The AI Platform Built for Education

Privacy Policy

Last updated: July 10, 2026  ·  Effective: July 10, 2026

AlignAI is a brand of AscendX Innovations Pvt. Ltd.

Overview

AlignAI is a product and brand of AscendX Innovations Pvt. Ltd.

This Privacy Policy explains how AscendX Innovations Pvt. Ltd., operating under the brand name AlignAI, collects, uses, processes, stores, shares, retains, and protects personal data when users access or use the AlignAI website, applications, platform, artificial intelligence features, and related services.

In this Privacy Policy, “AlignAI,” “we,” “us,” and “our” refer to AscendX Innovations Pvt. Ltd. “Service” refers collectively to the AlignAI website, platform, applications, integrations, tools, artificial intelligence features, and related services.

By accessing or using the Service, you acknowledge the practices described in this Privacy Policy.

1. Scope of This Privacy Policy

This Privacy Policy applies to users of AlignAI, including:

Independent teachers and educators
Schools, colleges, coaching institutes, training organisations, and other institutions
Organisation administrators
Employees and authorised representatives of institutions
Students
Parents or guardians
Website visitors
Individuals communicating with us
Other authorised users of the Service

Where an educational institution, teacher, or organisation provides personal data to AlignAI, that institution, teacher, or organisation may determine the purposes for which the data is processed.

In such cases, AlignAI may process the information on behalf of the relevant institution or account holder.

2. Information We Collect

2.1 Account and Profile Information

When an account is created or maintained, we may collect:

Full name
Email address
Phone number
Profile photograph
Organisation or institution name
User role
Job title or designation
Account preferences
Authentication information
Account identifiers
Subscription and plan details

We use this information to create, authenticate, administer, and secure user accounts.

2.2 Organisation and Membership Information

Where the Service is used by an institution or organisation, we may process:

Organisation name and profile
Membership and role information
Teacher and staff details
Student and parent details
Class, course, batch, and subject information
Permissions assigned by organisation administrators
Organisation settings and configuration data

2.3 Student and Academic Information

Teachers, institutions, administrators, students, or other authorised users may enter, upload, generate, or manage academic information, including:

Student names and identifiers
Contact details
Class and batch assignments
Attendance records
Lecture records
Assignments and submissions
Tests, questions, responses, and scores
Manual or automated evaluations
Grades and performance records
Teacher feedback
Academic reports
Action items
Calendar and scheduling information
Fee-related records
Parent or guardian information
Educational communications

2.4 Lecture, Digital Board, Audio, Video, and Document Content

When users upload, record, or submit lectures, digital board sessions, audio recordings, videos, presentations, images, documents, worksheets, or other materials, we may process and store such content to provide features including:

Digital board session recording and publishing
Board-note organization
Structured note generation
Question generation
Assignment generation
Test generation
Worksheet generation
Content analysis
Video processing
Educational assistance
Other artificial intelligence-based functionality

2.5 Communication Information

When users send messages or notifications through AlignAI, we may process:

Sender and recipient information
Email addresses
Phone numbers or messaging identifiers
Message content
Templates
Delivery status
Failure status
Timestamps
Related communication metadata

This may include communications sent through email, Telegram, WhatsApp, SMS, or other supported services.

2.6 Fee and Payment Information

Where fee-management functionality is used, we may process:

Fee amounts
Payment status
Outstanding amounts
Instalment schedules
Due dates
Fine or late-fee information
Transaction references
Payment history
Invoice and billing information

Payments for AlignAI subscriptions or institutional fees may be processed by authorised third-party payment providers.

AlignAI does not ordinarily store complete credit-card numbers, bank-account credentials, UPI PINs, card-verification values, or other sensitive payment authentication information where these are processed directly by the payment provider.

