Privacy Policy
Last updated: 10 July 2026
Vegus OMR (“the Service”), operated by Rohith Boddeda, helps educational institutes create exams, scan OMR answer sheets, and grade them automatically. This policy explains what we collect, why, and the choices you have. By using the Service you agree to this policy.
What we collect
- Account information — your name, email address, password (stored only as a salted hash), and optional profile photo.
- Institute data— your institute’s name, team member accounts and invitations, exams, sections, questions, answer keys, and OMR sheet templates you upload.
- Scanned answer sheets — images of filled OMR sheets you capture or upload, detected answers, and grading results. These images may include student names or roll numbers your institute printed or wrote on them; your institute is responsible for having the right to process them.
- Student records — names and roll numbers your institute attaches to scans.
- Billing information — your subscription plan and payment status. Card, UPI, and bank details are collected and processed by Razorpay, our payment provider; we never see or store them.
- Technical data — session tokens (cookies) needed to keep you signed in, and standard server logs (IP address, timestamps) for security and debugging.
How we use it
- To provide the Service: scanning, grading, results, exports, and team access.
- To send essential email: account verification, password resets, team invitations, payment receipts and failures, renewal reminders, and usage-limit alerts. We do not send marketing email.
- To enforce plan limits and prevent abuse.
- To debug problems and keep the Service secure.
We do not sell or rent your data, and we do not use it for advertising.
Multi-tenant isolation
Every institute’s data is segregated by institute at the database-query level. Members of one institute cannot access another institute’s exams, templates, scans, students, or results.
Where your data lives
Data is hosted with our infrastructure providers: application hosting, database, and job queue on our cloud providers, and uploaded images in Cloudflare R2 object storage. Uploaded images are never publicly accessible — they are served only to authenticated members of the owning institute. Payments are processed by Razorpay (India); transactional email is sent via Resend.
Retention & deletion
- Deleting a scan deletes its image and detected answers.
- Deleting an exam deletes its sections, questions, answer key, template, bubbles, and scans, including stored images.
- To delete your account or your entire institute’s data, email rohithboddeda2008@gmail.com from your registered address; we complete deletion within 30 days, except records we must keep for tax or accounting law.
Children
The Service is for institutes and their staff, not for children. Scanned sheets may contain student information; the institute (as the party collecting it) is responsible for any consent required from students or guardians.
Security
All traffic is encrypted in transit (HTTPS). Passwords are hashed, sessions are httpOnly cookies, payment webhooks are signature-verified, and uploads are tenant-scoped. No system is perfectly secure; report concerns to rohithboddeda2008@gmail.com.
Changes & contact
We will update this page (and its date) when the policy changes materially. Questions or requests: rohithboddeda2008@gmail.com. Operated by Rohith Boddeda, India.