Life at NC State ("the app") is a student-built dashboard. This policy explains what the app collects, why, and the choices you have. It describes what the app actually does.
What the app collects
- Your account. Creating an account stores your email and your password as a salted hash; the password itself is never stored or logged. Browsing as a guest stores neither: a guest board runs under a random identifier tied to a cookie in your browser, and when that cookie expires or is cleared there is no way back to it.
- What you put in your workspace. Goals, tasks, calendar events, and the class schedule you choose to import. You provide this, and the app stores it so it persists.
- Chat messages you post in the shared student chat or a friend group, and reports you file in the shared student chat.
- Your public friend profile. The app stores the name on your board and assigns a permanent six digit # number. It also stores friend requests, friendships, group membership, and your sharing choices.
- A home or living location, only if you add one. If you enter an address, it is sent to the U.S. Census geocoder to place a pin. A location you mark private is stored with your own account so your map works across your devices and is kept out of vault exports. It reaches a friend or group only while living location sharing is on for that view. A pin captured from your device cannot be shared.
What the app does not do
- It does not sell your data.
- It does not put personal data in URLs or query strings.
- It does not log your address or your chat contents to third parties.
- It does not track your device location. Friend map pins come from saved schedules. If nothing shared is scheduled, the map shows no current pin.
- It does not read your MyPack Portal or Moodle account. You export your own file and load it yourself.
How your data is stored and protected
- Workspace, friend, group, and chat data are stored in the app's database.
- API responses are marked private and are not cached by shared caches.
- Address lookups go only to the fixed U.S. Census endpoint.
- To slow down password guessing, the app counts recent failed sign-ins against a one-way hash of the network address and the email that was tried. The counters cannot be read back as an address or an email, they clear when you sign in, and they are discarded within a day.
- To limit friend search and request abuse across app servers, the app keeps recent request counts under one-way hashes of the account key and network address. Old windows are cleared during later use, and account deletion clears that account's counters.
- After account deletion, the app keeps only an opaque internal account key and a one-way proxy identity link. They contain no email, profile, workspace, messages, or friend data. They stop an old session or delayed request from restoring deleted data. Contact the address below if you later want to start again with the same upstream sign-in.
Third parties
- Map tiles come from OpenStreetMap. Loading the map sends tile requests to OpenStreetMap, subject to their policy. "© OpenStreetMap contributors" is shown.
- Address geocoding uses the U.S. Census Geocoder for addresses you enter.
- Public NC State search (organizations, events, careers) queries public sources and links you back to the official page. You sign in at the source, not here.
Your choices
- Edit or delete anything in your workspace at any time.
- Choose what friends can see. Class schedules, other plans, schedule based pins, and living pins start on for new accounts and each has a control. You can set a main rule, then change it for one friend or group. Turning off all sharing overrides every other setting.
- Delete your account and personal data. The Profile area erases your workspace, friend links, requests, groups, messages, feedback, and reports. Only the security keys described above remain.
Children
The app is intended for university students and is not directed to children under 13.
Chat safety
Slurs are blocked and profanity is masked automatically. Messages in the shared campus chat can be reported in the app. If the app becomes aware of child sexual abuse material, it will report it to the National Center for Missing & Exploited Children as required by law.
Changes
Material changes to this policy will be posted here with a new date.
Contact
Questions about this policy, a data request, or something to report: email liam.gergen@gmail.com.