← Back to Cmpus

Privacy Policy

Last updated: 1 October 2026

This Privacy Policy explains what data Cmpus (operated by Silverscale Technologies Private Limited) collects, why, and what rights you have over it. It is written to comply with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.

1. What we collect

  • Account data — name, email, username, college, course, year, avatar
  • Date of birth — collected once at signup solely to confirm you are 18 or over. It is never shown to other students and is not used for anything else.
  • Academic data you enter — timetable, attendance records, subjects, grades, deadlines
  • Content you create — vibes, stories, messages (including photos, voice notes, polls and your votes in them), listings, offers, comments, reports
  • Edited messages — if you edit a message you sent, we keep the earlier wording. No one in the chat can see it; it is looked at only if that message is reported, so that editing cannot be used to hide abuse.
  • Class streak — the number of class days in a row you attended, worked out on your device from your own attendance marks. Only the number is sent to us, so it can show on your profile.
  • Social graph — who you follow, your groups, link-up requests
  • Live status — free/bunking status and optional location hints you set yourself (we never track GPS)
  • Business data — business name, type, and contact if you register a campus business
  • Event data — passes you book, the seat assigned to you, whether you were checked in, and any amount still owed to the organiser. Event organisers can see the attendee list for their own event, including your name and seat.
  • Payment metadata, for the transactions that go through the Service — an amount, an order or registration id, and Razorpay's own transaction id. We never receive or store your card, UPI id, or bank account details; see section 1b.
  • Money data — expenses you log (amount, category, date, and any note you write), your monthly budget, and split bills you create. This is private to you and is never shown to other students; see section 6.
  • Delivery addresses — if you save one: the label you give it, hostel block, room number, and any landmark. Used only to pass to whoever is fulfilling your order, and only for that order.
  • Notification tokens — if you turn notifications on, we store the token your browser or phone gives us so we can actually deliver them. It identifies a device, not you, and it is deleted when you turn notifications off or delete your account.
  • Message delivery state — when a message was delivered and when it was read, plus any reactions, and who has opened a view-once photo. This is what powers read receipts, reaction counts and the "Opened" label. We do not read the contents of your messages; see section 3a.
  • Blocks — who you have blocked, so we can keep them away from you.
  • Technical data — device type, app version, and error reports (via Sentry) when something crashes

1b. Payments

Payments are not enabled in this version of the app. This section describes how they work once they are switched on.

Most money on Cmpus never touches the Service at all — a peer-to-peer marketplace sale or an at-gate event pass is settled directly between the two of you, in person, and we have no payment data about it whatsoever. Two narrower cases go through the Service: a listing from a verified campus organisation, and an event pass an organiser has marked payable online. Both are processed by Razorpay Software Private Limited, a licensed payment aggregator, under its own privacy policy in addition to this one. Razorpay collects and secures your payment instrument details directly — we never receive or store your card number, UPI id, or bank account details. What reaches us is limited to the amount, the order it paid for, and Razorpay's transaction identifiers, kept for order fulfilment, refunds, and accounting records.

1a. Device permissions we ask for

These apply on the web and in the iOS and Android apps. Your browser or phone will ask before granting any of these, and you can refuse or revoke each one at any time in your device settings — the rest of the app keeps working.

  • Camera — only while you are taking a photo or recording a video for a story, a chat message, a listing photo, or scanning your timetable or attendance screenshot. We never open the camera in the background.
  • Microphone — only while you are recording a video, so it has sound, or a voice note you choose to send in a chat. Recording starts when you tap the microphone and stops when you send or cancel. We do not record audio at any other time.
  • Screenshots — the iOS app, and the Android app on Android 14 and later, are told by your phone when you take a screenshot. If you take one while a chat is open, the chat shows a note saying so. Only the fact that a screenshot happened is shared, never the image. While a view-once photo is open, the Android app blocks screenshots of it.
  • Notifications — only if you turn them on, to tell you about messages, follows and campus activity. You can switch them off in Settings.
  • Photo library — only the specific file you pick when uploading.

We do not request location access at all. Any "where I am" text on your live status is a label you type or pick yourself, never a GPS reading.

2. What we do NOT collect

  • No GPS or background location tracking — location hints are labels you pick manually
  • No contact list or phone book access
  • No card, UPI, or bank account details — Razorpay handles those directly for the two payment paths described in section 1b; we only ever see the amount and a transaction id
  • No advertising identifiers, and we do not sell your data to anyone

3. Why we use your data

  • To run the Service — showing your feed, matching lecture threads, calculating attendance
  • To connect you with classmates at the same college
  • To send notifications you have enabled
  • To keep the Service safe — moderation, spam prevention, enforcing our Terms
  • To fix bugs, using crash reports

3a. We do not read your private messages

Cmpus does not monitor, scan, or run automated checks over direct messages or group chats. No automated system reads them, and no one at Cmpus reads them in the ordinary course. They are stored so we can deliver them to the people in the conversation. They are never sent to an AI service.

The only time anyone looks at a specific message is when someone in that conversation reports it, or when we are required to by a court order or a lawful request from an authority. In that case we look only at what the report concerns — not your wider chat history. A view-once photo is no exception: our moderators can open one only after it has been reported, and otherwise no one at Cmpus can see it. Public content is treated differently: marketplace listings and vibes are screened automatically when you post them, because they are broadcast to your whole campus — see section 5b.

Cmpus is an intermediary under the Information Technology Act, 2000. We host what students send each other; we do not select, initiate, or alter it.

