Last Updated: August 5, 2026
Effective Date: August 5, 2026
Version: 2.0
1. Introduction
Easy2Crack ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring transparency in how we collect, use, and protect your personal data. This Privacy Policy explains our practices regarding personal information collected through:
- Easy2Crack mobile application (iOS and Android)
- Easy2Crack website (https://www.easy2crack.com)
- Related services, APIs, and integrations
This policy is governed by the laws of India, with provisions to ensure compliance with international privacy regulations including GDPR, CCPA, and COPPA.
2. Information We Collect
2.1 Information You Provide Directly
Account & Authentication:
- Full name, email address, mobile number
- Password (encrypted before storage)
- Google Sign-In profile metadata (name, email, profile picture, unique ID)
- Login timestamps and authentication history
Profile & Learning Data:
- Academic background (class, exam preference: IIT-JEE, NEET, etc.)
- Study preferences and learning goals
- Quiz performance and test scores
- Test attempt history and answer submissions
- Bookmarks, saved notes, and study materials
- Leaderboard rank and comparative performance metrics
Transaction & Payment Data:
- Order IDs and transaction references
- Coupon/promo code usage
- Subscription purchase history
- Refund/cancellation requests
- We do NOT store credit card or bank account details (handled by PhonePe)
Communication Data:
- Support tickets and customer service inquiries
- Feedback, surveys, and user-submitted reports
2.2 Information Collected Automatically
Device & Technical Information:
- Device OS and version (iOS/Android version)
- Unique device identifier / Advertising ID (for device limit enforcement)
- App version and build number
- Device model, manufacturer, and hardware specs
- IP address and geolocation (approximate, derived from IP)
- Mobile network provider
- Timezone and language settings
- Device free storage and available RAM
Usage Analytics:
- App session start/end times and duration
- Feature interactions (quiz attempts, video plays, page views)
- Crash logs and error reports
- Search queries within the app
- Time spent on each content module
- Video watch history (play, pause, seek events)
- Push notification events (delivered, opened, dismissed)
Cookies & Identifiers:
- Session cookies for authentication
- Google Analytics cookies (if analytics enabled)
- Firebase Cloud Messaging (FCM) tokens
- Persistent device fingerprints (for multi-device tracking)
2.3 Information from Third Parties
- Google Sign-In: Profile data shared upon OAuth consent
- Payment Gateway (PhonePe): Payment status and transaction success/failure
- Firebase Services: Crash reporting and analytics data
- Device OS Providers: Push notification delivery confirmations
3. Legal Basis for Processing (GDPR/CCPA)
We process your personal data based on one or more of the following legal grounds:
| Data Category | Purpose | Legal Basis |
| Account credentials | Service provision & authentication | Contract (necessity to provide service) |
| Learning data (quiz scores, progress) | Personalization & core functionality | Contract + Legitimate Interest (service improvement) |
| Device ID | Device limit enforcement (anti-fraud) | Legitimate Interest (security) |
| Analytics & usage data | Product improvement & feature development | Legitimate Interest (service optimization) |
| Payment data | Transaction processing | Contract + Legal Obligation (tax/audit) |
| Push notifications | Service updates & exam reminders | Consent (with opt-out mechanism) |
| Google Analytics | Understanding user behavior | Consent (disabled by default in EU) |
| Leaderboard data | Competitive engagement & motivation | Legitimate Interest + User Consent |
Consent: When required by law (e.g., GDPR, CCPA), we obtain explicit consent before processing sensitive data. You may withdraw consent at any time via Settings > Privacy & Notifications.
