Who is responsible for your data
Comeback Academy operates the Comeback Academy service. For privacy, correction, access, or deletion questions, email support@comebackacademy.live. Please do not send passwords, OTPs, payment credentials, CAPTCHA responses, or full result records.
Data we collect and why
- Account data: Firebase user ID, email address, verification state, display name, and identity-provider profile data for authentication and account management.
- Academic preferences and learning activity: batch, branch, semester, bookmarks, note/course progress, entitlements, and resource actions to personalize and synchronize learning access.
- Search: search text and filters are sent to the API to return results. Search text is not intentionally attached to analytics events; infrastructure security logs may process request metadata for a limited operational period.
- Individual result lookup: the registration number and selected examination are transmitted only after a user requests a lookup. A keyed, non-readable lookup value and the returned result may be cached for up to 30 days. CAPTCHA answers, BEU tokens, cookies, and sessions are transient and are not intentionally persisted.
- Orders and access: order references, Razorpay payment references, amount, status, resource, access period, and entitlement history are used for payment reconciliation, access delivery, disputes, fraud prevention, and accounting. Comeback Academy does not store full card, bank-account, UPI PIN, or wallet credentials.
- Device and notification data: a one-way installation identifier, platform, Firebase installation information, notification token, and device access state support the one-device rule, security, and announcements.
- Diagnostics and analytics: Firebase Analytics receives limited app interaction categories. Firebase Crashlytics receives crash, device, OS, and diagnostic information. We prohibit sending emails, registration numbers, result fields, payment credentials, protected URLs, or authentication tokens in these events.
- Support: messages and identifiers you voluntarily provide are used to investigate and respond to the request.
Service providers and external sources
Data is processed only as needed by Firebase Authentication, App Check, Analytics, Crashlytics, Cloud Messaging, the hosting and PostgreSQL providers, Cloudflare R2, Razorpay, and support/monitoring providers configured for the service. YouTube processes course video playback under its own terms. Individual result lookup communicates with Bihar Engineering University (BEU). Comeback Academy is independent and is not affiliated with or endorsed by BEU. The official university source is https://beu-bih.ac.in/.
Advertising and identifiers
The Android app does not display advertising, use an advertising SDK, or intentionally collect the Android Advertising ID. Advertising-ID collection and ad-personalization signals are disabled in the Android release manifest.
Security
Production traffic uses HTTPS. The service uses Firebase authentication, server-side authorization, App Check/Play Integrity where available, access controls, input validation, rate limits, short-lived protected-content URLs, encrypted provider connections, and sensitive-log redaction. No internet service can promise absolute security.
Retention
- Result-cache entries expire after 30 days; CAPTCHA and upstream session data are transient.
- Bookmarks, progress, device records, and profile data are removed on account deletion.
- Orders, payment events, and the minimum de-identified entitlement history required for accounting, tax, disputes, fraud prevention, and legal compliance are retained only for the applicable statutory or dispute period.
- Security, diagnostic, support, and backup records expire according to the configured provider retention schedule and operational or legal need.
Account and data deletion
Signed-in users can select Profile → Delete Account in the Android app. This deletes the Firebase sign-in identity and removes or de-identifies the profile, academic preferences, bookmarks, progress, device registration, active access, and managed local files. Legally required transaction records are separated from the identity and kept without the email or display name. Users without the app can use the public account-deletion request page.
Your choices
You may use public catalog and individual result lookup features without an account, disable announcement notifications in the app or system settings, remove local downloads, request correction, or delete your account. Generated result PDFs stay on-device unless you choose a save or share destination.
Changes to this policy
Material changes will be reflected here and in the in-app policy with a revised effective date. Continued use after an update is subject to the updated policy and applicable law.