How We Protect & Respect Your Privacy
Acadex is built by students, for students. We believe in 100% transparency. Here is a clear, thorough, and jargon-free explanation of what information we handle, why we need it, where it goes, and how you stay in complete control.
Privacy at a Glance (The 4 Big Promises)
Zero Ads or Data Selling
We will never sell, rent, monetize, or give away your personal data to ad networks, data brokers, or marketers. Period.
Irreversible Password Hashing
Your actual password is never stored or visible to anyone. It is transformed into a cryptographic bcrypt hash on our servers.
Secure Academic Cloud
Uploaded notes, assignments, and practicals are safely hosted on Google Drive and organized strictly for your class section.
Opt-in Notifications Only
Web Push notifications for new notes or upcoming deadlines are 100% voluntary and never collect your location or phone number.
Quick Jump to Section:
1. Introduction & Our Mission
Why Acadex exists and what this policy covers
Acadex is a modern, student-driven academic resource platform created to replace chaotic WhatsApp group shares, lost Google Drive links, and disorganized assignment trackers. Our goal is simple: make studying effortless, organized, and collaborative.
Because Acadex is built for students, we treat your privacy with the highest respect. We only collect the minimal information necessary to identify you, put you in the right classroom section, show you relevant study materials, and send you important academic alerts.
Summary: This Privacy Policy applies to the entire Acadex web platform at au-acadex.com and any associated Progressive Web App (PWA) installation. By using Acadex, you acknowledge the data handling practices described here.
2. Exact Data We Collect (And Why)
Every piece of data we handle, categorized clearly
A. Account & College Identity
- Full Name: To identify you to teachers, peers, and admins.
- College ID / Roll No: Your primary login username and unique identifier.
- Email Address: Optional or provided during registration; used exclusively for password resets (OTPs) and account approval updates.
- Stream, Semester & Section: Needed to automatically connect you to the exact syllabus, subjects, and study materials for your branch.
- Profile Picture: Optional image you choose to upload for your user profile.
B. Security & Authentication Data
- Password Hashes: We never save your raw password. We store a non-reversible cryptographic hash generated with the bcrypt algorithm.
- Session Tokens: Stored inside a secure HTTP-Only cookie to keep you logged in safely across browser tabs.
- Temporary OTPs: 6-digit one-time codes generated when resetting passwords or verifying emails. These automatically self-destruct after a few minutes.
C. Academic Files & Progress
- Uploaded Resources: PDF files, documents, or images you upload as Notes, Assignments, or Practicals, along with your chosen title and description.
- Completion Checkmarks: Which assignments or practicals you have marked as "Completed" on your personal dashboard to track your study deadlines.
D. Preferences & Push Subscriptions
- App Customization: Your selected Theme (Light/Dark/System), Accent Color, and Mobile Navigation Bar position.
- Web Push Keys: An encrypted push subscription token provided by your browser if you choose to enable device alerts. (No GPS or phone number).
- Notification Toggles: Which specific alert types you want to receive (e.g. only new notes, only deadlines).
Administrative & Security Activity Logs
To protect student data against vandalism or unauthorized account takeovers, Acadex records administrative actions and high-level events (such as user logins, file uploads, role changes, and access request decisions) in an internal activity log. These logs are strictly accessible to authorized administrators for security auditing.
3. What We Never Do (Zero Exploitation)
Clear boundaries on what will never happen to your data
No Selling or Renting Data: We will never sell your student profile, email, or usage data to recruiters, advertisers, or third parties.
No Ad Tracking or Pixels: We do not load Facebook Pixels, Google AdSense, or third-party behavior trackers on Acadex.
No AI Model Training on Notes: We do not feed your uploaded assignments or notes into external AI/ML models for commercial training.
No Intrusive Device Access: We never request access to your device microphone, camera, contacts, or GPS location.
4. How Passwords & Logins Work (In Plain English)
Understanding cryptographic hashing vs. plain passwords
A lot of websites store passwords insecurely. We want you to feel 100% confident in how Acadex handles your credentials:
You Type Your Password
When logging in or signing up, your password is transmitted over an encrypted HTTPS connection to our secure server.
One-Way bcrypt Hashing
Our server converts the password into a scrambled digital fingerprint (hash). This mathematical formula is impossible to reverse back into plain text.
Secure HTTP-Only Cookie
Upon successful login, your browser gets a secure JWT cookie called acadex-token that cannot be stolen by JavaScript.
What this means for you: Even if someone gained unauthorized access to the database, your actual password is never stored anywhere. Even Acadex developers cannot see what your password is.
5. File Uploads & Google Drive Integration
How notes, assignments, and practicals are stored
When you upload a lecture note, assignment, practical guide, or profile photo to Acadex, the file is processed through our secure upload pipeline:
- Direct Google Drive Storage: To guarantee high download speeds and massive storage reliability, files are uploaded directly to our cloud repository on Google Drive via official Google APIs.