2.7 Technical and Usage Information

When users access the Service, we may automatically collect:

IP address
Device type
Operating system
Browser type and version
Login activity
Session information
Pages and features accessed
Actions performed within the Service
Date and time of access
Application events
Error reports
Performance information
Security events
Audit logs
Diagnostic information

2.8 Customer Support Information

When users contact us, we may collect:

Name and contact information
Account information
Support request details
Screenshots or recordings
Technical logs
Correspondence
Feedback
Information voluntarily provided during the support process

3. How We Collect Information

We may collect information:

Directly from users
From organisation administrators
From teachers or educational institutions
Through use of the Service
Through uploaded files and recordings
Through third-party integrations authorised by users
Through payment providers
Through cookies and similar technologies
Through customer support communications
Through security and monitoring systems

Institutions and account holders are responsible for ensuring that they have appropriate authority, consent, or another lawful basis before providing personal data relating to students, parents, employees, teachers, or other individuals.

4. How We Use Information

We may process information to:

Create and manage user accounts
Authenticate users
Provide access to the Service
Manage organisations, users, classes, main batches, subject batches, and roles
Process lectures, digital board sessions, recordings, documents, and educational content
Generate AI-assisted outputs
Manage attendance
Manage tests and assignments
Record grades and academic performance
Manage fee records and reminders
Deliver notifications and communications
Process subscriptions and payments
Provide customer support
Respond to queries and complaints
Improve platform functionality
Analyse usage and performance
Maintain security and availability
Detect misuse, fraud, abuse, or unauthorised access
Troubleshoot technical issues
Maintain audit and operational records
Comply with legal and regulatory obligations
Establish, exercise, or defend legal claims
Enforce our Terms of Service and other agreements
Communicate policy, product, billing, and security updates

We do not sell personal data to third-party advertisers.

6. Artificial Intelligence and Automated Processing

AlignAI uses artificial intelligence and automated systems to process educational and operational content.

AI-assisted outputs may include:

Transcriptions
Summaries
Notes
Questions
Tests
Assignments
Worksheets
Suggested answers
Suggested evaluations
Reports
Data extraction
Performance insights
Educational recommendations
Communication drafts

Artificial intelligence outputs may contain errors, omissions, incomplete information, or inaccurate conclusions.

Teachers, institutions, administrators, and other authorised users must review AI-generated outputs before using them for:

Official academic decisions
Final grading
Student evaluations
Disciplinary actions
Financial decisions
Legal or regulatory decisions
High-impact institutional decisions

Users remain responsible for decisions made using AI-generated outputs.

Customer content is not used to train third-party general-purpose artificial intelligence models without authorisation or consent where such authorisation or consent is required.

Certain AI features may be provided through trusted third-party model or infrastructure providers acting as service providers to AlignAI.

7. Disclosure and Sharing of Information

We may share information in the circumstances described below.

7.1 Service Providers

We may use trusted service providers for:

Cloud hosting
Database hosting
Storage
Content delivery
Authentication
Artificial intelligence processing
Audio and video processing
Email delivery
Messaging services
Payment processing
Analytics
Error monitoring
Infrastructure monitoring
Customer support
Security testing
Security assessment
Vulnerability assessment
Backup and recovery
Professional and legal services

These providers may process information only as necessary to perform authorised services or meet legitimate operational requirements.

7.2 Organisation Administrators

Where an account is managed by an organisation, the organisation’s administrators may be able to:

Access account information
Assign or remove roles
Manage users
View academic information
View organisation activity
Manage subscriptions
Configure organisation settings
Restrict or terminate access
Export or delete authorised data

Users should contact their organisation administrator regarding access controlled by the organisation.

7.3 Integrations

When a user enables or uses a third-party integration, information may be transmitted to or received from that service.

The third party’s own privacy policy and terms may apply to its independent processing.

