Legal

Privacy Policy - GoStuds

How Outnext Private Limited (operating GoStuds) collects, uses, stores, shares, and protects your personal data, and the rights you have under the Digital Personal Data Protection Act, 2023.

Last updated: 17/06/2026

1. Introduction and Data Fiduciary

This Privacy Policy ("Policy") describes how Outnext Private Limited ("Outnext", "Company", "we", "us", or "our"), the operator of the GoStuds platform ("GoStuds", "Platform", or "Service"), collects, uses, stores, shares, and otherwise processes personal data of users ("you", "your", or "Data Principal").

For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made thereunder, Outnext Private Limited is the "Data Fiduciary" with respect to the personal data processed in connection with the Platform.

Registered Entity: Outnext Private Limited, a company incorporated under the laws of India, having its registered office at Nathawatpura, Sikar, Rajasthan – 332001, India.

By accessing, registering for, or using GoStuds, you confirm that you have read, understood, and agreed to this Policy. If you do not agree with any part of this Policy, you must not use the Platform. This Policy is a legally binding document and forms an integral part of our Terms of Service.

2. Definitions

In this Policy, the following terms have the meanings set out below; capitalised terms not defined here have the meanings given in the Terms of Service or under applicable law.

  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
  • "Processing" means any wholly or partly automated operation or set of operations performed on Personal Data, including collection, recording, organisation, structuring, storage, use, disclosure, erasure or destruction.
  • "Data Principal" means the individual to whom the Personal Data relates.
  • "Data Fiduciary" means the person who, alone or in conjunction with others, determines the purpose and means of Processing of Personal Data — in this Policy, Outnext Private Limited.
  • "Data Processor" means any person who processes Personal Data on behalf of the Data Fiduciary.
  • "Consent" means a free, specific, informed, unconditional and unambiguous indication of your wishes by which you, by a clear affirmative action, signify agreement to the Processing of your Personal Data for the specified purpose.
  • "DPDP Act" means the Digital Personal Data Protection Act, 2023 and the rules and regulations issued thereunder.
  • "IT Act" means the Information Technology Act, 2000 and the rules made thereunder, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

3. Information We Collect

We collect only the Personal Data that is necessary to operate the Platform, fulfil our obligations to you, comply with applicable law, and improve our Service. The categories of Personal Data we collect are described below.

(a) Account and identity data you provide at registration: first name, last name, username, email address, hashed password, and (where you sign in with Google) your Google account identifier, name, email address and profile picture as released by Google to us.

(b) Profile data you choose to provide: profile photo, cover photo, headline, biography, current role, experience level, work preferences, availability, skills, languages, city, state, country, project interests, roles you are open to, GitHub username and URL, LinkedIn URL, portfolio URL, and education history (college, degree, start and end years).

(c) Onboarding data: project types you are interested in, roles you are open to, your main goal on the Platform, and how you heard about us.

(d) User-generated content: projects, tasks, posts, comments, files, images you upload, and any other content you submit through the Platform.

(e) Communications data: direct messages, group messages, project chats, message attachments, comments, follow / connection requests, project invites, join requests, and other interactions on the Platform.

(f) AI-feature inputs and outputs: text and structured inputs you submit to AI-powered features (such as idea strength checks, project description generation, task generation, teammate recommendations, system architecture generation, system design generation, platform-flow generation, the AI chat assistant / copilot, and code and diagram generation) and the outputs generated in response.

(g) Activity and usage data: profile view events, align (connection) events, collaboration events (invites, join requests, accepts, rejects, kicks), project upvotes, follows, login events, and other interactions logged for the operation and improvement of the Platform.

(h) Authentication and security data: hashed passwords, one-time passwords (OTPs) sent to your email for verification (retained for up to 10 minutes), session and refresh tokens stored as HTTP-only cookies, and email-verification status.

(i) Device, technical and log data: IP address, browser type and version, operating system, device type, language preferences, referrer URLs, pages visited, request timestamps, and server / application logs (including Docker container logs). This data is collected automatically when you interact with the Platform and is required for security, abuse prevention and operational diagnostics.

(j) Cookies and similar technologies: see Section 10 (Cookies and Tracking Technologies).

(k) Communications with us: information you provide when you contact us by email, through support channels, or in response to surveys.

