Privacy Policy

Last updated: July 2026

1. Who runs ExamDB

ExamDB (examdb.org) is built and operated by Pranjal Bhatnagar, an individual based in India. For the purposes of India's Digital Personal Data Protection Act, 2023, that is the Data Fiduciary responsible for the personal data described below, and the contact point for any grievance.

Contact: psbhatnagar.in@gmail.com

2. The short version

You can browse all of ExamDB without an account, and browsing collects no personal data beyond ordinary server logs. An account is optional - it exists only so you can save exams and organise them into lists. If you make one, we store your email address and display name and nothing else about you. You can delete it yourself at any time, and the deletion is immediate and complete.

There is no advertising, no cross-site tracking, and no third party we sell or share your data with. We do use privacy-preserving analytics to count page views - it sets no cookies, stores nothing on your device, and cannot follow you to other sites or link visits back to you.

3. What we collect

3a. If you browse without an account

Standard web server logs, recorded automatically on every request:

  • IP address
  • Browser type and version (User-Agent)
  • Pages or API paths accessed, and timestamps
  • Referring URL

This is used only for security, abuse prevention, and diagnosing faults. Logs are retained for a maximum of 30 days. Your IP address is also held briefly in memory to enforce API rate limits; it is not stored permanently for that purpose.

3b. If you create an account

Accounts are created by signing in through an external provider - Google, GitHub, Microsoft or Facebook. ExamDB never sees or stores your password. From the provider we receive, and store:

  • Your email address, and whether the provider has verified it
  • Your display name
  • The provider's permanent identifier for you (an opaque ID, used as your login key)
  • Which provider you used, and when the account and each linked login were created
  • The time you last signed in

We also store what you do with the account:

  • The exams you save, and when you saved them
  • Any lists you create, their names, and their contents
  • Active sign-in sessions - an expiry, a last-seen time, and a SHA-256 hash of your session token. The token itself is never written to the database, so a copy of the database cannot be used to sign in as you.

We do not request or receive your profile photo, contacts, or anything else your provider may offer. We do not ask for your date of birth, phone number, address, or any exam registration number or roll number.

4. Cookies and local storage

ExamDB sets no advertising or tracking cookies of any kind, and our analytics is cookieless - it stores nothing on your device. If you are signed out and have never signed in, ExamDB sets no cookies at all.

The cookies that exist are strictly necessary ones:

  • examdb_session - your sign-in session. Set only after you sign in. It holds a random opaque token, is HttpOnly, Secure and SameSite=Lax, and expires after 30 days. Signing out deletes it and destroys the session on the server.
  • A short-lived sign-in state cookie, valid for 30 minutes, which exists only to carry you safely through the redirect to your provider and back. It protects against sign-in request forgery.

Separately, your browser's local storage holds your theme preference (light/dark, colour and accent) and a cached yes/no flag for whether you are signed in, so the header does not flicker on load. Local storage is never transmitted to our servers. Clearing your browser data removes it.

5. Why we are allowed to hold this

Account data is processed on the basis of your consent, given when you choose to sign in - you are never asked for an account to read anything on the site. Server logs and rate limiting are processed on the basis of our legitimate interest in keeping the service available and free from abuse. Withdrawing consent is the same action as deleting your account (see §8).

6. Who else touches your data

We do not sell, rent, trade, or share your personal data with anyone for any commercial purpose. It is disclosed only to the infrastructure providers needed to run the service, and only where required by law.

  • Vercel- hosts the website, may log request metadata for delivery and performance, and provides the cookieless analytics described in § 4. For analytics it receives the page viewed plus coarse technical details such as country, browser and device type. It does not receive your name or email, and the measurement is not tied to your account. Privacy policy
  • Neon - managed PostgreSQL. Your account row, saved exams and lists physically live here. Privacy policy
  • Upstash - managed Redis, used only for API rate limiting. Holds short-lived request counters, no account data.
  • Your sign-in provider - Google, GitHub, Microsoft or Facebook, whichever you chose. They necessarily know that you signed in to ExamDB. Their handling of that is governed by their own privacy policy, not this one.

Some of these providers operate servers outside India, so your account data may be stored or processed abroad.

7. How long we keep it

  • Server logs - 30 days
  • Rate-limit counters - minutes
  • Sign-in sessions - 30 days from sign-in, or instantly on sign-out
  • Account data, saved exams and lists - until you delete your account. There is no automatic expiry, because a saved exam is only useful if it stays saved.

8. Your rights

If you have an account, you have the right to access your data, to correct it, to have it erased, and to nominate someone to exercise these rights on your behalf.

  • Access - everything we hold about you is shown on your account page. For a machine-readable copy, email us.
  • Correction - your email and name come from your sign-in provider. Change them there and they update on your next sign-in.
  • Erasure- delete your account from your account page. This is immediate and not reversible: your account, every linked sign-in identity, every session, every saved exam and every list are removed from the database in a single operation. Nothing is retained in a “deleted” state and there is no grace period.
  • Grievance - email psbhatnagar.in@gmail.com. We aim to respond within 30 days. If you are not satisfied, the Data Protection Board of India is the statutory escalation route.

If you have no account and want an IP address removed from the logs, email us - bearing in mind that logs are discarded after 30 days regardless.

9. Younger users

A large share of the people ExamDB is built for are school students, many of them under 18. We are not going to pretend otherwise by setting an age limit we could not enforce and would not want to.

All of ExamDB's exam information is readable without an account, and reading it collects no personal data. Anyone of any age can use the site fully without giving us anything.

For those who do sign in, the protections India's DPDP Act is most concerned with for children are ones we apply to every user, whatever their age: we do not track you across sites, we do not build behavioural profiles, we do not serve advertising, and we do not sell or share your data. An account holds your email address, your display name, and the exams you chose to save. Nothing else.

If you are under 18, you should have a parent or guardian's permission before creating an account. A parent or guardian who wants a child's account removed can email us and it will be deleted, no questions asked - or delete it directly from the account page, which takes effect immediately.

10. Security

All traffic is served over HTTPS. Session tokens are random, opaque, and stored only as a SHA-256 hash. Sign-in cookies are HttpOnly, so page scripts cannot read them. Passwords are never handled at all - authentication is delegated entirely to your provider. Administrative endpoints are separately authenticated and access is restricted to the operator.

No system is perfectly secure. If you find a vulnerability, please report it to psbhatnagar.in@gmail.com rather than disclosing it publicly.

11. Changes to this policy

This policy describes what ExamDB does today, not what it might do. If that changes - if analytics are ever added, or a new provider introduced - this page is updated in the same change that ships the feature, and the date at the top moves. Significant changes will be announced on the site.

12. Contact

Questions, requests, or complaints: psbhatnagar.in@gmail.com