Privacy Policy

Version: 2026-08-11
Effective date: 2026-08-11

This Privacy Policy explains how ABTalks (“we”, “us”) collects, uses, shares, and protects personal data when you use our Service. It is designed around our actual product practices and India’s Digital Personal Data Protection Act, 2023 (DPDP), with disclosures relevant to US-facing cohort and program features.

Contact for privacy / data rights: team@abtalks.in
You can also submit a request in-product at /privacy/requests.

How to read this Policy. Each section starts with a short plain-English note, then the full detail. The short notes are guides only — the full text is what governs.


1. Who we are — Data Fiduciary identification

In plain English: We are ABTalksOnAI, a sole proprietorship. We decide why and how your data is used for this Service. You can contact our Grievance Officer at team@abtalks.in.

We are the Data Fiduciary for the personal data described in this Policy.

FieldDetail
Registered entityABTalksOnAI
Entity typeSole Proprietorship (Proprietary)
Enterprise scaleMicro (Udyam)
Major activityServices
Industry (NIC)62099 — Other information technology and computer service activities n.e.c.
ProprietorSuman Shukla
Trading nameABTalks
Unit nameABTalksOnAI
Registered addressFlat No 803-A, Tower 2A, 8th Floor, Panchsheel Wellington, Crossing Republic, Ghaziabad, Uttar Pradesh 201016, India
Udyam registration numberUDYAM-UP-29-0250625
Udyam registration date01 August 2026
Date of incorporation25 July 2026
Contactteam@abtalks.in

ABTalks operates learning challenges, workshops, hackathons, an AI cohort program, and related recruiter/community features at our websites (including abtalks.in and related domains).

1.1 Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Rules, 2021, and the Consumer Protection (E-Commerce) Rules, 2020:

FieldDetail
NameSuman Shukla
DesignationProprietor and Grievance Officer
Emailteam@abtalks.in
AddressFlat No 803-A, Tower 2A, 8th Floor, Panchsheel Wellington, Crossing Republic, Ghaziabad, Uttar Pradesh 201016, India

We acknowledge grievances within 24 hours of receipt and aim to resolve them within 15 days. Full contact details are also published at /contact.


2. Data we collect

In plain English: We collect what you give us (profile, applications), what you do on the product (submissions, scores), sign-in from Google, and a small set of cookies. Hosting logs may briefly include technical details like IP.

2.1 Account and profile

  • Google account email, name, and profile image (via Google OAuth)
  • Challenge profile: full name, student/professional fields (college, graduation year, organization, role, experience), domain, skills, LinkedIn URL, GitHub username, resume URL, phone number (OTP-verified for Indian mobiles where required)
  • Program profile: job role, company, education, university, GitHub repo URL, optional phone (admin-only; not shown to recruiters)
  • Recruiter profile: name, company, optional phone

2.2 Applications and events

  • Workshop registration: name, email, phone, role, organization, graduation year
  • Hackathon: name, email, phone, college, graduation year; team membership; submission URLs
  • US cohort application (Supabase): name, email, LinkedIn, visa / work-authorization category, education, experience, industry, free-text essays, commitment confirmations
  • India cohort application (Supabase): similar fields without US visa; India-origin confirmation

2.3 Activity data

  • Challenge submissions (optional GitHub/LinkedIn proof URLs), quiz answers, streaks, enrollments
  • Program mission payloads, concept attempts, project repos/writeups, AI feedback, scores
  • Exit voice interview audio processed in real time; transcript, scores, and summary stored
  • Job applications (optional note); marketplace redemptions (shipping address, recipient phone)
  • Referral and share-link attribution
  • Admin remarks and audit logs of admin actions

2.4 Certificates

  • Snapshot of recipient name and completion metadata; public verification by certificate ID