4. How We Use Your Information
4.1 Core Service Delivery
- Registering and maintaining your account
- Providing educational content, quizzes, mock exams, and video tutorials
- Tracking progress and generating performance analytics
- Enforcing device limits (max 2 simultaneous active devices per subscription)
- Processing purchases and subscriptions
- Account security and fraud prevention
4.2 Personalization & Recommendations
- Suggesting relevant courses based on exam preference and learning level
- Customizing learning paths and difficulty levels
- Ranking students on leaderboards (if opted-in)
- Recommending weak areas for focused study
4.3 Communication
- Sending exam updates, policy changes, and important notices (transactional)
- Sending study reminders and exam schedules (with opt-out available)
- Responding to support requests
- Sending promotional offers (with unsubscribe option)
4.4 Product Development
- Analyzing feature usage to improve UX/UI
- Identifying and fixing bugs via crash logs
- A/B testing new features
- Understanding user behavior for strategic planning
- Generating anonymized, aggregated reports on learning trends
4.5 Legal & Compliance
- Complying with legal obligations, court orders, or regulatory requests
- Investigating and preventing fraud, abuse, or terms-of-service violations
- Enforcing our agreements and policies
- Protecting the security and integrity of our platform
5. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
Data is shared only with:
5.1 Service Providers (Data Processors)
5.2 Legal Disclosures
We may disclose your information when required by:
- Court orders or legal summons
- Government agencies (law enforcement, regulatory bodies)
- Legal compliance obligations (anti-money laundering, Know Your Customer)
- Protection of legal rights and fraud prevention
5.3 Data Processing Agreements
All service providers are contractually obligated to:
- Process data only as instructed
- Maintain confidentiality and security
- Comply with applicable data protection laws (GDPR, CCPA, India DPA)
- Delete data upon contract termination (where not required by law)
5.4 Business Transfers
If Easy2Crack is acquired, merges, or transfers assets, your data may be transferred as part of that transaction. We will notify you and provide options to consent or opt-out before such transfer.
6. Data Retention & Deletion
6.1 Retention Schedule
| Data Category | Retention Period | Reason |
| Active User Account | Duration of subscription + 30 days after cancellation | Business continuity & billing |
| Quiz/Test Scores & Progress | Duration of subscription + 365 days | User reference & academic history |
| Transaction Records | 7 years | Legal/Tax compliance (India GST Act) |
| Crash Logs & Error Data | 90 days | Security & product improvement |
| Firebase Analytics Data | 14 months (auto-delete by Firebase) | Firebase default policy |
| Device Fingerprints | Until account deletion or 2 years of inactivity | Device limit enforcement |
| IP Logs & HTTP Logs | 30 days | Security monitoring |
| Support Tickets & Chats | 1 year from last interaction | Customer service reference |
| Deleted Account Data | 7 days (grace period) + permanent deletion | User-initiated deletion |
6.2 Account Deletion
You have full control over your data. To delete your account:
Option 1: In-App Deletion
- Open Easy2Crack app
- Tap Profile icon (bottom-right)
- Scroll to "Danger Zone"
- Tap "Delete My Account"
- Confirm deletion
Option 2: Web Deletion
- Visit https://www.easy2crack.com/delete-account
- Log in with your credentials
- Confirm deletion request
What Happens Upon Deletion:
- Your account is immediately deactivated
- You are logged out across all devices
- All personal data enters a 7-day grace period
- You can contact [email protected] within 7 days to cancel the deletion
- After 7 days, all personal data is permanently deleted from primary databases
- Transaction records are retained for 7 years (legal compliance)
- Anonymous/aggregated data may be retained for analytics
6.3 Data Portability
Upon request, we can provide your personal data in a portable format (CSV/JSON):
- Account information
- Quiz scores and test history
- Leaderboard rankings
- Purchase history
To request data export, email: [email protected] with subject "Data Portability Request"
7. Your Privacy Rights
7.1 General Rights
You have the right to:
- Access: Request a copy of all personal data we hold about you
- Rectification: Correct inaccurate or incomplete information
- Erasure: Request deletion of your data (subject to legal retention requirements)
- Restriction: Request we limit how we process your data
- Portability: Receive your data in a portable format
- Object: Opt-out of specific processing activities (marketing, analytics)
- Withdraw Consent: Withdraw previously granted consent at any time
7.2 How to Exercise Your Rights
Email: [email protected]
Subject: "[PRIVACY REQUEST] [Type of Request]"
Specify:
- Full name and registered email
- Type of request (access, deletion, correction, etc.)
- Any supporting information
We will respond within 30 days (extendable to 60 days for complex requests).
