Back to Home
Data Governance & Transparency Notice

Privacy Policy

Effective Date: September 29, 2026Last Updated: September 29, 2026Platform: Pathubs (pathubs.com)

1. Introduction & Platform Overview

Welcome to Pathubs (“we”, “us”, or “our”), accessible at pathubs.com. Pathubs is a modern, independent online educational platform dedicated to helping students, developers, and career changers navigate technology roadmaps, study structured engineering curricula, and practice hands-on coding skills without paywalled courses.

This Privacy Policy explains in detail our practices regarding the collection, use, storage, synchronization, and disclosure of information when you interact with our website, use our interactive study sandboxes, complete knowledge assessments, register for an optional learning account, or submit voluntary support inquiries. For terms governing your use of our platform, please review our Terms & Conditions, and for details on browser storage, see our Cookie Policy.

Core Privacy Principle: You can explore roadmaps, study curricula, read documentation, and run practice queries on Pathubs completely anonymously without creating an account. Where personal data or telemetry is collected, it is handled transparently and subject to strict consent and security controls.

2. Operator Identity & Governance Notice

Pathubs is operated and maintained as an educational platform originated in India. For questions regarding our data protection practices, you may reach our administrative and support team directly via email at supportpathubs@gmail.com.

Notice Regarding Corporate & Statutory Registration:
Pathubs operates currently as an independent digital web project. As the platform scales, formal corporate incorporation details (e.g., Corporate Identification Number, registered company name, registered physical office address, and designated statutory Grievance Officer in accordance with the Digital Personal Data Protection Act, 2023 and the notified Digital Personal Data Protection Rules, 2025, adhering to their phased commencement schedule) will be formally updated in this section prior to any commercial restructuring.

3. Categories of Information We Collect

We organize the information processed on Pathubs into four distinct categories:

A. Information You Voluntarily Provide

  • Account Credentials: If you choose to register for a Pathubs account, we collect your name, email address, avatar URL, and authentication provider details (such as Google OAuth or email/password).
  • Feedback & Inquiries: When you submit feedback through our global widget, inline topic feedback cards, or footer support forms, we collect the feedback category (e.g. suggestion, bug, praise), satisfaction rating, page URL, submission timestamp, and your voluntary comment and contact email (if provided).
  • Community Submissions: If you suggest educational resources, we collect the recommended resource URL, topic title, educational reason, and your chosen contributor display name.
  • Voluntary Financial Contributions: If you voluntarily contribute to support platform hosting via our Support Us page, transaction metadata (amount, currency, order ID, and payment identifier) is processed through our payment gateway.

B. Information Generated Through Educational Use

  • Curriculum Progress: Completed topic identifiers, roadmap percentage calculations, and milestone completion timestamps.
  • Knowledge Check Results: Numerical scores and pass/fail indicators for milestone quizzes and certification tests.
  • Saved Bookmarks: Resource identifiers added to your personal learning library.
  • Recent Learning History: Up to 20 recently visited career modules to facilitate resumption of studies across sessions.
  • Career Discovery Responses: Categorical interests submitted in the Discovery Quiz to calculate matching career roles.

C. Technical, Security & Anti-Abuse Telemetry

  • Network Identifiers: Internet Protocol (IP) address, referring URL, HTTP user-agent header, and request timestamp.
  • Bot Verification Signals: Privacy-preserving interaction tokens processed via Cloudflare Turnstile to prevent automated scraping and spam attacks.
  • Rate-Limiting Counters: Short-term request frequency counters managed via Upstash Redis to prevent Denial of Service (DoS) attacks.

D. Product Usage & Analytics Data (Consent-Gated)

When you affirmatively consent to Analytics, Google Analytics 4 collects pseudonymous technical telemetry, including page paths, session durations, device category, approximate geographical location (country/city level via IP lookup before IP truncation), and custom educational interaction events.

