Privacy Policy
Effective Date: 01-05-2026
Last updated on : 01-05-2026
RuruVerse Studio Private Limited (CIN: [U85500MH2025PTC450236], having its registered office at A-103, Ist Floor Freight Forwarders Premises Co-op Society Ltd,Plot No.5, Sector I, Dronagiri, Uran, Raigad, NAVI MUMBAI, MAHARASHTRA 400707) (“Company”, “we”, “our”, or “us”) owns and operates the website https://www.mypeblo.com/ (“Website”), the mobile application by the name of ‘Peblo’ (the “App”), and any other digital platforms made available by the Company, under the brand name “Peblo” (collectively, the “Platform”). The Company develops, creates, produces, publishes and distributes interactive content, adaptive quizzes and videos with AI-assisted learning features, voice-enabled learning tools, progress tracking and other digital services (collectively, the “Services”).
This Privacy Policy (“Privacy Policy”) explains how we collect, use, disclose, store and otherwise process personal data in connection with the Platform and the Services. This Privacy Policy applies to Parents, Children and other Users who access or use the Platform.
For the purposes of this Privacy Policy, a parent or legal guardian who creates and manages an account is referred to as the “Parent”, such account is referred to as the “Parent Account”, and the individual learning profile created for a child through the Parent Account is referred to as the “Child Profile”. A child who uses the Services through a Child Profile is referred to as the “Child”.
We take reasonable measures to protect Children from content and interactions that may be harmful to them. We do not knowingly process Child personal data in a manner that is likely to cause harm to a Child, and our AI Features include safety moderation measures for flagged Child-AI interactions.
PERSONAL DATA WE COLLECT
We collect personal data necessary to create and manage Parent Accounts and Child Profiles, provide and personalise the Services, administer Subscriptions, maintain records of parental consent, and operate and secure the Platform.
Parent Data - We may collect the following information relating to the Parent:
mobile number and OTP verification records, which are used for account creation, login and as the identity anchor for parental consent;
email address and Parent name, where provided, for communications and receipts;
Subscription and entitlement information, including Google Play purchase tokens and related transaction or order metadata, for billing and entitlement administration; and
consent records, including the Parent and Child identifiers, purpose of consent, consent status, Privacy Policy version, date and time, and channel through which consent was provided.
Google Play is the merchant for in-app purchases. We do not receive or store payment card details and receive purchase tokens and order metadata necessary to verify and administer the applicable Subscription.
Child Profile Data – We may collect the Child’s full name, date of birth, grade, selected avatar and subject preferences for personalising the learning experience and providing grade-appropriate content. We do not collect Child photographs, addresses, school names or government-issued identification documents. An avatar selected by the Child is a cartoon representation and is not a photograph of the Child.
Learning and Assessment Data - We may collect quiz sessions and answers, including the option selected, correctness, time taken, revision count, hint usage, device input method, self-reported emoji mood and per-answer model feature information. We may also collect and generate derived learner information, including per-topic and skill accuracy, misconception flags, mastery states, spaced-review schedules, prediction-model weights and knowledge graphs. This information is used for adaptive difficulty, learning progress, parent reporting, and the adaptive learning and mastery systems.
Video and Content Usage Data - We may collect video watch progress, playlists and playback sessions for resume playback, recommendations and parent reporting. For premium playback, VdoCipher receives playback events associated with a viewer token and not the Child’s name.
Technical Data - We collect server logs containing API request information, including Child and Parent identifiers in request paths, IP addresses and timestamps, for security, debugging and applicable CERT-In obligations. We may also collect crash and error reports for service stability and in-app analytics events for product improvement. In-app analytics use a Families-policy-compliant SDK and do not use advertising SDKs or behavioural advertising identifiers. Where enabled, push notification tokens may be collected for sending notifications to the Parent’s device.