7.4 Legal Requirements

We may disclose information where we reasonably believe disclosure is necessary to:

Comply with applicable law
Comply with a court order or lawful governmental request
Respond to legal proceedings
Protect the rights, property, or safety of AlignAI, our users, or others
Investigate fraud, misuse, or security incidents
Enforce our agreements
Establish, exercise, or defend legal claims

7.5 Business Transfers

Information may be transferred as part of:

A merger
An acquisition
A corporate restructuring
A financing transaction
A sale of assets
An insolvency proceeding
A transfer of the AlignAI business

Where required, appropriate notice will be provided before personal data becomes subject to a materially different privacy policy.

8. Vendor and Third-Party Risk Management

AlignAI selects third-party service providers based on factors including:

Operational capability
Security practices
Privacy practices
Reliability
Confidentiality commitments
Data-handling requirements
Relevance to the Service

Depending on the nature of the service and associated risk, our vendor-management process may include:

Reviewing available security and privacy documentation
Reviewing independent security reports or certifications where available
Evaluating the type and sensitivity of information processed
Restricting access to information necessary for the service
Applying contractual confidentiality requirements
Applying contractual data-protection obligations
Reviewing provider permissions and integrations
Monitoring material security or availability issues
Periodically reviewing critical providers
Removing provider access when the relationship ends
Deleting or returning information where appropriate and contractually supported

Providers involved in security assessments, vulnerability assessments, infrastructure monitoring, or similar services receive access only where reasonably necessary and subject to appropriate restrictions.

A provider’s certification or independent assessment does not guarantee complete security. Vendor controls are applied using a risk-based approach.

9. Data Storage and International Processing

Information may be processed or stored in India or other countries where AlignAI or its service providers maintain infrastructure.

Those countries may have privacy and data-protection laws that differ from those in the user’s country.

Where required, we use appropriate contractual, technical, and organisational safeguards for international transfers and processing.

We may restrict or modify international transfers where required by applicable law or governmental direction.

10. Data Retention

We retain personal data only for as long as reasonably necessary to:

Provide the Service
Maintain active accounts
Fulfil contractual obligations
Maintain academic and organisational records
Process payments and billing
Comply with legal, tax, accounting, and regulatory requirements
Resolve disputes
Enforce agreements
Prevent fraud and abuse
Maintain security and audit records
Establish, exercise, or defend legal claims

Retention periods may vary according to:

The type of information
The purpose for which it was collected
The organisation’s instructions
Applicable contractual obligations
Legal requirements
Security requirements
Whether an account remains active

Account data is generally retained while the account remains active.

Information controlled by an organisation may remain available until it is deleted by an authorised organisation administrator, the organisation’s relationship with AlignAI ends, or retention is no longer necessary.

When personal data is no longer required, we may delete, anonymise, aggregate, or securely isolate it.

Anonymised or aggregated data that no longer reasonably identifies an individual may be retained for analytics, platform improvement, security, and research.

11. Backup and Recovery

AlignAI uses Neon’s managed database infrastructure for its production database backup and recovery processes.

Automated database backups are performed daily and retained for up to 60 days, unless a different retention period is required for legal, contractual, operational, or security reasons.

Backups are maintained to support recovery from events including:

Accidental deletion
Data corruption
Infrastructure failure
Application failure
Security incidents
Operational disruption
Disaster-recovery events

Backup and recovery safeguards include, where applicable:

Access restricted to authorised personnel
Infrastructure-level protection
Encryption or equivalent protection
Defined retention periods
Monitoring of backup processes
Periodic review of backup status
Periodic testing of recovery procedures

Backup copies are maintained for business continuity and disaster recovery. They are not intended to provide users with permanent historical archives or access to every previous version of their information.

When information is deleted from active systems, copies may remain temporarily in secured backups until the relevant backup reaches the end of its 60-day retention period and is deleted or overwritten.

AlignAI does not ordinarily restore individual user records from backups unless required for broader recovery, security, legal, or operational purposes.

