Unofficial student app · Draft for legal review

Privacy Policy Package

Prepared for KIIT Pulse · Effective date [EFFECTIVE DATE] · Not legal advice

1 · Short list of missing information

Resolve these before the policy can be published.

  1. Effective date of the policy
  2. Privacy contact email
  3. Developer/business legal name
  4. Website URL
  5. Account-deletion URL or process — no in-app deletion flow exists yet in the code (see §22)
  6. Developer/business legal location (state/country) — determines which laws apply
  7. Hosting provider confirmation — a Vercel cron config exists in the code, suggesting Vercel hosting, but this should be explicitly confirmed
  8. Data retention period — no retention schedule is currently defined in the app
  9. Whether Google Sign-In will be added — the current build only supports email/password sign-in
  10. Whether push/email notifications will be activated — the database supports notification records, but no delivery service is wired in yet
  11. Whether an AI extraction service will be activated — an API key placeholder exists but is unused; extraction currently runs on a deterministic (non-AI) parser
  12. Backup retention/removal timeframe on Supabase's side

2 · Complete Privacy Policy

Privacy Policy for KIIT Pulse

Effective Date: [EFFECTIVE DATE]

01Introduction

This Privacy Policy explains how KIIT Pulse ("the App," "we," "us") collects, uses, stores, and protects information when you use our mobile application and website. Please read this policy carefully. By using KIIT Pulse, you agree to the practices described here.

If you do not agree with this policy, please do not use the App.

02About KIIT Pulse

KIIT Pulse is a student productivity tool that helps students access:

  • Personalized class timetables
  • Placement and internship opportunities
  • Application deadlines and countdown timers
  • Placement preparation resources and past-year papers
  • Notices and announcements from the college's placement and academic teams
  • Personal tracking of their own job/internship applications
  • A basic student profile
  • In-app notifications and reminders (see §14 for the current status of push notifications)

03Independent and Unofficial Status

KIIT Pulse is an independently operated, unofficial application. It is not created, endorsed, hosted, or officially affiliated with KIIT (Kalinga Institute of Industrial Technology) or KIIT Deemed to be University, unless explicitly stated otherwise in writing. Notices, timetables, and placement information displayed in the App are sourced from documents uploaded by App administrators for informational convenience and may be incomplete, delayed, or contain errors. Always verify time-sensitive information (such as application deadlines) against your college's official channels.

04Information Users Provide

When you use KIIT Pulse, you may provide:

  • Account information: email address and password, used to create and sign in to your account.
  • Academic/student profile information: full name, roll number, branch, batch/graduating year, semester, section, and CGPA. Backlog status may also be recorded to help determine placement eligibility.
  • Contact information: phone number (optional field).
  • Profile photo: the App's database includes an optional field for a profile picture. Is a photo-upload feature currently active for students, or is this field reserved for future use?
  • Application activity you record: which opportunities you mark as interested, applied, or otherwise track, along with any personal notes you choose to add to an application.
  • Notification preferences: your choices about which types of alerts you want to receive.

We do not currently provide a feature for students to upload resumes, personal documents, or other files through the App. Confirm if this changes in a future version.

05Information Collected Automatically

Some technical information may be collected automatically as part of operating the App and its hosting/database infrastructure, such as:

  • Basic request/server logs generated by our hosting provider
  • Timestamps of account actions (e.g., sign-in, application status changes)
  • File size and file type metadata for documents uploaded by administrators (not by students)
We do not currently have a dedicated analytics or crash-reporting service integrated into the App (see §15). If device information, IP addresses, or usage analytics are collected by our hosting or infrastructure provider as part of normal operation, this section must be updated to describe that specifically.

06Google Sign-In and Authentication Data

KIIT Pulse currently uses email-and-password authentication through our backend provider, Supabase Auth. Google Sign-In is not currently implemented.

If Google Sign-In is added in a future release, this section must be rewritten to describe the data Google provides (name, email, profile photo) and how it is used.

Your password is not stored by us in readable form; authentication is handled by Supabase Auth using industry-standard password hashing.

07Student Profile and Academic Information

To personalize your timetable and to show you relevant placement opportunities, we ask for academic details including your branch, batch, semester, section, and CGPA. This information is used only to:

  • Show you your correct class schedule
  • Help you understand whether you may be eligible for a given placement or internship opportunity

Eligibility information shown in the App is for your convenience only and is never used to prevent you from viewing an opportunity, applying, or being considered by a recruiter — final eligibility is always determined by the recruiter/college placement team.