(l) Payment and transaction data: when you purchase a paid subscription, we receive limited transaction information from our payment processor, Razorpay — such as order identifiers, payment identifiers, the subscription plan purchased, the amount, the currency, and the success or failure status of the payment. We do not collect or store your full payment-card number, CVV, UPI PIN, or netbanking credentials; these are handled directly by Razorpay under applicable payment-security standards (including PCI-DSS).

We do not knowingly collect government-issued identifiers (Aadhaar, PAN, passport), full payment-card numbers or bank-account credentials, biometric data, health data, caste, religion, sexual orientation or political opinions. You are requested not to submit such data to the Platform, including in free-text fields, profile content, messages, or AI inputs.

6. AI Features and Automated Processing

Certain features of the Platform use artificial-intelligence services, specifically Google Gemini accessed through Google Cloud Vertex AI (operated by Google LLC and its affiliates, "Google"). When you use AI features, the inputs you submit (such as project descriptions, task descriptions, profile fields and other content you provide) are transmitted to Google for processing and we receive the generated outputs in response.

Google processes such inputs as our Data Processor under its standard Google Cloud / Vertex AI terms. As of the Last Updated date of this Policy, customer prompts and outputs submitted to Gemini via Vertex AI are not used by Google to train its general-purpose foundation models, in line with Google Cloud's published data-protection commitments. You should nonetheless avoid submitting Personal Data of third parties, sensitive information, confidential business information, credentials, or anything you would not wish to share with a third-party service provider.

AI outputs are generated by automated means and are provided on an "as is" basis. They are suggestions only and not professional advice. You are responsible for reviewing, validating and deciding whether to act on any AI output, and Outnext is not liable for decisions made on the basis of such outputs. To the extent any feature involves a decision that produces a legal or similarly significant effect on you and is based solely on automated Processing, you may contact us to request human review.

7. Messaging, Projects and Collaboration Data

Messages, project content, tasks, files and related collaboration data are stored on our infrastructure to enable real-time and asynchronous collaboration, message history, search, notifications and continuity across sessions. Messages are visible to the participants of the relevant conversation or workspace and to authorised personnel of Outnext on a strict need-to-know basis (for example, to investigate abuse reports or to comply with a legal request).

Outnext does not sell the contents of your messages, use them for advertising, or share them with third parties for marketing purposes. Message contents may be transmitted through real-time delivery infrastructure (Redis-based channel layers) and stored in our managed database for the duration set out in Section 11 (Data Retention).

8. Sharing and Disclosure of Information

We do not sell your Personal Data. We share Personal Data only in the limited circumstances described below.

(a) With other users: information you choose to make public (such as your profile, public projects, comments and posts) is visible to other users of the Platform and, where applicable, to non-logged-in visitors and search engines. Information you share in direct or group messages is visible to the participants of that conversation.

(b) With Data Processors and sub-processors: we engage trusted service providers to host the Platform, send emails, store media, deliver content, operate AI features and provide related infrastructure. These providers act on our documented instructions, are bound by confidentiality and data-protection obligations, and are permitted to use Personal Data only to provide their services to us. The current sub-processors are listed in Section 9.

(c) Legal and safety disclosures: we may disclose Personal Data where we believe in good faith that disclosure is necessary to (i) comply with applicable law, a binding court order, summons, or lawful request from a government or regulatory authority, (ii) enforce our Terms of Service or investigate suspected breaches, (iii) detect, prevent or address fraud, abuse, security or technical issues, or (iv) protect the rights, property or safety of Outnext, our users or the public.

(d) Business transfers: if Outnext is involved in a merger, acquisition, financing, reorganisation, bankruptcy or sale of all or part of its assets, Personal Data may be transferred as part of that transaction, subject to the acquirer's commitment to honour the terms of this Policy or to provide notice and choice consistent with applicable law.

(e) With your consent: we may share Personal Data with third parties for any other purpose with your explicit Consent.

9. Sub-processors and Third-Party Services

We rely on the following categories of sub-processors and third-party services to operate the Platform. Each provider operates under its own privacy and security policies; by using the Platform you acknowledge and agree that your Personal Data may be Processed by these providers for the limited purposes described.

