1. Introduction
Welcome to TheBlueMustard (“we,” “us,” “our,” or “the Platform”), accessible at thebluemustard.com, its subdomains (including creator storefronts at <slug>.thebluemustard.com and the assessments portal at tests.thebluemustard.com). We are committed to protecting your personal information and respecting your right to privacy. This Privacy Policy explains how we collect, use, disclose, store, and safeguard your information when you access or use the Platform.
TheBlueMustard is a combined digital product marketplace, online assessment platform, and subscription billing service, and it offers a set of AI-powered features - an in-app AI assistant that can draft content and, with your confirmation, carry out actions in your store; standalone AI tools that draft assessments and questions, suggest marks, and summarise or analyse candidate material; and an optional connection to Telegram so you can use the assistant from a chat app. §5 describes these AI features in full: what they are, what data they process, which third parties may receive it, and what control you have over them. Depending on how you use the Platform, we may act as a data fiduciary for you as a buyer or visitor, as a data processor for a creator when they use us to administer assessments to their own candidates and team members, or both.
This Privacy Policy applies to all users of the Platform, including visitors, registered users, creators (sellers and assessment authors), store staff and team members, buyers, guest purchasers, candidates taking assessments, admins, and grievance officers. By accessing or using the Platform, you consent to the data practices described in this Privacy Policy. If you do not agree with these practices, please discontinue use of the Platform.
This Privacy Policy is published in compliance with the Information Technology Act, 2000 (in particular Section 43A), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020, and the Digital Personal Data Protection Act, 2023 (to the extent notified), together with any other applicable Indian data-protection laws and regulations.
2. Types of Data Collected
2.1 Account & Profile Information
When you register for an account on the Platform (via our authentication provider, Clerk), we may collect the following personal information:
- Full name, first name, last name, and display name
- Email address and, where offered by Clerk, phone number
- Username (unique on the Platform)
- Profile avatar or photograph
- Bio or personal description
- Website URL (optional)
- Social handles - Twitter/X, Instagram, YouTube, LinkedIn, GitHub (all optional)
- Language and timezone preferences, and privacy toggles (whether your profile, sales metrics, follower count, and contact email are publicly visible)
- Whether two-factor authentication is enabled on your account
- Session and device metadata surfaced by Clerk (session identifier, last active time, issuing device fingerprint)
2.2 Creator, Store & Team Information
If you register as a creator, own a store, or are added to a store as a team member, we additionally collect:
- Store name, description, tagline, custom slug, and branding assets (logo, banner, favicon, brand colours, brand theme, support email and support phone)
- Store registration policy (invite-only / public / approval) and any custom registration fields the store owner has configured (for example: employee ID, roll number, department, cohort)
- Store-scoped role assignments (owner, admin, manager, team member, customer, or any custom role a store creates)
- Team invitations that you send or receive, including the invited email, role keys, invitation message, acceptance state, and expiry
- Product listing details (titles, descriptions, pricing, currency, compare-at price, categories, cover image, sample images with alt text and tags)
- Digital product files you upload for sale, together with their filename, MIME type, size, and SHA-256 checksum
- Subscription plans, prices, and coupons that you author, and the subscribers they attract
2.3 Assessment & Candidate Data (Creators as Authors and Assessors)
If you use the Platform to author or administer online assessments, we collect and store - on your behalf and under your direction - the following information about the tests you build and the candidates who take them:
- Test configuration: title, slug, instructions, duration, passing score, maximum attempts, randomization flags, access mode (public, private, invite-only), launch mode (candidate self-serve or supervisor-launched), timer mode (whole-test or section-wise), navigation policy, and any per-test share token or test code
- Question bank content: prompt HTML, options and correct answers, explanations, difficulty, subject, tags, translations, immutable version snapshots, and duplicate fingerprints for de-duplication
- Candidate profile data (per store): name, father’s name, email, mobile number, date of birth, address, photograph, qualification, acquisition source, and work status, plus store-defined custom fields
- Candidate groups, tags, bulk-import spreadsheets you upload for validation, and the outcome report of each import
- Assessment invitations: invited email, attempts allowed, availability window, expiration, delivery status (SES message ID, delivery/bounce/complaint), and open/start/complete timestamps
2.4 Candidate Runtime Data (Candidates Taking a Test)
When you are a candidate taking a test on the Platform (whether via a share link, a test code, or an emailed invitation), we collect the following information for the store that is administering the assessment:
- Name and email you provide at registration (and, if the assigning creator has provided one, a link back to your global Candidate profile)
- The test you registered for, the number of attempts, and each attempt’s start, activity, submission, and evaluation timestamps
- Your answers to each question, per-question time spent, and any “flag for review” marks
- Client snapshot metadata (viewport dimensions, user-agent hints, connection details) captured at attempt start
- Client-reported proctoring signals when the creator has enabled them: tab switches, window blur, fullscreen exits, copy/paste attempts, right-clicks, developer-tools openings, together with a running violation count
- Real-time connection presence (connected/disconnected) while an attempt is in progress
- Real-time messages exchanged with the assessor during a live session (see §2.5)
- Section-wise state (pending, active, completed, expired) with server-anchored deadlines, and whether a section was auto-submitted because a timer expired
- Score, maximum score, percentage, pass/fail, and evaluation state (pending, auto-graded, manual review, complete)
- If the store you tested with uses AI-assisted marking or summarisation (see §5.3), your submitted answer text, or your full attempt’s question/answer content, may be sent to a third-party AI model provider to generate a suggested mark or a summary for the human reviewing your attempt. The suggestion is not applied automatically - see §5.3
- Your test-response and result-share emails and their delivery status
- Language preference at the time you took the test (for reporting in the same language you experienced)
2.5 Live-Session, Messaging & Real-Time Data
Some assessments are launched inside a supervisor-run live session. For those we also collect and store:
- Live-session lifecycle events (waiting, active, ended) and their timestamps
- Messages sent between assessors and candidates (individual and broadcast), including sender, recipients, priority (info/warning/critical), content, and read receipts
- Assessor actions targeted at a candidate (warnings, force-submit, ban with reason)
- Presence and connectivity signals of connected sockets so assessors can see who is currently online
2.6 Financial, Payment & Billing Information
When you make a purchase or subscribe on the Platform, payment information is collected and processed securely by our third-party payment gateway, Razorpay Software Private Limited. This may include:
- Credit or debit card details (card number, expiry date, CVV)
- UPI ID and, for QR-based tip flows, UPI handle
- Net banking credentials
- Digital wallet information
- EMI and BNPL provider details (when offered by Razorpay)
Important: TheBlueMustard does not directly collect, store, or have access to your full credit-card numbers, debit-card numbers, CVV codes, banking PINs, or UPI PINs. All sensitive payment information is processed exclusively by Razorpay in accordance with their PCI-DSS Level 1 compliance standards and their privacy policy. We only receive confirmation of payment status (success or failure), transaction reference identifiers, and the payment method type used.
