Legal
Privacy policy
We ask for a college email because the network only works if everyone in it is a real student. This page explains exactly what that means for your data — what we hold, what we cannot see, and what you can make us delete.
Last updated 28 August 2026 · DPDP Act, 2023 · CampusLoop Inc.
01What we collect
- College email address
- Verification only
Used to confirm you belong to an accredited institution (.ac.in, .edu). Never displayed publicly, never sold or rented.
- Profile details
- Name, course, branch, year, photos, interests
Whatever you choose to fill in. All of it is editable, and most of it is optional.
- Content you post
- Posts, comments, polls, stories, messages
Stored so it can be shown back to the people you shared it with.
- Security telemetry
- Sign-in events, coarse device information
Kept to detect account takeover and abuse. Not used to build an advertising profile.
02How anonymity works
Anonymous posts and confessions are not simply hidden in the interface — the link to your profile is removed before the post is written.
- The stored post carries a pseudonym handle, not your profile ID. There is no foreign key left to join against.
- Recovering the author requires a separate encryption key held outside the database, and is limited to audited administrator actions for legal or safety escalations.
- No other student, senior, or faculty member can inspect the author of an anonymous post through any part of the product.
- Before you publish, a client-side check warns you if your text contains a phone number, roll number, or personal email that would identify you anyway.
04Your rights
As a Data Principal under the Digital Personal Data Protection Act, 2023, you hold these rights, and you can exercise all of them without giving a reason.
- Access. Review everything linked to your account from Profile Settings.
- Correction. Edit any profile information at any time.
- Erasure. Request permanent deletion of your account and its data at privacy@campusloop.space.
- Grievance redressal. Escalate any concern to our Grievance Officer, listed below.
05Storage and encryption
Data is encrypted in transit with TLS 1.3 and at rest with AES-256, on Neon serverless PostgreSQL behind the Cloudflare edge network. Anonymous author identities are sealed with a separate key that the application database never holds.
06Grievance officer
Appointed under the DPDP Act, 2023 and Rule 3(2) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
- Officer
- Data Protection & Grievance Officer
- Response time
- 24–48 working hours
