Privacy policy
Draft for institutional review, written to match what this software stores. India’s Digital Personal Data Protection Act, 2023 applies; have it checked before launch.
What we store
Your full name, username, email address, institution name, the role you selected, account status, registration and last sign-in times, and when you accepted these policies. Your password is stored only as a salted, one-way hash that nobody, including administrators, can read back.
Security records
To protect accounts we keep sign-in attempts, password resets and administrator actions in an audit log, including the IP address the request came from.
Each time you sign in we record the IP address, the approximate location Cloudflare derives from it (city, region and country — not your precise position), your network provider and your browser and operating system. Only administrators can see this, it is used to spot unauthorised access to accounts, and it is deleted after 90 days.
Who can see it
Administrators can see your profile details and account status to manage access. They cannot see your password.
Cookies
One essential cookie keeps you signed in. It is not used for tracking or advertising.
Deletion
Ask an administrator to delete your account. Deletion removes your profile; audit entries keep only an anonymous identifier and the type of event.