4. Purposes of Data Processing

We process information strictly for the following defined, transparent purposes:

  • Core Educational Delivery: To render interactive coding workspaces, evaluate practice sandboxes, and display roadmap diagrams.
  • Progress Persistence: To save your study checkmarks, quiz scores, and bookmarks locally or in your synchronized cloud profile.
  • Account Administration: To authenticate your identity, prevent unauthorized access to your saved progress, and manage sessions.
  • Support & Communications: To investigate reported bugs, answer technical inquiries, and acknowledge user feedback.
  • Security & Abuse Mitigation: To protect server infrastructure, mitigate automated bot submissions, enforce API rate limits, and ensure uptime.
  • Platform Optimization: Subject to your affirmative consent, to analyze aggregate drop-off rates in learning modules, identify popular tech topics, and optimize site navigation.
  • Payment Verification: To verify voluntary platform contributions and comply with statutory financial transaction records.

6. Product Analytics & Zero-PII Controls

Pathubs uses Google Analytics 4 (GA4) with Google Consent Mode v2 to understand platform health. Our behavioral analytics architecture adheres to strict privacy-by-design standards:

  • Strict Consent Gating: All analytics tracking functions evaluate pathubs_cookie_consent_v1.analytics === true before dispatching any event. If consent is ungranted or denied, telemetry calls return immediately without transmitting data.
  • Explicit PII Exclusion Layer: Our centralized analytics dispatcher ([`src/lib/analytics.ts`](file:///c:/Users/newsa/.gemini/antigravity/scratch/roadmap-platform/src/lib/analytics.ts)) contains an automated filter that automatically deletes parameters named email, name, user_id, account_id, password, token, jwt, secret, phone, message, or comment.
  • No User Profiling or Tracking IDs: We do not send authenticated user IDs (e.g. Supabase account UIDs) to Google Analytics. Analytics metrics represent anonymous, aggregate behavior.
  • IP Anonymization: IP addresses are anonymized by Google Analytics at the earliest possible stage and are not stored or exposed to Pathubs administrators.
  • Summary of Tracked Event Categories: With consent, we measure aggregate actions including: roadmaps viewed (e.g. data-analytics), topic workspaces opened, completion checkmarks toggled, quizzes started/completed (numerical score only; question text and user answers are excluded), resource clicks, help drawer opens, onboarding tour completion, and authentication method used (google or email).

8. Authentication & Multi-Device Cloud Sync

Pathubs provides optional account creation so that your study checkmarks, quiz milestones, and bookmarked articles are synchronized across all your devices.

  • Authentication Infrastructure: Account identity is powered by Supabase, an open-source database and authentication platform. You can register via Google Identity Services (GIS) OAuth or with an email and password.
  • Password Protection: Passwords are never stored in plaintext. Supabase handles industry-standard cryptographic hashing and secure authentication handshakes.
  • Client-Side Scoped Storage: For registered learners, progress is cached in your browser's localStorage under user-scoped keys (e.g. skillpath_progress_v1_[userId]) and securely synchronized with private database tables (`user_topic_progress`, `user_bookmarks`, `user_learning_history`, `user_quiz_results`).
  • Guest Privacy: If you use Pathubs without creating an account, your study progress remains strictly local to your browser on that device and is never uploaded to our cloud databases.

9. Student Feedback, Support & Community Contributions

We provide several avenues for voluntary user participation:

  • Student Feedback: When you submit suggestions, bug reports, or topic ratings, the submission is securely saved in our Supabase database (`student_feedback`) and may be forwarded to our support mailbox (supportpathubs@gmail.com) via Resend. We use this data solely to debug platform errors and enhance educational clarity.
  • Community Resource Index: If you recommend learning articles or videos via our community suggestion feature, submissions are reviewed by platform maintainers before publication. Approved suggestions display your chosen contributor name alongside the educational link.

10. Voluntary Contributions & Payment Processing

Pathubs is 100% free to access. To help offset global cloud infrastructure costs, users may make voluntary financial contributions on our Support page.

