Legal

Privacy Policy

Updated on: August 02, 2026

This Privacy Policy (“Privacy Policy” or “Policy”) applies to your use of our website https://www.genvolve.ai/ (the “Platform”) and products and services offered through the Platform (hereinafter collectively referred to as “Services”) which are owned, controlled and operated by Genvolve Private Limited, a company incorporated under the laws of India, and having its registered office at 212, 2nd Floor, Hare, Govind Complex, Zone-1, Shiksha Mandal, Bhopal, Huzur, Madhya Pradesh, India, 462011 (“Company” or “Genvolve”).

For the purposes of this Privacy Policy, “we,” “our” and “us” shall mean the Company and “you” and “your” shall mean any person who accesses or uses our Platform or its related Services, whether registered or not. For the purposes of this Privacy Policy, the term “parent” includes, where applicable, a lawful or legal guardian. The term “child” shall mean an individual who has not completed the age of eighteen years. Unless the context otherwise requires, references to a “child,” “children,” “child user” or “child users” in this Privacy Policy shall be construed accordingly and include children using the Platform.

We operate a web-based AI learning companion designed specifically for children aged 6 - 14 years. We are a purpose-built platform that combines AI-assisted learning with parent oversight through a parent-controlled account model. The Platform provides AI chat (text and voice), image generation, daily challenges, practice quizzes, multilingual support and parental monitoring tools, including conversation visibility, learning insights, topic restrictions, flagged content alerts, challenge management and time controls.

This Privacy Policy sets out how we collect, use, store, disclose and otherwise process your personal data when you access or use the Services.

Please read this Privacy Policy carefully before using the Services. By accessing or using the Services, you acknowledge that you have read, understood and agree to the terms of this Privacy Policy. We may update this Privacy Policy from time to time to reflect changes in our Services, applicable laws or practices. Where required, we will notify you of any material changes through email or a prominent notice on our Platform before such changes take effect. Your continued use of the Services after the updated Privacy Policy becomes effective constitutes your acceptance of the revised Policy. If you do not agree with any changes, you may discontinue using the Services and, where applicable, withdraw your consent in accordance with this Privacy Policy.

Data Fiduciary Information

The Company is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDPA”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), (together the “DPDP Framework”). The Company is responsible for determining the purposes and means of processing your personal data.

Our Commitments

  • Process personal data only with consent or under legitimate uses specified in the DPDP Framework;
  • Obtain verifiable parental consent before processing any child’s data in accordance with the DPDP Framework;
  • Implement appropriate technical and organisational measures to ensure effective observance of the DPDP Framework; and
  • To protect personal data in our possession, by taking reasonable security safeguards to prevent personal data breach.

Registered Office: 212, 2nd Floor, Hare, Govind Complex, Zone-1, Shiksha Mandal, Bhopal, Huzur, Madhya Pradesh, India, 462011

Contact: director@genvolve.ai

Collection & Processing of Personal Data

We collect and process personal data that is necessary to provide, maintain and improve the Services. Some personal data is required to create and manage your account and enable you to use the Services, while other information is optional. We will indicate where the provision of personal data is mandatory and where it is optional. We may also collect additional personal data as you continue to use the Services.

Depending on how you use the Services, we may collect personal data such as your name, email address, mobile number, account credentials and other information required to provide the Services. Where the Services are used by a child, we collect only the personal data necessary to provide the Services. This includes the child’s first name or nickname, age or age range, parent-child relationship mapping, chat prompts, AI responses, generated images, learning preferences, moderation events and session activity.

We also automatically collect certain technical information, such as your IP address, browser type, device type, operating system, device identifiers, usage logs and information about how you interact with the Services, to maintain the security and functionality of the Platform.

Where required to enable certain features, we may request access: (i) to your device’s microphone (to access voice mode), (ii) to browser’s microphone to capture speech and convert the speech to text for the user’s device using the browser’s built-in web speech API), (iii) camera or photo library, for the image upload feature. You may withdraw these permissions at any time through your device settings; however, certain features of the Services may no longer function as intended.

We collect only the personal data that is reasonably necessary to provide the Services as per applicable law.

We do not sell or rent your personal data to third parties and no audio is transmitted to any server. We process personal data only for the purposes described in this Privacy Policy and in accordance with applicable law.

