BACK TO HOMEPAGE
PRIVACY POLICY

Your data, on your terms.

Effective date: 1 March 2026 · Last updated: 24 February 2026 · Operator: KhojByte Research Lab Pvt. Ltd., Kathmandu, Nepal.

1. Who we are

KhojByte Research Lab Pvt. Ltd. (“KhojByte”, “we”, “us”) is a Nepal-registered research-publication and academic mentorship platform. We operate the website khojbyte.com and the underlying applications (collectively, the “Service”). This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and the choices and rights you have. It applies to every visitor and registered user — client, mentor, tutor, institutional partner, or admin.

2. Data we collect

  • Account data — name, email address, profile picture, role (client / mentor / tutor / admin), affiliation, academic level, country, password hash (bcrypt). Provided by you at sign-up or imported from your Google account when you choose Sign in with Google.
  • Research project data — research ideas, abstracts, methodology notes, drafts, datasets, chat messages, comments, deliverables, scheduled meetings, and any other content you submit into your workspaces.
  • Payment data — for paid services (e.g. Custom Guidance, premium courses) we receive a payment confirmation token from Khalti, eSewa, or Stripe. Card / bank credentials never reach our servers — they are entered on the processor's page.
  • Communication data — direct messages, project chat, mentor↔client correspondence, support emails.
  • Device & usage data — IP address, browser fingerprint, pages visited, button clicks, error logs. Used for security and product improvement.
  • Cookies — a single session_token HTTP-only cookie for authentication. We do not run third-party advertising trackers. We use Google Analytics 4 (anonymised IP) for aggregate traffic reporting.

3. Google user data and OAuth scopes

KhojByte uses Google's OAuth 2.0 to let you (a) sign in with Google and (b) optionally connect Google Drive, Google Meet, and Google Calendar so collaborators can co-author documents and join meetings without leaving the workspace. We request the minimum scopes needed.

ScopeWhy we request it
openid email profileIdentify you so we can create your KhojByte account or sign you in.
drive.fileRead & write only the files KhojByte creates inside your Drive (the shared KhojByte / <project> folder). We have no visibility into the rest of your Drive.
meetings.space.createdCreate instant or scheduled Google Meet links for your workspace meetings.
calendar.eventsAdd the scheduled meeting to your Google Calendar so attendees get a notification.

Limited Use compliance. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • We use Google user data only to provide and improve user-facing features of the Service.
  • We do not transfer Google user data to third parties except (a) to comply with applicable law, (b) to protect against fraud / security threats, or (c) when you give us explicit consent.
  • We do not use Google user data for advertising, profiling, credit-scoring, or training generalised AI / ML models.
  • Human access to Google user data is restricted to (a) you and your collaborators, (b) the small subset of KhojByte engineers who maintain the platform under signed confidentiality agreements, and (c) law-enforcement when compelled by valid legal process.

4. How we use your data

  • To provide the core Service — authentication, project workspaces, chat, deliverables, certificates, meetings, payments.
  • To send transactional emails (account verification, password reset, meeting invites) and operational notifications (mentor assigned, deliverable feedback received).
  • To run the platform reliably — monitoring, backups, debugging, abuse prevention.
  • To comply with legal obligations — invoice records, tax filings, court orders.
  • With your opt-in consent, to send occasional product newsletters. You can unsubscribe at any time.

We never sell your personal data and we do not use your research workspaces or Google user data to train any third-party AI / ML model.

5. Sharing

Your data is shared with three categories of recipients, all under contract:

  • Collaborators you choose. Workspace members (assigned mentor, co-researchers, institutional reviewers) see the project data you place in that workspace.
  • Sub-processors that power the Service. Google LLC (OAuth, Drive, Meet, Calendar, Analytics), MongoDB Atlas (database hosting), Cloudflare (CDN / WAF), Resend (transactional email), Khalti & eSewa & Stripe (payment processing). Each operates under their own privacy commitments — links available on request.
  • Authorities when compelled by valid legal process or to protect KhojByte's legal rights.

6. Data retention

  • Account data — kept for the life of your account.
  • Workspace data (ideas, drafts, chat) — kept until you delete the project or your account.
  • Google OAuth tokens — refreshed on use, deleted within 24 hours of you disconnecting the integration or deleting your account.
  • Invoices & payment records — retained for 5 years to comply with Nepalese tax law.
  • Server logs — purged after 90 days.

7. Your rights

You can at any time:

  • Access a copy of the personal data we hold about you — email us at privacy@khojbyte.com.
  • Correct inaccurate data from your profile settings.
  • Delete your account from Account → Delete account. We will erase your personal data within 30 days, retaining only what we are legally required to keep (invoices for 5 years).
  • Disconnect Google integrations from Account → Connected apps or anytime from Google Account Permissions. We delete our copy of your refresh token within 24 hours.
  • Export your research projects as ZIP from the project actions menu.
  • Lodge a complaint with the Nepalese data-protection authority or any supervisory authority of competent jurisdiction.

8. Security

We protect your data with:

  • TLS 1.2+ encryption in transit (HSTS preload).
  • Encryption at rest on database storage volumes (AES-256).
  • HTTP-only, SameSite session cookies — no client-side access to your auth token.
  • bcrypt-hashed passwords (work factor 12) — never stored or logged in plain text.
  • Principle-of-least-privilege access for engineers, with audit logs of every administrative action.
  • Automated daily backups stored in a separate region with 30-day retention.
  • Vulnerability scanning & penetration tests at least once per year.

No system is 100% secure. If we ever experience a personal-data breach we will notify affected users within 72 hours and the relevant supervisory authority where required.

9. International transfers

Our infrastructure runs in the EU and US (MongoDB Atlas, Cloudflare). When you use the Service from outside those regions, your data is processed there. We rely on Standard Contractual Clauses with our sub-processors to safeguard such transfers.

10. Children

The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

If we make material changes we will notify registered users by email at least 30 days before the changes take effect. The “Last updated” date above always reflects the latest revision.

12. Contact

Please also see our Terms of Service.