08Timetable, Placement, Application, and Notice Data

  • Timetable data is uploaded by timetable administrators and matched to your section to build your personal schedule view.
  • Placement and internship opportunity data is uploaded by placement administrators, reviewed, and published for eligible/relevant students to view.
  • Your application-tracking data (status such as "applied," "shortlisted," "interview scheduled," notes, etc.) is private to your account. Placement administrators can view your application status and may also publish official status updates (e.g., "shortlisted"), but they do not have the ability to edit your personal notes.
  • Notices and events are published by administrators and may be shown to all students or only to students in a targeted batch/branch.

09Uploaded Files and Documents

Administrators (not students) upload original documents — such as PDF notices, scanned notices, images, Word documents, and spreadsheet timetables — so that the App can extract and display structured information. Original uploaded files are retained and can be viewed by students via a "View Original Notice" link where applicable, so you can always verify the source document.

Uploaded documents are stored in a private storage location and are only made accessible through short-lived, secure links generated by our system; they are not publicly browsable.

If a future version allows students to upload files (e.g., resumes), this section must be expanded to cover that data specifically.

10AI-Assisted Document Processing

KIIT Pulse currently extracts structured information (such as company name, deadlines, eligibility criteria, and CTC/stipend figures) from uploaded documents using automated pattern-matching (not a third-party AI service). This extracted information is always reviewed and approved by a human administrator before it is published or shown to students — it is never published automatically.

The App's codebase includes an optional integration point for a third-party AI language model provider (Anthropic) to assist with document extraction in more difficult cases. As of the effective date of this policy, this integration is not active. If it is activated in the future, this section must be updated to name the provider, describe what document content is sent to it, and confirm the provider's own data-handling terms.

11How Information Is Used

We use the information described above to:

  • Create and secure your account
  • Display your personalized timetable
  • Show you placement/internship opportunities and notices relevant to your batch, branch, and eligibility
  • Let you track your own applications
  • Send you in-app notifications and reminders you have opted into
  • Maintain the accuracy and integrity of published notices (e.g., detecting when a document extends an existing deadline rather than creating a duplicate listing)
  • Keep basic records (audit logs) of administrator actions, such as who published or edited a notice, for accountability and troubleshooting
  • Maintain and improve the App's functionality and reliability

We do not use your information for advertising. KIIT Pulse does not currently display advertisements.

12Legal Basis or Purpose of Processing

India-specific — depending on the location of our users and the applicable law (such as India's Digital Personal Data Protection Act, 2023, once its rules are fully in force), our processing of your information is generally based on: your consent when you create an account and use the App; our legitimate interest in operating and improving a service you have chosen to use; and compliance with legal obligations where applicable. We do not claim compliance with any specific data protection law unless confirmed by legal review — see §26.

13Cookies and Similar Technologies

The KIIT Pulse website and app may use essential cookies or local storage required for you to stay signed in and for the App to function correctly.

Do we use any non-essential cookies, such as for analytics or marketing? If none are used, this section can state that explicitly. If any are added later (e.g., via an analytics provider), this section and §15 must be updated together.

14Push Notifications and Device Permissions

KIIT Pulse's database supports several types of notifications (e.g., new eligible opportunity, deadline approaching, timetable change). Currently, these are delivered as in-app notifications only.

Push notifications (e.g., via Firebase Cloud Messaging) and email notifications are planned but are not currently active in the deployed App as of the effective date of this policy. If and when push notifications are activated, this section must be updated to describe the push notification provider, what data it processes (such as a device token), and how you can disable notifications at the device or app level.

15Third-Party Services

KIIT Pulse relies on the following third-party service provider to operate:

  • Supabase (database, authentication, and file storage provider). Supabase processes and stores your account credentials, profile data, application data, and uploaded documents on our behalf, in accordance with Supabase's own privacy and security practices. Link to Supabase's current privacy policy and confirm the data region/hosting location used for our project.
Hosting — the App's deployment configuration suggests Vercel may be used as the hosting provider for the website/app backend. This must be confirmed before publishing, and if confirmed, Vercel should be added here as a data processor along with a link to its privacy policy.