We operate under a parent-controlled account model. A parent creates the account, completes email verification, accepts the Terms of Use and Privacy Policy, and creates the child profile(s). A child’s access to the Services is linked to the parent account. All parental consent actions are timestamped and auditable. We may introduce additional parental verification measures in the future, such as payment card verification, age-verification services and optional government-issued identification verification. In accordance with Rule 10 of the DPDP Rules, such verification will be carried out either by relying on identity and age details already voluntarily provided to and held by us, or through virtual tokens (such as an Aadhaar-linked token) authenticated via a Digital Locker service provider (such as DigiLocker).

Grounds for Processing Personal Data

We process your personal data only where we have a valid legal basis to do so under the DPDP Framework. Depending on the nature of the processing, we rely on one or more of the following grounds:

Consent: We process personal data based on your free, specific, informed, unconditional and unambiguous consent, including, where applicable, the verifiable consent of a parent for child users. You may withdraw your consent at any time in accordance with this Privacy Policy.

Legitimate Uses: We may process personal data without obtaining consent where such processing is permitted under the DPDP Framework, including:

  • to provide or maintain the Services requested or subscribed to by you;
  • to comply with applicable laws, regulations or lawful directions of governmental or regulatory authorities;
  • to provide medical treatment or health services during emergencies;
  • for recruitment, employment, intellectual property, or other related purposes, where appropriate safeguards exist; and
  • for any other legitimate purposes as may be prescribed by the Central Government.

Purpose Limitation: We process personal data only for the purposes for which it was collected or as otherwise permitted under legitimate uses. Where we intend to process personal data for a new purpose that requires consent, we will obtain such consent before undertaking the processing.

Category of Personal DataPurpose of ProcessingGround for Processing
Guardian Account (name, email, hashed password, Google OAuth profile)To authenticate users, administer accounts and manage subscriptions.Parental consent
Child profile (display name, age, school year, subjects, avatar)To provide personalised AI tutoring and parent dashboard functionality.Parental consent
Chat / session data (messages, session IDs, timestamps, token counts)To provide AI tutoring, maintain session continuity and enable parent monitoring.Legitimate use, Parental consent
Voice output only (AI-generated text sent to ElevenLabs, audio returned to the child)To generate AI-powered voice responses through text-to-speech. No child data is sent to ElevenLabs; only the AI tutor’s generated text is shared for this purpose.Legitimate use, Parental consent
Voice input (audio captured by browser microphone and processed client-side via the browser’s built-in Web Speech API)To convert speech to text on the user’s device for AI tutoring. No audio recordings are transmitted to our servers, OpenAI or any third party; only the resulting text is processed as a chat message.Legitimate use, Parental consent
OTP / verification (email, SHA-256 hashed OTP code)To verify user accounts and authenticate access to the Platform.Legitimate use, Parental consent
Subscription / billing (email, plan type)To manage subscriptions and process billing. Payment card information is processed directly by Stripe and is not stored by us.Legitimate use, Parental consent

Use of Personal Data

We may use your personal data for the following purposes:

  • to create, manage and administer your account;
  • to provide, operate and maintain the Services;
  • to provide AI-powered learning experiences and generate responses based on your inputs;
  • to process payments;
  • to monitor learning progress and provide insights and reports to parents, where applicable;
  • to provide parents with visibility into their child’s AI conversations and activity;
  • to enable parental controls, including topic restrictions, challenge management, time controls and flagged content alerts and account management features;
  • to respond to your queries, requests and provide customer support;
  • to generate learning insights for parents;
  • to communicate with you regarding the Services, including service updates, security alerts and other administrative communications;
  • to improve, develop and enhance our Services, features and user experience;
  • to monitor, maintain and improve the security, integrity and performance of the Platform, and prevent fraud, misuse and unauthorised access;
  • to comply with applicable laws, regulations and lawful directions of governmental or regulatory authorities;
  • to establish, exercise or defend our legal rights and resolve disputes; and
  • to process personal data for any other purpose for which you have provided your consent or as otherwise permitted under applicable law.

We will use your personal data only for the purposes described in this Privacy Policy or as otherwise permitted under the DPDP Framework and applicable law.

Sharing of Personal Data

We do not sell or rent personal data to third parties. A child’s personal data is never sold and is not used for behavioural advertising purposes. No child voice recordings or audio are transmitted to any third party.

We may share your personal data with trusted third-party service providers that assist us in providing the Services, however we do not share personal data with advertising or third-party analytics providers. These service providers process personal data only on our behalf and only for the purposes described in this Privacy Policy.

