Privacy Policy
Last updated: 7 August 2026
This policy explains what personal data Craw Security collects through the Craw LMS Android app (package in.craw.lms) and the website at lms.craw.in, why we collect it, who we share it with, and how you can have it deleted. The app and the website are one service and share one account, so this policy covers both.
1. Who we are
Craw Security (“we”, “us”), New Delhi, India, operates Craw LMS — the learning platform used by students enrolled in our cybersecurity training courses. We are the data controller for the personal data described below.
2. Information we collect
Information you give us
- Account details — your name, email address, phone number and password. Passwords are stored only as a salted hash; we never see or store your password in readable form.
- Profile photo, if you choose to upload one.
- Support tickets and class chat — the messages you send, and any image or document you choose to attach. The app asks for access to your photos or files only at the moment you pick an attachment, and reads only the file you select.
- Course activity you generate — notes and bookmarks you save, quiz and exam answers you submit, and course reviews you write.
Information collected automatically
- Learning progress — chapters completed, quiz and exam results, class attendance, certificates issued, and which courses you are enrolled in.
- Push notification token — a device token issued by Google Firebase Cloud Messaging, used only to deliver notifications to your device. You can revoke it at any time by turning off notifications for the app.
- Session and device data — a device identifier and sign-in timestamps, used to keep you signed in, to show you your active sessions, and to sign you out of every device when you ask.
- Technical logs — IP address, request time and error details, kept briefly to keep the service secure and to diagnose faults.
If you sign in with Google
We receive your name, email address, profile photo and the fact that Google has verified your email. We do not receive your Google password and we request no access to your Gmail, Drive, contacts or any other Google service.
What we do not collect
We do not collect your location, your contacts, your call or SMS logs, or the contents of your device storage. We do not use advertising identifiers, we run no third-party advertising or analytics SDKs in the app, and we do not track you across other apps or websites.
3. How we use your data
- To create your account and sign you in securely.
- To give you access to the courses, live classes, batch chat, attendance records and certificates you are enrolled in.
- To record and show your learning progress and exam results.
- To send you notifications about your classes, announcements, trainer availability and account activity.
- To answer your support tickets.
- To process payments for courses, exams and store purchases.
- To keep the service secure — detecting abuse, preventing fraudulent sign-ins, and enforcing our terms.
- To meet our legal, tax and academic record-keeping duties.
We process this data because it is necessary to provide the service you signed up for, because you consented (for example, to push notifications), or because we have a legal obligation to keep certain financial and academic records.
4. Who we share it with
We do not sell your personal data, and we do not share it for advertising. We share it only with the following, and only as far as each needs it to do its job:
- Google (Firebase Cloud Messaging) — receives your device push token in order to deliver notifications to your phone.
- Google Sign-In — if you choose to sign in with Google, to verify your identity.
- Stripe — our payment processor. Card details are entered on Stripe’s systems and are never sent to or stored on our servers; we retain only the transaction reference and the amount paid.
- Craw Security’s internal training system — our own batch management system, which holds live class schedules, attendance, trainer chat and support tickets. Your name, email and enrolment details are shared with it so those features work.
- Our email provider — to send verification codes, password resets and course announcements to your email address.
- Authorities — where we are legally required to disclose data, or where it is necessary to establish or defend a legal claim.
5. How long we keep it
We keep your account data for as long as your account exists. If you delete your account, we erase your personal data as described below. Records of payments, orders and certificates issued to you are kept in anonymised form afterwards, because they are financial and academic records we are required to retain — once your account is erased they can no longer be linked back to you.
6. Deleting your account and your data
You can delete your account at any time, either from inside the app (Profile → Delete account) or on the web at lms.craw.in/account/delete. You do not need to install the app to use that page.
When you request deletion you are signed out of every device immediately. The request is then held for 14 days, during which you can sign back in and cancel it with nothing lost. After that we permanently erase your name, email address, phone number, profile photo, password, saved notes, bookmarks, notifications and push notification tokens.
You may also ask us to access, correct or export your personal data, to withdraw consent, or to object to a particular use of it. Write to us at the address in section 10 and we will respond within 30 days.
7. How we protect your data
- All traffic between the app and our servers uses HTTPS.
- Passwords are stored as salted hashes and are never recoverable in readable form.
- On your device, sign-in tokens are kept in the platform’s encrypted secure storage (Android Keystore), not in plain app files.
- Sign-in sessions expire automatically, are refreshed with rotating tokens, and are revoked across all your devices if we detect a stolen token.
- Access to student data by our staff is limited to the roles that need it.
No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority as required by law.
8. Children
Craw LMS is intended for students aged 16 and above and is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has given us personal data, contact us and we will delete it.
9. Changes to this policy
If we change how we handle your data we will update this page and change the “last updated” date above. For significant changes we will also notify you in the app or by email.
10. Contact us
For any question about this policy, or to exercise any of the rights described above, write to us at support@craw.in.