Campus Coffee

Privacy Policy

Version 2026-07-29 · Last updated

This is the whole of it. Every item below is something the app actually stores, and the list is written from the database rather than from good intentions.

Under the Digital Personal Data Protection Act, 2023, Nashim Aktar Mondal is the Data Fiduciary for your personal data and you are the Data Principal. This page is the notice that Act requires, and section 11 is how you exercise your rights under it.

The short version: your college mailbox proves you're a student and is then left alone. Your face is checked against your own photos on your phone, and no face template ever leaves it. Your location is read only during a meeting you agreed to. Your reliability score is shown to nobody, including you. Nothing is sold, and there are no advertising trackers anywhere in the app.

01Who is responsible for your data

Campus Coffee is run by Nashim Aktar Mondal, an individual student at Manipal University Jaipur. It is not a registered company, and it charges nothing.

Write to support@campuscoffee.online for anything covered by this document.

Grievance Officer: Nashim Aktar Mondal · support@campuscoffee.online. Complaints are acknowledged within 24 hours and resolved within 15 days, as required by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Complaints about a photo of you shared without consent, or about someone impersonating you, are acted on within 24 hours.

02What is collected, and why

Signing in and proving you're a student. The Google account you sign in with gives an email address and a name. To verify, you email a one-time code from your college address; the app reads the sender address only, records the outcome, and stores your @muj.manipal.edu address against your account. The body of that email is never stored. Your display name is derived from the address. Purpose: making sure only MUJ students get in, one account each.

Your card. Full name, date of birth, gender, branch, year, a short bio, interests, subjects, study style, diet, mess hall, mess timing, your timetable, one prompt answer, and which pools you've opted into. Others see your age, never your date of birth. Purpose: matching you with people you'd actually sit with.

Photos and one selfie. Three to five photos plus a selfie. They live in a private bucket — never a public URL — and are shown through links that expire within the hour. Purpose: so a match knows who they're meeting.

The face check. Your selfie is compared against your own photos entirely inside your browser. The model is downloaded on demand from the jsDelivr CDN (which sees your IP address, as any download does). Only a yes/no verdict and a similarity number reach the server. No face template, descriptor or biometric measurement is ever transmitted or stored.

Matches, chats and plans. Who you matched with, your messages, the time and place you agreed, your private yes/no decisions, and the result of a check-in. Purpose: running the thing you're using.

Location, and only then. During a check-in window for a meeting you agreed to — from ten minutes before until twenty minutes after — the meet screen sends your latitude and longitude so the app can work out whether two phones are within about thirty metres. There is no background location, no location history, no location at any other time, and your coordinates are never shown to your partner — they see only "near" or "not near". Purpose: confirming a meeting happened, which is the only thing the reliability score is built from.

Notifications. If you switch on lock-screen alerts, your browser hands over a push endpoint, two keys, and a short label like "Chrome on Android". Payloads are encrypted end to end, so the push service forwards something it cannot read. Purpose: reaching you when the app is closed.

The campus feed. Posts, captions, likes, comments, and the automatic tag of the partner a post is about. Photos are re-encoded in your browser before upload, which strips the GPS tag your phone attaches. Purpose: the feed.

Technical records. Vercel keeps standard server logs (IP address, browser, time of request) and Supabase keeps sign-in records. Vercel Analytics counts page views by route pattern — the shape of the URL, never the actual thread id — and sets no cookies and builds no cross-site profile. Purpose: keeping the service up and catching abuse.

Verification attempts. Every inbound verification email is logged as sender address, code and outcome. Purpose: catching someone trying codes that aren't theirs.

03What is never collected

  • Phone numbers. There is no field for one anywhere. While a blind match is anonymous and apart, the server accepts only the canned phrases — free typing isn't blocked so much as absent — and the one free-text field in that phase, the fifty-character note about where to meet, is stripped of numbers, links and handles before it is stored.
  • ID documents, registration certificates or fee receipts. The college mailbox is the only proof used.
  • Payment details of any kind — there is nothing to pay for.
  • Your contacts, your calendar, your photo library beyond the pictures you deliberately pick.
  • Background location, movement history, or where you were when you weren't checking in.
  • The contents of your verification email, or any other mailbox access.
  • Advertising identifiers, third-party trackers, or cross-site cookies. None, anywhere.
  • Voice calls are never recorded and never pass through a server that could record them.

Your personal data is not sold, rented, or shared for advertising, and is not used to train machine-learning models.

04Who can see what

A blind-coffee partner sees your first initial and nothing that names you: no full name, no bio, no photos. They do see your age, your year, up to three of your interests, your subjects and study style, your diet, mess hall and mess timing, your one prompt answer — and your branch only if you left that switch on. Those are what a conversation needs; none of them is you. The rest stays shut until you have both met and both said it went well.

An open match or a browsable candidate sees all of that plus your display name, your full name, your bio and your photos, and eight interests instead of three.

Everyone verified on this campus sees anything you post to the feed, including the partner it tags.

Nobody, ever sees your reliability score or the matching weights learned from your outcomes. They are kept in a table with no client-readable policy at all — the database refuses the read rather than the code remembering to omit it. You can't see them either. Nor does anyone see who you turned down: a "no" dissolves the match quietly and is never announced.