  • Cloud hosting and compute: Google Cloud Platform (operated by Google LLC) — provides virtual compute, networking and managed services used to run the Platform.
  • Managed database: Google Cloud SQL (managed PostgreSQL on Google Cloud Platform) — stores account, profile, messaging, project and other relational data.
  • Media storage and delivery: Cloudinary Ltd. — stores and delivers user-uploaded images, including profile pictures, cover photos and project media.
  • Content delivery network and edge security: Cloudflare, Inc. — provides DNS, CDN, DDoS protection and TLS termination for the Platform.
  • AI services: Google LLC (via Google Cloud Vertex AI / Gemini models) — processes inputs you submit to AI features and returns generated outputs.
  • Email delivery: Gmail SMTP (operated by Google LLC) — used to send transactional emails including OTPs, password resets and notifications.
  • Authentication: Google Sign-In / Google Identity Services (operated by Google LLC) — verifies your identity when you choose to sign in with Google.
  • Real-time infrastructure and background jobs: Redis (self-managed on our infrastructure) — used for caching, real-time messaging channels and background job queues.
  • Payment processing: Razorpay Software Private Limited — processes payments for paid subscriptions and handles your payment-instrument data (card, UPI, netbanking) directly under applicable payment-security standards (including PCI-DSS). We receive only limited transaction metadata (such as order and payment identifiers, plan, amount and status).

We will use commercially reasonable efforts to keep this list up to date. Material changes to our sub-processors will be reflected in updates to this Policy.

10. Cookies and Tracking Technologies

We use cookies and similar local-storage mechanisms only as necessary to operate the Platform. We do not use third-party advertising cookies, behavioural-advertising trackers, or cross-site tracking pixels. The cookies and storage we use fall into the following categories:

  • Strictly necessary cookies — "refreshToken" (HTTP-only, used to refresh your authentication session), "hasSession" (non-sensitive flag indicating an active session), Django session and CSRF cookies ("sessionid", "csrftoken") used to maintain server-side sessions and protect against cross-site request forgery.
  • Functional cookies — "gs_dark_mode" (stores your dark-mode preference for up to 12 months so the interface matches your last setting on first paint).
  • Operational cookies set by Cloudflare for security, bot mitigation and load balancing (such as "__cf_bm" and similar), governed by Cloudflare's privacy policy.

You can manage or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent you from signing in or using core features of the Platform.

11. Data Retention

We retain Personal Data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal, accounting and reporting obligations, and to resolve disputes and enforce our agreements. In summary: Personal Data is deleted within 60 (sixty) days of account closure; deleted messages are purged from active systems immediately and from backups within 7 (seven) days; server logs are retained for up to 90 (ninety) days; and financial and tax records are retained for up to 8 (eight) years as required by Indian law.

The specific retention periods that apply to each category of data are set out below.

  • Account, profile and onboarding data: retained for as long as your account is active.
  • Account deletion and right-to-erasure requests: upon receipt of a valid deletion request, your account is moved to a soft-deleted state and recoverable by you for 30 (thirty) days. Between day 31 and day 60, your Personal Data (profile, messages, projects, tasks, AI inputs, and other user-generated content) is irreversibly deleted from our production PostgreSQL database. By day 60, residual copies in backups containing your data are also overwritten in the ordinary course. Total elapsed time from deletion request to full wipe is 60 (sixty) days.
  • Email OTPs: retained for up to 10 (ten) minutes from issue, after which they expire automatically.
  • Authentication tokens (refresh tokens): retained for the duration of the configured session lifetime (currently up to 1 (one) day) or until you log out, whichever is earlier.
  • Messages, project and collaboration content: retained for as long as your account is active or as required for the operation of the workspace in which the content was created. Subject to the account-deletion timelines above.
  • Deleted messages (individual message deletion by user action): removed from the active database immediately upon deletion. Such messages may persist in routine daily database backups for up to 7 (seven) days (the Cloud SQL backup window), after which they are purged.
  • AI inputs and outputs: retained in identifiable form for up to 30 (thirty) days for the purposes of debugging, quality assurance and abuse investigation. After 30 days, identifiers are stripped and only anonymised, aggregate metrics (such as response latency, error rates and feature usage counts) are retained. Your prompts and outputs are not used to train foundation models or any of our own models without your explicit, separate Consent.
  • Server and application logs (including IP addresses, request metadata and Docker container logs): retained for up to 30 (thirty) days in the ordinary course (in line with the default Google Cloud Logging retention period).
  • Security and audit logs (including administrative actions, identity and access management events, and similar audit trails): retained for up to 1 (one) year for security, compliance and incident-investigation purposes.
  • Application error logs: retained for up to 90 (ninety) days for diagnostics and reliability monitoring.
  • Analytics events (profile views, align events, collaboration events): retained for as long as your account is active and may be aggregated or anonymised thereafter; identifiable analytics data tied to your account is removed in line with the account-deletion timelines above.
  • Financial, tax and statutory business records (including invoices, payment records, GST records, income-tax records and Companies Act records): retained for up to 8 (eight) years from the end of the relevant financial year, or for such longer period as may be required under the Companies Act, 2013, the Income-tax Act, 1961, the Goods and Services Tax Act, 2017, the Prevention of Money Laundering Act, 2002 (where applicable) and other applicable Indian laws. These records relate to financial transactions only and do not include user-generated content (such as messages, project notes or AI inputs).
  • Records required to be retained under any other applicable law, court order or regulatory direction: retained for the period prescribed thereunder.

