The short version
- You can read the syllabus and previous year papers without an account.
- If you sign up, we keep your account details, the branch and semester you study, and what you create on the site: notes, practice attempts and AI assistant chats.
- Microsoft Clarity shows us how pages are used. Cloudflare delivers and protects the site. Razorpay handles payments. OpenRouter runs the AI assistant.
- CampusPrep shows no ads and loads no advertising trackers.
- Questions or requests go to [email protected].
Browsing without an account
We do not ask for any personal details to read the syllabus or previous year papers.
- Cloudflare sits in front of the site. It processes your IP address, browser details and the pages you request so it can deliver pages and block abuse.
- Microsoft Clarity records how visitors use pages, such as page views, clicks, scrolling, and device and browser type, and can replay a visit as a session recording. We use it to find problems and improve pages. Microsoft handles this data under its own privacy statement.
- Your display settings (light or dark mode and theme) and the last branch and semester you opened are stored on your device. See Cookies and storage.
Creating an account
- Email sign-up: your email address and a password. We store only a hashed form of the password. We email you a link to verify the address, and a reset link if you ask for one.
- Google sign-in: Google shares your name, email address, profile picture link and Google account ID with us. We keep that profile with your account.
- Your username is made from the part of your email address before the @.
- Account setup: we ask for your first and last name, phone number, branch and semester, and use the branch and semester to show your study material. We do not send SMS or verify the phone number.
- Cloudflare Turnstile runs on the sign-up, log-in, password reset and account setup forms to check that a person is using them. Cloudflare receives a check token and your IP address.
What you create on the site
When you are signed in, we store:
- Notes you write for a subject or unit, up to 50 earlier versions of each note, and images you add to notes.
- Highlights, pen strokes and notes you add while reading.
- Practice attempts: each answer, whether it was right, your score and the time taken.
- Study activity: points, streaks, the last day you were active and your study sessions. While a document is open, the reader sends the number of seconds you spent actively reading about once a minute. The check for whether you are active runs in your browser; your mouse and key presses are not sent to us.
- Notifications we show you on the site.
- If you allow browser notifications, the push subscription your browser gives us, the browser name and its user agent string.
Signed-in visits also install a small background script (a service worker) that keeps copies of pages you opened on your device, so they load faster and work offline. Account, payment, AI and API pages are not kept.
The AI assistant
Your chats, messages, attached files and usage counts are stored with your account. Each time you send a message, we send the AI provider:
- your message and up to 200 earlier messages from the same chat;
- your assistant preferences, the “about me” text and custom instructions you saved, and up to 30 saved memories;
- files you attach: images, and the text of PDF and text files.
The provider is OpenRouter, which passes the request to the company that runs the chosen model, for example Google (Gemini) or Anthropic (Claude). Free models can be run by other providers through OpenRouter. Each provider handles the request under its own terms, so do not put sensitive personal information in a chat.
Memories: after every 50 messages you send, your recent messages are sent to the model to create or update short memories about your preferences. You can review and delete them in the assistant’s memory settings.
Quality monitoring: when tracing is switched on, prompts and answers are recorded in Langfuse, a service for monitoring AI quality.
Shared chats: if you share a chat, anyone with the link can read its title and messages, the model name, usage counts, times, image thumbnails and file names. Your username is not shown. You can stop sharing a chat at any time.
Payments and Gold Pass
- Razorpay processes payments. Card, UPI and bank details go to Razorpay; CampusPrep never receives them.
- We send Razorpay the amount, an order reference built from internal IDs, and your username and email address to fill in the payment form.
- We keep a record of each purchase: what you bought, the amount, the Razorpay order and payment IDs, the status and the date. Payment events are also written to a log for auditing.
- Invoices show your name, email address, the payment and order IDs and the amount.
- The checkout page loads a placeholder avatar image from avataaars.io, which receives your IP address when it loads.
Cookies and storage
- sessionid
- Keeps you signed in and holds short-lived reader state.
- Set by CampusPrep · Up to 2 weeks
- csrftoken
- Protects forms from requests sent by other sites.
- Set by CampusPrep · Up to 1 year
- theme, campusprep_theme, campusprep_style, campusprep_light, campusprep_dark
- Remember light or dark mode and your display theme.
- Set by CampusPrep · 1 year
- Clarity cookies
- Usage analytics.
- Set by Microsoft · kept under Microsoft’s own rules
- Security cookies
- Bot checks and protection.
- Set by Cloudflare · kept under Cloudflare’s own rules
- Checkout cookies
- Running the payment form.
- Set by Razorpay · kept under Razorpay’s own rules
The site also keeps some settings in your browser’s local storage, which stays on your device: display preferences, reader panel settings, the last page you opened in a PDF, annotations waiting to be saved, the assistant’s window layout, and the last branch and semester you opened (used for the “Continue” shortcut). You can clear cookies and site data at any time in your browser settings.
Who else handles your data
- Cloudflare: delivers the site, runs Turnstile checks and stores uploaded files.
- Microsoft Clarity: usage analytics.
- Google: Google sign-in if you use it, and the font the site uses, which your browser loads from Google Fonts.
- Razorpay: payments.
- OpenRouter and the model providers it routes to: the AI assistant.
- Langfuse: AI quality monitoring, when tracing is switched on.
- Our email provider: verification and password reset emails.
- Browser push services run by your browser’s maker: delivery of notifications you allowed.
- Public content networks (jsDelivr, unpkg and cdnjs): your browser downloads scripts and styles from them.
- YouTube, only when a note contains a YouTube video, and avataaars.io on the checkout page.
How long we keep it
- Account and profile details: for as long as your account exists.
- Chats and memories: until you delete them. Attachments stay in storage after their chat is deleted; when your attachment storage is full, the oldest files are removed automatically.
- Notes: the current version plus up to 50 earlier versions.
- Purchase records: kept as the record of each payment. The payment log is kept in rotating files of about 10 MB each, five at most.
- Sign-in sessions: up to two weeks.
- Analytics: kept by Microsoft Clarity under its own retention rules.
- We do not delete inactive accounts automatically.
Your choices and requests
- You can use the syllabus and previous year papers without an account.
- Signed in, you can change your branch and semester, delete chats, stop sharing a chat, and delete memories. You can turn off notifications in your browser settings.
- You can clear cookies and site data in your browser, and block analytics with your browser’s tracking protection.
- To get a copy of your data, correct it, or have your account and data deleted, email [email protected] from the address on your account. There is no self-service deletion yet, so these requests are handled by email.
Changes to this policy
When the site starts collecting something new or changes how it uses your data, we update this page and the date at the top. Questions about this policy: [email protected].