Privacy policy
LearnMap is a study tool. This page says exactly what it stores, what leaves our server, and what you can have removed. It describes what the software actually does today, not what a template says it might.
Last updated 2 October 2026
Who is responsible
LearnMap is operated by Pavan P Udupa, at 1st cross road, Udupi, 576103. For anything on this page, write to learnmap.in@gmail.com.
What we store about your account
When you sign up we store:
- your email address;
- a display name, which by default is just the part of your email before the @;
- your password, as a bcrypt hash. We never hold the password itself and cannot recover it for you;
- the date you signed up;
- which plan you are on, the payment and order identifiers given to us by the payment provider, and the date your access ends;
- counters for the current 30-day period: videos added, sets of notes generated, pages read by OCR, AI questions asked, top-ups bought.
We do not store your IP address, your phone number, your postal address, your date of birth, or your card details. Card details are handled entirely by the payment provider and never reach our server.
What we store from your use of the app
- YouTube links you add — the URL, the video id, its title, thumbnail and duration, and the transcript we retrieve for it, line by line with timings.
- Study notes we generate from those transcripts, and from your documents.
- Your conversations with the tutor — every question you ask and every answer given, kept so the thread is still there when you come back.
- PDFs you upload, stored as files on our server, plus the text extracted from them.
- Photographs of handwritten notes, stored as image files, plus the combined PDF made from them and the text read out of them by OCR.
- Your highlights, pen marks and notes on a document, your folders, and anything you save.
- A record of each paid API call we make on your behalf — which provider, which model, how many tokens, what it cost. We use this to watch our own costs. It contains no content, only counts.
Files are kept on a server we rent and operate. They stay there until you delete them or ask us to close your account.
What other users can and cannot see
Your library, your saved items, your folders, your annotations and your tutor conversations are yours. No other account can list them, open them or search them.
There are three places where work is shared, and they are worth understanding because they are unusual:
- Identical files are stored once. A document is identified by a fingerprint of its exact bytes. If you upload a file that another account has already uploaded — the same prescribed textbook, the same circulated question paper — you are both given access to the one stored copy and the one extraction, rather than us reading and billing it twice. This only ever happens for byte-identical files. A scan of your own notebook is unique to you and can never collide with anyone else's. Your own title for the document, your place in it, your folders and your annotations stay private to you either way.
- Transcripts of public YouTube videos are cached for everyone. They are captions YouTube already publishes, so once one account has fetched a video's transcript we keep it and serve it to the next person who adds that video. This is why adding a popular lecture is instant and costs nothing.
- Answers about public videos and shared documents are cached. If you ask a question about a public YouTube video and somebody later asks a materially identical one, they may be served your answer — and your question as it was phrased. The same applies to a document held by more than one account, and to AI descriptions of figures in one. Do not put anything private into a question about a public video. Questions you ask across your own library are never shared, because the material they draw on is yours alone.
Who else receives your data
We use other companies to do work we cannot do ourselves. Each receives only what that job needs:
- Our AI provider — to generate study notes, to answer your questions, and to read a photographed page when local OCR cannot. It receives the transcript or document text concerned, your question, and in the OCR case the page image. Processing happens outside India.
- Our handwriting-recognition provider — to read handwriting that our own local OCR could not. It receives the page image. Processing happens outside India.
- Our caption provider — to fetch a video's published captions. It receives only the YouTube video id, never anything about you.
- Our payment provider — to take payment. It receives your email address and an account reference. Your card details go to it directly from your browser and never touch our server.
- Google Fonts — the page's typefaces are loaded from Google, so your browser's IP address and user agent reach Google on each page view. This is the only third-party request the site makes.
We do not sell your data, we do not share it for advertising, and we do not give it to anyone not listed above except where the law requires it.
Tracking and cookies
There is no analytics, no advertising and no tracking of any kind on this site. No Google Analytics, no advertising pixels, no session recording.
We set exactly one cookie, verbatim_session. It holds a signed token identifying your account, it cannot be read by JavaScript, and it lasts 30 days or until you sign out. Without it you cannot stay signed in, so there is nothing to consent to and nothing to switch off.
Deleting your data
Inside the app you can delete any video, document, folder, saved item, annotation or tutor conversation yourself, at any time. Deleting a video or a document removes it from your library; the underlying file is removed from our server unless another account also holds that exact file, as described above.
To close your account and remove everything, email learnmap.in@gmail.com from the address you signed up with. We will delete your account and everything attached to it — transcripts, notes, tutor conversations, documents, annotations and saved items — within 30 days, and confirm when it is done. There is no self-service delete button yet; we are adding one.
Two things survive, and neither identifies you: the cached transcript of any public YouTube video, which is YouTube's published captions and was never yours; and our own record of what each API call cost, with the account reference removed.
Your rights
You may ask us what we hold about you, ask for a copy of it, ask us to correct it, or ask us to delete it. Write to learnmap.in@gmail.com and we will respond within 30 days. If you are not satisfied with how we handle a request, you may complain to the relevant data protection authority.
Age
LearnMap is intended for users aged 18 and over. If you are under 18, you may use it only with the involvement of a parent or guardian, who must agree to our terms and make any payment. If you believe a child has created an account without that, tell us and we will remove it.
Security, honestly stated
Passwords are hashed with bcrypt. Sessions use a signed, http-only cookie. Access to your library is checked on every request against the account making it. Traffic to the site is encrypted.
No service can promise it will never be breached, and we will not pretend otherwise. If your data is ever exposed we will tell you what happened and what was affected, without waiting to be asked.
Changes
If we change what we collect or who receives it, we will update this page and change the date at the top. Significant changes will be told to you by email rather than left here to be discovered.