Last updated: 6 August 2026 · Version 3
Project Sahitya (“we,” “us,” “our”) is a nonprofit early-literacy programme. This policy explains what personal data we collect, why, who else touches it, how long we keep it, and what you can make us do about it.
It covers everything we run: the website at projectsahitya.org, the School Portal at projectsahitya.org/portal, the WhatsApp teaching service that delivers daily lessons to registered schools, the printable toolkit packs, the newsletter, and the certificate check at /verify.
We are the data fiduciary (under India's Digital Personal Data Protection Act, 2023) and the data controller (under the UK and EU GDPR) for that data. Where a school collects information about its own children and gives it to us, we act on that school's instructions for that part — and we hold ourselves to this policy either way.
The short version
- We have never sold personal data and we never will.
- We do not advertise, and we run no advertising or tracking pixels.
- We do not use anyone's personal data — least of all a child's — to train AI or machine-learning systems.
- We collect children's data from their school, never from the child, and never without the guardian consent the school holds.
- Children's names are encrypted before they are stored. Photographs live in a private store and are never published without consent on file for that child.
- You can ask us what we hold, ask us to fix it, or ask us to delete it. Write to inquiries@sahitya.org.in and we answer within 30 days.
This summary is for orientation. The sections below are the policy.
1. What we collect, and from whom
What we hold about you depends entirely on which of these you are. Most visitors to this website are in the first group only.
a. Anyone who visits the website
- Security and abuse-prevention data: your IP address is used at the edge to rate-limit requests and block abuse. Where we record it at all — in our audit trail or a cookie-consent receipt — it is hashed with SHA-256 and truncated first, so the stored value cannot be reversed back to your address.
- Browser information: user-agent string, stored alongside a cookie consent receipt.
- Aggregate analytics: page views and referrers via Cloudflare Web Analytics, which sets no cookies, writes no client-side state, and does not identify or follow individual visitors.
b. Newsletter subscribers
- Your email address, and the date you subscribed or unsubscribed.
- A Cloudflare Turnstile verification signal, used once to establish you are not a bot.
- Delivery outcomes reported back by our email provider — whether a message was delivered, bounced, or marked as spam — so we stop emailing addresses that do not want us.
c. Schools that apply to register
Applications are submitted through a Google Form embedded on our partner and volunteer pages. Responses land in a Google Sheet owned by Project Sahitya. For schools we take forward, we transfer the details into our own database, where they become the school record. We collect:
- Contact name, email address and WhatsApp number.
- School name, country, and language of instruction.
- How many children and teachers the programme would reach, whether the school can print, and the date it hopes to start.
- Anything else you choose to write in a free-text answer.
Please do not put children's names into an application form. We do not need them at that stage, and we will delete them if you do.
d. Teachers at registered schools
- Name, WhatsApp number, preferred language, and which school you teach at.
- Messages exchanged with our WhatsApp service: the lessons we send, your replies, the buttons you tap, and the delivery receipts Meta returns (sent, delivered, read, failed). This is how the service works — it is a conversation, and a conversation is a record.
- Which lessons were delivered on which day, attendance you report, and any rating you give a lesson.
- Whether you are active. Replying STOP deactivates you immediately and we stop sending; START reverses it.
e. Children taught through the programme
This is the data we are most careful with. It is collected by the child's own teacher, on the basis of the guardian consent the school holds — never by us, and never from the child directly.
- The child's name, encrypted at rest with AES-256 before it is written to the database.
- Date of birth and gender.
- Screening responses and scores across letter recognition, phonemic awareness, sight reading and engagement.
- A literacy level, calculated by a fixed arithmetic rule (see section 12), and the lesson sequence linked to it.
- Attendance, progress over time, and re-assessment records.
- The consent record itself — that consent exists, and when it was given.
f. Photographs, videos and guardian consent forms
- Proof-of-teaching media: registered schools send us photographs of lessons happening, over WhatsApp. These may show children. They are stored in a private object store that is not publicly readable, and every one arrives marked unreviewed and unpublished.
- Guardian consent scans: schools upload the signed forms through the School Portal, filed under a label the school chooses (“child 14”) rather than the child's name. These are stored privately and are visible only to the school that filed them and to us.