12. Information Security

AlignAI maintains technical and organisational safeguards designed to protect information against:

Unauthorised access
Unauthorised disclosure
Accidental loss
Destruction
Misuse
Alteration
Corruption
Unlawful processing

Safeguards may include:

Encryption of information in transit
Authentication controls
Role-based access controls
Least-privilege access
Environment separation
Network and infrastructure restrictions
Audit logs
Security monitoring
Secure software-development procedures
Vulnerability assessment
Backup and recovery
Incident-response procedures
Vendor security controls
Credential and secret management
Change-management procedures

No internet transmission, storage system, or technical environment can be guaranteed to be completely secure.

Users are responsible for protecting their passwords, authentication credentials, devices, and account access.

Users should immediately report suspected unauthorised access or other security concerns to contact@alignai.in.

13. Access Control

Access to production systems, administrative tools, source-code systems, infrastructure, databases, and personal data is restricted according to legitimate operational requirements.

Our access-control practices may include:

Role-based permissions
Least-privilege access
Authentication requirements
Restricted production access
Separation of development, testing, and production environments
Logging of sensitive administrative activity
Review of access permissions
Removal or adjustment of access when no longer required
Restriction of service-provider access
Session and token revocation where appropriate

Organisation administrators are responsible for managing access within their organisation.

Administrators should promptly remove or restrict access where a student, teacher, parent, institution employee, contractor, or other organisation user no longer requires access.

14. Secure Software Development

AlignAI applies security considerations throughout the development and maintenance lifecycle of the Service.

Depending on the nature and risk of the relevant system or change, practices may include:

Security-conscious system design
Secure-coding practices
Source-code review
Peer review of material changes
Version-control systems
Restricted access to source-code repositories
Separation of development, testing, and production environments
Testing before production deployment
Authentication and authorisation testing
Input-validation checks
Dependency and package checks
Vulnerability scanning
Testing for common application-security risks
Infrastructure configuration review
Error and security monitoring
Security patching
Remediation of identified vulnerabilities
Post-deployment monitoring

14.1 Secret and Credential Management

Passwords, API keys, database credentials, tokens, certificates, and other secrets are managed using practices designed to prevent unauthorised disclosure.

These practices may include:

Keeping production secrets outside publicly accessible source code
Restricting access to authorised personnel and services
Using environment-based or managed secret configuration
Avoiding unnecessary exposure of secrets in logs
Replacing or rotating credentials when compromise is suspected
Revoking credentials that are no longer required
Separating credentials between environments where practical

14.2 Vulnerability Management

AlignAI may conduct internal or third-party security checks appropriate to the nature and risk of the Service.

These may include:

Dependency scanning
Application-security testing
Infrastructure reviews
Vulnerability assessments
Penetration testing
Security configuration checks
Authentication and access-control testing
Review of common web-application vulnerabilities

Identified vulnerabilities are evaluated and prioritised according to factors such as severity, exploitability, affected information, and operational impact.

No security test can guarantee that a system is free from every vulnerability.

15. Change Management

Changes to applications, infrastructure, databases, integrations, configurations, and production systems are managed using procedures designed to reduce security, privacy, and operational risks.

Depending on the type and impact of the change, procedures may include:

Recording the proposed change
Reviewing source-code or configuration changes
Evaluating privacy and security impact
Testing changes before deployment
Maintaining version-control history
Restricting deployment permissions
Using controlled deployment processes
Maintaining database migration records
Monitoring systems after deployment
Using rollback or recovery procedures where reasonably practicable
Reviewing failed or high-impact changes
Applying expedited processes for urgent security updates

Material changes to the way personal data is processed may result in an update to this Privacy Policy or another appropriate notice.

16. Security Incident Response

AlignAI maintains procedures for responding to suspected or confirmed security or privacy incidents.

