This policy describes the public guidance website as it operates today. We do not run
student accounts, we do not ask for your name or email to read anything, and we do not
run advertising or analytics trackers. Where data is collected, it is set out below in
specific terms rather than general ones.
Last updated 5 August 2026Applies to indiancareerguide.comAccounts Not yet available
In short
The short version
You can read every public page without giving us any personal information.
There are no student accounts yet, so there is no profile, no password and no saved history.
We do not use advertising cookies, behavioural tracking or third-party analytics.
We do not sell, rent or share personal data with data brokers, colleges or coaching institutes.
Fonts are loaded from Google's servers, which means Google receives your IP address. This is the one third party involved in an ordinary page view.
We never ask for Aadhaar, marksheets, application IDs or payment details.
This summary is for readability. The sections below are the operative policy, and
they govern if there is any inconsistency between the two.
Specifics
What is actually collected
Rather than list every category a website could theoretically collect, here is what
this site does collect, and why:
Nothing, to browse
Reading guides, courses, careers, exams, comparisons and the calendar requires no registration and no personal details.
Search terms
Words you type into the site search are sent to our server to return results. They are processed to answer the request and are not linked to an identity.
Technical error logs
When a page fails, we record the technical fault details, the file and line involved, and the time. These records are kept to fix defects. They do not contain your name, email or IP address.
Server and hosting logs
Like any website, our hosting infrastructure processes standard request data — including IP address, browser type and requested page — to deliver pages and defend against abuse.
Staff audit records
Actions taken by our own editorial and administrative staff inside the internal admin panel are logged, including the staff account, the change made, IP address and browser. This applies to our staff, not to public visitors.
Rate-limit checks
Sign-in attempts to the internal admin area are rate-limited per IP address to resist brute-force attacks. This check happens in memory and is not stored as a profile.
We do not operate newsletters, contact forms, lead-generation forms or "get a call back"
widgets on this site. If you ever see one, treat it as suspicious and report it.
Cookies
Cookies we set
We use a deliberately small number of cookies, all of them strictly necessary for the
site to function securely. We do not use advertising, profiling or analytics cookies.
ICG.AntiForgery
A security cookie that protects form submissions against cross-site request forgery. Strictly necessary. Set with HttpOnly and a strict same-site policy.
ICG.Auth
Signs in members of our own editorial and administrative team to the internal admin area. Ordinary visitors never receive this cookie. It expires after eight hours of inactivity.
Because these cookies are strictly necessary for security and access control, they do
not require consent under standard cookie rules. If we ever introduce analytics or any
non-essential cookie, we will ask for your consent first and update this section before
it is switched on.
Third parties
Who else is involved in a page view
We keep third parties to a minimum, but we should be precise about the ones that exist:
Google Fonts. Typefaces are loaded from Google's servers. To deliver
those files, Google necessarily receives your IP address and basic request information.
We do not send Google any other data about you, and we do not use Google Analytics,
Google Ads or any Google tracking product on this site.
Our hosting provider. Processes requests on our behalf to serve pages
and maintain security.
Links to official exam authorities, universities and government portals point to sites
we do not control. Once you follow one, that site's own privacy policy applies, not ours.
Important
Students under 18
A large share of our readers are school students, many of them under 18. Indian law —
in particular the Digital Personal Data Protection Act, 2023 — treats anyone under 18
as a child and places strict obligations on anyone processing their personal data,
including a requirement for verifiable parental consent and a prohibition on tracking,
behavioural monitoring and targeted advertising directed at children.
Our current design is the simplest way to respect that: we do not collect
personal data from any visitor, of any age, to read this site. There is no
account, no profile, no behavioural tracking and no advertising.
Before student accounts launch, we will publish an updated policy
covering age assurance, parental consent and the additional protections children are
entitled to. Accounts will not be opened to under-18 users until those safeguards are
in place.
If you believe a child's personal data has reached us in any way, contact us and we
will delete it.
Purpose
How the information is used
The limited data described above is used only to:
Deliver the pages you request and keep the site available.
Diagnose and fix defects reported through the error log.
Protect the site against abuse, brute-force attempts and automated scraping.
Maintain an internal record of who changed published content, and when.
Understand which sections need better coverage, in aggregate and without identifying individuals.
We do not use it to build advertising profiles, to score or rank individuals, or to
make automated decisions about anyone.
Disclosure
Sharing and selling
We do not sell personal data. We do not share it with colleges,
coaching centres, admission consultants, lead-generation companies or data brokers.
This matters in our sector: student contact data is routinely traded in Indian
education, and we have chosen not to participate in that market.
We disclose information only where:
A service provider processes it strictly on our behalf under contract, such as our hosting provider.
We are required to by law, a court order, or a lawful request from a competent authority.
It is necessary to investigate a security incident, prevent fraud, or protect the rights and safety of users.
Retention
How long records are kept
Technical error logs — kept while the defect is open and for a reasonable period after it is resolved, then cleared.
Staff audit records — retained for accountability over published content changes.
Hosting logs — retained for a short operational period for security and diagnostics.
Session cookies — the admin session cookie expires after eight hours of inactivity; the antiforgery cookie ends with the browser session.
Security
How the site is protected
No system is perfectly secure, but the following measures are in place today:
All traffic is served over HTTPS, with HTTP Strict Transport Security enabled.
Security response headers are applied to every request.
Session and antiforgery cookies are HttpOnly, same-site restricted and secure in production.
The administrative area sits behind a non-obvious address, role-based authorisation and rate-limited sign-in.
Administrative passwords must meet length and complexity requirements, with lockout after repeated failures.
Records are soft-deleted with an audit trail rather than silently destroyed.
Your rights
Your rights over your data
Under Indian data protection law you have rights to access, correct and erase your
personal data, to withdraw consent, and to raise a grievance. In practice, because we
do not collect personal data from visitors, there is usually nothing held about you to
retrieve or delete.
If you believe we hold personal data about you, you may contact us to ask what is held,
to have it corrected, or to have it erased. We will respond within the timelines
required by applicable law. See the contact page for how to
reach us and how to mark a message as a privacy request.
A named grievance officer and published contact address will be added here before the
public launch, as required for Indian websites.
Changes
Changes to this policy
This policy will be updated when the site's functionality changes — most significantly
when student accounts, saved shortlists or the AI advisor are introduced, each of which
will involve collecting information we do not collect today.
When that happens we will revise this page, update the "last updated" date at the top,
and describe what changed. Material changes affecting personal data will be announced
on the site before they take effect.
This policy is written to describe our actual practices, not to serve as legal advice.
Before public launch it should be reviewed by a qualified Indian data protection
practitioner, together with the grievance officer details and the additional
protections required for users under 18.
Your AI guide
Ask about courses, exams and careers
AI can make mistakes. Always confirm dates, fees and eligibility with the official
authority before you apply. Disclaimer