The categories of recipients include:

  • Amazon Web Services (AWS): to host, store and process application data, including the Platform infrastructure, databases and backups.
  • OpenAI: to process AI prompts and generate AI text responses and images through its API. When a child submits a prompt, the prompt is first received by us and processed through our safety filters. To maintain conversational context, OpenAI receives the full chat message history for the relevant session, including the child’s text prompts and AI-generated responses for generating AI tutor responses via gpt-4o-mini. Once OpenAI returns a response, we apply additional child-safety checks before displaying the response to the child. We do not intentionally transmit parent passwords, payment details, government IDs or internal account credentials to OpenAI. No audio or voice data is transmitted to OpenAI.
  • OpenAI (Fallback Text-to-Speech): where ElevenLabs is unavailable, we use OpenAI’s text-to-speech API to convert AI-generated text responses into speech. In such cases, only the AI-generated text response is transmitted to OpenAI for text-to-speech conversion. No child prompts, chat history or other personal data are transmitted for this purpose.
  • Elevenlabs: to convert AI-generated text responses into audio using its text-to-speech services. Only the AI-generated text response is transmitted to ElevenLabs for this purpose. No child voice recordings, audio or other voice data are transmitted to ElevenLabs.
  • Google: to authenticate users who choose to sign in using their Google account. Where you use the “Sign in with Google” feature, we receive basic profile information, such as parent’s name and parent’s email address, from Google solely for authentication purposes.
  • Email Service Provider (Resend/SMTP): to send one-time passwords and account verification emails to parent’s email address.
  • Payment Service Providers (Stripe): to process subscription payments and billing. Where you subscribe to a paid plan, we share information such parent’s email address and subscription details with Stripe for payment processing. Payment card information is collected and processed directly by Stripe, and we do not store your payment card details.

We may also disclose personal data where required by applicable law, legal process or a lawful request from a governmental or regulatory authority.

Your Rights as a Data Principal

Subject to the DPDP Framework and applicable laws, you are entitled to exercise the following rights in relation to your personal data:

  • Access: You may request confirmation as to whether we process your personal data, a summary of such personal data and information relating to its processing.
  • Correction and Erasure: You may request the correction, completion, updating or erasure of your personal data in accordance with applicable law.
  • Grievance Redressal: You may raise any concerns regarding the processing of your personal data by contacting our Grievance Officer using the details provided in this Privacy Policy. You may exercise your rights by contacting our Grievance Officer using the contact details provided in this Privacy Policy.
  • Nominate: You may nominate another individual to exercise your rights under the DPDPA in the event of your death or incapacity.
  • Withdraw Consent: Where we rely on your consent to process personal data, you may withdraw your consent at any time through the Platform by contacting us or through a registered Consent Manager. Withdrawal of consent will not affect the lawfulness of processing carried out prior to such withdrawal. Please note that withdrawing consent may affect our ability to provide certain Services.

Consent Management and Withdrawal

Before collecting or processing your personal data, we will provide a clear and easily accessible privacy notice setting out:

  • the categories of personal data to be collected;
  • the purposes for which such personal data will be processed;
  • the manner in which you can withdraw your consent; and
  • the contact details of our Grievance Officer.

Consent will be obtained through a clear affirmative action (such as selecting “I Agree,” clicking an opt-in button or through any other equivalent mechanism made available on the Platform) and will be specific to the purpose for which the personal data is collected. Where different processing activities require separate consent, such consent will be obtained independently.

You may use a registered Consent Manager to give, review or withdraw your consent.

Before processing a child’s personal data, we will obtain verifiable consent from the parent in accordance with applicable law. As part of this process, we may require the parent to identify themselves through the Platform and undertake appropriate verification measures to confirm that they are an identifiable adult who is the parent of the child. Such verification may be carried out using reliable identity and age information already available with us, identity and age information voluntarily provided by the parent, or a virtual token or other verification mechanism issued or made available by an authorised entity, including through a Digital Locker Service Provider, where applicable. We may also require additional verification or re-obtain verifiable parental consent where there is a change in the scope of processing or where otherwise required under applicable law.

Upon withdrawal of consent:

  • we will cease processing your personal data for the relevant purpose, unless such processing is required or permitted under applicable law;
  • we will erase your personal data within reasonable time of receipt of the withdrawal request, unless we are required to retain such personal data under applicable law; and
  • you may no longer be able to access or use certain features of the Services that depend on the processing of your personal data.

Withdrawal of consent will not affect the lawfulness of any processing undertaken prior to such withdrawal.