  • Payment Gateway: Payment processing is handled entirely by Razorpay Software Private Limited, an RBI-authorized and PCI-DSS Level 1 certified payment gateway.
  • Zero Card Storage: Pathubs does not collect, process, or store credit card numbers, debit card PINs, CVVs, or online banking passwords. All sensitive payment details are submitted directly to Razorpay via their encrypted checkout SDK.
  • Transaction Records: Pathubs servers receive only transaction confirmation metadata (Razorpay Order ID, Payment ID, amount, and currency) to verify payment completion and maintain statutory accounting records.

11. Third-Party Service Providers & Disclosures

We do not sell, rent, monetize, or trade your personal data to third parties. We share information only with trusted technical service providers necessary to operate the platform:

ProviderRole & Service ProvidedData Transferred / HandledPrivacy Information
Supabase, Inc.Cloud Database & AuthenticationAccount email, display name, cryptographically hashed passwords / OAuth tokens, synced study progressSupabase Privacy
Google LLCAggregate Analytics (GA4) & AdSensePseudonymous usage events, sanitized search terms (consent-gated)Google Privacy
Cloudflare, Inc.Bot Verification (Turnstile) & CDNClient IP, browser telemetry tokens for bot mitigationCloudflare Privacy
Razorpay Software Pvt LtdPayment Processing (Donations)Checkout transaction details, contribution amount, order IDsRazorpay Privacy
Upstash, Inc.Serverless Redis Rate LimitingTemporary client IP addresses for DoS attack preventionUpstash Trust
Resend, Inc.Transactional Email RoutingNotification emails containing feedback and support ticketsResend Privacy

In addition to the service providers above, we may disclose information where required by law, subpoena, or valid legal process issued by a court or governmental authority having competent jurisdiction.

12. International Data Transfers

Pathubs is operated from India, while our technical cloud providers (such as Supabase, Cloudflare, Google, Upstash, and Resend) operate distributed data centers across the United States, Europe, and Asia.

When information is transferred across national boundaries, our service providers utilize standard contractual clauses, encryption in transit and at rest, and international transfer safeguards recognized under applicable data protection laws. By using Pathubs, you acknowledge that your information may be processed in jurisdictions with data protection frameworks different from your own.

13. Data Retention & Deletion Schedule

We retain personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected, subject to operational, security, and statutory requirements:

Data CategoryRetention Period & Criteria
Registered Account Data & Synced ProgressRetained for the active lifetime of your account. Permanently deleted upon verified account deletion request.
Local Browser Storage (Progress, Bookmarks, History)Remains stored locally in your browser until you clear your browser cache or reset website storage data.
Student Feedback & Support MessagesRetained for up to 24 months to assist in longitudinal product quality improvement, then archived or deleted.
Security Telemetry & Rate-Limiting RecordsUpstash Redis rate-limiting keys expire automatically within 1 minute to 1 hour. Server logs are purged within 30 to 90 days.
Analytics Telemetry (GA4)Standard Google Analytics event retention (configured to standard 2-month or 14-month rolling retention period).
Donation & Contribution RecordsRetained as reasonably necessary for accounting, taxation, statutory dispute verification, and regulatory compliance under applicable Indian laws, or as advised by formal organizational tax counsel.

14. Your Data Protection Rights

Depending on your jurisdiction and applicable data protection legislation, you are entitled to specific statutory rights regarding your personal data:

A. Rights Under the Digital Personal Data Protection Act, 2023 & DPDP Rules, 2025 (India)

If you are a Data Principal located in India, you hold statutory rights under the DPDP Act, 2023 and the notified DPDP Rules, 2025 (subject to their phased commencement schedule):

  • Right to Access Information (Section 11): Right to obtain a summary of personal data processed by Pathubs and identities of third parties with whom it was shared.
  • Right to Correction & Erasure (Section 12): Right to request correction of inaccurate data, completion of incomplete data, or erasure of personal data that is no longer necessary.
  • Right of Grievance Redressal (Section 13): Right to readily accessible grievance redressal mechanisms regarding personal data obligations.
  • Right to Nominate (Section 14): Right to nominate an individual who shall, in the event of death or incapacity, exercise your data rights.
  • Right to Withdraw Consent (Section 6(4)): Right to withdraw consent as easily as it was given, without affecting the lawfulness of processing prior to withdrawal.

