Legal

Privacy Policy

Last updated: September 2, 2026

ArcharyaX is a study-abroad guidance platform available at archaryax.ai and through the ArcharyaX Android app. This policy explains what information we collect when you use ArcharyaX to build your profile, get university recommendations, and manage your applications — and how we handle it. We do not sell your personal data, we do not share it with third parties for advertising or marketing purposes, and we do not use it to train AI models. If you sign in with Google, section 3 sets out exactly what Google data we receive and what we do with it.

1. Who we are

ArcharyaX (“ArcharyaX”, “we”, “us”) operates the website at https://archaryax.ai and the ArcharyaX Android application. We are the controller of the personal data described in this policy. You can reach us at any time at support@archaryax.ai.

2. Information we collect

We collect information you provide directly, and some generated as you use the product:

  • Account information — your email address, and a password stored only as a salted hash. If you sign in with Google, we store your email address and your Google account identifier instead of a password (see section 3).
  • Profile & onboarding data — academic history, target degree, field of study, budget, preferred destinations, test scores, and similar details you enter to get personalised recommendations.
  • Documents you upload — resumes, transcripts, statements of purpose, and other application documents you choose to store in ArcharyaX for your own reference and tracking.
  • Usage & product data — the recommendations, roadmaps, gap analyses, and chat conversations ArcharyaX generates for your journeys, and basic usage logs (feature used, timestamps, response times) that help us keep the product working and priced fairly via our credit system.
  • Payment information — if you purchase credits, payment is processed by Razorpay. We receive confirmation of successful/failed payments and an invoice reference; we do not receive or store your card, UPI, or bank details ourselves.
  • School-provisioned accounts — if your school or institution sets up your account, your school administrator may provide your name and email to create it.

3. Google sign-in and Google user data

Signing in with Google is entirely optional — you can always create an ArcharyaX account with an email address and password instead. If you do choose Google sign-in, this section describes precisely what we request, receive, store, use, and share.

Limited Use disclosure

ArcharyaX's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we request

ArcharyaX requests only the three basic OAuth scopes needed to identify you: openid, email, and profile. We request no sensitive or restricted scopes.

What Google sends us

After you consent, Google returns a signed ID token containing your Google account identifier, your email address, whether that email is verified, and basic profile details such as your display name.

What we actually store

  • Your email address, which becomes your ArcharyaX account identifier.
  • Your Google account identifier (the stable sub claim), so we can recognise you on subsequent sign-ins and link the Google account to the right ArcharyaX account.

That is the complete list. We request online access only — we never ask for offline access or a refresh token, and the short-lived credentials returned during sign-in are used once to verify your identity and then discarded. We do not retain Google access tokens, and we do not store your Google profile picture.

How we use it

Solely to authenticate you, to create or link your ArcharyaX account, and to send you account and transactional emails at that address. Google user data is never used for advertising or marketing, is never sold or transferred for value, and is never used to train, retrain, or fine-tune any AI or machine-learning model — ours or anyone else's. Your Google identifier is not shared with our AI model provider.

What we never access

ArcharyaX holds no permissions over Gmail, Google Drive, Google Contacts, Google Calendar, Google Photos, or any other Google service, and cannot read, write, or delete anything in your Google Account. The scopes above do not grant that access, and we do not request it.

On the Android app

In the ArcharyaX Android app, Google sign-in opens in your device's system browser rather than inside the app, so your Google credentials are never entered into an ArcharyaX-controlled screen. Once Google confirms your identity, a single-use token valid for two minutes returns your session to the app. The app never sees your Google password or tokens.

Revoking access

You can disconnect ArcharyaX from your Google Account at any time at myaccount.google.com/permissions. Revoking stops any future Google sign-in; to also delete the data we already hold, follow section 10.