- A safeguarding acknowledgement naming the person at the school who accepted our child-protection terms, and the version they accepted.
g. Reading tallies
Once a term, a school sends four numbers describing how many children are at each reading stage. These are aggregate counts only. There is no child-level column and we never ask for one.
h. Volunteers and certificate holders
- Name, email address, role, and the date a certificate was issued.
- We store the inputs used to render your certificate rather than the PDF itself, so it can be re-issued identically.
- Public by design: anyone who has your certificate number can look it up at /verify and will see the name on it, the role, and the issue date. That is the point of a verifiable certificate. Tell us if you would rather not be verifiable and we will revoke the number.
i. Administrators and portal users
- Staff accounts: email address, a password hash held by our authentication provider (we never see or store the password), and session cookies.
- An audit trail of administrative actions — who did what, to which record, when — with the actor's IP address hashed, not stored.
- School Portal access uses a signed session cookie tied to your school's application, valid for about 30 days and revocable by us at any moment. There is no password and no school identifier the browser can tamper with.
2. What we never do
- We do not sell, rent, or trade personal data. Not to funders, not to researchers, not to anyone, at any price.
- We run no advertising. There are no ad networks, no marketing pixels, and no cross-site profiling by us. The only third-party content on the site is the occasional embedded Instagram post — it loads only if you accept cookies, and section 6 explains exactly what that means.
- We do no behavioural tracking or targeted advertising directed at children — prohibited by Section 9 of the DPDP Act, and something we would not do regardless.
- We do not use personal data to train AI or machine-learning models, and we do not send it to a third-party AI service. The literacy scoring is arithmetic, not a model.
- We do not publish a photograph of a child without the guardian consent for that child on file.
3. Why we are allowed to hold it
Under the DPDP Act 2023 we rely on:
- Consent (Section 6) — for newsletters, applications, and every photograph of a child. Consent is asked for in plain words, is specific, and can be withdrawn at any time without penalty.
- Verifiable guardian consent (Section 9) — for anything concerning a child. It is obtained by the school from the parent or guardian, recorded, and can be revoked, after which we stop.
- Legitimate uses (Section 7) — replying to an enquiry you sent us, and meeting legal obligations.
If the UK or EU GDPR applies to you, the corresponding lawful bases are:
- Consent (Art. 6(1)(a)) — newsletter, cookies beyond the strictly necessary, publication of images.
- Contract (Art. 6(1)(b)) — running the programme for a school that has registered with us.
- Legitimate interests (Art. 6(1)(f)) — keeping the service secure, preventing abuse, and keeping an audit trail. We have balanced these against your rights and will share that assessment on request.
4. What we use it for
- Delivering the daily lessons, the toolkit and the portal to registered schools.
- Working out which lesson a child needs next, and noticing when a child is not progressing so a human can look at it.
- Knowing that teaching is actually happening, so we can help a school that has gone quiet before it gives up.
- Answering you when you write to us.
- Sending the newsletter, to people who asked for it.
- Reporting our impact — always as aggregate numbers, or with named, specific consent.
- Keeping the service secure, and meeting our legal and safeguarding obligations.
We will not use your data for a new and unrelated purpose without telling you first and, where the law requires it, asking again.
5. WhatsApp, specifically
The teaching service runs over the WhatsApp Business Cloud API, operated by Meta. Three things follow from that and you should know all of them:
- Meta processes the messages. Your phone number and the content of the conversation pass through Meta's systems and are handled under Meta's own terms and privacy policy, in addition to ours.
- The messages stay on your phone until you delete them there. We cannot delete them from your device.
- You can stop it in one word. Reply STOP at any time. Sending ends immediately and we confirm it. Ask us and we will delete your teacher record entirely.
We hold the messages we sent and received in our own database so that delivery problems can be diagnosed and so a school's history is not lost when a phone is.
6. Cookies
On your first visit a banner lets you accept all cookies or keep to the necessary ones only. Your choice is recorded — including a hashed IP and your user agent — as proof of consent.
Strictly necessary (always active):
- Authentication session cookies (sb-*): keep an administrator signed in.
- School Portal session cookie: a signed token identifying your school for about 30 days. Without it the portal cannot know who you are.
- Cloudflare cookies (__cf_bm, __cflb): bot protection, security and load balancing.