In addition, for creators who wish to receive payouts and for buyers on subscriptions or business (B2B) invoices, we collect and store:
- Payout preferences: payout provider (for example: Razorpay Route or bank transfer), external account reference, payout currency, payout schedule (daily, weekly, monthly)
- Billing account details: billing email, currency, and Goods and Services Tax Identification Number (GSTIN) for tax-compliant invoicing
- Provider references: Razorpay customer IDs, plan IDs, subscription IDs, and invoice/order/payment IDs (never full instrument data)
2.7 Order, Subscription & Entitlement Data
We collect and store the following transaction-related data on our servers:
- Order ID and order status (Pending, Paid, Fulfilled, Failed, Refunded, Cancelled), currency, and total amount
- Line items (product, test, store or bundle purchased, plan / price snapshots, and price at purchase)
- Razorpay order ID, payment ID, and payment status (Pending, Captured, Failed, Refunded), plus a signature reference
- License key(s) generated for one-time purchases and their download counters and last-download timestamp
- Entitlements (the single source of access-truth), including their resource type, source (one-time, subscription, manual grant, promo, invitation, migration), validity window, and per-metric caps
- Subscription lifecycle (trialing, active, paused, grace, past-due, canceled, expired), current billing period, grace window, and cancel-at-period-end preference
- Invoices (with sequential GST-compliant numbering), invoice lines (subscription, one-time, usage overage, credit pack, discount, tax), tax lines (CGST/SGST/IGST, rate, GSTIN), credit notes, and refunds
- Usage events and per-period usage counters for metered features (for example: tests created, assessments run, candidate invites, candidate attempts, AI-assisted generations and evaluations, emails sent, API calls, cumulative storage). As described in §5.6, technical metering of AI usage exists in our systems but is not yet switched on in any environment, so AI usage is not currently capped or drawn down against a credit balance in practice
- Credit balances and an append-only credit-transaction ledger (purchase, promotional, consumption, refund, adjustment, expiry) with signed amounts and running balances, covering assessment, AI, invite, and email credit types
- Coupon redemptions (including referral coupons) tied to your account or subscription
- An append-only billing audit log that records every finance-grade action (payment captured, order fulfilled, entitlement granted, refund issued, and so on) with before / after state - this log is retained for regulatory and dispute purposes
- Date and time of each transaction and each billing event received from the payment provider (with an idempotency ledger that prevents duplicate processing of redelivered webhooks)
2.8 Technical, Device & Usage Data
We automatically collect certain technical and usage data when you access the Platform, including:
- IP address (and, when relevant, the IP recorded for a specific download or attempt)
- Browser type, version, and language settings
- Operating system and device type
- Pages visited, features used, search terms, and navigation patterns
- Date, time, and duration of visits
- Referring website or URL
- Download history, including the file, license, timestamp, IP address, and (for guests) the email associated with the download
- User-agent string
- Request identifiers and correlation identifiers that the server attaches to each request for distributed tracing and debugging (never used for cross-site tracking)
- Rate-limiting and abuse signals attached to a request (per-IP quotas by 1 s / 10 s / 60 s buckets, and, for the AI assistant and any connected channel, additional per-account and per-conversation quotas described in §5)
2.9 Engagement, Community & Discovery Data
The following additional signals are collected when you interact with the marketplace and community features:
- Wishlist entries you add or remove
- Product views (a naive lifetime counter per product)
- Product reviews (rating 1–5, optional title and body, whether the reviewer is a verified purchaser, and moderation state)
- “Helpful” votes on reviews
- Follows (of a store or a creator)
- Content reports (subject type - product, store, or creator - reason, optional note, and moderation status). Anonymous reports without a signed-in user are permitted
- Recently viewed history maintained in your browser
- Read / dismissed state for in-app UI messages, tips, banners, and announcements
2.10 Guest Purchase & Guest Access Data
If you interact with the Platform as a guest (without creating an account), we collect only what is required to fulfil your action:
- Guest purchases: your email address, optionally a phone number, a one-shot secure download token, and its expiration (default 30 days), together with the transaction data listed above
- Guest OTP authentication: a hash of a 6-digit one-time password sent to your email, the number of verification attempts, and the expiry timestamp. The OTP itself is stored only as a hash and is discarded after use or expiry (default expiry: 3 minutes; default max attempts: 3)
- Guest session token: a short-lived signed JWT (default lifetime 15 minutes) that lets you list and download the purchases tied to a verified email without registering an account
2.11 Support, Communications & In-App Messaging Data
When you contact us or use in-app communication features, we may collect and retain:
- The name, email, subject category, and message content you submit through the Contact form
- Emails, replies, and threaded correspondence exchanged with our support team
- Email lifecycle events (sent, delivered, bounced, complaint) surfaced by our email providers via SES/SNS or Resend webhooks - used to suppress deliveries to invalid or complaining addresses
- Read/dismissed state for platform-driven UI messages and banners
2.12 Administrative & Audit Data
For accountability, security, and dispute resolution we maintain the following internal records. Most of these fields are visible only to the Grievance Officer and authorised platform-owner personnel:
- Audit log: an immutable log of security-relevant actions taken on the Platform (actor, action, resource, before/after state, IP, user-agent, request and correlation identifiers, status, and any reason). This includes a record of every AI-assisted operation that was requested - what capability was invoked, by whom, when, and whether it succeeded, was declined by policy, or failed - see §5.5. The audit record does not itself contain the prompt or the AI-generated content; see §5.5 for where that content is (and is not) stored
- Activity log: a retained log of operational events (imports, bulk jobs, moderation, imports/exports, and similar)
- Impersonation sessions: when a platform-owner administrator uses the Super Admin console to impersonate an account for support purposes, the session, reason, target, IP, and start / end timestamps are recorded and remain visible to the impersonated user on request
- Kill switches, feature flags and system settings: the flags and settings applied to your account or store at a given time, together with their version history
- Bulk jobs: the parameters, status, and per-item outcomes for bulk-import and bulk-administrative jobs you run
2.13 AI Assistant, AI-Assisted Tools & Connected Channel Data
If you use any of the AI features described in §5, we additionally collect and store:
- Assistant conversations: each message thread you have with the AI assistant inside a given store, including your messages, the assistant’s replies, the tools it called, and any action it proposed that was awaiting your confirmation. A thread belongs to you and the store it was opened in - it is not visible to other team members of that store, even ones with broader permissions than you, and not to store owners or admins either
- Assistant attachments: files you upload into a conversation with the assistant (up to five per message) - filename, file type, size, and a checksum used to avoid storing duplicate uploads twice. For text-based documents (PDF, Word, Excel, CSV, plain text, Markdown, JSON) we extract and store the text content, up to a length limit, so the assistant can read it. Images are sent to the underlying AI model as visual input and are not text-extracted or stored as extracted text. You can remove an attachment before you send the message it is attached to; once sent, it becomes part of the conversation record and is not individually deletable by you - see §5.7 for how to request its deletion
- Content you submit to standalone AI tools: a topic, brief, or job description (for drafting an assessment or questions); an existing question’s text (for rewriting, translating, simplifying, or retuning its difficulty); a candidate’s answer text and any rubric or model answer you supply (for answer-evaluation assistance); the question/answer content of a full attempt (for submission summarisation); or resume text (for resume analysis)
- Connected-channel data (currently Telegram, optional): if you link a Telegram account to the assistant, we store the Telegram account’s platform-assigned identifier, the display handle at the time you linked it, the store and the specific set of permissions you chose to delegate to that channel, and records of the confirmations you approved or declined over that channel. We do not use your Telegram username, display name, phone number, or email for any authorisation decision - only the verified link record is
- AI-related audit entries as described in §2.12
3. How Data is Collected
We collect your data through the following means:
- Account Registration: personal information provided by you during sign-up through our authentication provider, Clerk (email/password, one-tap, or social sign-in as supported by Clerk).
- Profile, Store & Team Setup: information you voluntarily provide when setting up your user profile, creator profile, store branding, or when accepting a team invitation to another creator’s store.
- Product & Test Authoring: information and files you upload when listing digital products for sale, building tests, importing questions or candidates in bulk, and exporting question banks.
- Assessment Participation: information you provide when registering for a test (email, name, optional store-defined fields), while taking an attempt (answers, per-question timing, flags, client-reported proctoring events), and during live-session messaging.
- AI & Assistant Interactions: messages and files you send to the AI assistant, requests you make to a standalone AI drafting or evaluation tool, and (if you choose to link one) messages exchanged over a connected channel such as Telegram. See §5.
- Payment Processing: financial data collected by Razorpay when you initiate a payment transaction or start a subscription.
- Cookies and Session Data: essential cookies set by our authentication system (Clerk) for session management, subdomain routing cookies, and - only when enabled - optional analytics cookies (see §8).
- Automated Collection: technical and usage data collected automatically through server logs, application traces, request-context middleware, and rate-limiting counters when you interact with the Platform.
- Email & Delivery Providers: delivery, bounce, and complaint events reported by Amazon SES (via SNS webhooks) and Resend, so we can maintain deliverability and honour opt-outs.
- Real-Time Gateway: connection presence, room subscriptions, and messaging exchanged over the Platform’s Socket.IO realtime gateway.
- Communications: information you provide when you contact our support team, submit a content report, or reply to any of our transactional emails.
4. Purpose of Data Usage
We use the information we collect for the following lawful purposes:
- Account Management: to create, authenticate, and manage your user account, including enforcing suspend, soft-delete, and account-restoration lifecycles.
- Service Delivery - Marketplace: to enable creators to set up stores, list products, process sales, deliver purchased files, and enable buyers to browse, purchase, download, and access digital products.
- Service Delivery - Assessment Platform: to enable creators to build question banks, author tests, invite and manage candidates, run live proctored sessions, evaluate results, and share reports; and to enable candidates to register, take attempts, receive their submission copies, and (when the creator shares them) their scored reports.