Depending on the nature and severity of an incident, the response may include:

Detecting and validating the incident
Assessing the scope and severity
Identifying affected systems, users, and information
Restricting or containing unauthorised access
Isolating affected systems
Revoking sessions or access tokens
Resetting or rotating affected credentials
Preserving relevant records and evidence
Investigating the cause
Coordinating with infrastructure providers or security specialists
Removing or mitigating the cause
Restoring affected systems and information
Monitoring for continuing or repeated activity
Evaluating legal and contractual notification obligations
Conducting root-cause analysis
Implementing corrective and preventive measures

Our incident-response priorities are to:

Protect affected individuals
Limit unauthorised access
Minimise further exposure or damage
Restore affected services
Preserve evidence
Meet applicable notification obligations
Reduce the likelihood of recurrence

Where required by applicable law, AlignAI will notify affected individuals, institutions, regulators, authorities, or other appropriate parties.

Security concerns should be reported promptly to contact@alignai.in.

17. Customer, Organisation, and Platform User Offboarding

When a teacher, student, parent, organisation administrator, institution employee, contractor, or other platform user account is deleted, suspended, disabled, or removed from an organisation, AlignAI or the relevant organisation administrator may:

Disable account access
Remove organisation membership
Revoke active sessions and authentication tokens
Remove access to classes, batches, files, and shared information
Transfer ownership of authorised organisational content where appropriate

Retain information required for security, legal, contractual, audit, or academic-record purposes

Delete eligible account information
Preserve academic or institutional records where the organisation remains responsible for them

Organisation administrators are responsible for promptly offboarding platform users who should no longer have access.

This includes:

Former institution employees and staff
Former teachers and contractors
Students who have left the institution or completed the applicable course
Parents or guardians who no longer require access
Temporary users
Other persons whose authorised relationship has ended

Deletion from active systems does not necessarily cause immediate deletion from secured backups. Backup copies may remain until the relevant 60-day retention period expires.

18. AlignAI Workforce Access, Onboarding, Role Changes, and Offboarding

AlignAI manages access for its employees, contractors, consultants, interns, and other authorised workforce members throughout their relationship with the company.

Workforce onboarding and access-management procedures may include:

Verifying the individual’s identity, role, and access requirements
Providing individually assigned accounts and role-based, least-privilege access
Requiring multi-factor authentication where supported and appropriate
Obtaining confidentiality, acceptable-use, and data-protection commitments
Providing security and privacy awareness appropriate to the individual’s responsibilities

Recording or approving access to sensitive systems, production environments, source-code repositories, cloud infrastructure, databases, and administrative tools

When responsibilities change, access may be reviewed and adjusted so that permissions remain appropriate to the individual’s current role.

When a workforce member leaves AlignAI or no longer requires particular access, offboarding procedures may include:

Disabling company and system accounts
Revoking production, database, cloud, infrastructure, source-code, and administrative access
Revoking active sessions, tokens, API keys, SSH keys, and other credentials
Rotating shared or sensitive credentials where necessary
Recovering company-controlled devices, information, and records
Transferring ownership of files, systems, and responsibilities
Removing access to internal communication and collaboration tools
Confirming continuing confidentiality and data-protection obligations
Reviewing relevant activity where appropriate

Access is granted, reviewed, adjusted, and removed according to the individual’s responsibilities, the systems involved, and the associated security and privacy risk.

19. Children and Student Privacy

AlignAI is intended to be used by teachers, educational institutions, students, parents, guardians, and other authorised users.

Educational institutions, teachers, and organisation administrators are responsible for ensuring that they possess the authority, permissions, notices, and consents required to provide and process student data.

Where an institution uses AlignAI on behalf of students, the institution may control the relevant student information and may be responsible for:

Providing appropriate notices
Obtaining parental or guardian consent where required
Authorising student accounts
Managing student access
Responding to student or parent requests
Determining appropriate retention periods

AlignAI does not knowingly collect personal data directly from a child without the authorisation or consent required by applicable law.

Where legally required, verifiable consent from a parent or lawful guardian may be required before processing a child’s personal data.

AlignAI does not knowingly undertake tracking or behavioural monitoring of children for targeted advertising.

We do not knowingly direct targeted advertising to children through the Service.

A parent, guardian, teacher, or institution that believes a child’s information has been provided without appropriate authority may contact us at contact@alignai.in.