4. How we use your information

  • To generate your university matches, admit-chance predictions, gap analysis, roadmap, and AI advisor responses.
  • To operate your account — authentication, session management, and the credit system that meters AI-powered features.
  • To process credit purchases and keep accurate records of your transactions and invoices.
  • To maintain and improve ArcharyaX — debugging, security monitoring, and understanding which features are actually useful.
  • To communicate with you — account emails (password resets, receipts) and, if you contact us, to respond.

We do not use your personal data for advertising, for marketing profiles, or for automated decisions that produce legal effects.

5. AI processing

Generating your recommendations, roadmap, and chat responses requires sending relevant parts of your profile (never your raw documents in full, only what's needed for the specific request) to our AI model provider, Groq, which hosts the open-weight models that power those features. This processing happens to serve your request in real time — it is not used to build advertising profiles, we do not sell this data, and it is sent under terms that do not permit using it to train models. Data received from Google Sign-In is never included in these requests.

6. Data storage & security

ArcharyaX runs entirely on Cloudflare's infrastructure — your account, profile, and journey data is stored in Cloudflare D1 (database), uploaded documents in Cloudflare R2 (object storage), and session/cache data in Cloudflare KV, all within Cloudflare's global network. Passwords are stored as salted hashes, never in plain text. Session cookies are signed and HttpOnly, and all traffic is served over HTTPS. Access to production data is restricted to the people who operate the service.

No system is perfectly secure, but we take reasonable technical measures to protect your data against unauthorized access, alteration, or disclosure.

7. Sharing of information

We do not sell your personal information, and we do not share it with third parties for advertising or marketing purposes. We share data only with the service providers necessary to operate ArcharyaX:

  • Cloudflare — hosting, database, file storage, and content delivery.
  • Razorpay — payment processing for credit purchases.
  • Google — only if you choose to sign in with Google, and only to complete that sign-in.
  • Groq — AI model hosting, to generate the recommendations and chat responses you request.
  • Email delivery provider — to send account and transactional emails.

Data received from Google Sign-In is not transferred to any of these providers, except that we send account and transactional email to the same address. It is never transferred to advertisers, data brokers, or information resellers.

We may also disclose information if required by law, or to protect the rights, safety, or property of ArcharyaX, our users, or others.

8. Cookies

We use a small number of essential cookies to keep you signed in (a signed session cookie) and, during Google sign-in, short-lived cookies to complete the OAuth flow securely. We do not use third-party advertising or tracking cookies.

9. Data retention

We retain your account and journey data for as long as your account is active, so your progress, documents, and history remain available to you. You can delete individual journeys at any time from your dashboard. Transaction and invoice records may be kept longer where tax or accounting law requires it.

10. Deleting your data

To have your ArcharyaX account and its associated data deleted, email support@archaryax.ai from the address on the account, or use our contact page, with the subject “Account deletion request”.

We confirm and complete deletion requests within 30 days. Deletion removes your profile, journeys, uploaded documents, chat history, and — for Google-linked accounts — the stored email address and Google account identifier described in section 3. Records we are legally required to keep, such as payment invoices, are retained for the statutory period and nothing more. Deleting your ArcharyaX account does not by itself revoke ArcharyaX's connection to your Google Account; do that separately at myaccount.google.com/permissions.

11. Children's privacy

ArcharyaX is intended for students planning post-secondary education and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information without appropriate consent, contact us and we will remove it.

12. Your rights

You can access, update, or delete most of your profile information directly from your account settings. You also have the right to request a copy of the personal data we hold about you, to have inaccurate data corrected, to have your data deleted (section 10), and to withdraw consent for optional processing — including disconnecting Google sign-in. Email us and we'll help; we respond within 30 days.

13. Changes to this policy

We may update this policy as ArcharyaX evolves — for example, as we add new features, integrations, or once we have more detail to share about our data practices. We'll update the “Last updated” date above when we do. Material changes will be communicated on this page. If a change would expand how we use data received from Google APIs, we will describe it here before it takes effect.

14. Contact us

Questions about this policy or your data? Email support@archaryax.ai or use our contact page, or read our Terms of Service.