- AI-Assisted Features: to draft assessments, questions, and question revisions for a creator to review; to suggest marks or summaries for a human reviewer evaluating a candidate’s answers; to structure resume content for a creator reviewing an applicant; and, through the AI assistant, to carry out an action inside your store that you have specifically requested and, where required, confirmed. See §5 for exactly how each of these works and what is sent to a third-party AI provider.
- Payment & Subscription Processing: to facilitate secure transactions through Razorpay, manage recurring subscriptions, generate GST-compliant invoices, and process refunds, credit notes, and coupons where applicable.
- License & Entitlement Management: to generate, manage, and validate license keys for one-time purchases, and to resolve subscription-based entitlements at every access-controlled surface (downloads, test attempts, feature gates).
- Order Fulfilment: to deliver purchased digital products, send order confirmation and receipt emails, provide download-access links and Assessment Codes, and mark orders as fulfilled exactly once.
- Assessment Integrity & Proctoring: to enforce server-anchored timers, log client-reported violations, warn or force-submit candidates who breach configured rules, and give creators the tools to review, ban, or waive violations for their own candidates.
- Communication: to send transactional emails (welcome, creator activation, store created, purchase receipts, sale notifications, store invitations, assessment invitations with test codes, candidate exam-report copies, and scored candidate result emails), respond to support enquiries, and notify you of important account, policy, or billing changes.
- Platform Improvement: to analyse aggregate usage, benchmark performance, troubleshoot technical issues, and improve the Platform’s features, reliability, and user experience.
- Security, Anti-Abuse & Fraud Prevention: to detect, prevent, and address fraud, unauthorised access, quota abuse, spam, content violations, and other harmful activities, including via rate limits, kill switches, and platform-owner moderation tooling.
- Compliance & Enforcement: to comply with applicable laws, regulations, legal process, or enforceable governmental requests, and to enforce our Terms and Conditions.
5. AI Features and How They Process Your Data
This section explains, in plain terms, every AI-powered feature on the Platform: what it does, what data it sends to a third-party AI model provider, what the Platform does with what comes back, and what control you have over it. Where a claim below depends on how a specific deployment of the Platform is configured (for example, which AI provider is actually connected), we say so rather than guess.
5.1 What the AI features are
- AI assistant (“Ask AI”): a conversational assistant, available to signed-in creators and store team members inside a specific store, that can answer questions about your store’s own data and, where you ask it to and it has the necessary tools, take actions in that store on your behalf - for example, drafting or updating assessment content, looking up candidates or orders, or preparing an invitation. It only ever acts with your own permissions in that store; it cannot do anything you could not otherwise do yourself through the Platform.
- Standalone AI drafting tools: “Generate with AI” for a full assessment or a set of questions from a brief you provide; and a question-improve tool that rewrites, simplifies, retunes the difficulty of, translates, or explains an existing question. Both return a draft for your review - nothing is added to your test or question bank until you separately choose to add it.
- AI-assisted evaluation tools: a tool that suggests a mark for one candidate answer against a rubric or model answer you provide, and a tool that summarises a candidate’s whole attempt for a human reviewer. Both return a suggestion only - no score or summary is recorded against a candidate’s result unless a human reviewer separately applies it.
- Resume analysis: a tool that reads resume text you provide and returns a structured breakdown of skills, experience, and gaps against a role you describe, for you to review.
- Connected channel (optional, currently Telegram): you may link a Telegram account to the AI assistant so you can talk to it, and approve or decline the actions it proposes, from a chat app instead of the web dashboard. See §5.4.
These features sit behind the same permission, quota, and kill-switch checks as every other action on the Platform - they are not a separate, less-governed system.
5.2 What is sent to a third-party AI provider, feature by feature
The Platform is built to work with more than one AI model provider; which provider (or providers) is actually active in a given deployment depends on which provider is configured for that deployment, and requests may be routed to whichever configured provider is best suited to the request. As of this policy’s last update, the Platform supports OpenAI, Anthropic, and DeepSeek as possible AI model providers. Regardless of which is active, the data sent depends on the feature you use:
- Drafting an assessment, questions, or a question revision: the topic, brief, job description, or existing question text you supply, plus any parameters you set (difficulty, question count, question types, target language, and similar). This does not include candidate data.
- Answer-evaluation assistance: the question text, the candidate’s actual answer text, the marks available, and any rubric or model answer you provide.
- Submission summarisation: the full question/answer content of the attempt you ask it to summarise, and, optionally, a description of the role the candidate was being assessed for.
- Resume analysis: the resume text you provide, which will typically include a candidate or applicant’s name, contact details, education, and work history, plus, optionally, a description of the role you are matching against. We instruct the model not to infer or report on demographic characteristics (age, gender, nationality, or similar) that are not evidenced by the resume itself; this is a prompt instruction to the model, not a technical guarantee of the model’s output.
- The AI assistant: your message, the recent history of your conversation, the content of any file or image you attach (see §2.13), and - when the assistant calls a tool to look something up or take an action - the store data that tool returns (for example, a product’s current details, or a list of matching candidates), so the assistant can use it to respond to you or decide its next step.
In every case above, only the AI model provider actually processing the request receives this data - it is not additionally sent to any analytics, logging, or “AI operations” third party. We do not send your prompts or the AI’s responses to any observability or logging vendor; our internal logs record metadata about an AI request (which feature, when, by whom, how long it took, whether it succeeded) but not its content. See §5.5.
