Policy

Privacy Policy

Effective date: February 22, 2026. Last updated: July 2, 2026.

Chorcha Ghor / চর্চা ঘর ("we", "our", "us") provides educational services through the Chorcha Ghor app and website. This Privacy Policy explains, in plain language, what information we collect, why we use it, where it is stored, and what choices you have when you use SSC, BCS, Python, English, Scholarship, Tutor, account, and admin features.

1. Authentication and Access Control

You can use the app with email/password login or with a Firebase anonymous account for explore mode.

  • If a protected SSC/BCS MCQ or short-question or english/python dataset is opened without an existing signed-in account, an anonymous Firebase account may be created automatically.
  • Firebase authentication tokens (JWT) are used to authorize protected API requests to AWS services.

1.1 Android App Permissions

The Android version declares these permissions in AndroidManifest.xml:

  • android.permission.INTERNET -> Used to connect to Firebase Authentication, Firestore, AWS content APIs, load learning data/images, submit reports, tutor/scholarship requests, and open external links. This is required for normal online app features.
  • android.permission.ACCESS_FINE_LOCATION -> Requested only when you use tutor location features and choose to share precise location, such as finding nearby tutors or saving a tutor listing location. It is not used in the background.
  • android.permission.ACCESS_COARSE_LOCATION -> Requested only when approximate location is enough for tutor distance/search or tutor listing location. If location permission is denied, manual location input is still available.

Location permissions are optional and are not required for SSC, BCS, Python, English, or scholarship reading features.

2. Content Source Transparency

This section describes educational content sources and ownership claims.

  • SSC MCQs are based on Bangladesh government education board questions (Dhaka, Rajshahi, Khulna, Barishal, Sylhet, Chattogram, Dinajpur, Cumilla, Jashore, and Mymensingh) from 2015 to 2023.
  • Chorchaghor is not a government app and does not represent any government entity, education board, or public service commission.
  • For official BCS information, users should verify details from the Bangladesh Public Service Commission website: https://bpsc.gov.bd/
  • For official SSC curriculum, textbook, or syllabus information, users should verify details from official sources such as the Ministry of Education website https://moedu.gov.bd/ and the National Curriculum and Textbook Board website https://nctb.gov.bd/
  • No questions from private institutions are intentionally used in SSC and BCS MCQ datasets.
  • SSC short questions are prepared by our team.
  • Some MCQs include images/diagrams created by our team; we do not intentionally use institution-owned diagrams.
  • BCS MCQs are based on previous Bangladesh government commission exam questions.
  • Scholarship listings are informational posts and must be verified through each official university, scholarship provider, or application link before applying.
  • We do not claim ownership of official government exam notices, syllabuses, or previous exam questions. Where official/public exam materials are used for educational practice, they are provided with source transparency and users should verify against the official source. This is not a claim that all materials are copyright-free.
  • Python and English learning materials are created or managed by our team, and additional modules may be released over time.

3. Information We Collect

a) Account and technical identifiers:

  • Email address and password authentication data when you register or login with email/password.
  • Firebase user ID, anonymous account ID, authentication tokens, and similar account identifiers used to keep the app secure.
  • Device or installation identifiers used by Firebase, Android, or backend services for app functionality, security, fraud prevention, and abuse prevention.

b) User-submitted and listing data:

  • Tutor profile details such as display name, subjects, phone number, email address, WhatsApp contact, avatar/photo URL, bio, education, monthly fee, location name, and optional latitude/longitude if you choose to share location.
  • Tutor profile approval requests, moderation status, review decisions, and related notes used by authorized project administrators to approve or reject tutor profiles.
  • Scholarship information submitted for review, such as selected university, country, scholarship name, level, intake, application period, scholarship type, details, official university websites, and application links.
  • Public scholarship records published by authorized project administrators after review. Scholarship submissions do not require a WhatsApp number or personal contact number.
  • The Firestore university list used for scholarship submissions, including canonical university names, normalized university keys, timestamps, and the administrator account that added the university.
  • Question reports, profile updates, scholarship submissions, tutor profile content, and support/contact messages you submit.

c) Internal moderation and administrator data:

  • Internal permission fields used for tutor-profile approval and project administration. Project administrator access is managed directly by the project owner through Firebase Console or Admin SDK and is not granted from the public app or website.
  • Administrator tools are used for internal web/backend management and are not a normal mobile-app role for users.
  • Review records for tutor approvals, scholarship submissions, reported questions, and public scholarship changes.

d) Location:

Location permission is requested only for tutor-related features. If granted, approximate or precise location may be used to calculate distance, show nearby tutors, or save a tutor listing location when the user chooses to publish a tutor profile. If denied, manual location input is still available.

e) App activity and learning data:

  • App interactions such as opening protected learning content, submitting question reports, managing tutor profiles, and submitting scholarship information.
  • Quiz, SSC/BCS, Python, English, scholarship, and tutor content may be cached locally to make the app faster and available with fewer repeated downloads.

f) External service interactions:

When you open YouTube, WhatsApp, university portals, application links, or other external links, those services handle your interaction under their own policies.

