Who is responsible
UniLore is run by the UniLore team, which is not yet a registered company. Under the Digital Personal Data Protection Act, 2023 we are the Data Fiduciary for the personal data described here, and we are reachable at me@unilore.in.
What we collect
- Your institutional email address. Stored encrypted. When we need to find your account by email we compare a one-way fingerprint of it rather than decrypting anything.
- A display name, and optionally your real name. Your real name is shown only to other verified students on your campus, never publicly.
- Your branch and graduating batch.
- Proof that you study here. Either your address is on a domain the campus accepts, in which case we store nothing extra — or you upload a student ID. See below.
- What you post: memories, Moments, comments, Signals, Commons topics, archive contributions, and any images attached to them.
- Vibe activity: your Vibe profile answers, who you passed on or connected with.
- Direct messages, which we store but cannot read. See the next section.
- A push notification token, if you allow notifications.
What we cannot see
Direct messages are end-to-end encrypted. They are encrypted on your device with a key we have never held. We store the encrypted result and cannot read it — not for moderation, not for analytics, not if we are asked to. Images sent in a conversation are encrypted before they are uploaded, so the same is true of them.
There is exactly one exception, and it only happens when you choose it. If you report a conversation, your device decrypts the last few messages and sends them to campus moderators along with proof of who wrote each one. Nothing else in your history is shared, and reporting is the only mechanism by which any message content ever leaves your device in a readable form.
Because we cannot read messages, no automatic filter applies to them — not for language, not for images. What protects you there is being able to report, block, and the fact that only verified students on your campus can message you at all.
Student ID documents
If your email domain does not verify you automatically, you can upload a student ID. That document is encrypted at rest, is visible only to a campus reviewer, and every time a reviewer opens one it is recorded in an audit log. Once a decision is made, the document is destroyed. We keep the decision, not the evidence.
Location
The campus map and arrival alerts run entirely on your device. Your coordinates are never sent to us and we do not store them. If you type a place name into a post, that text is part of the post — but it is something you wrote, not something we measured.
Photographs
Images you post are re-encoded when uploaded, which removes the EXIF metadata your camera writes into a file — including GPS coordinates. We store a short mathematical fingerprint of each image so that a moderator's decision about one picture applies to the same picture if it is uploaded again.
Who else receives your data
- Clerk — sign-in and session management. Processes in the United States.
- Cloudflare R2 — image storage. Images are private and served through short-lived links.
- Voyage AI — search. When you search the campus archive, the words you type are sent to Voyage AI in the United States so the search can understand meaning rather than only matching keywords. We do not log your query on our side, but it does leave. If you would not want a sentence read by a third party, do not put it in the search box.
- Expo — push notification delivery. A notification carries a short title and a destination inside the app. Notifications about direct messages deliberately contain no message content — they say only that one arrived.
- Resend — email, used only to alert the operator about a safety escalation. It is never used to email students.
- Railway — hosting for the servers and the database, in Singapore.
- Vercel — hosting for this website and for UniLore on the web, including its built-in analytics, which counts page views and where they came from. It sets no cookie, builds no profile, and does not follow you to other sites.
We do not sell your data and we do not run advertising. Nothing measures what you tap, read or scroll past — the counting above is page views, not behaviour, and there is no analytics of any kind in the app you install from an app store.
Where your data is
Your account, your posts and your messages are stored in Singapore. That is where the servers and the database run. Nothing about UniLore is hosted in India today, so your data leaves the country the moment you use it — which is legal under the Digital Personal Data Protection Act, 2023, and which you should know rather than have to work out.
Some processing happens elsewhere. Sign-in runs through Clerk and search queries go to Voyage AI, both in the United States. Images are stored on Cloudflare's network. This website is served by Vercel.
Wherever it sits, your direct messages are encrypted before they leave your device. Their location is a fact about where ciphertext is stored, not about who can read it.
How long we keep things
- Your account and posts — until you delete them or your account.
- Deleted posts — permanently removed 30 days after deletion.
- Moments — expire after 24 hours; removed entirely within 7 days.
- Direct messages — kept until you or the other person deletes them. They do not expire.
- Vibe passes and ended connections — 90 days.
- Notifications — 180 days.
- Abuse-prevention counters — 2 days. These never store your IP address.
- Student ID documents — destroyed as soon as a decision is made.
Safety, and the one case where we keep something you cannot delete
Campus moderators can remove content and suspend accounts. Those decisions are logged with the reason and the moderator.
If material is identified as suspected child sexual abuse material, it is placed under legal hold rather than deleted, and the uploading account is suspended immediately. This is the one category where we preserve rather than remove, because destroying it would destroy evidence of a crime. No one in the product can view such material at any level of access, including administrators. Handling then happens outside this platform through the proper legal channel.
Your rights
Under the Digital Personal Data Protection Act, 2023 you may:
- ask what personal data we hold about you;
- correct anything inaccurate;
- have your data erased, subject to what the law requires us to keep;
- nominate someone to exercise these rights if you cannot;
- complain to us, and then to the Data Protection Board of India.
Email me@unilore.in and we will respond within 15 days. We cannot recover the contents of your direct messages for you — we never had the key.
Age
UniLore is for enrolled university students. If you are under 18, Indian law requires a parent or guardian's consent before your personal data is processed, and you should not use UniLore without it.
Grievance Officer
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:
The UniLore team
me@unilore.in
Complaints are acknowledged within 24 hours and resolved within 15 days. Reports of non-consensual intimate imagery are acted on within 24 hours.
Changes
If this policy changes in a way that affects you, we will tell you in the app before it takes effect rather than quietly updating the date at the top.