B. Rights Under the General Data Protection Regulation (EEA & UK)

If you access Pathubs from the European Economic Area or United Kingdom, you hold rights under GDPR / UK GDPR Articles 15–22:

  • Right of Access & Portability: Obtain confirmation and copies of your personal data in a structured, machine-readable format.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data where retention is no longer justified.
  • Right to Restrict or Object: Restrict processing or object to processing based on legitimate interests.
  • Right to Lodge a Complaint: Lodge a complaint with a supervisory authority in your country of residence.

C. How to Exercise Your Rights

To exercise any of the above rights, please contact our administrative team at supportpathubs@gmail.com with the subject line “Data Privacy Rights Request”. To safeguard your account, we may ask you to verify your identity from your registered email address before completing data erasure or disclosure requests.

15. Children's Privacy

Pathubs provides technical curriculum roadmaps aimed at post-secondary students, adult professionals, and self-directed learners.

We do not knowingly collect personal data from children under the age of 18 (in India, pursuant to the DPDP Act) or under 13 (under US COPPA standards) without verifiable parental consent. If you believe that a child has provided us with personal information through a support form or account creation, please contact us immediately at supportpathubs@gmail.com, and we will take prompt steps to verify and delete such information from our records.

16. Technical & Operational Security Measures

We maintain industry-standard administrative, technical, and physical safeguards designed to protect personal information from accidental loss, unauthorized access, alteration, or disclosure:

  • HTTPS / TLS Encryption: All communications between your browser and Pathubs servers are encrypted in transit using modern Transport Layer Security (TLS 1.2 / TLS 1.3 supported across our global edge network).
  • Content Security Policy (CSP): Strict HTTP security headers, including CSP directives, prevent Cross-Site Scripting (XSS) and unauthorized code execution.
  • Distributed Rate Limiting: Multi-tiered Redis rate limiters protect public endpoints against automated brute-force attacks and resource exhaustion.
  • Bot Protection: Cloudflare Turnstile validates form authenticity without tracking users across unrelated sites.
  • Least Privilege Architecture: Server-side database operations use restricted API keys, and database access is restricted via Row-Level Security (RLS) policies.

Security Reality Notice: While we implement rigorous technical safeguards, no method of transmission over the Internet or electronic storage is completely infallible. We encourage users to maintain unique, secure passwords and safeguard their device login credentials.

17. Modifications to This Policy

We may revise this Privacy Policy periodically to reflect updates to our educational curriculum, changes in technical service providers, or evolving legal requirements.

When changes are made, we will update the “Last Updated” date at the top of this page. For significant updates that materially alter how personal data is processed, we will provide prominent notice on the platform homepage or via our cookie banner. We encourage you to review this policy periodically.

18. Contact & Grievance Redressal

For any questions, concerns, feedback, or grievance redressal regarding this Privacy Policy or our data handling practices:

Platform: Pathubs

General Support & Privacy Desk: supportpathubs@gmail.com

Response Timeline: We acknowledge data privacy communications within 48 to 72 business hours and endeavor to resolve statutory inquiries within 30 days.

Administrative Grievance Redressal Note:
Pursuant to Section 13 of the Digital Personal Data Protection Act, 2023, Data Principals in India may address grievances directly to our support desk. If any statutory authority requests administrative contact details, please cite reference “Pathubs Data Governance Desk” at supportpathubs@gmail.com.