AI Model Training

We use OpenAI’s API and Elevenlabs API services to provide certain AI-powered features. Neither OpenAI’s API nor Elevenlabs API uses customer data to train its respective models, and we do not opt into any model training programmes using customer data. OpenAI may retain limited API data for abuse monitoring and security purposes in accordance with its policies. We maintain data processing agreements with relevant subprocessors.

Data Retention and Deletion

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected or as otherwise required or permitted under applicable law.

The table below sets out the categories of personal data collected by us and the corresponding retention periods:

Category of Personal DataRetention Period
Account Information (Parent and Child)Only for the duration of the account.
Chat messages and sessionsOnly for the duration of the account.
OTP recordsOnly for the duration necessary for the purpose.
Usage Logs & Technical Data1 year from collection of such data.
Billing recordsAs required under applicable law.
Support Data and CommunicationsOnly for the duration necessary for the purpose.

You may request deletion of your personal data at any time through the Platform or by contacting us using the details provided in this Privacy Policy. Upon a parent’s request for deletion, the parent account, associated child account(s), conversations and profile information are removed from active systems.

We will delete your personal data immediately as set out above upon verifying your request, except where:

  • retention is required or permitted under applicable law; or
  • the personal data is required for legal or regulatory proceedings.

Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, use, disclosure, alteration, loss or destruction. These measures include:

  • Role-based access controls (RBAC) to restrict access to personal data to authorised personnel with a legitimate business need;
  • AWS Identity and Access Management (IAM) permissions, multi-factor authentication (MFA), access logging and security reviews to manage and monitor access;
  • Encryption in transit using TLS 1.2+ and HTTPS for communications between user devices, Genvolve, AWS services and the OpenAI API;
  • Encryption at rest using AES-256 for databases, file storage, backups and snapshots, with encryption keys managed through AWS Key Management Service (KMS).

Access to children’s conversations is strictly restricted and is limited to authorised support personnel (where required), security administrators and infrastructure administrators, solely to the extent necessary to perform support, security or operational functions. All administrative access is logged and auditable.

While we take reasonable steps to protect personal data, no method of transmission over the internet or electronic storage is completely secure. Accordingly, we cannot guarantee the absolute security of personal data.

If we become aware of a personal data breach, we will take appropriate steps to investigate, contain and respond to the incident, including notifying affected individuals and the authorities in accordance with the DPDP Framework and applicable law.

Incident Response

We maintain an incident response plan to detect, investigate, contain, remediate and recover from security incidents. Security monitoring includes AWS CloudTrail, AWS GuardDuty, Amazon CloudWatch alerts, infrastructure monitoring and application logging. Our incident response process includes detection, containment, investigation, remediation, recovery and post-incident review.

Cross-Border Transfers of Personal Data

Personal data may be transferred to and processed outside India in connection with the provision of the Services. Such transfers are permitted under the DPDP Framework, except to any country or territory that may be restricted by the Central Government by notification under Section 16 of the DPDPA. As on the date of this Privacy Policy, no such restriction has been notified.

Cookies

We may use cookies and similar technologies to improve the functionality of the Platform, remember your preferences, analyse usage of the Services and enhance your overall user experience. You can manage or disable cookies through your browser or device settings. However, disabling cookies may affect the functionality of certain features of the Services.

Children’s Privacy

We are designed for children between the ages of 6 to 14 years. We are committed to protecting the privacy of children and process children’s personal data in accordance with applicable law.

We operate through a parent-controlled account model. Parents create and manage child accounts. Parents have visibility into their child’s conversations and activity through the parent interface. Children cannot edit, delete or hide messages or conversations from the parent account.

We obtain verifiable consent from a parent before collecting or processing a child’s personal data. We do not undertake processing that is likely to have a detrimental effect on the well-being of a child or use children’s personal data for behavioural monitoring or targeted advertising.

Parent Rights

Parents may, in accordance with applicable law:

  • access and review their child’s personal data;
  • manage topic restrictions, challenge settings and time control;
  • receive flagged content alerts and learning insights;
  • request correction, updating or deletion of their child’s personal data;
  • withdraw their consent for the processing of their child’s personal data; and
  • raise any concerns or complaints regarding the processing of their child’s personal data.

Educational Institutions

Schools may provide access to our Platform to their students through licensing arrangements with us. As part of the enrolment process, a school may share basic enrolment information (such as the names and contact details of the student and parent, and the child’s age or grade) with us to help set up an account.

Sharing this information is undertaken pursuant to a valid contract and does not activate a child’s account. We independently obtain verifiable parental consent through our own consent mechanism before activating any child account or processing a child’s personal data on the Platform, as set out above in this Privacy Policy.