What we cannot yet tell you from this policy alone: the specific AI provider(s) actually connected in the production environment you are using, and that provider’s own data-retention and model-training practices, are governed by our contract with that provider rather than by this Platform’s code, and are not something we can state definitively in a document like this without confirming it against our live configuration and vendor agreements. We do not claim that any AI provider deletes, anonymises, or refrains from training on this data unless and until we have confirmed that in writing with the provider - see §16 (Changes to This Privacy Policy) for how we will update this section once that is confirmed.
5.3 AI outputs are drafts and suggestions, not decisions
None of the drafting or evaluation tools in §5.1 write anything to your store, your test, your question bank, or a candidate’s result on their own. Each one returns its output to you for review; a separate, explicit action by a person (for example, adding a generated question to a test, or confirming a bulk-import draft, or entering a mark) is what actually changes anything. A suggested mark or a submission summary is never applied to a candidate’s result automatically. This means a candidate’s score always reflects a decision made or approved by a human at the administering store, not the AI model directly.
5.4 AI-assisted actions, confirmation, and what the assistant cannot do
When the AI assistant (in the web dashboard or over a connected channel) proposes an action that would change something in your store, the Platform classifies that action by risk. Purely read-only actions (for example, looking up a candidate or an order) can run without a separate confirmation step, within your own permissions. Actions we classify as higher-risk - for example, inviting or removing candidates, or publishing a product - require you to explicitly confirm them before they run; the assistant shows you what it is proposing to do and will not proceed without your approval. A confirmation is bound to the exact action proposed - if the underlying request changes, the confirmation is no longer valid and a new one is required.
Some actions are never available to the assistant or to any connected channel, regardless of your own permissions or any confirmation you might give: deleting or transferring a store, managing billing, cancelling a subscription, managing team members or their roles, opening or controlling a live proctored session, and terminating a live proctoring session. These are excluded structurally - they are not offered to the assistant as an available action at all, rather than being offered and then declined.
If you connect Telegram (§2.13), messages the assistant sends you there may include personal or business data from your store that you are otherwise authorised to see (for example, a candidate’s name or email, if you ask for it) - connecting a channel does not restrict what the assistant can tell you beyond what it can already tell you in the web dashboard. We do filter what is sent to a connected channel to remove things like credentials, signed file-download links, and raw internal data dumps, but this is a technical safety filter, not a personal-data filter.
5.5 Logging, audit, and what is (and is not) stored
Every AI-assisted request - whether it is a drafting tool, an evaluation tool, or an assistant action - is recorded in our audit log with metadata: which capability was called, by whom, in which store, when, and whether it succeeded, was declined by policy, or failed. This audit metadata does not include the prompt text or the AI-generated content itself.
Full conversation content is stored only for the AI assistant (§2.13) - your messages, the assistant’s replies, and any attachments you send it, scoped to you and the store the conversation is in, and not visible to other team members of that store. The other AI tools in §5.1 (assessment/question drafting, question improvement, answer evaluation, submission summarisation, resume analysis) are designed so that the request you send and the draft or suggestion that comes back are not persisted by the Platform beyond the audit metadata above - they exist only for the duration of the request, and only what you separately choose to save (for example, a question you add to your bank) becomes ordinary stored data at that point.
5.6 Metering, plan limits, and kill switches for AI features
AI usage is one of several metered activities on the Platform, alongside things like candidate invitations and emails sent, and is intended to draw down against your plan’s allowance and any prepaid AI credit balance you hold. As of this policy’s last update, our usage-metering system exists and is fully built but is not yet switched on in any environment - so while we intend to enforce plan limits and credit balances against AI usage, that enforcement is not currently active, and AI features are not currently being capped or charged against a credit balance in practice. We will update this section once metering is switched on.
Administrators can disable AI-assisted features platform-wide, but as currently implemented this is done through the same emergency control that disables assessment operations generally, rather than a dedicated AI-only switch - so disabling AI in an emergency also pauses non-AI assessment activity for the duration.
5.7 Retention of AI-related data
We do not currently run an automatic, time-based deletion process for AI assistant conversations, attachments, or connected-channel link records - as things stand, this data is kept for as long as your account and the store it belongs to exist, in the same way as the rest of your account data described in §9. “Deleting” a conversation from the assistant interface archives it (removes it from your active list) rather than erasing its content from our systems. If you want a specific AI conversation, attachment, or connected-channel record permanently deleted, contact us using the details in §17 and we will action the request, subject to the retention exceptions described in §9 (for example, where content has already become part of a store’s ordinary records, such as a question you added to your bank). Records that are narrowly scoped and short-lived by design - such as a channel-linking code or a pending confirmation token - expire automatically within hours, as described in §9.
6. Payment Data Handling
All monetary transactions on the Platform are processed exclusively through Razorpay, a payment gateway authorised by the Reserve Bank of India (RBI) and certified under PCI-DSS Level 1 security standards.
- TheBlueMustard does not store, process, or have access to your full credit-card numbers, debit-card numbers, CVV codes, banking PINs, or UPI PINs at any point.
- Payment data is transmitted directly from your browser or device to Razorpay’s secure servers using industry-standard TLS encryption.
- We receive only payment confirmation details (transaction ID, payment status, and payment-method type) from Razorpay, which are stored on our servers solely for order fulfilment, subscription billing, invoicing, refund processing, and record-keeping.
- For recurring subscriptions we additionally store Razorpay customer, plan, and subscription identifiers so we can reconcile lifecycle events (renewals, dunning, cancellations) with your entitlements. Provider webhooks are recorded once in an idempotency ledger to prevent duplicate processing.
- The optional Support-a-Creator page lets a creator receive voluntary tips on their free products. The creator chooses one or both of two payment surfaces:
- UPI QR & UPI ID (off-Platform): the tip page displays the creator’s personal UPI QR and/or VPA. TheBlueMustard does not process, collect, or hold funds sent this way; they flow directly through your UPI provider to the creator. We record only that a buyer clicked the surface (for the creator’s dashboard analytics) and, if provided, the buyer’s email.