- Cloudflare Turnstile (cf_clearance): CAPTCHA verification on forms.
- Your cookie preference (sahitya-cookie-consent): stored in localStorage so we do not ask again.
- Instagram embeds (cookies set by instagram.com): some pages feature posts and reels from our Instagram account. The post is served by Meta, which sets its own cookies and can see your IP address and which page you are on. Nothing from Instagram loads until you choose "Accept All". If you decline, you get a placeholder instead, and clicking it loads that one post and nothing else.
Cookie-free analytics: Cloudflare Web Analytics measures page views without cookies, without client-side storage and without identifying individuals.
We set no advertising, marketing or cross-site tracking cookies of our own. Embedded Google Forms are served by Google, and embedded Instagram posts by Meta; both are subject to their own cookie practices.
7. Who else touches your data
We keep this list short on purpose. Each of these is a processor acting on our instructions, under a contract, and none of them is permitted to use your data for their own purposes.
- Cloudflare — application hosting (Workers), CDN and DNS, DDoS protection, rate limiting, Turnstile CAPTCHA, cookie-free analytics, and R2 object storage for media. Globally distributed.
- Supabase — PostgreSQL database and administrator authentication, hosted on AWS in the United States (Virginia).
- Meta Platforms — WhatsApp Business Cloud API. Processes teacher phone numbers and message content to deliver the service. Meta also serves the Instagram posts embedded on some pages, but only after you accept cookies.
- Resend — transactional and newsletter email delivery. United States.
- Google — Google Forms and Sheets for applications, and Google Workspace for our mailbox. United States and globally.
Beyond these, we disclose personal data only where we are legally compelled to, or to protect a child from harm. If we are served with a legal demand for your data we will tell you, unless we are prohibited by law from doing so.
If Project Sahitya ever merges with or transfers its programme to another organisation, personal data would move only to a body bound by terms at least as protective as these, and we would notify affected people first.
8. Data leaving India
Some of the providers above hold data outside India — principally our database and email delivery, in the United States, and Cloudflare's global edge network. Registering a school outside India means that school's data is processed across borders by design.
Every transfer is made under a written contract with the provider containing data protection terms, and, where the GDPR applies, on the basis of the European Commission's Standard Contractual Clauses or an adequacy decision. We monitor notifications under Section 16 of the DPDP Act restricting cross-border transfer of children's data, and will move that processing to Indian infrastructure if and when the law requires it.
9. How long we keep things
- Newsletter subscription: until you unsubscribe. Your address is then kept on a suppression list for 1 year so we cannot accidentally re-add you.
- Cookie consent receipts: 1 year.
- Administrative audit logs: 2 years, then deleted. They contain hashed IPs and record identifiers, never a child's name.
- School applications: for schools we register, as long as the school is in the programme. For applications we do not take forward, 12 months, then deleted.
- Teacher records and message history: while the teacher is active, and for 12 months after they leave or reply STOP, so a school returning after a break does not start from nothing. Deleted sooner on request.
- Children's screening and progress data: for as long as the school is running the programme, and deleted on request from the school or a guardian. Consent records are kept for 3 years as evidence that consent existed.
- Photographs and consent scans: until the school leaves the programme or consent is revoked, then deleted from storage along with the record that pointed at them.
- Certificates: kept indefinitely so they remain verifiable, unless you ask us to revoke and erase yours.
- Email you send us: retained under our mailbox policy. Deleted on request.
Where we are required to keep something longer — a legal, audit or safeguarding obligation — we keep only that, and only for as long as the obligation lasts.
10. How we protect it
- Everything is transmitted over HTTPS with TLS.
- Children's names are encrypted with AES-256 before being written to the database, so a database copy alone does not reveal them.
- Photographs and consent scans are held in a private bucket with no public URL, and are served only to an authenticated request that has been checked against the school that owns them.
- IP addresses are hashed before being written to our audit trail or consent records.
- Access to production data is limited to a small number of named administrators and to the application's own service credentials. Administrative actions are logged.
- Passwords are hashed by our authentication provider and never stored in plain text or visible to us.
- Rate limiting, CAPTCHA, signed webhooks and security headers guard the public surface against abuse.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data we will notify the Data Protection Board of India and every affected person without undue delay, and — where the GDPR applies — the relevant supervisory authority within 72 hours. We will tell you what happened, what we know, and what to do about it, in plain language.