7.3 GDPR-Specific Rights (EU Users)
If you are located in the EU, you have additional rights:
- Lodge a complaint with your local Data Protection Authority
- Request erasure ("right to be forgotten")
- Obtain data export in machine-readable format
EU DPA Contact: Your member state's Data Protection Authority
7.4 CCPA-Specific Rights (California Users)
If you are located in California, you have the right to:
- Know what data is collected
- Know whether data is sold or shared
- Request deletion (with limited exceptions)
- Opt-out of "sales" or "sharing" of personal information
- Non-discrimination for exercising CCPA rights
California Privacy Rights: We do not "sell" data as defined by CCPA, but we do share data with analytics providers.
8. Marketing & Communication Preferences
8.1 Notification Types
- Transactional: Account updates, login alerts, billing (cannot be disabled)
- Study Reminders: Quiz schedules, exam dates, learning suggestions (opt-in)
- Promotional: New courses, discounts, offers (opt-in)
- Security Alerts: Password changes, suspicious logins (always enabled)
8.2 How to Manage Preferences
In-App:
- Profile > Settings > Notifications & Preferences
- Toggle notification types on/off
- Configure frequency and timing
Email Unsubscribe:
- Click "Unsubscribe" link at bottom of any promotional email
- Or email: [email protected]
SMS Opt-Out:
- Reply "STOP" to any SMS notification
- Or change preferences in app
9. Children & Parental Controls (COPPA)
9.1 Target Audience
Easy2Crack is designed for users 13 years and older preparing for competitive exams (IIT-JEE, NEET, etc.).
9.2 Children Under 13
We do not knowingly collect personal data from children under 13 without verifiable parental consent.
If you are a parent/guardian of a child under 13:
- Do NOT register your child without providing verifiable parental consent
- To provide consent or remove your child's account: contact [email protected] with:
- Child's name and email
- Your name and email
- Proof of parental/legal guardianship
9.3 How Parents Can Control Their Child's Account
- Access parental controls via Parent Portal (if enabled)
- Set device usage limits and content restrictions
- Monitor quiz performance and progress
- Disable in-app purchases
- Request account deletion
Parent Portal: https://www.easy2crack.com/parent-portal
10. Security & Data Protection
10.1 Technical Measures
- Encryption: All data transmitted via HTTPS/TLS 1.2+
- Password Security: Passwords hashed with Argon2id (resistant to rainbow tables)
- Authentication: Secure session tokens with auto-expiry
- Database Security: Role-based access control, encrypted backups
- API Security: JWT tokens, rate limiting, input validation
- Device Fingerprinting: Secure hashing of device identifiers (not reversible)
10.2 Organizational Measures
- Employee training on data protection
- Strict access controls (principle of least privilege)
- Regular security audits and penetration testing
- Incident response plan for breaches
- GDPR/CCPA-compliant Data Processing Agreements
10.3 Limitations
While we implement industry-standard security, no method of transmission over the internet is 100% secure. You use the app at your own risk. Never share your password; we will never ask for it via email.
11. Data Breach Notification
11.1 If a Breach Occurs
In the event of a data breach involving your personal information:
- Notification: We will notify affected users within 72 hours via:
- Email to your registered address
- In-app notification
- Public statement (if 100+ users affected)
- Information Provided:
- Description of the breach
- Data types potentially compromised
- Steps we're taking to secure data
- Your recommended actions (password reset, monitoring, etc.)