- Razorpay Checkout (on-Platform): tips paid via Razorpay flow through the same PCI-DSS Level 1 gateway that handles regular purchases (see above). We store the tip amount, the tipping user or email, and the Razorpay order and payment identifiers for reconciliation and dispute handling; no license or invoice is generated for a tip. Tip settlement to the creator follows their standard payout arrangement.
- Razorpay’s handling of your payment data is governed by their own privacy policy and terms of service. We encourage you to review Razorpay’s privacy policy at razorpay.com/privacy.
7. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for marketing or advertising purposes. We may share your data with the following parties, strictly on a need-to-know basis and for the purposes outlined below:
7.1 Service Providers & Processors
- Clerk (Clerk Inc.): our authentication and identity-management provider. Clerk processes your login credentials, manages your authentication sessions, and (via webhooks signed with the svix protocol) mirrors profile changes into our database. Clerk’s handling of your data is governed by their own privacy policy.
- AI model providers: when you use any of the AI features described in §5, the data listed in §5.2 is sent to the AI model provider actually configured for that feature. The Platform is built to work with OpenAI, Anthropic, and/or DeepSeek, and a given deployment may have one, more than one, or (if none is configured) none of these active. Each provider processes the data it receives under its own privacy policy and terms; none of these providers is based in India, so this transfer is also addressed in §11 (International Data Transfers).
- Telegram (optional): if you choose to link a Telegram account to the AI assistant, messages exchanged with the assistant over that channel pass through Telegram’s own infrastructure and are subject to Telegram’s own privacy policy and terms in addition to this one.
- Razorpay: our payment gateway. Razorpay processes your payment and recurring-subscription information securely in accordance with PCI-DSS standards and their privacy policy, and returns transaction and lifecycle events to us via signed webhooks.
- Amazon Web Services (AWS): our cloud-infrastructure provider. AWS hosts our servers, databases, and file storage (Amazon S3). Digital product files, product cover images, candidate photographs (when uploaded), assistant attachments, and bulk-import spreadsheets are stored in S3 with private access controls, server-side encryption, and short-lived signed URLs.
- Amazon Simple Email Service (SES) and/or Resend: our transactional email providers. One or both is used to send account, order, subscription, invitation, assessment, candidate report, and result emails. Amazon SNS is used to surface SES delivery, bounce, and complaint events back to the Platform so we can keep our sender reputation and suppression list current.
- Redis / BullMQ: deployed alongside our infrastructure to run background jobs (bulk imports, exports, invitation emails, report emails, result emails, connected-channel message processing), realtime pub/sub for the Socket.IO gateway across multiple instances, and in-memory rate limiting. Redis holds transient queue state and short-lived presence data.
- Google Analytics 4 and Meta Pixel (optional, opt-in): analytics scripts that may be enabled per environment via server configuration. They run only when the corresponding measurement or pixel identifier is configured; when unconfigured the scripts are not loaded at all. GA4 is configured with anonymize_ip. Where and when either provider is enabled, this section is updated and, where required, consent is obtained.
7.2 Creators, Stores & Store Team Members
When you purchase a product from a creator’s store, register as a candidate for a creator’s test, or accept an invitation into a store, the creator (and store team members authorised through their store roles) will receive the information they need to fulfil the interaction. This may include:
- Your name and email address
- The product(s) purchased, the amount, and download / license status
- For candidates: your assessment answers, attempt timings, per-section state, scores, any AI-suggested marks or summaries a reviewer has seen (see §5.3), proctoring violations, and any messages you exchanged with the assessor during a live session
- For team members: your role assignments in the store, the store-specific profile fields the store owner has configured, and your last-active timestamp
Creators act as an independent data fiduciary for the store data, candidate data, and assessment content they collect and store on the Platform. Their treatment of that data is additionally governed by their own privacy notice and internal policies. Any store-specific fields collected at candidate or team registration (for example: a university roll number or an employer’s employee ID) live only inside that store’s scope and are never promoted to your global profile.
7.3 Legal and Regulatory Compliance
We may disclose your information if required to do so by law, regulation, legal process, or enforceable governmental request, or if we believe in good faith that such disclosure is necessary to:
- Comply with applicable laws, regulations, or legal processes.
- Enforce our Terms and Conditions.
- Protect the rights, property, or safety of TheBlueMustard, its users, or the public.
- Detect, prevent, or address fraud, security, or technical issues.
8. Cookies and Tracking Technologies
8.1 Essential Cookies We Use
We use essential cookies for the following purposes:
- Authentication cookies set by Clerk to manage your login session and keep you securely authenticated as you navigate the Platform.
- Storefront routing cookie (
_bm_store): a same-site session cookie that pins the storefront slug you opted into so that navigating between <slug>.thebluemustard.com and the apex site keeps you inside the storefront experience you chose. - Tests portal cookie (
_bm_portal): a same-site session cookie that keeps you inside the dedicated assessments portal at tests.thebluemustard.com after you opt in. - Session and preference storage (via cookies and browser storage) to maintain your session state, cart contents, recently viewed items, dismissed banners, and locally saved search history.
8.2 Optional Analytics Cookies
When configured for a deployment, the Platform may load Google Analytics 4 and/or Meta Pixel scripts (see §7.1). Both are opt-in at the deployment level and no-op when unconfigured. Where they run, GA4 is initialised with anonymize_ip and Meta Pixel is initialised with a PageView event only. If the deployment you are using enables either provider and applicable law requires consent, we will surface a consent notice and honour your choice.
