Legal

Privacy Policy

Nybble collects as little as it can and never sells your data. This page sets out exactly what we hold, why we hold it, who else processes it, and how to get it changed or deleted.

Last updated: 31 July 2026

1.Who is responsible for your data

Nybble, operated at getnybble.com as a sole proprietorship based in India, is the data fiduciary (data controller) for the personal data described here. For any privacy question, request, or complaint, write to bytes@getnybble.com. Our operations are based in Nagpur, Maharashtra, India.

2.What we collect

If you only read Snack, signed out

No account, no sign-in, no personal data. You are counted in the aggregate analytics described below and nothing else.

If you sign in

  • Account details from Google. When you sign in with Google we receive your email address, name, profile picture, and Google account identifier. We do not receive your Google password and we have no access to your Gmail, Drive, contacts, or any other Google service.
  • Profile details you give us. Anything you set on your profile, such as your display name and preferences.
  • Learning activity. Which Snack items and Stack explainers you have read, your Hack quiz answers and scores, and when each happened.
  • Progress records. Your bit balance and the ledger of how it was earned, your badges, your unlocks, and your current and longest streak.
  • Your time zone. Derived from your browser so that daily streaks roll over at midnight where you are rather than in some other part of the world.
  • Certificates you claim. The assessment it relates to, your score, and the date it was issued.

If you subscribe to a paid plan

We store a record of your subscription: which plan, its status, when the current period starts and ends, and the payment and subscription identifiers issued by Razorpay, our payment processor. We share your email address with Razorpay so it can raise the mandate and send you payment receipts.

Your card, UPI, and bank details are entered on Razorpay’s side and are never seen or stored by us. What we receive back is confirmation of whether a payment succeeded, never the instrument used.

Analytics, for everyone

We use Vercel Analytics and Vercel Speed Insights to understand which pages are used and how fast they load. These are privacy-first products: they do not set cookies, do not track you across other websites, and do not build a profile of you. They record page views and coarse technical details such as browser type, device type, referring page, and country-level location, in aggregate.

If you contact us through the in-app form

We store the message you wrote, the email address you provided (or the one on your account if you were signed in), and a one-way hash of your IP address that we use only to rate-limit abusive submissions. The raw IP is never stored. We use this record to reply to you and to keep track of what needs fixing.

What we never collect

We do not ask for or store payment card, UPI, or bank details, government identifiers, precise location, or any special category data. Nybble does not build its own marketing profile of you, and we do not show ads. Section 11 covers cookies, including one third-party script that is present on the site but serves nothing today.

3.Why we use it

  • To create your account and sign you in, and to show your name and picture in the interface.
  • To keep your place: reading history, quiz results, and the progress that makes Stack and Hack useful across sessions.
  • To run bits, badges, streaks, and leaderboards, including the daily caps and freezes that make the system fair.
  • To take payment, manage your subscription and its renewal, issue receipts, and handle cancellations and refunds.
  • To issue certificates you ask for and to answer verification requests from anyone you share one with.
  • To operate, secure, and debug the service, and to prevent abuse.
  • To understand aggregate usage so we can decide what to build next.
  • To meet legal obligations and to establish or defend legal claims where necessary.

We process this data on the basis of your consent, given when you sign in, and because it is necessary to provide the service you asked for. You can withdraw consent at any time by deleting your account, as described in section 6.

We do not sell your personal data, rent it, or share it with data brokers, we do not hand it to advertisers, and we do not use it to train AI models.

4.Who else processes it

We use a small number of service providers to run Nybble. Each processes data only on our instructions.

  • Supabase — database and authentication. Holds your account and all progress data.
  • Vercel — hosting for the website, plus the analytics and speed measurement described above.
  • Railway — hosting for our backend API, which processes requests in transit.
  • Google — sign-in only, through Google OAuth, when you choose to use it.
  • Razorpay — payment processing for paid plans, if you subscribe. Razorpay receives your email address and collects your payment details directly, under its own privacy policy, and is regulated as a payment processor in India.
  • Google AdSense — a publisher script that is loaded on the site but is not currently showing ads. While it loads, Google may set or read cookies and device identifiers (see section 11).

We also use OpenAI and Google Gemini to help write and edit the news summaries and explainers we publish. These tools process public articles and our own editorial material. Your personal data and your learning activity are never sent to them.

We may also disclose data where we are legally required to, or to protect the rights, safety, or property of Nybble or its users.

5.Data that becomes public or visible to others

Most of what we hold is private to you. Three things are not, and you can control each of them. None of them ever exposes your email address in full, your quiz answers, your bit balance, or your reading history.

Badge pages

When you earn a badge, a public page for it is created automatically at getnybble.com/badge. This is on by default. The page is reachable by anyone who has its link, may be indexed by search engines, and generates a preview image for social platforms. It shows your display name, the badge, and the date you earned it. The link is not announced anywhere — it is there for you to share if you want to — but it is publicly reachable whether or not you share it.

