Unofficial student app · Draft for legal review
Privacy Policy Package
1 · Short list of missing information
Resolve these before the policy can be published.
- Effective date of the policy
- Privacy contact email
- Developer/business legal name
- Website URL
- Account-deletion URL or process — no in-app deletion flow exists yet in the code (see §22)
- Developer/business legal location (state/country) — determines which laws apply
- Hosting provider confirmation — a Vercel cron config exists in the code, suggesting Vercel hosting, but this should be explicitly confirmed
- Data retention period — no retention schedule is currently defined in the app
- Whether Google Sign-In will be added — the current build only supports email/password sign-in
- Whether push/email notifications will be activated — the database supports notification records, but no delivery service is wired in yet
- Whether an AI extraction service will be activated — an API key placeholder exists but is unused; extraction currently runs on a deterministic (non-AI) parser
- Backup retention/removal timeframe on Supabase's side
2 · Complete Privacy Policy
Privacy Policy for KIIT Pulse
Effective Date: [EFFECTIVE DATE]
01Introduction
This Privacy Policy explains how KIIT Pulse ("the App," "we," "us") collects, uses, stores, and protects information when you use our mobile application and website. Please read this policy carefully. By using KIIT Pulse, you agree to the practices described here.
If you do not agree with this policy, please do not use the App.
02About KIIT Pulse
KIIT Pulse is a student productivity tool that helps students access:
- Personalized class timetables
- Placement and internship opportunities
- Application deadlines and countdown timers
- Placement preparation resources and past-year papers
- Notices and announcements from the college's placement and academic teams
- Personal tracking of their own job/internship applications
- A basic student profile
- In-app notifications and reminders (see §14 for the current status of push notifications)
03Independent and Unofficial Status
KIIT Pulse is an independently operated, unofficial application. It is not created, endorsed, hosted, or officially affiliated with KIIT (Kalinga Institute of Industrial Technology) or KIIT Deemed to be University, unless explicitly stated otherwise in writing. Notices, timetables, and placement information displayed in the App are sourced from documents uploaded by App administrators for informational convenience and may be incomplete, delayed, or contain errors. Always verify time-sensitive information (such as application deadlines) against your college's official channels.
04Information Users Provide
When you use KIIT Pulse, you may provide:
- Account information: email address and password, used to create and sign in to your account.
- Academic/student profile information: full name, roll number, branch, batch/graduating year, semester, section, and CGPA. Backlog status may also be recorded to help determine placement eligibility.
- Contact information: phone number (optional field).
- Profile photo: the App's database includes an optional field for a profile picture. Is a photo-upload feature currently active for students, or is this field reserved for future use?
- Application activity you record: which opportunities you mark as interested, applied, or otherwise track, along with any personal notes you choose to add to an application.
- Notification preferences: your choices about which types of alerts you want to receive.
We do not currently provide a feature for students to upload resumes, personal documents, or other files through the App. Confirm if this changes in a future version.
05Information Collected Automatically
Some technical information may be collected automatically as part of operating the App and its hosting/database infrastructure, such as:
- Basic request/server logs generated by our hosting provider
- Timestamps of account actions (e.g., sign-in, application status changes)
- File size and file type metadata for documents uploaded by administrators (not by students)
06Google Sign-In and Authentication Data
KIIT Pulse currently uses email-and-password authentication through our backend provider, Supabase Auth. Google Sign-In is not currently implemented.
Your password is not stored by us in readable form; authentication is handled by Supabase Auth using industry-standard password hashing.
07Student Profile and Academic Information
To personalize your timetable and to show you relevant placement opportunities, we ask for academic details including your branch, batch, semester, section, and CGPA. This information is used only to:
- Show you your correct class schedule
- Help you understand whether you may be eligible for a given placement or internship opportunity
Eligibility information shown in the App is for your convenience only and is never used to prevent you from viewing an opportunity, applying, or being considered by a recruiter — final eligibility is always determined by the recruiter/college placement team.
08Timetable, Placement, Application, and Notice Data
- Timetable data is uploaded by timetable administrators and matched to your section to build your personal schedule view.
- Placement and internship opportunity data is uploaded by placement administrators, reviewed, and published for eligible/relevant students to view.
- Your application-tracking data (status such as "applied," "shortlisted," "interview scheduled," notes, etc.) is private to your account. Placement administrators can view your application status and may also publish official status updates (e.g., "shortlisted"), but they do not have the ability to edit your personal notes.
- Notices and events are published by administrators and may be shown to all students or only to students in a targeted batch/branch.
09Uploaded Files and Documents
Administrators (not students) upload original documents — such as PDF notices, scanned notices, images, Word documents, and spreadsheet timetables — so that the App can extract and display structured information. Original uploaded files are retained and can be viewed by students via a "View Original Notice" link where applicable, so you can always verify the source document.
Uploaded documents are stored in a private storage location and are only made accessible through short-lived, secure links generated by our system; they are not publicly browsable.