8.3 Managing Cookies
You can control and manage cookies through your browser settings. Disabling essential cookies may impair the functionality of the Platform, including your ability to log in, make purchases, receive live-session updates, or take a test.
9. Data Retention Policy
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law:
- Account Data: retained for as long as your account is active. “Delete account” in Settings deactivates (soft-suspends) your account rather than immediately erasing your data; a full deletion is completed on request as described in §12, subject to any legal retention obligations. A record of the deletion reason may be retained for dispute-resolution purposes.
- AI Assistant, AI-Tool & Connected-Channel Data: as described in §5.7, we do not currently run an automatic deletion process for assistant conversations, attachments, or connected-channel link records - they are retained for as long as the underlying account and store exist, and are deleted on request. Narrow, short-lived records tied to a single operation expire automatically: a connected-channel link code or a pending action confirmation is not usable beyond a short window measured in minutes and is purged from our systems within roughly a day of expiring; a record of a webhook event received from a connected channel (used only to avoid processing the same event twice) is purged within about three days. A record that a channel was ever linked - and, if applicable, later unlinked - is kept indefinitely as a record of the consent you gave and (if applicable) withdrew, in the same way we keep a record of other account actions.
- Transaction & Tax Records: retained for a minimum of 8 years from the date of the transaction, as required under Indian tax and financial regulations (including the Income Tax Act, 1961 and the Central Goods and Services Tax Act, 2017). This covers orders, payments, invoices, invoice lines, credit notes, refunds, and the billing audit log.
- Subscription & Entitlement Records: retained for the life of the subscription plus the tax retention period above. Usage events and per-period counters are retained for at least 24 months to support billing reconciliation.
- Digital Product Files: creator-uploaded product files are retained for as long as the product listing is active. Upon deletion of a product or store, the associated files are removed from our storage systems within a reasonable timeframe.
- Assessment & Candidate Data: tests, question banks, question versions, candidates, invitations, attempts, answers, results, and live-session messages are retained for as long as the owning store keeps them. Immutable question versions and results survive individual edits so historical reports stay reproducible. Soft-deleted tests and candidates remain in the recycle bin until the store owner permanently deletes them or a scheduled purge runs.
- Guest Purchase Data: email addresses and transaction records from guest purchases are retained for the duration required to fulfil download access (default 30 days for the download token) and to comply with legal and tax retention requirements. Once verified, a guest may create an account to permanently associate past guest purchases with a login.
- Guest OTP Records: the 6-digit code is stored only as a hash and is discarded on verification, expiry (default 3 minutes), or attempt-limit exceeded (default 3 attempts). Guest JWTs are short-lived (default 15 minutes) and are not stored server-side after issuance.
- Email Events, Bounces & Complaints: delivery, bounce, and complaint events are retained for up to 24 months so we can maintain a suppression list and protect deliverability.
- Audit, Activity & Billing Audit Logs: the audit log is append-only and retained indefinitely as a security and regulatory record. Activity logs are retained for up to 24 months. Impersonation-session records are retained for at least 24 months.
- Technical Logs: server logs and usage data are retained for up to 12 months for security, analytics, and troubleshooting purposes, after which they are anonymised or deleted.
10. Data Security Measures
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption in transit: all data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS/HTTPS). Realtime traffic uses Secure WebSockets (WSS).
- Encryption at rest: data stored in our managed PostgreSQL database and file storage systems is encrypted at rest using industry-standard algorithms.
- Secure authentication: user authentication is handled by Clerk, which implements multi-factor authentication (opt-in), secure password hashing, and brute-force protection. Server-side session verification runs on every authenticated request.
- Guest OTP security: guest one-time passwords are stored only as hashes, are single-use, expire quickly, and are rate-limited per identifier.
- Access controls: access to personal data is restricted to authorised personnel on a need-to-know basis. The Platform implements a layered RBAC model with platform-owner emails, admin roles / permissions, and per-store roles for team members. Every sensitive administrative action passes through the immutable audit log.
- AI action controls: the AI assistant and any connected channel act only within the permissions of the person who authorised them, recomputed on every request rather than cached indefinitely; certain high-impact permissions (deleting or transferring a store, billing management, team/role management, live proctoring control) can never be delegated to the assistant or a connected channel at all; and higher-risk actions require your explicit, single-use confirmation, bound to the exact action proposed, before they run. See §5.4.
- Prompt-injection safeguards: when the AI assistant reads content that did not come directly from you - such as an uploaded document or the result of a tool call against your store’s own data - that content is marked internally as data to be read, not as an instruction to follow, so that text embedded in a file or a record cannot impersonate you and direct the assistant to do something you did not ask for.
- Signed URLs: digital product files, cover images, sample images, candidate photographs, assistant attachments, and bulk-import spreadsheets on Amazon S3 are protected with private access controls and time-boxed pre-signed URLs (default 15-minute expiry) so files are downloadable only by authorised users during a short window.
- PCI-DSS compliance: payment processing is handled by Razorpay, which is PCI-DSS Level 1 certified, ensuring the highest level of security for payment data.
- Webhook signature verification: incoming Clerk webhooks are verified using svix signatures and incoming Razorpay webhooks are verified using a per-endpoint shared secret before any state change occurs. Incoming events from a connected channel are verified using that channel provider’s own webhook authentication mechanism before we act on them.
- Rate limiting & kill switches: per-IP, per-route rate limits (short/medium/long windows) protect against abuse, and the AI assistant and any connected channel carry additional, dedicated limits (per account, per conversation, and on the channel’s inbound webhook). Platform-owner kill switches let us pause outbound email, block a compromised store or product, or freeze a specific capability without a code deploy; the switch that currently governs AI-assisted assessment features is shared with assessment operations generally rather than being AI-specific (see §5.6).