AI COMPANION AND VOICE FEATURES
Certain Services include AI-assisted learning features (collectively, the "AI Features"). These include an AI story feature, which generates and narrates stories and does not require voice input, and a voice-based learning companion, which operates through spoken interaction and is available only where the Parent has separately enabled voice features and granted microphone permission. The remainder of the Services, including video content, quizzes and stories, is available without enabling voice
Voice Data - Where the Parent has separately enabled voice features, the Child may interact with the AI Features using the device microphone. The Child’s spoken audio is streamed in real time and processed through Google’s Gemini Live API for speech-to-text processing and to enable the AI companion and voice-coaching features. We do not persist the Child’s spoken audio as audio files. Transcripts of what the Child says and related conversation records may be stored by us for conversation continuity, Parent visibility, safety review and product improvement. Speaking assessment scores and related performance metrics may also be stored for the voice-coaching feature.
AI Conversation Data - Transcripts and conversation turns relating to the Child’s interactions with the AI companion may be processed by Google Gemini to generate AI responses. AI conversation records are retained for the period specified in the “Data Retention” section below.
AI Voice Output - The AI companion’s voice response may be generated through ElevenLabs. ElevenLabs receives the AI-generated response text and does not receive the Child’s voice audio or name. AI-generated voice output is not retained by us.
Safety Moderation – We maintain safety-layer records relating to flagged content in Child-AI conversations for Child-safety moderation. Such records are retained for the period specified in the “Data Retention” section below.
CHILDREN’S PERSONAL DATA AND PARENTAL CONSENT
Peblo is designed primarily for Children and knowingly processes children’s personal data to provide the Services. For the purposes of applicable Indian data protection law, a Child means an individual under eighteen (18) years of age. The Parent is the account holder and the consenting party in relation to the processing of the Child’s personal data.
Parental Consent - Before creating a Child Profile or processing Child personal data, we obtain verifiable parental consent through the consent mechanism made available on the Platform. The consent mechanism includes:
creation of a Parent Account using a phone number and OTP verification;
an adult verification or Parent Gate;
confirmation by the Parent that they are the parent or legal guardian of the Child and are over eighteen (18) years of age; and
a consent screen identifying the purposes for which Child personal data will be processed.
Consent is purpose-specific and may include separate consent for core learning Services, voice features, product analytics and Parent communications. Consent records are maintained against the relevant Parent Account and Child Profile and include the applicable purpose, consent status, policy version, date and time, and method or channel through which consent was provided.
Voice Consent - Voice features are optional and disabled by default and will be available to a Child only where the Parent has separately provided the required consent.
No Behavioural Advertising or Profiling of Children - We do not use children’s personal data for behavioural tracking, behavioural monitoring, behavioural profiling for advertising, or targeted advertising directed at Children. We do not sell children’s personal data, and we do not disclose children’s personal data to advertisers or data brokers. The Platform does not contain third-party advertising.
Consent Withdrawal and Parental Controls - The Parent may manage applicable consent settings through the Parent Dashboard. Optional consents may be withdrawn at any time. Withdrawal of voice consent takes effect immediately and disables the voice features. Upon request, existing voice-related transcripts will be deleted, subject to applicable retention requirements. Withdrawal of core learning consent initiates the applicable account closure and erasure process. Where the Privacy Policy is materially changed, the Parent will be shown a summary of the changes and required to re-confirm applicable consent before Child sessions continue.
COMPLIANCE WITH CHILDREN’S PRIVACY LAWS OUTSIDE INDIA
The Platform is currently offered to Users in India. Where the Platform is made available in other jurisdictions, we comply with applicable laws and regulations relating to children in those jurisdictions.
4.1 United States – COPPA. Where the Services are made available to Users in the United States, we comply with the Children’s Online Privacy Protection Act (“COPPA”) and the rules made thereunder. We do not knowingly collect personal information from a child under thirteen (13) years of age without verifiable parental consent. We collect from Children only the personal information that is reasonably necessary to participate in the Services, and we do not condition a Child’s participation on the disclosure of more personal information than is reasonably necessary. A Parent may review the personal information collected from their Child, refuse to permit its further collection or use, and request its deletion, by using the mechanisms set out in the “Parental Rights and Data Requests” section below.
4.2 European Union and United Kingdom – GDPR. Where the Services are made available to Users in the European Union or the United Kingdom, we comply with the General Data Protection Regulation and the UK GDPR, including the provisions applicable to information society services offered to children. Where processing is based on consent and the User is below the applicable age of digital consent, such consent is given or authorised by the holder of parental responsibility. Data subjects have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority.