2.5 Cookies and similar tech

CookiePurposeCategory
Auth.js session cookieKeep you signed in (httpOnly)Strictly necessary
abtalks_consentStores your cookie choice so we don’t ask again (~180 days, readable by the page)Strictly necessary
abtalks_refReferral code from ?ref= (httpOnly, ~7 days)Attribution — set only with your consent
abtalks_srcFirst-touch share attribution from ?s= (httpOnly, ~30 days)Attribution — set only with your consent

Your choice. On your first visit we ask you to choose Allow all, Limited, or Deny (Reject all). Attribution cookies (abtalks_ref, abtalks_src) are set only if you choose Allow all or Limited; choosing Deny means we set no attribution cookies and expire any we already set. Strictly necessary cookies are required for sign-in and cannot be switched off. You can change your choice any time at /cookies. Full details: Cookie Policy.

Third-party scripts and embeds.

  • Phone verification (MSG91). If you use phone/OTP verification, your browser loads a script from verify.msg91.com in order to run the verification widget. That provider may set its own cookies or browser storage under its domain, governed by its own privacy policy. The script loads only when you actually use phone verification.
  • Video embeds (YouTube). All video embeds use the privacy-extended youtube-nocookie.com domain, which does not set advertising cookies. On program mission pages and the video library, videos are click-to-load: nothing is requested from Google until you press play, and the video’s preview thumbnail is fetched from YouTube only if you chose Allow all. On challenge day pages the tutorial player loads together with the page, so Google is contacted when you open that page.

We do not currently use third-party advertising analytics SDKs (e.g. Google Analytics, PostHog) in the product. If that changes, we will update this Policy and add the relevant category to the cookie choice above.

Do Not Track. Some browsers send a “Do Not Track” (DNT) signal. We do not currently change our practices in response to DNT signals. Your cookie choice on this Service (Allow all / Limited / Deny) is the control we honour for optional cookies.

2.6 Technical and hosting logs

When you use the Service, our hosting and infrastructure providers (for example Vercel) and application servers may automatically process limited technical data needed to deliver pages and keep the Service secure. That may include:

  • Internet Protocol (IP) address
  • Approximate request time, URL path, HTTP status, and user-agent / browser type
  • Device or browser characteristics commonly sent with web requests

We use this for security, abuse prevention, debugging, and reliable operation — not for advertising profiles. Log retention follows provider defaults and our operational needs and is typically short compared with account data. We do not sell this information.

2.7 Sources

You; Google (sign-in); GitHub API (public repo/commit checks for program features); cookies as above; hosting/technical logs (§2.6); admins (assessment fields on curated reports).


3. How we use data

In plain English: We use your data to run the product you signed up for, send service messages, optional product updates if you leave the newsletter box ticked, and (only if you opt in) recruiter visibility.

  • Provide accounts, tracks, day unlocks, grading, certificates, and support
  • Send transactional email/SMS (welcome, workshop/hackathon confirmations, OTP, account notices)
  • Send occasional marketing / product updates (new challenges, workshops, and opportunities) when the newsletter box on signup is left selected — see §3.1
  • Operate referrals, leaderboards, and peer profiles (limited fields)
  • Admin operations, integrity (anti-cheat), and security
  • AI-assisted feedback, grading, recommendations, and interview evaluation
  • Recruiter discoverability only if you opt in (program talent pool)
  • Improve the Service using aggregated or de-identified insights where feasible
  • Operate, secure, and troubleshoot the Service using technical logs (§2.6)

3.1 Newsletter / marketing email

At signup (and on other registration funnels) we show a checkbox offering occasional updates about new challenges, workshops, and opportunities. That box is selected by default. You may untick it before submitting, or unsubscribe later at any time (every marketing email will include an unsubscribe link once campaigns begin). Newsletter opt-in is never a condition of using the Service — declining it does not block registration. Opt-in records are stored separately from your legal Terms/Privacy acceptance.