11. Children
Our work is with children aged roughly 5–10. Section 9 of the DPDP Act sets a high bar for their data and we treat it as a floor, not a ceiling.
- We never collect data directly from a child. Our website, portal and WhatsApp service are for adults — teachers, school staff and volunteers.
- A child's data reaches us only through their school, which must hold the parent or guardian's consent before it does.
- No tracking, no profiling, no advertising is directed at children, ever.
- Names are encrypted; photographs are private and unpublished by default; reading tallies are aggregate counts with no child-level detail.
- A guardian can revoke consent at any time, through the school or directly to us. Publication stops immediately and the material is removed from anywhere it appears; the stored copy is deleted when we process the erasure, which we complete within 30 days.
- Anonymised, aggregated data may be used in research — only with the school's agreement, and only in a form from which no child can be identified.
If you believe we hold data about a child that we should not, write to us and say so. That request goes to the top of the queue.
12. Automated decisions and profiling
A child's literacy level is calculated by a fixed, published arithmetic rule applied to the answers a teacher records. There is no AI, no machine-learning model, and no profiling. The same answers always produce the same level, and we can show any school exactly how a level was reached.
The level decides only which lesson comes next. It does not decide eligibility, access, funding or anything else about a person, and a teacher or our staff can override it. We make no decision producing legal or similarly significant effects by automated means alone.
13. Your rights
Whoever and wherever you are, you can ask us to:
- Tell you what we hold about you and how it is being used (DPDP s. 11; GDPR Art. 15).
- Correct or complete it if it is wrong (DPDP s. 12; GDPR Art. 16).
- Delete it, subject only to what we are legally required to keep (DPDP s. 12; GDPR Art. 17).
- Withdraw consent, as easily as you gave it (DPDP s. 6; GDPR Art. 7(3)). Withdrawal does not undo processing that was lawful before it.
- Complain, and get an answer within 30 days (DPDP s. 13).
- Nominate someone to exercise your rights if you die or become incapacitated (DPDP s. 14).
If the UK or EU GDPR applies to you, you also have the right to:
- Restrict processing while a dispute about your data is resolved (Art. 18).
- Object to processing based on legitimate interests, and object absolutely to direct marketing (Art. 21).
- Receive your data in a structured, machine-readable format, and have it sent to another organisation (Art. 20).
- Not be subject to solely automated decisions with legal or similar effects (Art. 22) — we make none.
14. How to exercise them
Email inquiries@sahitya.org.in with “Data Rights Request” in the subject line. Tell us your name, the email address or phone number the data sits under, and what you want done. For the newsletter you do not need to write at all — the unsubscribe link in any email is immediate.
We will verify who you are before acting, because acting on a forged request would itself be a breach. Then we will do it, free of charge, within 30 days. If we cannot do all of it, we will tell you which part and exactly why. There is no fee, and asking costs you nothing in service.
A school can exercise these rights on behalf of the children it has registered, and a parent or guardian can come to us directly.
15. If we get it wrong
Start with our Grievance Officer, below. We acknowledge within 24 hours and resolve within 30 days.
If our answer does not satisfy you, you can escalate:
- India: the Data Protection Board of India, established under the DPDP Act 2023.
- United Kingdom: the Information Commissioner's Office (ICO).
- European Union: the supervisory authority in your country of residence.
You do not need to go through us first, but it is usually faster if you do.
16. Changes to this policy
We update this page when our practices change. When we do, we change the “Last updated” date and the version number at the top. For material changes we also email newsletter subscribers, message registered schools, and put a notice on the site. If a change affects the basis on which we hold your data, we ask for consent again rather than assume it.
We do not apply changes retroactively to make previously unlawful processing lawful.
17. Contact
Grievance Officer (DPDP Act 2023, Section 13 & IT Rules 2011, Rule 5(9))
Name: Yashwardhan Saraf
Role: Grievance Officer and data protection point of contact
Email: inquiries@sahitya.org.in
Acknowledgement within 24 hours; resolution within 30 days of receipt. As a small nonprofit we are not required to appoint a formal Data Protection Officer under the DPDP Act, and this is the named person who does the job.
See also our terms of service and the toolkit licence.