- Contact information for questions
- Authority Notification: We will notify relevant data protection authorities as required by law
12. Cookies, Tracking & Analytics
12.1 Cookies Used
| Cookie Name | Type | Purpose | Duration |
session_token | Functional | Authentication | Session |
user_id | Functional | User identification | 1 year |
_ga, _gid | Analytics | Google Analytics tracking | 13-24 months |
fcm_token | Functional | Push notifications | 30 days |
theme_preference | Functional | UI theme selection | 1 year |
12.2 Cookie Consent
EU/GDPR Users: We obtain explicit consent before setting non-essential cookies (analytics). You can:
- Accept all cookies
- Accept only functional cookies
- Customize preferences
- Manage preferences anytime in Settings
12.3 Third-Party Analytics
We use Google Analytics to understand app usage:
- Anonymized session data
- User flow and feature popularity
- Device/OS breakdowns
- Geographic trends
You can:
- Opt-out in Settings > Privacy > Disable Analytics
- Use Google Analytics Opt-Out Browser Extension
- Disable Advertising ID on your device (iOS/Android settings)
13. International Data Transfers
13.1 Where Your Data Is Stored
Easy2Crack operates in India and uses cloud infrastructure in:
- Primary: Google Cloud Platform (USA)
- Secondary: Cloudflare R2 (USA/EU)
13.2 GDPR Data Transfers (EU Users)
For EU users, international transfers of personal data are governed by:
- Standard Contractual Clauses (SCCs) between us and cloud providers
- Supplementary Measures ensuring adequate data protection
- Compliance with GDPR Chapter 5
You can request a copy of our Data Processing Agreements: [email protected]
13.3 Data Residency Options
Currently, data residency in India is not available. If you require India-only storage, please contact: [email protected]
14. Device Limits & Multi-Device Enforcement
14.1 Device Limit Policy
Subscriptions allow:
- Basic/Free: 1 active device
- Pro/Premium: 2 simultaneous active devices
14.2 How We Enforce Limits
We use unique device identifiers (combination of):
- Device hardware ID
- Android/iOS system identifier
- App installation ID
- Hashed MAC address
This identifier is:
- Stored securely (hashed)
- Used only for enforcing device limits
- Linked to your account
- Reset when you delete your account
14.3 Opt-Out or Change
To use a new device, log out from the older device:
- Settings > Devices & Sessions
- Select inactive device > Log Out
- Log in on new device
15. Leaderboard & Public Data
15.1 Leaderboard Participation
Your name and ranking may appear on public leaderboards if you:
- Opt-in during onboarding or Settings
- Have an active subscription
- Meet the ranking threshold
15.2 Data Displayed
Public:
- Username/initials
- Exam rank (e.g., "Rank 42 in IIT-JEE")
- Achievement badges
Hidden (Private):
- Full name
- Email address
- Phone number
- Detailed performance data
15.3 Opt-Out
- Profile > Settings > Leaderboard & Privacy
- Toggle "Show on Leaderboard" OFF
- Changes take effect within 24 hours
16. Policy Updates & Amendments
16.1 Change Notification
We may update this policy to reflect:
- New features or services
- Legal/regulatory changes
- Technical improvements
- Security updates
Material changes (affecting your rights) will be notified via:
- In-app notification
- Email (30 days notice)
- Prominent banner on login
Minor changes (clarifications, corrections) take effect immediately.
16.2 Version History
| Version | Date | Changes |
| 2.0 | August 5, 2026 | Major update: Added GDPR/CCPA/COPPA compliance, data retention, third-party transparency |
| 1.0 | Prior | Initial policy |
17. Contact & Grievance Redressal
17.1 Privacy Inquiries
General Questions:
- Email: [email protected]
- Website: https://www.easy2crack.com/support
- Response time: 24-48 hours
17.2 Data Subject Requests (GDPR/CCPA)
Subject Access, Deletion, Portability:
- Email: [email protected]
- Subject: "[PRIVACY REQUEST] [Request Type]"
- Response time: 30 days (extendable to 60 days)
17.3 Privacy Concerns & Escalation
Complaint:
- Email: [email protected]
- Include: Your name, email, detailed description, supporting documents
- Response time: 7-14 days
If unsatisfied: File a complaint with the Data Protection Authority (in India, or the relevant DPA in your country).
17.4 Data Protection Officer (DPO)
India:
18. Specific Compliance Certifications
- GDPR: Compliant (SCCs in place, DPA signed)
- CCPA: Compliant (privacy rights, opt-outs)
- COPPA: Parental consent mechanisms in place
- India Personal Data Protection Act (DPDP): Compliant (under development)
- ISO 27001: Security standards adhered to
19. Jurisdiction & Governing Law
This Privacy Policy is governed by the laws of India without regard to conflict of law principles.
For disputes:
- Indian users: Jurisdiction of courts in Bangalore, India
- International users: GDPR/CCPA takes precedence where applicable
- Dispute resolution: Good faith negotiation > Mediation > Arbitration/Courts
20. Acknowledgment & Consent
By using Easy2Crack, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, please discontinue using the app and delete your account.
Thank you for trusting Easy2Crack with your data. We are committed to your privacy.
© 2026 Easy2Crack. All Rights Reserved.
For the most up-to-date version of this policy, visit: https://www.easy2crack.com/privacy-policy