4. Anonymous features

When you post anonymously, your identity is hidden from other users but retained in our database linked to your account. We enforce this server-side so other users cannot uncover it. We disclose it only when required by law or valid legal process, or to investigate serious violations of our Terms.

5. Where your data lives

Your data is stored with Supabase in the Mumbai (ap-south-1) region — inside India. Our service providers: Supabase (database, authentication, storage), Vercel (hosting), Sentry (crash reporting), Resend (sending the emails the app has to send you — sign-in links, password resets, and event or conference mail), and — only for the two payment paths described in section 1b — Razorpay (payment processing). Each receives only the minimum needed to do its job.

GIF and sticker search. When you search for a GIF or sticker in a chat, the words you type are sent to Tenor, a Google service, to find matching results. The search goes from our server, not your phone, and carries nothing that identifies you or your account. The GIF you pick is then loaded from Tenor. Google's privacy policy applies to Tenor.

5a. What Cmpus stores on your device

Cmpus does not use cookies, and there are no advertising or analytics trackers in the app. It does keep some things in your phone or browser's own storage, so that it works without a connection and does not have to re-download everything each time you open it:

  • Your sign-in session, so you are not asked to log in every time.
  • A copy of the screens you have already loaded — your timetable, attendance, messages and feed — so the app still shows them when you have no signal.
  • Small preferences, such as which tips you have dismissed.

All of this stays on your device. It is never sent anywhere, and it is cleared when you sign out or uninstall the app. Signing in as a different person on the same device clears the previous person's copy first.

5b. AI processing

Two features send content to Google's Gemini API, and nothing else in Cmpus uses an AI service:

  • Timetable scanning — when you choose to scan a photo or screenshot of your timetable, that image is sent to Google to be read into a list of classes. It is not stored by Cmpus afterwards; only the classes you confirm are saved. If you would rather not, you can enter your timetable by hand or use a classmate's code.
  • Screening public posts — the text of a marketplace listing or a vibe may be checked for prohibited content (such as drugs, weapons or harassment) when you post it. A flag goes to a human moderator; nothing is removed or penalised automatically.

Private messages, group chats, your attendance, grades and money data are never sent to an AI service. Google's processing is governed by the Gemini API terms and may take place outside India.

6. Who can see what

  • Your basic profile — name, username, college, course, year, city, avatar, bio — is visible to any signed-in Cmpus student, on any campus, so search, cross-campus messaging, and the referral leaderboard can work. Setting your account to private restricts who can follow you and see your content, not this basic lookup.
  • Your attendance, grades, timetable, and money data are private to you. The one exception is your class streak — the number only, never the marks behind it — which shows on your profile unless you turn off Settings → Show class streak. If your account is private, only approved followers see it.
  • Vibes and stories follow the audience setting you choose
  • Messages are visible only to chat participants. A view-once photo can be opened once by each of them, for a short time, and the sender sees whether it has been opened.
  • Photos and media are served through short-lived signed links, authorised per request
  • Marketplace listings are visible to your campus. The marketplace is not enabled in this version of the app.

7. Retention and deletion

We keep your data while your account is active. When you delete your account, your profile and content are deleted from live systems; residual copies in backups are purged on their rotation cycle. Some records may be retained where the law requires it. You can also delete individual pieces of content at any time.

Deleting is one tap in Settings → Delete account, and there is a full walkthrough — including how to do it if you have already uninstalled the app or can no longer sign in — at cmpus.app/delete-account.

8. Your rights

Under the DPDP Act you have the right to access, correct, and erase your personal data, and to raise a grievance. You do not have to ask us for any of it. Open Settings → Download my data and you get a file containing everything we hold about you, immediately — your profile, your academics, your posts, your tickets, and the messages you sent. Correcting your details and deleting your account are in the same place. For anything else, write to support@cmpus.app — we respond within the timelines set by law.

Your download contains what you wrote and what identifies you. It does not contain messages other people sent you: those are their personal data, not yours, and an access request is not a way to obtain someone else's chat history.

Withdrawing consent. You can withdraw it at any time by deleting your account, in Settings → Delete account or at cmpus.app/delete-account. Withdrawal does not undo processing that already, lawfully, happened — a message you sent stays in the other person's chat, and records we are required to keep are described in section 7.

Nomination. The DPDP Act lets you nominate someone to exercise these rights on your behalf if you die or become unable to act. There is no screen for this — write to support@cmpus.app from your account's email address and we will record it.

9. Age

Cmpus is strictly for users 18 and older. Under the Digital Personal Data Protection Act, 2023 anyone under 18 is a child, and we have chosen not to process children's data at all rather than do so under parental consent. We ask for your date of birth at signup and refuse accounts below 18. We do not knowingly collect data from anyone younger — if you believe a minor is using the Service, report it and we will remove the account.

9a. If something goes wrong

If your personal data is exposed by a security breach, the DPDP Act requires us to inform the Data Protection Board of India and every affected person, and we will. You will be told what happened, what data was involved, what we have done about it, and what you should do — by email to your account address and, where it affects your account directly, in the app. We will not wait for certainty about the full scope before telling you it happened.

10. Changes

We will announce material changes to this policy in the app before they take effect.

11. Contact

Data questions and grievances: support@cmpus.app

Grievance Officer: Gottumukkala Mokshit Rayudu, Silverscale Technologies Private Limited

© 2026 Cmpus · A product of Silverscale Technologies Private LimitedCIN: U62011TS2026PTC2214484-1/2, BJP Office Road, Kukatpally, Tirumalagiri, Hyderabad 500072, Telangana