1. Introduction
CrackCMS ("we", "our", "us") is operated by CrackLabs AI. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use the CrackCMS mobile or web app, or purchase a premium subscription. CrackCMS is a free study desk for MBBS graduates preparing for UPSC CMS, NEET PG, INI-CET, FMGE, USMLE and other medical entrance exams. We offer question banks, mock tests, AI tutor explanations, flashcards and progress analytics — supported by an optional paid tier for candidates who want unlimited AI tutoring.
By accessing CrackCMS you agree to the practices described in this policy. If you do not agree, please discontinue use of the service.
2. Information We Collect
2.1 Account information
When you register, we collect your name, email address, mobile number (optional), profile picture (optional), and password (stored as a one-way hash). If you sign in via Google or other OAuth providers, we receive a verified email and profile identifier.
2.2 Usage & learning data
To power AI tutoring, spaced-repetition flashcards, and personalised analytics, we record:
- Questions attempted, answered, flagged, and bookmarked.
- Time spent per question, per subject, and per mock test.
- Mock-test scores, streaks, XP, and badges.
- AI tutor conversations (used to improve model quality, with content moderation).
2.3 Device & technical data
We automatically receive IP address, browser type, device model, operating system, locale, referring URL, and aggregate usage analytics via privacy-respecting tooling (Datadog RUM, Google Analytics 4 with IP-anonymisation enabled).
2.4 Payment data
Payments are processed by PCI-DSS compliant third-party gateways (Razorpay / Stripe). We do not store full card numbers, CVV, or expiry dates on CrackCMS servers.
3. How We Use Your Information
- Provide AI tutoring, mock-test scoring, and personalised study plans.
- Maintain your account, process subscriptions, and send transactional notifications.
- Detect cheating, fraud, and abuse; protect the integrity of leaderboards.
- Improve our models and content; conduct aggregate research on learning patterns.
- Comply with Indian and international legal obligations.
4. Sharing of Information
We do not sell your personal data. We share data only with vetted vendors: cloud hosting (Render, AWS, Supabase), analytics (Datadog, GA4), AI providers (Groq, Cerebras, Gemini, OpenRouter, Cohere, HuggingFace, Mistral, DeepSeek, Together, AI/ML API), and payment gateways. Each vendor is bound by confidentiality and data-processing agreements.
5. Cookies & Local Storage
CrackCMS uses essential cookies for authentication and preference storage (theme, sidebar state, exam track). We do not use advertising cookies. You can disable cookies in your browser settings; some features (login, dark-mode toggle) may stop working.
6. Data Retention
We retain your account information for as long as your account is active. AI tutor transcripts are retained for 12 months for quality and safety review, then anonymised for research. You can request immediate deletion of all personal data — see Section 8.
7. Your Rights
Under GDPR, the India DPDP Act 2023, and analogous frameworks, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion ("right to be forgotten").
- Object to or restrict processing.
- Data portability in a machine-readable format.
8. How to Exercise Your Rights
Email [email protected] from the address registered with your account. We respond within 30 days. For deletion, we will anonymise your account and remove personal identifiers within 7 days.
9. Children's Privacy
CrackCMS is intended for medical graduates and senior medical students (typically aged 18+). We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, contact us for immediate deletion.
10. International Data Transfers
Some AI providers process prompts outside India (United States, European Union). Where required, we rely on Standard Contractual Clauses or equivalent safeguards. Aggregated diagnostic data is processed in India.
11. Security
We use TLS 1.3 encryption in transit, AES-256 at rest, hardware-backed key storage, JWT authentication with short-lived tokens, brute-force protection via django-axes, single- device session enforcement, and routine penetration testing.
12. Changes to This Policy
We may update this policy to reflect product, legal, or operational changes. Material changes will be communicated via in-app notification and email at least 14 days before taking effect.
13. Contact
Data Protection Officer
CrackLabs AI
Email: [email protected]
Postal: B-12, Sector 62, Noida, Uttar Pradesh 201301, India
