Privacy & Data Protection Policy

DOCUMENT REF: NOE-POL-2026-V1.4 | LAST REVISED: AUGUST 2026 | STATUS: ACTIVE

This Privacy & Data Protection Policy ("Policy") governs the data collection, processing, and storage protocols of Noesis ("Company", "we", "us", or "our") across our browser extensions, web applications, and integrated application programming interfaces (collectively, the "Services").

By accessing or utilizing the Services, you ("User", "Data Subject") explicitly consent to the data practices described in this document. This Policy is engineered to comply with global data protection frameworks, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Digital Personal Data Protection Act (DPDP).

1. Definitions and Scope

2. Data Collection Architecture

We operate on a principle of data minimization. The Services collect only the exact telemetry required to execute core functional pathways.

2.1. Account and Identity Data

Authentication is routed securely via OAuth 2.0 standards. We collect your encrypted email address, designated profile nomenclature, and a unique cryptographic user identifier. Passwords are never stored on Noesis infrastructure.

2.2. Contextual Query and RAG Payloads

When you initiate an active scan of a DOM environment (webpage extraction) or submit a query, the payload is converted into high-dimensional vector embeddings. This data is utilized strictly for Retrieval-Augmented Generation (RAG) against our proprietary, verified educational database to generate deterministic responses.

3. Sub-Processor Infrastructure

4. Authorized API Integrations (Google Workspace)

Noesis requests scoped access to the Google Tasks API (https://www.googleapis.com/auth/tasks) exclusively for the programmatic scheduling of user-initiated study reminders. Noesis complies fully with the Google API Services User Data Policy, including the Limited Use requirements. We do not read, scrape, or persistently cache unauthorized calendar or task metadata.

5. User Data Rights and Sovereignty

Depending on your global jurisdiction, you are entitled to comprehensive data sovereignty rights:

To execute a data request, submit a formal inquiry to our Data Protection Officer (DPO) at legal@noesis.app. Compliance requests are executed within 30 standard business days.

6. Governing Law and Jurisdiction

This Policy, and any disputes arising directly or indirectly hereunder, shall be governed by and construed in accordance with the laws of India, without regard to its conflict of law provisions. Both parties consent to the exclusive jurisdiction and venue of the competent courts located in Hyderabad, Telangana, for the resolution of any legal proceedings related to this platform.