DSAIEngineeringGym

Last updated 2 October 2026

Privacy policy

DSAIEngineeringGym ("the gym", "we", "us") is run by Mohit Saharan, an individual based in India. This policy explains what personal data the gym collects, why, who processes it for us, how long it is kept, and your rights. It is written to meet India's Digital Personal Data Protection Act, 2023 (the DPDP Act) and, for people in the European Union or the United Kingdom, the GDPR.

Contact and grievance officer: Mohit Saharan, mohit.saharan.ai@gmail.com. We answer within 30 days.

What we collect

  • Account: your name (for GitHub sign-ins, your GitHub username if your profile has no name) and email address, and either a password (stored only as a salted scrypt hash, never in readable form) or the GitHub or Google account you sign in with. From those providers we keep the account ID, your provider-verified email address, and the profile picture link if they share one. We do not keep the access or ID tokens they issue.
  • Learning activity: lessons opened and completed, how you rated each flashcard and when it is next due, and the XP you earn each day, from which your streak is worked out.
  • Social features, if you use them: your public username, friend requests and friendships, cheers, the members you block, and whether you appear on the global leaderboard.
  • Settings: your time zone, read from your browser, so that days and streaks follow your calendar.
  • Security data: your IP address and email address are used to limit repeated attempts (for example, password guesses). They are stored only as keyed one-way hashes, in counters that stop counting within an hour (a day for limits on member accounts) and are cleared out after that.
  • Technical data: our hosting provider logs requests (IP address, browser, page) to run and protect the service. When something breaks, an error report records what failed, on which page, and in which browser, without cookies, form contents, or request bodies. Page-view analytics count visits without cookies and without identifying you.
  • Bot checks: when you sign up or ask for a password reset, Cloudflare Turnstile checks that a person is filling in the form, using signals from your browser.

We do not collect payment details (the beta is free), sell personal data, show ads, or use your data to train AI models.

Why we use it

  • To run the gym for you: your account, progress, review schedule, and the social features you choose. In GDPR terms, this is needed to provide the service you signed up for; under the DPDP Act, you consent to it when you create an account.
  • To keep the gym secure and working: rate limits, bot checks, logs, and error reports (our legitimate interest in a safe, working service).
  • To improve lessons: counting visits and activity in aggregate (our legitimate interest; page-view analytics are cookieless and anonymous).
  • To email you about your account: email confirmation, password resets, and replies to reset requests. We do not send marketing email without asking you first.

What other members see

Pages behind sign-in are visible only to signed-in members.

  • Global leaderboard: in any week you earn XP, signed-in members can see your username and that week's XP if you make the top 20, unless you opt out on the Friends page. You appear only once you have a username and a confirmed email.
  • Friends see your name, username, streak, this week's XP, whether you are training right now, and the lessons you finished in the last 7 days. A friend you cheer sees the cheer.
  • Friend requests show the people you send them to your name and username.
  • Invite links: anyone with your invite link sees your username.
  • Blocking ends any friendship or request between you. Members you block cannot send you requests, neither of you sees the other on the global leaderboard, and they are not told.

Who processes it for us

These service providers handle data only to provide their service to us:

  • Vercel Inc. (United States): hosting, request logs, and page-view analytics.
  • Neon Inc. (United States): the database.
  • Resend (United States): sending account emails.
  • Cloudflare, Inc. (United States): Turnstile bot checks.
  • Functional Software, Inc. (Sentry) (United States): error reports.
  • GitHub and Google: only if you sign in with them. Their own privacy policies apply to your accounts there.

Your data may therefore be stored or processed outside India and outside the EU and UK. Where the GDPR applies, these transfers rely on the providers' standard contractual clauses or equivalent safeguards.

Cookies

The gym sets only the cookies needed to sign you in: a session cookie (it lasts up to 30 days), a security (CSRF) cookie, one that remembers where to return after signing in, and, during a GitHub or Google sign-in, short-lived cookies that protect that sign-in. Signing out leaves a small note in your browser's storage so other open tabs sign out too. There are no advertising or tracking cookies, which is why there is no cookie banner.

How long we keep it

  • Account and learning data: until you delete your account. You can do that at any time on your Account page: it takes effect at once, removes everything tied to the account, and signs out your other devices. You can also email us from your account's address, and we delete it within 7 days.
  • Backups: deleted data can remain in our backups until they rotate out (we keep the last 30, in encrypted storage) and in our database provider's short restore history.
  • Security data: rate-limit counters stop counting within a day and are then cleared out. Email confirmation links expire after 24 hours and password-reset links after an hour.
  • Logs and error reports: kept by our providers for a limited time, up to 90 days.
  • If the gym closes: we will email you at least 30 days before when we can (as the terms say), and delete all personal data afterwards.

Your rights

  • Under the DPDP Act: you can ask for a summary of your data and how it is used, have it corrected, completed, or erased, have a grievance addressed, and nominate someone to exercise these rights if you die or cannot act. If we do not resolve a grievance, you can complain to the Data Protection Board of India.
  • Under the GDPR, if it applies to you: you can access, correct, erase, restrict, or object to the processing of your data, receive it in a portable format, and complain to your local data protection authority.
  • Withdrawing consent: delete your account; processing stops, except what the law requires us to keep.

Email mohit.saharan.ai@gmail.com from your account's address to use any of these rights. We answer within 30 days.

Children

The gym is for adults: you must be 18 or older to create an account. If we learn that a child has an account, we delete it.

Security

Passwords are hashed with scrypt, traffic is encrypted with HTTPS, and repeated attempts are rate-limited. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.

Changes to this policy

We will update the date at the top when this policy changes, and email you before significant changes take effect.