Legal

Privacy Policy

Last updated 29 July 2026

In short: we collect what Libly needs to run your library and nothing more, we never sell your data, and the student records you enter belong to you. The detail is below.

Who this policy covers

Libly is operated from India and provides software that library owners use to run study halls, reading rooms and coaching libraries. This policy applies to two groups of people, and the distinction matters.

If you sign up for a Libly account to run your library, you are our customer and we handle your data as described below. If you are a student whose details were entered into Libly by a library you attend, that library decides what to collect and why — they are the data fiduciary, and Libly stores and processes that information on their instructions. Requests about a student record should go to the library first.

What we collect

We collect only what the product needs to function. We do not buy data about you from third parties, and we do not build advertising profiles.

  • Account information you give us when signing up: name, email address, phone number and your library's name.
  • Student records you enter: student name, phone number, seat and shift allocation, plan, fee history and attendance.
  • Payment records: amounts, dates, plan type and receipt numbers. Card and UPI credentials are handled by the payment provider and never stored on Libly's servers.
  • Usage data: pages visited, approximate location derived from IP address, browser and device type, collected via Google Analytics and Vercel Analytics.
  • Support correspondence: messages you send us by email, phone or WhatsApp.

Cookies and similar technologies

We use a small number of cookies, and none of them are for advertising.

  • A session cookie that keeps you signed in. Removing it signs you out.
  • A referral cookie set when you arrive via a link containing a ref code, so the person who referred you is credited. It lasts 30 days.
  • An affiliate cookie set when you arrive via a link containing an aff code, used for the same purpose on our affiliate program. It lasts 30 days.
  • Analytics cookies set by Google Analytics to measure aggregate traffic.

How we use your information

  • To operate your library: allocating seats, tracking shifts, recording fees and generating receipts.
  • To send the automated WhatsApp and in-app reminders you configure, such as fee-due and plan-expiry notices to your students.
  • To provide support when you contact us.
  • To bill you if you move onto a paid plan, and to credit affiliate or referral commissions where they apply.
  • To understand aggregate product usage so we can decide what to build next.
  • To detect and prevent fraud, abuse and security incidents.

Who we share it with

We do not sell your data. We share it only with the service providers needed to run Libly, and only to the extent each one needs.

  • Supabase — database hosting and authentication.
  • Vercel — application hosting and privacy-friendly analytics.
  • Google Analytics — aggregate traffic measurement.
  • Our WhatsApp messaging provider — to deliver the reminders you schedule.
  • Our payment provider — to process subscription payments.
  • Law enforcement or regulators, where we are legally required to respond.

Where your data is stored

Libly's database and application are hosted on infrastructure configured for Indian-region storage where the provider supports it. Some of our service providers, including analytics, may process limited data outside India. Where that happens we rely on the provider's contractual data-protection commitments.

How long we keep it

We keep your account and library data for as long as your account is active. If you close your account, we delete your library's operational data within 90 days, except where we are required to retain financial records for tax and accounting purposes — in India that is generally eight years for payment and invoice records.

Backups are retained on a rolling basis and are overwritten in the ordinary course, so deleted data may persist in backups for a short period after removal from the live system.

Your rights

Subject to applicable Indian law, including the Digital Personal Data Protection Act 2023, you can ask us to do the following.

  • Access the personal data we hold about you.
  • Correct information that is inaccurate or incomplete.
  • Delete your account and the data associated with it, subject to the retention exceptions above.
  • Export your library's data in a machine-readable format.
  • Withdraw consent for non-essential processing, such as analytics.
  • Complain to the Data Protection Board of India if you believe we have mishandled your data.

Security

Data is transmitted over HTTPS and stored in a database protected by row-level security policies, so one library's records are not reachable from another library's account. Passwords are hashed, never stored in readable form. Access to production data by our team is limited to what is necessary to provide support.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authority as required by law.

Children's data

Libly is sold to library operators, not to students directly, and it is not designed for children under 18 to use on their own. Where a library enters records for a student under 18, the library is responsible for obtaining the consent required by law from a parent or guardian.

Changes to this policy

We will update this page when our practices change and revise the date at the top. If a change materially affects how we handle your data, we will tell you by email or an in-app notice rather than relying on you to re-read this page.