Privacy Policy
Last updated: [Effective date — fill in before publishing]
VedicNeev Institute Suite (“we,” “us,” or “our”) operates omrtest.vedicneev.com, a batch OMR grading platform for coaching institutes. This Policy describes what data we collect from an institute and its administrators, how OMR scan images are stored and secured, and your rights over that data. It applies to every Institute Admin who signs in to this platform. It is separate from, and covers different data than, the Privacy Policy for our consumer product at vedicneev.com/privacy.
1. Who This Covers
This Policy applies to Institute Admins — the coaching-center staff who sign in to omrtest.vedicneev.com to create test batches, generate OMR sheets, and upload scans for grading. Student data appears here only as it's printed on and scanned from an OMR sheet (roll number, name if provided, and bubble responses) — students themselves never create an account or sign in to this platform.
2. Information We Collect
- Admin identity. Your WhatsApp-verified phone number and name, used for sign-in and to attribute actions (test creation, uploads) to an account.
- Institute profile. Institute name, branch/city, target exam category, and optional brand color/logo used to customize your printed OMR sheets.
- Test batch data. Batch names, test codes, subjects, question counts, and the answer key you set for grading.
- OMR scan images. Photos or scans of filled answer sheets you upload for grading, and the roll number, bubble responses, and score derived from each.
- Credit ledger activity. A record of scan-credit grants and consumption tied to your institute account (see Section 5).
3. How We Store & Secure OMR Scan Images
Every uploaded scan is stored in a private Supabase Storage bucket (omr-uploads) — not publicly readable by URL, and accessible only through this application's authenticated, institute-scoped API routes. A request for one institute's scans is always checked against that institute's own session before the file is served; one institute can never read another's uploads. The database itself (PostgreSQL on Supabase) encrypts data at rest and in transit, and all traffic to omrtest.vedicneev.com is served over HTTPS.
We retain scan images for as long as your institute account remains active, so batches and grading history stay auditable. On request, we will delete an institute's scan images and associated records, except where we're required to retain credit-ledger records to resolve a billing dispute.
4. Anti-Fraud Sheet Tokens
Each printed OMR sheet carries a unique, pre-assigned sheet ID bubbled directly onto the sheet, used only to match an uploaded scan to the correct student roster entry and prevent a photocopied sheet from being scored twice. This token is not personally identifying on its own and is discarded from usefulness once a batch's grading is complete.
5. Institutional Credit Ledger
Scan credits are tracked in an append-only ledger tied to your institute account (grants, consumption per successful scan, and refunds for a rejected/duplicate scan). We retain this ledger to support billing accuracy and dispute resolution, and it is visible to your own institute's admins and, for support and compliance purposes, to VedicNeev's own administrators.
6. Third-Party Service Providers
- Supabase — database and private file storage hosting.
- Meta (WhatsApp Business Cloud API) — delivery of sign-in one-time codes.
- Vercel — application hosting.
We do not permit these providers to use your data for their own independent purposes.
7. Your Rights
Subject to applicable law, an Institute Admin can:
- Request a copy of the data we hold for their institute account.
- Ask us to correct inaccurate institute profile information.
- Request deletion of their institute's account, scan images, and associated records.
8. Changes to This Policy
We may update this Policy as the platform evolves. We will update the “Last updated” date above when we do.
9. Contact Us
Questions about this Policy? Contact us at admin@vedicmindai.in.
This page is a draft aligned with how this platform actually handles data today. It should receive a legal review before publication.