10AI-Assisted Document Processing
KIIT Pulse currently extracts structured information (such as company name, deadlines, eligibility criteria, and CTC/stipend figures) from uploaded documents using automated pattern-matching (not a third-party AI service). This extracted information is always reviewed and approved by a human administrator before it is published or shown to students — it is never published automatically.
11How Information Is Used
We use the information described above to:
- Create and secure your account
- Display your personalized timetable
- Show you placement/internship opportunities and notices relevant to your batch, branch, and eligibility
- Let you track your own applications
- Send you in-app notifications and reminders you have opted into
- Maintain the accuracy and integrity of published notices (e.g., detecting when a document extends an existing deadline rather than creating a duplicate listing)
- Keep basic records (audit logs) of administrator actions, such as who published or edited a notice, for accountability and troubleshooting
- Maintain and improve the App's functionality and reliability
We do not use your information for advertising. KIIT Pulse does not currently display advertisements.
12Legal Basis or Purpose of Processing
13Cookies and Similar Technologies
The KIIT Pulse website and app may use essential cookies or local storage required for you to stay signed in and for the App to function correctly.
14Push Notifications and Device Permissions
KIIT Pulse's database supports several types of notifications (e.g., new eligible opportunity, deadline approaching, timetable change). Currently, these are delivered as in-app notifications only.
15Third-Party Services
KIIT Pulse relies on the following third-party service provider to operate:
- Supabase (database, authentication, and file storage provider). Supabase processes and stores your account credentials, profile data, application data, and uploaded documents on our behalf, in accordance with Supabase's own privacy and security practices. Link to Supabase's current privacy policy and confirm the data region/hosting location used for our project.
Services NOT currently used by KIIT Pulse (listed here for clarity and to avoid overstating our practices):
- No Google Analytics, Firebase Analytics, Crashlytics, Sentry, or similar analytics/crash-reporting service is currently integrated.
- No advertising network is integrated.
- No payment processor is integrated.
- No Firebase Cloud Messaging or other push notification service is currently active (see §14).
If any of the above are added in the future, this Privacy Policy will be updated before that feature is activated, and this section will name the specific provider.
16External Placement and Application Links
Some placement and internship opportunities in KIIT Pulse include a link that takes you to an external website to complete your application — for example, a company's own careers portal or a recruitment platform used by the placement cell (such as Superset). When you click these links, you leave KIIT Pulse and become subject to that third party's own privacy policy and terms. We do not control, and are not responsible for, the privacy practices of these external sites. Please review their policies before submitting any information.
Separately, KIIT Pulse also lets you record your own application status (e.g., "applied," "interview scheduled") within the App, whether or not your actual application was submitted on our platform or an external one. This tracking data stays within KIIT Pulse.
17Data Sharing and Disclosure
We do not sell your personal information. We may share information in the following limited circumstances:
- With our service providers (currently Supabase, and — pending confirmation — our hosting provider) strictly to operate the App, under their own data-processing terms.
- With college placement administrators, who — as part of the App's core function — can view students' application status and academic eligibility data relevant to placement drives they manage.
- If required by law, such as in response to a valid legal request from a court or government authority.
- In connection with a business transfer, such as a merger or acquisition of the App, in which case affected users would be notified.
18Data Storage and International Processing
Your information is stored using Supabase's cloud infrastructure.
19Data Retention
20Data Security
We use reasonable administrative, technical, and organizational safeguards to help protect your information — including password hashing, access controls that restrict administrator-only data (such as unpublished draft notices) from being visible to students, and time-limited secure links for accessing uploaded documents rather than public file links.
We use reasonable administrative, technical, and organizational safeguards. However, no electronic transmission or storage method is completely secure, and we cannot guarantee absolute security of your information.
21User Rights and Choices
Depending on applicable law, you may have rights to:
- Access the personal information we hold about you
- Correct inaccurate profile or academic information
- Request deletion of your account and associated data (see §22)
- Withdraw consent for optional features, such as notifications
- Object to certain processing, where applicable
To exercise these rights, contact us at [PRIVACY CONTACT EMAIL].
22Account and Data Deletion
How to delete your account:
- By email to [PRIVACY CONTACT EMAIL], or
- Through the account-deletion request page at [ACCOUNT DELETION URL]
What will be deleted: Your profile information, academic profile, saved opportunities, notification preferences, and personal application notes will be deleted from active systems.
What may be retained:
- Records that administrators need to retain for institutional, legal, or audit purposes (such as audit logs recording that an administrator published a specific notice) may be retained separately from your personal account.
- Aggregated or anonymized information that no longer identifies you may be retained.
Backups: Data may also exist in routine system backups maintained by our infrastructure provider.
23Children's and Minors' Privacy
KIIT Pulse is intended for college students. Most users are expected to be 18 years of age or older; however, we recognize that some users — for example, students admitted through diploma or lateral-entry programs — may be under 18.