We will review the request and take appropriate action, which may include restricting processing or deleting eligible information.

20. User Rights and Requests

Depending on applicable law and the circumstances, individuals may have rights to:

Obtain information about the processing of their personal data
Request access to eligible personal data
Request correction of inaccurate information
Request completion of incomplete information
Request updating of outdated information
Request deletion of eligible information
Withdraw consent
Submit a grievance or complaint
Nominate another individual to exercise applicable rights where legally permitted
Request information about service providers or categories of recipients where required
Exercise other rights available under applicable law

Requests involving information controlled by a school, teacher, institution, or organisation may need to be directed to that organisation.

AlignAI may refer such requests to the relevant account holder or organisation administrator.

Before fulfilling a request, we may verify:

The requester’s identity
Their relationship with the relevant account
Their authority to act for another person
The validity and scope of the request

Certain requests may be restricted or refused where:

Retention is legally required
The data is required for an ongoing dispute
The request affects the rights of another individual
Identity or authority cannot be verified
Another lawful exception applies

Privacy requests may be submitted to contact@alignai.in.

21. Account and Data Deletion

Users may request deletion of eligible personal data by:

Using available account controls
Contacting their organisation administrator
Contacting AlignAI at contact@alignai.in

Deletion may be subject to:

Identity verification
Organisation-admin approval where applicable
Legal retention requirements
Contractual requirements
Tax and accounting obligations
Security requirements
Fraud-prevention requirements
Ongoing disputes or investigations
Backup-retention cycles

Following deletion from active systems, information may remain in secured backups for up to 60 days before being deleted or overwritten.

Information may be anonymised rather than deleted where it can no longer reasonably identify an individual.

22. Cookies and Similar Technologies

AlignAI may use cookies, local storage, and similar technologies to:

Maintain authenticated sessions
Remember preferences
Protect accounts
Prevent misuse
Support application functionality
Analyse platform usage
Diagnose errors
Improve performance
Maintain security

Certain cookies or storage technologies are necessary for the Service to function.

Users may control cookies through browser settings. Disabling essential cookies may prevent authentication or other features from functioning properly.

AlignAI does not use cookies to serve third-party behavioural advertisements.

23. Communications

We may send:

Account notifications
Security notices
Service-related communications
Billing and subscription notices
Product updates
Policy updates
Support communications
Educational or administrative messages requested by users

Users may be able to manage certain communication preferences.

Essential account, transaction, security, legal, and service notices may still be sent where necessary.

25. Security Responsibilities of Users

Users must take reasonable steps to protect their accounts, including:

Using strong and unique passwords
Keeping login credentials confidential
Restricting access to authorised individuals
Signing out from shared devices
Keeping devices and software updated
Promptly removing users who no longer require access
Reporting suspicious activity
Avoiding the upload of unnecessary personal data
Reviewing AI-generated content before official use

Organisation administrators are responsible for managing permissions and access within their organisation.

26. Grievance and Contact Mechanism

Users may contact us regarding:

Privacy questions
Data-access requests
Correction requests
Deletion requests
Consent withdrawal
Account concerns
Security concerns
Complaints or grievances

Contact:

AscendX Innovations Pvt. Ltd.

AlignAI

Email: contact@alignai.in

Website: https://www.alignai.in

Please include sufficient information to identify the relevant account and understand the request.

Do not send passwords, complete payment credentials, or other unnecessary sensitive information by email.

27. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

Changes to the Service
New features
Changes to data-processing practices
Security improvements
Changes to service providers
Legal or regulatory requirements
Organisational or operational changes

When the Privacy Policy is updated, the “Last updated” date will be revised.

Where appropriate, material changes may also be communicated through:

Email
An in-application notice
A website notice
Another reasonable communication method

The updated Privacy Policy will take effect on the effective date stated at the beginning of the policy.

Continued use of the Service following the effective date will be subject to the updated Privacy Policy, subject to any additional consent requirements under applicable law.