Where Personal Data is required to be retained beyond your account-deletion request to comply with a legal obligation (for example, financial records under the Companies Act, 2013), such data will be retained only for the limited purpose of that legal obligation, will be access-restricted, and will not be used for any other purpose.

When the retention period for any category of Personal Data expires, we will, within a reasonable time and in accordance with our deletion and backup-rotation processes, delete or irreversibly anonymise such Personal Data.

12. Data Security

We have implemented and maintain reasonable security practices and procedures as required under the IT Act and the DPDP Act, taking into account the nature, scope and purpose of Processing and the risks involved. These include, without limitation:

  • Encryption of data in transit using industry-standard TLS.
  • Storage of passwords as salted, one-way hashes — passwords are never stored in plain text and cannot be retrieved by Outnext personnel.
  • Authentication using short-lived JSON Web Tokens, with refresh tokens stored in HTTP-only cookies inaccessible to client-side scripts.
  • Rate-limiting and throttling on authentication, OTP, AI and other sensitive endpoints to mitigate brute-force and abuse.
  • Role-based access controls and need-to-know principles for personnel access to production systems.
  • Use of managed cloud services with documented security certifications (Google Cloud Platform, Cloudinary, Cloudflare).

No system can be guaranteed to be completely secure. While we work continuously to protect your Personal Data, we cannot warrant absolute security and you transmit and store information at your own risk. You are responsible for keeping your account credentials confidential and notifying us promptly of any suspected unauthorised access.

13. Your Rights as a Data Principal

Subject to the DPDP Act and other applicable laws, you have the following rights in respect of your Personal Data:

  • Right to information about Processing — to obtain confirmation of whether your Personal Data is being Processed, a summary of the Personal Data being Processed, the Processing activities undertaken, the identities of all other Data Fiduciaries and Data Processors with whom your Personal Data has been shared, and any other information related to that Personal Data and its Processing.
  • Right to correction, completion, updation and erasure — to request correction of inaccurate or misleading Personal Data, completion of incomplete Personal Data, updation of out-of-date Personal Data, and erasure of Personal Data that is no longer necessary for the purpose for which it was Processed, unless retention is required for a specified purpose or for compliance with applicable law.
  • Right of grievance redressal — to readily available means of grievance redressal in respect of any act or omission of Outnext regarding the performance of obligations under the DPDP Act in relation to your Personal Data or the exercise of your rights (see Section 19).
  • Right to nominate — to nominate any other individual who shall, in the event of your death or incapacity, exercise your rights as a Data Principal under the DPDP Act. You may submit a nomination by writing to contact@gostuds.com.
  • Right to withdraw Consent — as described in Section 5.

You may exercise these rights by sending a written request to contact@gostuds.com or to the Grievance Officer (see Section 19). We may require verification of your identity before acting on a request to protect your Personal Data from unauthorised access.

In exercising your rights, you are required by the DPDP Act to (i) comply with the provisions of all applicable laws, (ii) ensure not to impersonate another person while providing your Personal Data, (iii) ensure not to suppress any material information while providing your Personal Data for any document issued by the State, (iv) ensure not to register a false or frivolous grievance or complaint, and (v) furnish only such information as is verifiably authentic when exercising the right to correction or erasure.

14. Profile Visibility and Public Content

Certain Personal Data and content is, by design, visible to other users of the Platform and, in some cases, to the public (including search-engine indexers). This includes your username, profile photo, headline, biography, skills, public projects, public posts and comments, and similar discoverable fields. Where the Platform provides visibility controls, you can adjust what is visible to whom; otherwise, you should treat the information you place in such fields as public.