Note on pre-ticked defaults. Under DPDP, consent should be free, specific, informed, and given by a clear affirmative act. A pre-selected marketing box is a product decision we disclose here so the Policy matches the product; counsel may advise a different default in future. Withdrawal remains available as described above.


4. Legal bases / consent (DPDP-oriented)

In plain English: For optional things (newsletter, recruiter visibility, some cookies) we ask for your consent. For core service (account, day unlocks, grading) we process data because it is needed to provide what you asked for.

Under India’s DPDP framework and related rules, we process personal data where we have a lawful basis. In practice for ABTalks that means:

  1. Consent — where we ask you to agree before optional processing. Examples: acceptance of Terms/Privacy and age confirmation at signup; recruiter-visibility opt-in; interview recording notice; newsletter as presented at signup; optional cookie categories (Allow all / Limited). You may withdraw consent for optional processing as described in §10; withdrawal does not undo processing already lawfully completed.
  2. Necessary for the Service you request — processing that is needed to create and run your account, deliver the track or event you registered for, authenticate you, prevent abuse, issue certificates you earned, and respond to support or rights requests. Without this processing we cannot provide those features.
  3. Compliance and security — limited processing required to meet legal obligations (where applicable) or to protect the security and integrity of the Service (for example audit logs, anti-cheat, hackathon removal records as disclosed in §7).

Counsel may refine the wording of lawful bases as DPDP rules and guidance evolve. If you have questions about the basis for a specific use, contact team@abtalks.in.


5. Sharing

In plain English: We share data with the cloud and AI tools that run the product, with admins who operate it, and with recruiters only if you opt in. We do not sell your data.

We share personal data with:

RecipientWhat / when
Service processorsVercel (hosting), Neon (database), Google (OAuth), Supabase (certain applications/config), MSG91 (OTP), Resend & Brevo (email), Anthropic & OpenAI (AI/interview processing), GitHub (API checks)
AdminsFull operational access; CSV exports for running events
Approved recruiters (/talent)Opted-in program members: profile, email, LinkedIn, resume, GitHub, scores, projects, interview summary and scores (not full transcript; not phone) after cohort results are published
PublicCertificate verification pages (name + credential metadata); anyone with a published share-report link at /r/[token] sees the curated assessment without email or phone
Peers (signed-in)Limited profiles (name, college/org, skills, LinkedIn, GitHub, streaks) — not email/phone
Hackathon teammatesName and college (not email/phone)

We do not sell personal data.


6. International transfers

In plain English: Some providers are outside India (for example US cloud or AI). Using the Service means those transfers may occur.

Processors may process data in India, the United States, and other countries (e.g. cloud and AI providers). By using the Service you understand that such transfers may occur. We use reputable providers and contractual protections where applicable.


7. Retention

In plain English: We keep account data while you use the Service. After a confirmed delete request we aim to erase or anonymize within 30 days, with limited exceptions (certificates, security logs, hackathon abuse records).

  • Account and profile data: while your account is active
  • After a confirmed deletion request: erase or anonymize within 30 days, except certificates retained as public credentials unless revoked; limited audit/security records up to 24 months; longer if required by law or dispute
  • Hackathon removal records: if you are removed from, or leave, a hackathon team, we keep a removal record containing your name, email, phone, college and graduation year even after your participant record itself is deleted. We do this to prevent re-registration abuse and to keep team-attribution accurate. These records are retained for up to 24 months, then deleted.
  • Admin audit rows may be retained for integrity for up to 24 months
  • Consent records retained to demonstrate acceptance
  • Technical hosting logs (§2.6): typically short operational windows set by providers and our security needs

8. Security

In plain English: We use HTTPS, access controls, and hosted infrastructure. No system is perfectly secure; we will notify as required if a breach happens.