- Continuous review: we conduct regular security reviews, dependency audits, and apply timely security patches to our systems.
While we take all reasonable precautions to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents in accordance with applicable laws.
11. International Data Transfers
Our own infrastructure - servers, database, and file storage - is hosted in India. However, some of the service providers described in §7.1 are based outside India and process data on servers located outside India, meaning your data may be transferred internationally in the following circumstances:
- AI model providers: when you use an AI feature described in §5, the data sent to the AI provider processing that request (OpenAI, Anthropic, and/or DeepSeek, depending on what is configured - see §5.2 and §7.1) is transmitted to and processed on that provider’s own infrastructure, which is located outside India.
- Clerk: our authentication provider processes your account and session data on its own infrastructure, which is located outside India.
- Telegram: if you connect Telegram (§2.13), messages exchanged over that channel pass through Telegram’s own infrastructure, located outside India.
Where we transfer personal data outside India, we rely on the relevant provider’s own security and contractual commitments, and, where applicable, standard contractual or equivalent safeguards. We have not represented anywhere in this Policy that any specific data-processing activity is confined to India except where we host the infrastructure ourselves, and we do not claim a specific alternative safeguard (such as a particular standard-contractual-clause mechanism) is in place unless we have confirmed it with the relevant provider.
12. User Rights
In accordance with applicable Indian data-protection laws and principles, you have the following rights with respect to your personal data:
- Right to access: you may request access to the personal data we hold about you. You can view and update most of your personal information through your account settings on the Platform, and export a copy of your account and creator data through Settings → Export data. That export currently covers your profile, settings, stores, orders, and licenses; it does not yet include AI assistant conversations, attachments, or connected-channel data - to receive a copy of that data, contact us using the details in §17.
- Right to correction: you may request correction or updating of any inaccurate or incomplete personal data we hold about you.
- Right to deletion: you may request deletion of your personal data from our systems, subject to any legal or contractual retention obligations. You can deactivate your account from Settings → Delete account (which deactivates the account; see §9), or, for a full deletion request - including deletion of AI assistant conversations, attachments, or connected-channel records - contact us at support@thebluemustard.com or hi@imanveer.com. Records required to be retained under tax and financial regulations (see §9) will be kept for the mandated period even after account deletion.
- Right to withdraw consent: where we process your data based on your consent, you may withdraw that consent at any time by contacting us. If you have linked a connected channel such as Telegram, you may unlink it and revoke its access at any time from the Platform’s channel settings, which takes effect immediately. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
- Right to data portability: you may request a copy of your personal data in a structured, commonly used, and machine-readable format. The self-serve data export in Settings covers the majority of this data, subject to the AI-data scope note above.
- Right to raise a grievance: if you have any concerns regarding the processing of your personal data, you may raise a grievance with our Grievance Officer (details provided in §15 below).
Candidate-specific rights: if you were assigned an assessment or added as a candidate by a creator, the creator is the primary data fiduciary for that candidate profile - including for any AI-suggested mark or summary a reviewer at that store has seen about your attempt. Requests to correct, delete, or export candidate data are normally routed to the owning creator; you may also contact us and we will facilitate the request with the creator on your behalf.
To exercise any of these rights, please contact us at support@thebluemustard.com or hi@imanveer.com. We will respond to your request within 30 days of receipt.
13. Children’s Privacy
The Platform is not intended for use by children under the age of 13 years. We do not knowingly collect personal data from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take immediate steps to delete such information from our servers.
Users between the ages of 13 and 18 may use the Platform only with the verifiable consent and supervision of a parent or legal guardian. Creators who use the Platform to assess minors (for example: schools running exams) must obtain the required parental or guardian consent under applicable Indian law before uploading candidate data or administering an assessment, and remain the data fiduciary for that data - including for any decision to use an AI-assisted evaluation or summarisation tool (§5) on a minor candidate’s attempt, or an AI resume-analysis tool on a minor applicant’s resume. If you are a parent or guardian and believe that your child’s personal information is being processed on the Platform - including through an AI feature - without your consent, please contact us immediately at support@thebluemustard.com or hi@imanveer.com.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or business operations - including as our AI features, the AI providers we use, or our data-retention and metering practices for those features change or become more definitively confirmed. When we make changes:
- The revised Privacy Policy will be posted on this page with an updated “Last updated” date at the top.
- For material changes that significantly affect how we handle your personal data, we will endeavour to notify you via email or a prominent notice on the Platform prior to the changes taking effect.
- Your continued use of the Platform after the updated Privacy Policy is posted constitutes your acceptance of the revised policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
15. Third-Party Links and Services
The Platform may contain links to third-party websites, services, or resources that are not owned or controlled by TheBlueMustard - including links a creator adds to their store, product page, or assessment instructions, and including any AI-generated content that references or summarises material you supplied. This Privacy Policy applies only to our Platform. We are not responsible for the privacy practices, content, or security of any third-party websites or services. We encourage you to review the privacy policies of any third-party services you access through the Platform.
16. Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules framed thereunder, the details of our Grievance Officer are as follows:
- Name: Grievance Officer, TheBlueMustard
- Email: support@thebluemustard.com, hi@imanveer.com
- Response Time: we acknowledge grievances within 24 hours and endeavour to resolve them within 30 days of receipt.
17. Contact Details
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
- Business Name: TheBlueMustard
- Website: thebluemustard.com
- Email: support@thebluemustard.com, hi@imanveer.com
- Response Time: we endeavour to respond to all enquiries within 24–48 hours on business days.
Related: Terms and Conditions, FAQ, Contact Us.