School deployments operate as separate tenants, with technical controls including tenant isolation, role-based permissions, row-level security and audit logging to prevent cross-tenant access at both the application and database levels. School IT administrators have limited administrative access to manage the students assigned to their school, view school-specific analytics and school-generated content, and monitor service status for their school. School IT administrators cannot access our backend systems, family accounts, data relating to other schools or global platform data. Teachers do not have access to student data, and the parent-child monitoring relationship remains unchanged regardless of how access to the Platform is provided.

We remain responsible for determining the purposes and means of processing personal data on the Platform. Schools are responsible for ensuring that they are authorised to collect and share personal data with us in accordance with applicable law.

AI Service Provider

We use OpenAI’s API to generate AI text responses and images. Prompts are processed through our safety filters before being transmitted to OpenAI. AI responses are subject to additional child-safety checks before being displayed to the child. Only information necessary to generate the AI response is transmitted to OpenAI.

We use ElevenLabs’ API to generate AI-powered voice responses. Text submitted for voice generation is processed through our safety filters before being transmitted to ElevenLabs. Voice responses may be subject to additional child-safety checks before being made available to the child. Only the information necessary to generate the voice response is transmitted to ElevenLabs.

The technical flow is as follows:

  • A child sends a message (either as text or as voice converted to text client-side using the browser’s Web Speech API).
  • OpenAI generates the AI tutor’s text response.
  • The AI-generated text response is sent to the ElevenLabs /v1/text-to-speech/{voiceId}/stream endpoint.
  • ElevenLabs generates a streamed MP3 audio file. The browser plays the audio, allowing the child to hear the AI tutor’s response.

No child voice recordings or audio are transmitted to ElevenLabs. Only the AI tutor’s generated text response is sent to ElevenLabs for text-to-speech conversion. ElevenLabs’ eleven_multilingual_v2 model is utilised and provides 17 voice options, with each child’s preferred voice preference stored in the database. If ElevenLabs is unavailable, OpenAI’s tts-1 model using the nova voice is used as the fallback text-to-speech service.

AI Safety and Content Moderation

We use a layered safety approach to help protect children when using AI-powered features, including image generation:

  • Layer 1 – Input Moderation: User prompts are screened for inappropriate content, including sexual content, nudity, self-harm, violence, hate speech, illegal activity and child exploitation content before being processed.
  • Layer 2 – AI Provider Safeguards: OpenAI applies its own safety systems to AI requests.
  • Layer 3 – Output Review: Generated content may undergo additional checks before being displayed to users.

In case a child attempts to generate inappropriate content, the request is blocked, the child receives an appropriate educational message, and the attempt may be logged and surfaced to the parent through monitoring tools. We remain responsible for implementing reasonable child safety controls and moderation policies, while OpenAI remains responsible for the operation of its AI systems in accordance with its terms and policies.

Contact and Grievance Redressal

If you have any questions, concerns or complaints regarding this Privacy Policy or our processing of your personal data, or if you wish to exercise your rights under applicable law, you may contact our Grievance Officer using the details below:

Grievance Officer: Arjun Dhawan

Address: 212, 2nd Floor, Hare, Govind Complex, Zone-1, Shiksha Mandal, Bhopal, Huzur, Madhya Pradesh, India, 462011

Email: admin@genvolve.ai

Response Timeline and Notifications

We are committed to addressing your requests and complying with our obligations under the DPDP Framework.

We will respond to grievances submitted by data principals within a reasonable period not exceeding 30 days from the date of receipt.

In the event of a personal data breach, we will notify affected data principals and the Data Protection Board of India without delay after becoming aware of the breach. We will also submit a detailed report to the Data Protection Board of India within 72 hours, or within such extended period as may be permitted by the Board.

Grievance Redressal Process

Step 1: Submit your grievance to our Grievance Officer by email or post using the contact details provided above.

Step 2: We will review your grievance and provide our response within the timelines set out above.

Step 3: If you are not satisfied with our response, you may seek such remedies as are available under the DPDP Framework, including by approaching the Data Protection Board of India, where applicable.

Dispute Resolution

This Privacy Policy shall be governed by and construed in accordance with the laws of India.

Any dispute, controversy or claim arising out of or in connection with this Privacy Policy, including its interpretation, validity or implementation, shall be subject to the exclusive jurisdiction of the competent courts at Bhopal, Madhya Pradesh, India.