Services NOT currently used by KIIT Pulse (listed here for clarity and to avoid overstating our practices):

  • No Google Analytics, Firebase Analytics, Crashlytics, Sentry, or similar analytics/crash-reporting service is currently integrated.
  • No advertising network is integrated.
  • No payment processor is integrated.
  • No Firebase Cloud Messaging or other push notification service is currently active (see §14).

If any of the above are added in the future, this Privacy Policy will be updated before that feature is activated, and this section will name the specific provider.

16External Placement and Application Links

Some placement and internship opportunities in KIIT Pulse include a link that takes you to an external website to complete your application — for example, a company's own careers portal or a recruitment platform used by the placement cell (such as Superset). When you click these links, you leave KIIT Pulse and become subject to that third party's own privacy policy and terms. We do not control, and are not responsible for, the privacy practices of these external sites. Please review their policies before submitting any information.

Separately, KIIT Pulse also lets you record your own application status (e.g., "applied," "interview scheduled") within the App, whether or not your actual application was submitted on our platform or an external one. This tracking data stays within KIIT Pulse.

17Data Sharing and Disclosure

We do not sell your personal information. We may share information in the following limited circumstances:

  • With our service providers (currently Supabase, and — pending confirmation — our hosting provider) strictly to operate the App, under their own data-processing terms.
  • With college placement administrators, who — as part of the App's core function — can view students' application status and academic eligibility data relevant to placement drives they manage.
  • If required by law, such as in response to a valid legal request from a court or government authority.
  • In connection with a business transfer, such as a merger or acquisition of the App, in which case affected users would be notified.
Do we share any data with the college/placement cell as an official institution (separately from placement-admin App accounts), with recruiters directly, or with any advertisers or marketing partners? As of this draft, the App's design does not include any such sharing beyond what is described above.

18Data Storage and International Processing

Your information is stored using Supabase's cloud infrastructure.

Specify the data center region/country configured for our Supabase project, since this determines whether data is processed outside India and what safeguards, if any, apply to that transfer.

19Data Retention

We do not currently have a formally defined data retention schedule. As a general practice, we intend to retain your account and academic profile data for as long as your account remains active, and placement/notice records for institutional and historical reference. This section must be finalized with specific retention periods (e.g., "X months after graduation" or "X months after account deletion") before this policy is published.

20Data Security

We use reasonable administrative, technical, and organizational safeguards to help protect your information — including password hashing, access controls that restrict administrator-only data (such as unpublished draft notices) from being visible to students, and time-limited secure links for accessing uploaded documents rather than public file links.

We use reasonable administrative, technical, and organizational safeguards. However, no electronic transmission or storage method is completely secure, and we cannot guarantee absolute security of your information.

21User Rights and Choices

Depending on applicable law, you may have rights to:

  • Access the personal information we hold about you
  • Correct inaccurate profile or academic information
  • Request deletion of your account and associated data (see §22)
  • Withdraw consent for optional features, such as notifications
  • Object to certain processing, where applicable

To exercise these rights, contact us at [PRIVACY CONTACT EMAIL].

Indian law — we do not currently state compliance with any specific data-protection statute (such as India's DPDP Act, 2023) until this has been reviewed by a qualified legal professional. See §26.

22Account and Data Deletion

How to delete your account:

As of this draft, KIIT Pulse's codebase does not yet include a self-service, in-app "delete my account" button. Until this feature is built, users who wish to delete their account and data must submit a request:
  • By email to [PRIVACY CONTACT EMAIL], or
  • Through the account-deletion request page at [ACCOUNT DELETION URL]

What will be deleted: Your profile information, academic profile, saved opportunities, notification preferences, and personal application notes will be deleted from active systems.

What may be retained:

  • Records that administrators need to retain for institutional, legal, or audit purposes (such as audit logs recording that an administrator published a specific notice) may be retained separately from your personal account.
  • Aggregated or anonymized information that no longer identifies you may be retained.
Any other operational or legal retention needs, plus: specify the expected number of business days to process a deletion request.

Backups: Data may also exist in routine system backups maintained by our infrastructure provider.

State the maximum time such backups are retained before they are also purged, per Supabase's backup policy for our plan.

23Children's and Minors' Privacy

KIIT Pulse is intended for college students. Most users are expected to be 18 years of age or older; however, we recognize that some users — for example, students admitted through diploma or lateral-entry programs — may be under 18.

