This policy explains what personal data Recurse collects when you use the platform at cfa.recurse.institute, why we collect it, who else processes it, and what you can ask us to do with it. It is written to be read, not to be survived.
Recurse is operated from India, and this policy is written with the Digital Personal Data Protection Act, 2023 in mind.
1. What we collect
- Account details. Your name and email address, provided when you sign up. If you sign in with Google, we receive your name, email address and profile image from Google.
- Your study data. The questions you answer, the answers you choose, whether they were correct, how long you spent, your mock exam attempts and scores, and which readings you have opened. This is what makes the analytics and the progress tracking work.
- Your exam target. The exam date you tell us you are sitting, if you choose to enter one.
- Subscription and payment records. Which plan you bought, when it started and ends, and the payment and order identifiers returned by our payment gateway. We never see or store your card number, UPI PIN, CVV or bank credentials — those go directly to the payment gateway and never touch our servers.
- Messages you send us. Anything you write in the contact form, along with the email address you gave us to reply to.
- Technical data. IP address, browser and device type, and pages visited. This is used for security, rate limiting and understanding which parts of the product are used.
2. Why we use it
- To give you an account and keep you signed in.
- To show you your own progress, analytics and results.
- To take payment, give you the access you paid for, and remind you before a subscription renews.
- To answer you when you write to us.
- To keep the service working and to stop abuse: rate limiting, bot filtering and error diagnosis.
- To decide what to build next, from aggregate usage.
We do not sell your personal data, and we do not use it to serve advertising.
3. Who else processes it
We use a small number of specialist providers. Each one only receives what it needs to do its job.
- Clerk — sign-up, sign-in and session management.
- Neon — the PostgreSQL database holding your account, study data and subscription records. Hosted in Singapore.
- Vercel — application hosting and delivery.
- Razorpay — payment processing. Razorpay handles your payment instrument directly under its own privacy policy.
- Resend — sending transactional email, such as renewal reminders and replies.
- Cloudflare R2 — storage and delivery of study material files and images.
- Upstash — caching and rate limiting.
- Arcjet — abuse and bot protection.
- Sentry — error monitoring, so we find out about faults before you have to report them.
- PostHog — product analytics.
Some of these providers operate outside India, so your data may be processed abroad. We only use providers that offer contractual protection for the data we send them.
4. Cookies and similar technologies
- Essential cookies keep you signed in. Without these the service cannot work, so they are always set.
- Analytics cookies record how the product is used, in aggregate.
We do not use advertising or cross-site tracking cookies.
5. How long we keep it
- Account and study data are kept while your account is open, so that your progress is there when you come back.
- Payment and invoice records are kept for as long as tax and accounting law requires, even after an account is closed. This is the one category we cannot delete on request.
- Error and technical logs are kept for a short period and then discarded.
6. Your rights
You can ask us to:
- Show you the personal data we hold about you.
- Correct anything that is wrong.
- Delete your account and the personal data attached to it. We have a real erasure process, not a promise to think about it; the financial records described above are the exception, and we will tell you exactly what was kept and why.
- Withdraw consent to analytics.
Write to admin@recurse.institute and we will respond. If you are not satisfied with how we have handled a request, you may complain to the Data Protection Board of India.
7. Security
Access to the database is restricted and authenticated, traffic is encrypted in transit, payment credentials never reach our servers, and administrative actions on customer accounts are logged with the identity of whoever performed them. No system is perfectly secure, and we will not pretend otherwise; if a breach affects your data we will tell you.
8. Children
The service is intended for candidates aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, write to us and we will remove it.
9. Changes to this policy
If we change this policy materially we will post the new version here and, where the change affects how we use data you have already given us, tell you by email. Every published version of this page is kept, so the policy in force on a given date can always be established.
10. Contact
Questions, requests or complaints about this policy go to admin@recurse.institute.