Privacy policy
Last updated: 7 October 2026
This notice explains what personal data approvd.in collects, why, how long we keep it, and the rights you have. It is written to meet the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 of India. If anything here is unclear, write to us at info@learningowl.in.
1. Who we are
approvd.in is a product of Learning Owl Pvt Ltd (“Learning Owl”, “we”, “us”), a company incorporated in India (CIN: U72900MH2020PTC346055), with its registered office at 308/309, Prism Industrial Estate, MIDC, behind Pendharkar College, above Family Tree Hotel, Dombivli East 421201, Maharashtra, India. For the personal data described in section 3, Learning Owl is the Data Fiduciary: we decide why and how it is processed.
Contact for anything about your personal data: info@learningowl.in (subject line “Privacy”).
2. Two roles: our data, and our customers’ data
approvd.in is a review tool that studios and companies (our customers) use to collect feedback from their own teams and clients.
- Where we are the Data Fiduciary: visitors to this website, people who request an invite, and the account details of people who sign up (section 3).
- Where we are a Data Processor: everything a customer puts into their workspace: the people they invite (team members and client reviewers), comments, annotations, review rounds, sign-offs, activity history and the names and emails guest reviewers enter on a review link. We process this only on the customer’s instructions to provide the service. The customer is the Data Fiduciary for it, so requests about that data should go to the customer first. We will help them answer it.
- Files under review (videos, documents, packages) are stored in the customer’s own storage account, which the customer chooses and controls. Our servers handle files only temporarily, for tasks such as creating thumbnails, converting documents or video, and serving HTML5 packages to reviewers.
3. Personal data we collect as Data Fiduciary
We collect only what each purpose needs. We do not sell personal data, and we do not use it for advertising or profiling.
| Purpose area | Personal data | Why we use it | Basis under the DPDP Act | How long we keep it |
|---|---|---|---|---|
| Invite request | Name, work email, company, role, team size, content types you review, optional message, your consent | To assess your request, send your invite and contact you about it | Your consent | Up to 12 months after we last contact you, unless you open an account |
| Your account | Name, email, password (stored only as a bcrypt hash), role, optional phone number and profile picture, email-verification status, last sign-in time | To create and secure your account, sign you in, and send service emails (verification, invites, password resets) | Your consent at sign-up, and personal data you provide voluntarily to use the service | While your account is active; erased within 30 days of an erasure request or account closure (backups age out within 60 days) |
| Service emails | Your name and email address, and the content of the notification | To deliver verification, invite, password-reset and review-activity emails | Your consent at sign-up | Not kept by us after sending, beyond the email provider’s own records |
| Security records | Website server logs (IP address, browser type, page requested, time); IP address on staff actions in our operator console | To keep the service secure, detect abuse and investigate incidents | Personal data you provide voluntarily when you visit, and our duty to protect personal data | Website server logs: 14 days. Operator audit records: while the related account exists |
This website sets no cookies, runs no analytics and loads no third-party tracking. The approvd.in app uses only strictly necessary cookies to keep you signed in securely.
4. Consent, and withdrawing it
- Where we rely on consent, we ask for it with a clear action (for example, ticking the box on the invite form or creating an account), for the specific purposes shown above.
- You can withdraw consent at any time, as easily as you gave it: email info@learningowl.in with the subject “Withdraw consent”. You can also ask us to close your account.
- After you withdraw, we stop processing and erase the related personal data within 30 days, unless a law requires us to keep it. Withdrawing does not affect processing that already happened, and it may mean we can no longer provide the service to you.
5. Your rights
Under the DPDP Act you have the right to:
- Access information: a summary of the personal data we hold about you, what we do with it, and the identities of others we have shared it with (section 7).
- Correction and erasure: to have inaccurate or incomplete data corrected, completed or updated, and to have data erased when it is no longer needed or you withdraw consent.
- Grievance redressal: to complain to us and get a response (section 11).
- Nominate another person to exercise your rights if you die or become unable to do so.
To use any right, email info@learningowl.in from the address linked to your data (or tell us how to verify you). We will respond to your request. If your request concerns data in a customer’s workspace, we will pass it to that customer and help them respond.
The Act also asks you not to file false or frivolous complaints, not to impersonate anyone, and to give accurate information when you ask us to correct your data.
6. Children
approvd.in is a business tool for adults and is not meant for anyone under 18. We do not knowingly collect personal data of children, and we do not track, profile or target advertising at children. If we learn that we hold a child’s data without verifiable consent from a parent or lawful guardian, we will delete it. Customers who place content involving children into their workspace are responsible, as Data Fiduciary, for obtaining the consent the law requires.
7. Who we share personal data with
We share personal data only with service providers (Data Processors) that help us run approvd.in, under contract and only for these purposes, or when the law requires it:
- Oracle Cloud Infrastructure: hosts our servers and database in the Mumbai, India region.
- Our email delivery provider: delivers our service emails (verification, invites, password resets). If a customer sets up their own email server in their workspace settings, their notification emails are sent through that customer’s provider instead.
- The customer’s chosen storage provider (such as AWS, Cloudflare R2, Wasabi, Backblaze B2, DigitalOcean Spaces or MinIO): holds files under review. The customer engages this provider directly.
- YouTube (Google): only if a customer chooses to review YouTube links.
- Authorities: where Indian law requires us to disclose data.
8. Where your data is stored
Our application servers and database are located in India (Mumbai). Some service providers, such as an email delivery provider or a storage provider a customer chooses, may process data outside India. Any such transfer follows section 16 of the DPDP Act, and we will not transfer personal data to any country the Government of India restricts.
9. How we protect personal data
- Encryption in transit (HTTPS/TLS) for the website and the app.
- Passwords stored only as salted bcrypt hashes; sign-in sessions held in secure, HTTP-only cookies.
- Strict separation between customer workspaces, and role-based access control inside each workspace.
- Limited staff access, with operator actions recorded in an audit log.
- Daily database backups, regularly test-restored, so data can be recovered if something goes wrong.
- Server logs kept for 14 days to detect and investigate misuse.
No system is perfectly secure. If a personal data breach happens, we will inform affected people without delay, describing what happened, the likely impact, what we are doing about it and what you can do, and we will report it to the Data Protection Board of India as the DPDP Rules require, including a detailed report within 72 hours of becoming aware of it.
10. How long we keep personal data
| Data | Retention |
|---|---|
| Website server logs | 14 days, then automatically deleted |
| Invite requests | Up to 12 months after last contact, unless you open an account |
| Account data | While your account is active; erased within 30 days of an erasure request or closure |
| Database backups | Daily copies kept 14 days, weekly copies kept 60 days; erased data disappears from backups when they expire |
| Review data in a customer workspace | As decided by that customer (the Data Fiduciary), and removed when they delete it or close their account |
When the purpose is served, or you withdraw consent, we erase the data unless a law requires us to keep it for longer.
11. Grievances
If you have a concern about how we handle your personal data, contact us at info@learningowl.in with the subject “Privacy grievance”, and we will look into it. If you are not satisfied with our response, you may complain to the Data Protection Board of India under the DPDP Act.
12. Changes to this notice
If we change how we use personal data, we will update this page and the date at the top, and for material changes we will tell account holders by email before the change takes effect.