Please confirm the intended minimum age for using KIIT Pulse, and whether any additional parental-consent or age-verification safeguards are required for younger students. Until confirmed, we do not knowingly collect more information from users under 18 than is necessary for the App's core academic/placement functions described in this policy.

If you believe a user under the applicable minimum age has provided us with personal information inappropriately, please contact us at [PRIVACY CONTACT EMAIL] so we can review and, if appropriate, remove that information.

24Data Breaches and Incident Handling

In the event of a data breach affecting your personal information, we intend to take reasonable steps to investigate and address the incident, and to notify affected users and, where legally required, relevant authorities, within a reasonable timeframe. This section should be finalized with specific procedures and legally required timeframes after legal review.

25Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will update the "Effective Date" at the top of this policy when changes are made, and, where changes are significant, we will provide additional notice (such as an in-app message) before the changes take effect.

26Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact:

[DEVELOPER OR BUSINESS NAME]
Email: [PRIVACY CONTACT EMAIL]
Website: [WEBSITE URL]


This Privacy Policy was prepared based on the described functionality of KIIT Pulse. It is a starting draft and has not been reviewed by a lawyer. Please have this policy reviewed by a qualified legal professional familiar with Indian data-protection law and Google Play's Developer Program Policy before publishing it or submitting your app for review.

3 · Short version for the app signup screen

Your privacy, briefly: KIIT Pulse collects your email, password, and basic academic details (branch, section, semester, CGPA) to show you your timetable and relevant placement opportunities. We store this data securely using Supabase and do not sell your information or show ads. Some placement application links take you to external sites with their own privacy practices. You can request deletion of your account at any time by emailing [PRIVACY CONTACT EMAIL]. Read our full Privacy Policy for details.
Verify this stays accurate if push notifications, Google Sign-In, or AI extraction are activated later — update this short version alongside the full policy.

4 · Google Play Data Safety / Privacy-Policy Summary

Use as a starting reference for Google Play Console's Data Safety form. Confirm every line against the final, legally reviewed policy before submitting.

Data typeCollected?Shared?Purpose
Email addressYesNo (except with service provider Supabase)Account creation, authentication
PasswordYes (hashed, not stored in plain text)NoAuthentication
NameYesVisible to placement administratorsPersonalization, placement processing
Phone numberOptionalNoContact (optional field)
PhotoNEEDS CONFIRMATION
Academic info (roll no., branch, semester, CGPA, backlog status)YesVisible to placement/timetable administratorsTimetable personalization, eligibility display
App activity (applications tracked, saved opportunities)YesVisible to placement administrators for applications to their drivesApplication tracking
Files/documentsUploaded by administrators only, not studentsVisible to administrators; originals viewable by students for notices they're shownNotice/timetable publishing
Device or usage analyticsNEEDS CONFIRMATION — none currently integrated
LocationNot collected
Financial infoNot collected

Data deletion: Users may request account and data deletion via [ACCOUNT DELETION URL] or [PRIVACY CONTACT EMAIL].

Confirm before publishing whether Google Play requires an in-app deletion option specifically, given the App's account-based nature — as of this draft, deletion is a request-based process, not self-service.

Encryption in transit:

Confirm HTTPS is enforced across the deployed app and API.

5 · Pre-publishing verification checklist

  • Effective date filled in
  • Privacy contact email filled in and monitored
  • Developer/business legal name filled in
  • Website URL filled in
  • Account-deletion URL created, or deletion process finalized and described accurately
  • Developer/business legal location confirmed
  • Hosting provider confirmed (Vercel or otherwise) and added to §15/§18 if applicable
  • Supabase data region/hosting location confirmed for §18
  • Data retention periods defined for §19
  • Deletion timeframe and backup-purge timeframe defined for §22
  • Confirmed whether profile-photo upload is active (§4/§9)
  • Confirmed push/email notifications are inactive as described, or updated if activated (§14)
  • Confirmed AI extraction is inactive as described, or updated if activated (§10)
  • Confirmed minimum age / minors policy (§23)
  • Data Safety form in Google Play Console matches this policy exactly
  • Full policy reviewed by a qualified lawyer familiar with Indian data law and Google Play policy
  • Policy linked from both the app (signup/settings screen) and the website footer