4.3 Certification. We certify that the Platform, including all APIs, SDKs and any advertising components, complies with all applicable laws and regulations relating to children in the jurisdictions in which the Platform is made available.
HOW WE USE PERSONAL DATA
We use personal data for the following purposes:
to create and manage Parent Accounts and Child Profiles;
to verify, record and manage parental consent;
to provide adaptive learning, quizzes, educational videos and other Services, and to personalise the learning experience;
to provide learning and progress reports to Parents;
to provide and operate the AI Features, including voice-enabled learning and voice-coaching features;
to process and administer Subscriptions and related entitlements;
to send Parent communications, including tips and newsletters, where the Parent has provided the applicable consent;
to maintain the security, stability and functionality of the Platform, including debugging and crash/error reporting;
to conduct product analytics and improve the Platform and Services;
to carry out Child-safety moderation of AI interactions; and
to comply with applicable legal and regulatory obligations.
PARENTAL RIGHTS AND DATA REQUESTS
Subject to applicable law, the Parent may, in relation to the Child’s personal data: (a) access the personal data and information relating to its processing; (b) request correction, completion or updating of inaccurate or incomplete personal data; and (c) request erasure of personal data. The Parent may exercise these rights through the mechanisms made available through the Parent Dashboard or by contacting the Grievance Officer using the details set out in this Privacy Policy.
The Parent may request deletion of a Child Profile or the Parent Account through the Parent Dashboard. Upon a valid deletion request, the applicable deletion process will delete the relevant data across the applicable systems, including Child Profiles, quiz sessions, answers, derived learning data, model weights, knowledge graphs, AI conversation records, speaking assessments and playlists, as applicable. A deletion receipt will be provided to the Parent and a record of the deletion event will be retained. Personal data contained in backups will be purged through the applicable backup rotation process within thirty-five (35) days.
Requests through the Website. A Parent who no longer has access to the App, including a Parent who has uninstalled the App, may request deletion of the Parent Account and associated Child Profile data at https://www.mypeblo.com/delete-account, or by writing to the Grievance Officer at the address set out below. To protect account security, we will verify that a request originates from the registered Parent before acting on it. Verification is carried out by OTP confirmation to the registered mobile number or by confirmation from the registered email address. We will acknowledge a deletion request within seven (7) business days and complete the deletion within thirty (30) days of successful verification.
Data retained after deletion. We retain, after deletion, only the following: (a) consent records and deletion event records, for the purpose of demonstrating compliance; and (b) subscription and transaction metadata, for the period required under applicable financial-record and taxation law. These records are retained for the periods set out in the “Data Retention” section below and are not used for any other purpose.
DATA RETENTION
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by applicable law. Our current retention periods are as follows:
Parent phone number and OTP verification records — Life of account + 90 days
Parent email address and name — Life of account + 90 days
Subscription and transaction metadata — Applicable financial-record retention period; 7 years recommended for transaction metadata
Consent records — Life of account + 7 years
Child Profile data — Life of account; deleted upon valid erasure request
Quiz sessions and answer data — Active period + 24 months, thereafter aggregate-only
Derived learner state and learning models — Same as underlying learning data; deleted with source data
Video progress, playlists and playback sessions — Active period + 24 months
AI transcripts and conversation records — Active period + 12 months
Speaking assessment data — Active period + 24 months
AI safety records — 24 months
Server logs — 180 days
Crash and error reports — 90 days
In-app analytics events — 14 months, thereafter aggregated
Push notification tokens — Life of installation
Child voice audio — Not retained by us as audio files
AI-generated voice output — Not retained by us
SERVICE PROVIDERS AND SHARING OF PERSONAL DATA
We may engage service providers and technology providers to process personal data on our behalf to operate, secure and provide the Platform and the Services. Depending on the Services used, these may include the following categories:
Authentication, database and hosting providers, including Supabase;
SMS and OTP service providers for Parent Account authentication;
Cloud infrastructure and logging providers, including Google Cloud;
AI and speech-processing providers, including Google Gemini;
Text-to-speech providers, including ElevenLabs;
Video streaming and digital rights management providers, including > VdoCipher;
Crash reporting and application monitoring providers, including > Sentry;
Push notification providers, including Firebase, where enabled; and
Application marketplace and subscription providers, including Google > Play.