Nashim Aktar Mondal can technically reach the database, and does so to fix a bug, act on a report, or keep the service running — not to read conversations for interest.

06Who else handles your data

Campus Coffee runs on other people's infrastructure. These are all of them:

  • Google — sign-in. Google sees that you signed in to this app, under its own privacy policy.
  • Supabase — the database, authentication, realtime updates, and photo storage. Everything in the list above lives here.
  • Vercel — hosting, server logs, and cookieless page-view analytics.
  • Cloudflare R2 — private photo storage, when configured instead of Supabase Storage.
  • Brevo — sends the verification email and receives your reply. It handles the message that carries your code.
  • Your browser's push service (Google, Mozilla or Apple, depending on your phone) — delivers notifications it cannot read.
  • jsDelivr — serves the face-detection model to your browser. It sees the download request and your IP address; it receives no photo and no face data.

These providers act on instructions and are not permitted to use your data for their own purposes. Some of them store data on servers outside India; by using Campus Coffee you agree to that transfer, which is permitted under the DPDP Act except to countries the Government has restricted.

Beyond these, data is disclosed only where the law requires it — a court order or a lawful direction — or where it is genuinely necessary to protect someone's safety.

07One thing about the voice call

The in-app call is peer-to-peer. To connect it, your device and your partner's exchange network addresses directly with each other, which means a technically capable person on the other end could learn your IP address — the same as on any WhatsApp or FaceTime call.

Audio never touches a server, and nothing about the call is recorded or stored. The call only unlocks when you are both already at the same café.

08Cookies and what's stored on your device

  • Sign-in cookies (`sb-…-auth-token`) — set by Supabase, they're what keeps you signed in. Essential.
  • A routing cookie — remembers which onboarding step you're on, so a page doesn't bounce you around. Essential, cleared when you sign out.
  • Service worker cache — the offline screen and the app shell, so it opens on bad campus wifi.
  • Local storage — small things like whether you've dismissed the install prompt.

There are no advertising cookies, no analytics cookies and no third-party trackers. Nothing here follows you to another site.

09How long any of it is kept

While your account exists, your data exists. When you delete your account it is deleted immediately and permanently — your photos are removed from storage first, and then the account row is deleted, which takes your profile, matches, messages, posts, likes, comments, notifications, push subscriptions, private stats and verification records with it. There is no thirty-day grace period, no soft delete, and no archive it can be recovered from.

Two honest exceptions:

  • Server logs at Vercel and Supabase roll off on those providers' own schedules and are not individually deletable by this app.
  • A live safety report or a legal obligation — where a complaint about you is open, or the law requires a record to be kept, the minimum needed is retained until it is resolved.

Messages you sent to another student are stored once, in the conversation. Deleting your account removes them from their thread too.

10Your rights, and how to use them

Under the DPDP Act, 2023 you have the right to:

  • Know what is held about you and who it has been shared with — most of it is on your profile screen already; ask at support@campuscoffee.online for the rest.
  • Correct or complete it — your profile screen edits everything except your verified name, which comes from your college address by design.
  • Erase it — Profile → Delete my account. Immediate and total.
  • Withdraw consent — pause the account, or turn off a permission.
  • Nominate someone to exercise these rights if you can't. Email the request and it will be recorded.
  • Complain, and have that complaint answered — see the Grievance Officer above.

Requests by email are answered within 15 days. If you are still unhappy, you may complain to the Data Protection Board of India.

Note also your own duty under the Act: don't file false or frivolous complaints, and don't impersonate someone else when you make a request.

11Nobody under 18

Campus Coffee is for adults. Accounts require you to be 18 or older, and the date of birth entered at signup is checked on the server, not only in the form.

No account is knowingly created for anyone under 18, and no child's data is knowingly processed. If you believe someone under 18 has an account, write to support@campuscoffee.online and it will be removed and its data deleted.

12How it's kept safe

What the app actually does, rather than a paragraph about caring deeply:

  • Every table has row-level security on. A browser can only ever read your own row and the conversations you're in — the database enforces it, not the code.
  • Reliability scores and learned weights sit in a table with no client-readable policy at all, so they are unreachable from any browser by construction.
  • Photos live in a private bucket and are served through short-lived signed links, so a URL that leaks stops working.
  • Privileged work runs server-side with credentials that are never sent to the browser.
  • Notification payloads are encrypted end to end; the push service delivers a blob it cannot read.
  • Verification only trusts email that passed SPF/DKIM at the receiving edge — a forged `From` header is rejected.
  • The site sends a strict Content-Security-Policy, refuses to be framed, and is HTTPS-only with HSTS.
  • Secrets live in the host's environment, never in the repository.

None of that makes a system perfect. If you find a flaw, please report it to support@campuscoffee.online rather than testing it against other students' accounts — see security.txt. Reports made in good faith, without accessing anyone else's data, will not be pursued.

If a breach happens that affects your data, you and the Data Protection Board will be told, as the DPDP Act requires.

13Changes to this policy

Material changes are announced in the app before they take effect, and the version at the top of this page says what's current.

Current version: 2026-07-29, effective 29 July 2026.