- Organized Subfolder Hierarchy: Files are systematically structured by Stream → Semester → Subject → Resource Type so your batchmates find what they need instantly.
- Moderation Queue: User-submitted uploads pass through an administrative verification queue where student coordinators ensure study materials are clean, relevant, and free of spam.
- Public vs Class Visibility: Study materials are published for the academic benefit of students in your stream and semester. Do not upload confidential personal files to the academic repository.
6. Web Push Notifications (100% Opt-In)
How browser & device alerts work without tracking you
Acadex supports instant Web Push notifications so you never miss an assignment deadline or note upload. Here is how it operates:
How it connects: When you click "Enable Notifications", your browser securely negotiates an encrypted push subscription key (VAPID protocol) with your browser vendor (e.g. Google FCM, Mozilla, Apple).
No Tracking: This push token contains zero personal info—no phone number, no GPS, and no physical address. It is simply a secret electronic mailbox address so our server can tell your browser: "Hey, a new note was posted for your class!"
How to Turn Off: You can revoke notification permissions at any moment in your browser settings (click the lock icon next to the URL) or disable specific alert categories inside your Acadex Dashboard settings.
7. Cookies & Local Browser Storage
The few technical cookies we need to keep you logged in
We keep cookie usage to an absolute bare minimum. We do not use third-party marketing or cross-site tracking cookies.
| Key / Name | Type | Purpose | Lifespan |
|---|---|---|---|
| acadex-token | HTTP-Only Cookie | Keeps you securely authenticated to your account without exposing your token to client scripts. | 7 Days |
| theme | Local Storage | Remembers if you prefer Dark Mode, Light Mode, or your device system default. | Persistent |
| acadex_app_installed / banner | Local Storage | Remembers if you dismissed the "Install App" prompt so we don't bother you again. | Persistent |
8. Third-Party Infrastructure Services
Every external cloud service that powers the Acadex platform
To provide high availability, fast downloads, and 99.9% uptime, Acadex relies on trusted infrastructure partners:
Encrypted cloud database holding user profiles, subjects, access requests, and academic text records.
High-capacity cloud storage where all study materials (PDFs, PPTs, images) are safely stored and served.
Runs the web interface and serverless APIs with SSL/TLS encryption across global edge nodes.
Sends verification OTP codes, password reset links, and access approvals to your email.
9. Who Can See What? (Role-Based Privacy)
Understanding what other students or admins can see
👨🎓 Fellow Students
Can see your Name, Section, and study materials you have publicly published to the library. They cannot see your password, your personal completion checkmarks, or your private settings.
🧑🏫 Section Admins
Can see student rosters in their assigned branch/section, review submitted notes/assignments, and approve new account requests. Admins cannot see your raw password.
🛡️ Super Admins
Maintain overall platform infrastructure, manage syllabus structures, resolve technical bugs, and perform data backups.
10. Data Retention, Updates & Deletion
How long we keep data and how you can delete it
We keep your account information active for as long as you are enrolled and using Acadex to study.
- Updating Your Data: You can update your email, profile picture, password, and preferences directly in your Profile Settings anytime.
- Account Deletion: If you graduate, change colleges, or wish to delete your account permanently, you can submit a deletion request via our Contact Form or ask your section administrator.
- Resource Retention: Useful academic notes or syllabus materials you uploaded for the community may remain available to your juniors unless you explicitly request their removal.
11. Student Frequently Asked Questions (FAQ)
Common questions about privacy and security answered simply
Can my college professors or classmates see my password?
No, absolutely not. Your password is automatically scrambled with bcrypt into a one-way mathematical code before it ever touches our database. Nobody—not even the site creator—can see your password.
Are my uploaded assignments private to me or shared with everyone?
Acadex is designed for collaborative academic sharing. When you upload a note or assignment to the library, it is made available to authenticated students in your specific stream and semester after being reviewed by an admin. Do not upload personal, private, or non-academic documents.
Can Acadex or any admin track my GPS location?
No. Acadex does not ask for or collect your GPS location, device sensors, camera, or microphone permissions.
What happens if I forget my password?
If you linked an email address to your account, you can request a 6-digit One-Time Password (OTP) via the Forgot Password page to set a new password securely. Alternatively, your section administrator can generate a secure temporary password for you.
Is Acadex free and open source?
Yes! Acadex is an open-source initiative built with love for the student community. We do not place annoying advertisements or monetize your data.
12. Questions, Feedback & Contact
How to reach the team behind Acadex
We welcome any suggestions, privacy concerns, or data correction requests. You can contact us directly through any of these official channels:
Notice: This policy is maintained directly by the Acadex development and administration team. Updates are posted directly to this URL with a revised effective date.