Such service providers may access or process personal data only to the extent necessary to provide the relevant services to us. Certain systems used by us do not contain or process Child personal data. These include:
Qdrant, which is used for question-bank vectors;
Cloudinary, which is used for artwork and assets;
Anthropic Claude, which is used for curriculum/question-content > generation and does not receive User data;
Cloudflare, where used for free-tier video delivery, with access > tokens that are not child-identifying; and
the administrative review panel, which contains question content and > reviewer identities.
We do not sell personal data. We may also disclose personal data where required by applicable law, regulation, court order, legal process or governmental request, or where necessary to establish, exercise or defend legal claims.
INTERNATIONAL TRANSFERS
Some of our service providers may process personal data outside India. Depending on the Services used, such processing may involve:
Supabase, subject to the hosting region configured for the relevant project;
Google, including Google Gemini, Google Cloud, Google Play and Firebase, which may use global infrastructure;
ElevenLabs, including processing in the United States;
Sentry, including processing in the United States or European Union; and
VdoCipher, which processes relevant data in India.
We will take appropriate contractual, organisational and technical measures in relation towards such transfers to be carried out in accordance with applicable law.
COOKIES AND ANALYTICS
Our Website may use cookies and similar technologies that are necessary for functionality, security and performance. Where the Platform uses cookies or similar technologies, we may use them for functionality, security and analytics purposes. Where applicable law requires consent for a particular cookie or analytics technology, we will provide the relevant notice and consent mechanism. We do not use advertising SDKs or behavioural advertising identifiers in connection with Child Profiles.
DATA SECURITY
We implement reasonable technical, organisational and administrative measures designed to protect personal data against unauthorised access, use, disclosure, alteration, loss or destruction.
These measures include: (a) encryption of personal data in transit using industry-standard Transport Layer Security (TLS); (b) encryption of personal data at rest on our hosting and database infrastructure; (c) role-based access controls, so that personnel and service providers may access personal data only to the extent necessary for their function; (d) authentication of Parent Accounts through mobile number and OTP verification; (e) logging and monitoring of access to production systems; and (f) contractual security and confidentiality obligations imposed on our service providers.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Parents in the manner and within the timelines required under applicable law, and will comply with applicable CERT-In reporting obligations.
THIRD-PARTY PLATFORMS
The Platform may contain links to or content from third-party platforms, including YouTube and social media platforms. Information collected by such platforms is governed by their respective privacy policies and terms of use. We do not control their privacy practices.
CHANGES TO THIS PRIVACY POLICY
We may amend this Privacy Policy from time to time to reflect changes to the Platform, the Services, our data processing practices or applicable law. Where a material change affects the processing of Child personal data or previously provided consent, the Parent will be shown a summary of the changes and, where required, asked to re-confirm applicable consent before Child sessions continue. The updated Privacy Policy will be made available through the Platform with the revised “Last Updated” date.
GOVERNING LAW AND JURISDICTION
This Privacy Policy is governed by the laws of India. Any dispute arising out of or relating to this Privacy Policy or the processing of personal data by the Company shall be subject to the exclusive jurisdiction of the courts located in Navi Mumbai, Maharashtra, India.
ACCOUNT DELETION:
To delete your Peblo account and associated data, please visit https://www.mypeblo.com/delete-account for full details of the process.
GRIEVANCE OFFICER
For any questions, requests, grievances or concerns relating to this Privacy Policy, the processing of personal data, or any alleged breach of this Privacy Policy, you may contact our designated Grievance Officer at the details below:
Name: Sundar Ram
Email: finance@mypeblo.com
Address: A-103, Ist Floor Freight Forwarders Premises Co-op Society Ltd,Plot No.5, Sector I, Dronagiri, Uran, Raigad, NAVI MUMBAI, MAHARASHTRA 400707
Days and Timing: Monday to Friday, 10:00 AM to 6:00 PM, excluding public holidays.
We will acknowledge your grievance within seven (7) business days of receipt and will address the grievance within the period prescribed under applicable law.