Public content may be cached, indexed, copied or screen-captured by third parties (including search engines, archiving services and other users). Outnext cannot control or guarantee the removal of such third-party copies, although we will use reasonable efforts to remove content from our own systems upon a valid request.

15. Children's Privacy

The Platform is intended for and directed to individuals who are at least 18 (eighteen) years of age. By creating an account, you represent and warrant that you are at least 18 years old. We do not knowingly Process Personal Data of children (defined under the DPDP Act as individuals below 18 years of age).

We do not undertake tracking or behavioural monitoring of children, and we do not direct targeted advertising at children. If we become aware, or are informed in writing, that we have inadvertently collected Personal Data from a person below 18 years of age without verifiable parental or lawful guardian consent, we will, as soon as reasonably practicable, terminate the account, delete the associated Personal Data, and cease further Processing, except where retention is required to comply with applicable law.

If you are a parent or lawful guardian and believe that a person below 18 years of age has provided Personal Data to us, please contact the Grievance Officer at the address set out in Section 19.

16. International Data Transfer

Outnext is incorporated in India and our primary operations are conducted from India. However, certain of our sub-processors (including Google Cloud Platform, Google Cloud Vertex AI, Cloudinary and Cloudflare) operate global infrastructure and may Process and store Personal Data in data centres located outside India, including in jurisdictions whose data-protection laws may differ from those of India.

Where Personal Data is transferred outside India, we ensure that such transfers are made only to jurisdictions that are not restricted by the Central Government of India under the DPDP Act, and that appropriate contractual safeguards are in place with the relevant sub-processors to protect the confidentiality, integrity and security of the Personal Data. By using the Platform you acknowledge and consent to such cross-border transfers for the purposes described in this Policy.

17. Data Breach Notification

In the event of a personal-data breach affecting your Personal Data, we will, in accordance with the DPDP Act and the rules thereunder, notify the Data Protection Board of India and each affected Data Principal of the breach in the form, manner and within the timelines prescribed by applicable law. Such notification will include, to the extent known, the nature and circumstances of the breach, the categories and approximate number of Data Principals affected, the likely consequences, the measures taken to mitigate the breach, and the contact details for further information.

18. Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in our practices, the Platform, applicable law or for other operational, legal or regulatory reasons. The "Last Updated" date at the top of this Policy will be revised whenever a change is made. Where a change is material, we will provide additional notice (such as an in-Platform notice or an email to the address associated with your account) and, where required by law, obtain your fresh Consent. Continued use of the Platform after the effective date of the revised Policy constitutes your acceptance of the revised Policy.

19. Grievance Officer and Data Protection Contact

In compliance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, we have appointed a Grievance Officer who is also the point of contact for matters relating to the Processing of your Personal Data under this Policy. Outnext has not separately appointed a Data Protection Officer; the Grievance Officer serves as the primary contact for all data-protection matters.

Name: Sujal Verma

Designation: Grievance Officer, Outnext Private Limited

Address: Outnext Private Limited, Nathawatpura, Sikar, Rajasthan – 332001, India

Email: sujal@gostuds.com (general grievances: contact@gostuds.com)

We will acknowledge receipt of any grievance within 24 (twenty-four) hours of receipt and use our best efforts to dispose of the grievance within 15 (fifteen) days from the date of receipt, in accordance with the Intermediary Guidelines. Where the DPDP Act prescribes a different timeline, the timeline most protective of the Data Principal will apply.

20. Data Protection Board of India

If you are not satisfied with the response of the Grievance Officer, or if you believe your rights under the DPDP Act have been infringed, you may lodge a complaint with the Data Protection Board of India established under the DPDP Act, in the manner and within the timelines prescribed by the Board. Information about the Board and its procedures, when published by the Central Government, will be available through official Government channels.

21. Governing Law and Jurisdiction

This Policy shall be governed by, and construed in accordance with, the laws of the Republic of India, without regard to its conflict-of-laws principles. Subject to the statutory rights of Data Principals to approach the Data Protection Board of India or any other competent authority under applicable law, the courts at Sikar / Rajasthan, India, shall have exclusive jurisdiction over any dispute, claim or proceeding arising out of or in connection with this Policy.

22. Contact Us

If you have any questions about this Policy, the Processing of your Personal Data, or to exercise any of your rights as a Data Principal, you may contact us at:

Outnext Private Limited

Nathawatpura, Sikar, Rajasthan – 332001, India

Email: contact@gostuds.com