We take reasonable technical and organisational measures appropriate to the nature of the data we hold, including:

  • Transport encryption — the Service is served over HTTPS
  • Access control — admin functions are limited (for example email allowlists and role checks); ordinary users cannot access other users’ private data through the product UI
  • Hosted infrastructure — application and database hosting with reputable cloud providers (currently including Vercel and Neon) that apply their own physical and network controls
  • Secrets and configuration — production secrets are stored as environment configuration, not in client-side code
  • Least exposure by design — examples: recruiter views omit phone and full interview transcript; public share reports omit email and phone

These measures reduce risk; they do not guarantee absolute security. No method of transmission or storage is 100% secure. You are responsible for keeping your sign-in credentials (for example your Google account) secure.

Breach notification. If a personal data breach occurs, we will notify the Data Protection Board of India and each affected user in the manner and within the timelines required by the DPDP Act and its rules.


9. Children

In plain English: The Service is 18+. We do not knowingly collect data from children under 18.

The Service is for users 18+. We do not knowingly collect data from children under 18. If you believe a minor registered, contact us to delete the account.


10. Your rights

In plain English: You can ask to see, fix, or delete your data, withdraw optional consents, raise a grievance, or nominate someone for after death/incapacity. Use the form or email us.

Subject to applicable law, you may request:

  • Access to personal data we hold about you, including a summary of processing and the recipients we have shared it with
  • Correction of inaccurate data, and completion or updating of incomplete data (you can also edit much of your profile in-app)
  • Erasure / account deletion
  • Withdrawal of consent for optional processing (e.g. recruiter visibility, newsletter), which may limit features. Withdrawal is as easy as giving consent, and does not affect processing already carried out
  • Grievance redressal (DPDP §13) — you may raise a grievance with our Grievance Officer (§1.1) about our handling of your data or your rights request, regardless of whether you have used any other remedy. We acknowledge within 24 hours and aim to resolve within 15 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India
  • Nomination (DPDP §14) — you may nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. Submit a nomination through /privacy/requests

Submit requests at /privacy/requests or email team@abtalks.in. We may need to verify your identity. We aim to respond within a reasonable period (target: 30 days).

Your duties. Under DPDP §15, please do not impersonate another person when providing data, suppress material information, or file false or frivolous grievances.


11. AI processing notice

In plain English: Some features send your submissions or interview audio to AI providers for feedback and scores. Don’t put secrets in prompts.

Mission code, prompts, project context, and interview audio/transcripts may be sent to AI providers (Anthropic, OpenAI) to generate feedback, scores, or summaries. Do not include passwords, payment card numbers, or unrelated sensitive data in submissions.

Before starting a voice interview, you will see an in-product notice that the session is recorded/transcribed for evaluation.


12. US cohort applications

In plain English: US applications may include visa/work-auth category for cohort fit. Admins see it; it is not on public pages.

US-facing applications may collect visa or work-authorization category and related professional information to evaluate cohort fit. That data is stored with our application backend (currently Supabase) and accessible to ABTalks admins — not published on public pages.


13. Changes

In plain English: If we change this Policy in a material way, we will post a new version and may ask you to re-accept and/or notify you.

We may update this Privacy Policy from time to time. The version and effective date appear at the top of this page.

  • Non-material updates (clarifications, formatting, contact details) take effect when posted.
  • Material changes to how we collect, use, or share personal data will be signalled by a new version date on this page. Where appropriate we will also:
    • show an in-product notice or re-acceptance prompt (for example on the dashboard when your stored consent version is behind the current Policy version), and/or
    • send notice to the email address on your account, when we reasonably can.

We will use personal data in line with the Policy that applied when you submitted it, unless you accept a newer Policy or another lawful basis applies. Continued use after the effective date of a posted Policy constitutes acceptance where permitted by law; for material changes we prefer explicit re-acceptance where the product supports it.


14. Contact

In plain English: Questions or rights requests → team@abtalks.in, /contact, or /privacy/requests.

Grievance Officer and full entity details: /contact
Data rights requests: /privacy/requests
Cookie choices: /cookies
Email: team@abtalks.in