If you believe a user under the applicable minimum age has provided us with personal information inappropriately, please contact us at [PRIVACY CONTACT EMAIL] so we can review and, if appropriate, remove that information.
24Data Breaches and Incident Handling
25Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will update the "Effective Date" at the top of this policy when changes are made, and, where changes are significant, we will provide additional notice (such as an in-app message) before the changes take effect.
26Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact:
[DEVELOPER OR BUSINESS NAME]
Email: [PRIVACY CONTACT EMAIL]
Website: [WEBSITE URL]
This Privacy Policy was prepared based on the described functionality of KIIT Pulse. It is a starting draft and has not been reviewed by a lawyer. Please have this policy reviewed by a qualified legal professional familiar with Indian data-protection law and Google Play's Developer Program Policy before publishing it or submitting your app for review.
3 · Short version for the app signup screen
Your privacy, briefly: KIIT Pulse collects your email, password, and basic academic details (branch, section, semester, CGPA) to show you your timetable and relevant placement opportunities. We store this data securely using Supabase and do not sell your information or show ads. Some placement application links take you to external sites with their own privacy practices. You can request deletion of your account at any time by emailing [PRIVACY CONTACT EMAIL]. Read our full Privacy Policy for details.
4 · Google Play Data Safety / Privacy-Policy Summary
Use as a starting reference for Google Play Console's Data Safety form. Confirm every line against the final, legally reviewed policy before submitting.
| Data type | Collected? | Shared? | Purpose |
|---|---|---|---|
| Email address | Yes | No (except with service provider Supabase) | Account creation, authentication |
| Password | Yes (hashed, not stored in plain text) | No | Authentication |
| Name | Yes | Visible to placement administrators | Personalization, placement processing |
| Phone number | Optional | No | Contact (optional field) |
| Photo | NEEDS CONFIRMATION | — | — |
| Academic info (roll no., branch, semester, CGPA, backlog status) | Yes | Visible to placement/timetable administrators | Timetable personalization, eligibility display |
| App activity (applications tracked, saved opportunities) | Yes | Visible to placement administrators for applications to their drives | Application tracking |
| Files/documents | Uploaded by administrators only, not students | Visible to administrators; originals viewable by students for notices they're shown | Notice/timetable publishing |
| Device or usage analytics | NEEDS CONFIRMATION — none currently integrated | — | — |
| Location | Not collected | — | — |
| Financial info | Not collected | — | — |
Data deletion: Users may request account and data deletion via [ACCOUNT DELETION URL] or [PRIVACY CONTACT EMAIL].
Encryption in transit:
5 · Pre-publishing verification checklist
- Effective date filled in
- Privacy contact email filled in and monitored
- Developer/business legal name filled in
- Website URL filled in
- Account-deletion URL created, or deletion process finalized and described accurately
- Developer/business legal location confirmed
- Hosting provider confirmed (Vercel or otherwise) and added to §15/§18 if applicable
- Supabase data region/hosting location confirmed for §18
- Data retention periods defined for §19
- Deletion timeframe and backup-purge timeframe defined for §22
- Confirmed whether profile-photo upload is active (§4/§9)
- Confirmed push/email notifications are inactive as described, or updated if activated (§14)
- Confirmed AI extraction is inactive as described, or updated if activated (§10)
- Confirmed minimum age / minors policy (§23)
- Data Safety form in Google Play Console matches this policy exactly
- Full policy reviewed by a qualified lawyer familiar with Indian data law and Google Play policy
- Policy linked from both the app (signup/settings screen) and the website footer
6 · Links and contact details still needed
- Hosted URL for the full Privacy Policy (e.g.
[WEBSITE URL]/privacy) - [PRIVACY CONTACT EMAIL] — a monitored inbox, not a personal email if avoidable
- [ACCOUNT DELETION URL] — either a form, a settings-page action, or a documented email process
- [DEVELOPER OR BUSINESS NAME] — legal name to use consistently across the Play Store listing and policy
- [WEBSITE URL] — if the app doesn't have a marketing site yet, this may need to be created before Play Store submission
- Link to Supabase's current privacy policy (to cite as a sub-processor)
- Link to hosting provider's privacy policy, once confirmed
7 · Legal review note
Not legal advice
This document was generated based on the described technical functionality of KIIT Pulse. It is not legal advice and has not been reviewed by a lawyer. Given that this app processes student academic records and facilitates placement applications — and that Indian data-protection requirements (including the Digital Personal Data Protection Act, 2023, and its forthcoming rules) and Google Play's Developer Program Policy are both still evolving — you should have this policy reviewed by a qualified legal professional before publishing the app or this policy, particularly to:
- Confirm whether the App's data-collection practices trigger any specific obligations under Indian law
- Confirm the correct legal basis language for §12
- Finalize retention and deletion timeframes in §19 and §22
- Confirm minors-related obligations in §23 given that some users may be under 18