4. Content Delivery, Encryption, and Cache

SSC/BCS and other protected learning datasets are delivered via AWS (including S3-backed content/API routes) with JWT-authorized access.

  • Data is encrypted in transit using HTTPS/TLS.
  • On Android, protected question data may be stored in encrypted local cache after first fetch.
  • On web/browser experiences, browser storage may be used for local cache; browser storage security depends on the browser and device environment.
  • When shown in the UI, cached data is loaded only for app functionality.
  • Learning cache older than about 60 days is automatically cleaned.
  • Some question images are delivered via GitHub + CDN and may be cached locally for faster loading.

5. Feature-Specific Notes

  • SSC includes MCQ, short questions, and topic-based video links. Video links open public YouTube videos owned by third parties.
  • BCS includes MCQ and MCQ images with caching behavior similar to SSC. BCS currently has no short-question section and no video section.
  • Scholarship data and the approved university list are fetched from Firestore and do not use the same long-term question-bank cache model.
  • Signed-in users can submit scholarship information only for universities selected from the approved Firestore university list. Authorized project administrators can approve, reject, publish, update, or remove public scholarship records.
  • Tutor listings can be added/updated by tutors, and students can contact tutors via email, phone, and WhatsApp actions.
  • Project administrator access is not a normal mobile-app role and is not granted from the public app or website. The project owner manages this access directly in Firebase.

6. How We Use Information

  • Provide learning features (SSC, BCS, Python, English, tutor, scholarship).
  • Authenticate users, manage accounts, and secure API access.
  • Enable tutor search and user-initiated contact via WhatsApp.
  • Accept scholarship submissions for review and publish approved scholarship information for students.
  • Maintain one public scholarship page per approved university and prevent duplicate entries caused by spelling differences.
  • Operate, maintain, troubleshoot, and improve app performance and safety.
  • Respond to user reports, support requests, moderation, and compliance needs.

8. Sharing and Disclosure

We do not sell or rent personal information. We do not share personal information with third parties for advertising or marketing.

Service providers such as Firebase, AWS, GitHub/CDN, hosting providers, and browser/mobile platform services may process data only as needed to operate, secure, and deliver the app. External services such as YouTube, WhatsApp, university portals, and application links are opened by user action, and their own privacy policies apply to activity on those services.

We may disclose information if required by law, to enforce our terms, to investigate abuse, or to protect users, the public, and the service.

9. Data Retention

  • Local learning cache: up to about 60 days.
  • Locally cached question images: retained by app/device cache policy.
  • Account and profile data: kept while your account is active, unless deletion is requested.
  • If you delete your account in-app, we delete your authentication account and associated user profile data we control (such as users/{uid} and your reported question records).
  • Tutor records: kept until updated or removed by the tutor or an authorized project administrator, subject to safety and legal retention needs.
  • Scholarship submissions and public scholarship records: kept until reviewed, updated, rejected, removed by an authorized project administrator, or no longer needed for the service.
  • Approved university list records: kept while the scholarship feature needs those canonical names.
  • If your account has linked tutor profile data or public scholarship ownership, account deletion is blocked until those linked records are removed.
  • Reported question records: kept as needed for review, support, and safety operations.
  • Deletion requests are normally reviewed and processed within 30 days after we can verify the requester and account ownership.
  • Some backup, security, fraud-prevention, abuse, or legal-compliance records may be retained for up to 90 days unless a longer period is required by law or necessary for an active investigation.
  • For tutor discovery, we store tutor listing data for display; we do not intentionally store separate student profile data beyond authentication and technical operation data.

10. Security

We use reasonable technical and organizational safeguards, including HTTPS/TLS encryption for data in transit, Firebase authentication, token-based API access, least-privilege backend access, Firestore security rules, manual administrator assignment, and managed access controls on backend services.

11. User Controls and Rights

  • You may request access, correction, or deletion of personal data we hold.
  • For email/password accounts, you can delete your account in-app from Profile > Delete Account by confirming your account email and password.
  • Account deletion is not available until linked tutor profile data and scholarship records you own are removed first.
  • Internal administrator accounts may require manual review/support and might not be eligible for direct in-app self-deletion.
  • You may also request account deletion or data actions by contacting us at office@chorchaghor.com.
  • You may request deletion of specific data, such as tutor profile data or support/report records, without deleting your full account where technically and legally possible.
  • Tutors can delete their own tutor profile directly from the Tutor profile page.

12. Children and Minors

Our service is not directed to children under 13. We do not knowingly collect personal information from children under 13 without required consent. If we learn such data was collected, we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Updated versions will be posted in the app and/or website with a revised "Last updated" date.

15. Contact Us

For privacy questions, data requests, or deletion requests: Email: office@chorchaghor.com App: Use the in-app Contact/Support option