To turn this off, use the public badge pages setting on your profile. Switching it off makes all of your badge pages return “not found” immediately, including any you have already shared. You can also email bytes@getnybble.com and we will do it for you.

Certificates and their verification pages

A certificate is a credential, so it is only worth anything if a stranger can check it. Claiming one publishes a page at getnybble.com/certificate and a verification record that anyone with the certificate ID can look up without an account. These show your display name, what was certified, your score, the issue date, and a masked version of your account email — enough to tie the credential to you, not enough to contact you.

This is the point of the feature, so there is no switch for it: nothing is published until you choose to claim a certificate. If you need one taken down, email bytes@getnybble.com and we will revoke it.

Weekly leaderboards

If you take part in the weekly leaderboards, the other members of your cohort — around thirty accounts — can see your display name, your equipped profile flair, and the bits you earned that week. This is not a public web page and is not indexed; it is visible to signed-in members of your cohort.

Taking part is on by default and you can leave at any time from the league card on your profile, which removes you from the standings.

For anything published to the open web, note that search engines and social platforms may keep cached copies for a period after removal, which is outside our control.

6.Your rights

You can, at any time:

  • Access the personal data we hold about you, and receive a copy of it.
  • Correct anything inaccurate or incomplete, from your profile page or by writing to us.
  • Delete your account and the personal data attached to it.
  • Withdraw consent to our processing, which for a service like this means closing your account.
  • Complain to us, and to the Data Protection Board of India if you are not satisfied with our response.

To exercise any of these rights, including deleting your account, email bytes@getnybble.com from the address on your account. We will respond within 30 days and will not charge you for a reasonable request. We may ask you to confirm your identity before we act.

If you are in the EU or UK, you also have the right to object to processing, to request restriction, and to data portability, and you may complain to your local supervisory authority.

7.How long we keep it

  • Account, profile, and progress data: for as long as your account is open.
  • After you delete your account: your profile, reading history, quiz answers, bit ledger, badges, unlocks, and league standings are deleted within 30 days, and your badge and certificate pages stop resolving.
  • Billing and payment records: kept for as long as tax and accounting law in India requires us to keep them, even after an account is deleted. These are transaction records rather than learning data, so we cannot delete them on request.
  • Backups: deleted data may persist in encrypted backups for up to 90 days before those backups are rotated out.
  • Aggregate analytics: retained on an ongoing basis, but these contain no information that identifies you.
  • Records we are required to keep by law are kept for the period the law requires.

8.Where your data is held

Our service providers operate globally and your data may be stored or processed outside India, including in the United States and the European Union. We rely on our providers’ contractual safeguards, including standard contractual clauses where applicable, to protect it in transit and at rest.

9.Security

Traffic is encrypted in transit with TLS. Authentication uses signed tokens rather than passwords we hold, and database access is restricted per user by row-level security so that one account cannot read another’s data. No system is perfectly secure, and we cannot guarantee absolute security, but if a breach affects your personal data we will notify you and the Data Protection Board of India as the law requires.

10.Children

Nybble is intended for users aged 13 and over and is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has given us personal data, email bytes@getnybble.com and we will delete it.

11.Cookies and advertising

For the core service we use only what is strictly necessary: authentication cookies set by Supabase that keep you signed in, and local storage on your device that remembers interface preferences. Our own analytics (Vercel) are cookieless. None of this profiles you or tracks you across other sites, and none of it is set unless you sign in or change a setting.

Advertising. Nybble does not show ads. There are no ad slots anywhere in the product, and none inside quizzes, streaks, or badges. We are not funded by advertising, and if that changes we will update this page and say so on the site before any ad appears — and subscribers will not be shown ads.

One detail we would rather state than leave out: Google’s AdSense publisher script is loaded on the site while our AdSense account is under review, because Google requires it to be present to verify the site. It is not displaying any ads and no ad slots exist for it to fill, but while it loads Google may set or read cookies and similar identifiers on your device. It is the only third-party script here that touches cookies, and this is the section we will update if that ever changes.

Your choices. You can turn off personalised advertising across Google’s products through Google My Ad Center or aboutads.info, and you can read how Google uses cookies in advertising. Clearing your browser cookies and storage resets these choices and signs you out.

12.Changes to this policy

We will update this page when our practices change. The date at the top always reflects the current version. If a change materially affects how we use your personal data, we will give notice on the site or by email before it takes effect.

If Nybble is later incorporated as a company, or the business is reorganised, merged, or sold, personal data may transfer to the successor entity, which will remain bound by a policy at least as protective as this one. We will tell you if that happens.

13.Contact and grievances

For any privacy question, request, or grievance, contact our grievance officer at bytes@getnybble.com. We acknowledge grievances within 7 days and aim to resolve them within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.