: Revoke your consent to data processing at any time. Withdrawing consent will result in the immediate cessation of data processing and the deletion of your account, though it will not invalidate any processing performed legally prior to your withdrawal.

Verification and Minor Data

  • Identity Verification: To protect student privacy, we will verify your identity before fulfilling any statutory data requests.
  • Children’s and Minor Data: Our Services are strictly designed for users aged 18 and older. If you are a parent or legal guardian and believe an individual under the age of 18 has registered an account without verifiable parental consent, please alert us at hello@getoncourse.ai so we can immediately delete the minor's account and associated records.

13. Your Rights in the EEA, UK, and Switzerland (GDPR)

Lawful Bases for Processing

If you reside in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data under the following strict legal bases:

  • Contractual Necessity: Required to deploy our application, manage your premium medical subscriptions, and provide core functionalities.
  • Explicit Consent: Applied when you deliberately opt in to receive marketing communications, use optional voice features, or permit your data to be used for internal AI training.
  • Legitimate Interests: Leveraged to evaluate platform traffic, prevent fraud, debug technical errors, and refine our educational tools—provided your fundamental privacy rights do not override these business interests.
  • Legal Obligation: Mandatory processing to satisfy statutory tax regulations, financial accounting audits, or lawful court orders.

Your GDPR Rights

As a European or UK data subject, you possess the following rights:

  • The right to access your personal data and request copies.
  • The right to rectify inaccurate or incomplete information.
  • The right to erase your records ("the right to be forgotten").
  • The right to restrict or object to specific processing operations, including direct marketing.
  • The right to data portability, allowing you to transfer your learning data to another service provider.
  • The right to withdraw your consent cleanly at any time.
  • The right to lodge a complaint with your local Data Protection Authority (DPA) or Information Commissioner's Office (ICO).

Response Timeline

We will address your verified GDPR requests within one calendar month. This timeline may be extended by up to two additional months for highly complex data extractions, in which case we will notify you within the initial month.

Other International Jurisdictions

If you reside in another country (such as Canada under PIPEDA, Australia under the Privacy Act, or states within the United States), your local regulations may grant you equivalent rights to access, amend, port, restrict, or delete your personal data. We are dedicated to ensuring equal privacy protection globally and will never discriminate against you, increase subscription pricing, or deny app access if you choose to exercise your local privacy rights. Please direct all international privacy inquiries to hello@getoncourse.ai.

14. Children's Privacy

Due to the advanced technical nature of AI-generated medical education materials, we enforce strict age limits on who can access our platform:

  • Global Age Requirements: Our Services are designed primarily for users aged 18 and older. Individuals between the ages of 13 and 17 may only use the platform under the direct supervision and with the verifiable consent of a parent or legal guardian. We do not knowingly collect personal data from children under the age of 13 anywhere in the world.
  • Strict Provisions for Indian Residents: In compliance with Section 9 of the Indian DPDP Act 2023, anyone under the age of 18 is legally classified as a minor. Therefore, if you are a resident of India under 18 years old, you are strictly prohibited from registering an account or inputting data unless your parent or legal guardian provides verifiable consent through our approved parental verification channels.
  • Remedial Action for Parents: If we discover that we have accidentally collected personal data from a minor in violation of these territorial limits, we will take immediate technical steps to permanently purge that information from our active databases and backup servers. If you are a parent or legal guardian and believe your child has registered an account without proper authorisation, please contact us immediately at hello@getoncourse.ai.

Our Services may contain links to third-party websites, plug-ins, mobile applications, or digital services that are not operated, controlled, or monitored by Oncourse AI. We are not responsible for the privacy practices, tracking scripts, data security measures, or content deployed by these external parties. We strongly encourage you to thoroughly review the independent privacy policies of any third-party services you visit.

16. Grievance Officer / Data Protection Contact

In accordance with the Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology Act, 2000, and the rules framed thereunder, we have appointed a designated Grievance Officer to handle all inquiries, complaints, or data rights requests.

If you have a grievance regarding our data handling or wish to escalate a privacy issue, please contact our Grievance Officer:

Name of Officer: [Insert Name]
Designation: Grievance Officer & Data Protection Lead
Email Address: hello@getoncourse.ai
Postal Address: Oncourselearning Technologies Private Limited, Q98, Chaithanya Smaran, Kadugodi-Hoskote Road, Kannamangala, Bangalore, Karnataka 560067, India

Service Level Agreements (SLA): We will acknowledge receipt of your complaint within 48 hours. We aim to resolve all standard data privacy disputes internally within 30 days. Under statutory Indian DPDP Rules, all consumer grievances will be completely addressed and formalised within a mandatory maximum limit of 90 days. If you remain unsatisfied with our Grievance Officer's final resolution, Indian residents have the statutory right to escalate the dispute directly to the Data Protection Board of India (DPBI).

17. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy from time to time to reflect shifts in our AI technology or changing global regulations. If we execute material updates, we will notify you prominently before the revisions take effect. Notifications will be distributed via:

  • An explicit email blast to your registered email address;
  • A mandatory in-app pop-up announcement; or
  • A conspicuous notice displayed on our homepage.

The "Last updated" date displayed at the top of this document indicates when the policy was most recently revised. Your continued use of the platform after an update comes into force represents your explicit acceptance of the amended Privacy Policy.

18. Contact Us

For general corporate matters, security concerns, or alternate support channels, you may reach our engineering and administrative teams at the following coordinates:

Corporate Office: Oncourselearning Technologies Private Limited, Q98, Chaithanya Smaran, Hosakote Road, Kannamangala, Kadugodi, Bangalore Rural, Hosakote, Karnataka 560067, India.
General Privacy Inquiries: hello@getoncourse.ai
Copyright and DMCA Complaints: copyright@getoncourse.ai
WhatsApp Support Channel: +91 9740773310