Security & Data Protection
Last updated: 2 August 2026
Ministry of Exchange is operated by Nikshala AI. Here’s exactly how we protect student data — no vague claims, just what’s actually built.
Passwords
Every password is hashed with bcrypt before storage. Nobody, including our own team, can ever see a user’s actual password, even in the event of a data breach.
Data in transit
All data moving between your device and our servers is encrypted over HTTPS — standard, industry-wide protection against interception.
Sensitive data at rest
Private messages (direct messages, cohort group messages, trip/plan comments) and WhatsApp numbers are encrypted in our database itself, not just protected by access controls. This means even someone with direct access to a database backup or export cannot read this data without going through our application’s own controlled decryption process.
To be precise about what this does and doesn’t mean: this is encryption at rest with controlled server-side decryption for legitimate access paths (you reading your own messages, a mutual connection revealing a WhatsApp number, or an admin reviewing a specifically reported conversation). It is not end-to-end encryption, where even we could never decrypt the data under any circumstance. We believe in being exact about this distinction rather than overstating it.
Who can see what
- WhatsApp numbers stay completely hidden from other students until both sides have mutually accepted a connection. Even our own team can only reveal a number through a specific, logged action — never standing access.
- Private messages are not accessed by our team by default. Access only happens if a student specifically reports a conversation for a safety concern, and every single review is logged: who accessed it, when, and why.
- Usage analytics are aggregate and funnel-level only. We do not maintain a browsable log of any individual person’s click-by-click activity.
Account deletion
You can delete your account at any time. Deletion is soft with a 14-day reversible grace period (you can undo it via a link sent to your email), then permanently purged — consistent with GDPR’s right to erasure.
Compliance
We operate under both the EU’s GDPR (since our students are physically in EU host countries) and India’s DPDP Act 2023 (as an Indian entity). We build to satisfy the stricter of the two, not the minimum of either.
Questions
If your institution’s IT or legal team wants to review our practices in more detail, contact us at nd@nikshala.com or +91 82639 07201. We’re happy to walk through any of this directly.
See also our Privacy Policy and Terms & Conditions.