Privacy Policy

Your learning data should be understandable and controllable.

This policy explains the personal data processed by MockMindset, the purposes for using it and the choices available to visitors and registered learners.

Last updated: 31 August 2026

1. Scope and operator

This policy applies to the MockMindset website, accounts, practice tests, mock tests, Learning pages and related support services. References to “we”, “us” or “MockMindset” mean the operator of this platform.

Privacy questions may be sent to support@mockmindset.com.

2. Data we process

Account and security data

First and last name, email address, country, email-verification status, one-time-password security records, session records, browser/device label, hashed IP information and account timestamps.

Learning and assessment data

Quiz settings, questions assigned, submitted answers, correctness, scores, completion status, time of activity, Learning progress, topic accuracy, streaks and saved preferences.

First-party analytics data

Random visitor and session identifiers, page path and title, referrer hostname, page views, approximate country/region/city supplied by the deployment network, a one-way IP hash, an anonymised network prefix, user agent and active time. Full IP addresses are not stored in analytics tables.

Support data

Information you include when contacting us, including the relevant page, question ID and message.

3. Why data is used

  • Create and secure accounts and deliver login OTPs.
  • Run tests, save answers, calculate results and prevent unintended question repetition.
  • Personalise Learning progress and weaker-topic recommendations.
  • Remember learner settings and active sessions.
  • Understand aggregate traffic, countries, page use and active time.
  • Investigate abuse, diagnose faults, answer support requests and improve content.
  • Meet applicable legal, security and record-keeping obligations.

4. Retention

Analytics sessions are retained for up to 395 days by default, unless the configured production retention period is changed within the platform’s permitted range. Orphan analytics visitor records are removed.

Account, assessment and Learning-history data is retained while the account is active and as reasonably needed to provide progress history, resolve disputes, maintain security and meet legal obligations. Deletion requests may be subject to records that must be retained or de-identified.

5. Service providers and disclosures

Data may be processed by infrastructure, database, security and email-delivery providers acting for the platform. Amazon SES is configured as the production channel for account OTP email. Data may also be disclosed where legally required, to protect users or the service, or as part of a properly managed business reorganisation.

We do not sell personal data and do not use third-party advertising trackers in the current implementation.

6. Your choices and rights

Depending on applicable law, you may ask to access, correct or erase personal data, withdraw consent, object to certain processing or raise a grievance. Signed-in learners can update profile and analytics preferences under Settings.

Browser-level opt-out affects future analytics events from this browser. Do Not Track is also respected. Essential authentication and security processing is not disabled by an analytics choice.

7. Security and international processing

Reasonable technical and organisational safeguards are used, including hashed session tokens, hashed analytics identifiers, secure production cookies and controlled administrative access. No internet service can guarantee absolute security.

Providers may process data outside your country. Where required, appropriate legal and contractual safeguards should be used.

8. Children

The service is intended for adult project professionals and candidates. A person below the age at which they can independently consent under applicable law should use the service only with valid parent or guardian involvement.

9. Legal framework and changes

This policy is designed to provide clear notice in light of applicable privacy requirements, including India’s Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 as their provisions commence. It is not a statement that every law applies identically to every user.

Material changes will be reflected by updating the date above. Official references: DPDP Act on India Code and DPDP Rules on MeitY.