Privacy Policy
This policy describes what data the DSMNRU PYQ archive collects, why, and the choices you have. It reflects the services currently implemented by the website and the Android app.
Effective / Last updated: 4 September 2026
1. Information We Collect
- Account data — if you create an account: email address, and your profile fields (name, course, phone number if you add them). Sign-in is handled by Firebase Authentication (email/password, and Google Sign-In where enabled).
- Contribution data — when you upload a paper or images: your name and email (as entered), the file content, and the submission's review state.
- Feedback data — the content of Request PYQ / Report broken link submissions, plus the optional email you provide.
- Points data — reward balances and transaction history tied to your email or account.
- Device information (Android app) — an FCM registration token used only to deliver push notifications to your device; it is stored on your device, not in our database. The Android app also links to Firebase Analytics at the library level (see Section 4).
- Technical logs — web hosting and API infrastructure (Netlify, Cloudflare, Google) keep standard server logs, and the Cloudflare Worker uses short-lived counters keyed by request IP for rate limiting. These expire automatically.
2. How We Use Information
- To provide the archive: showing papers, search, previews, downloads and the Android app.
- To review and publish submissions you upload.
- To respond to feedback, requests and reports.
- To maintain your profile, saved papers, recent history and contribution points.
- To send push notifications if you install the Android app and allow them.
- To keep the service secure, prevent abuse and understand aggregate usage.
We do not sell personal data. The project is not affiliated with DSMNRU University.
3. Authentication & Account Data
Accounts use Firebase Authentication (project dsmnru-data) with email/password and Google Sign-In available on the website and in the Android app. Your profile document is stored in Firestore under your account ID. You can view your profile in the app/website; administrators can see account records needed to operate the archive.
4. Uploaded Content
When you submit a paper, the PDF/images are first uploaded to gofile.io, a third-party file-hosting service, and the resulting link plus your name/email is stored in the archive's review queue. After approval the item appears publicly in the archive. Do not upload files containing personal or confidential information you do not want shared — papers may be publicly visible.
5. Analytics
The website does not currently load an analytics script — the site deliberately removed Firebase Analytics / GA tracking to reduce data collection and Firestore reads. The Firebase configuration file still contains a measurement ID string, but no analytics SDK is loaded on the site.
The Android app includes the Firebase Analytics library as part of its Firebase setup. We have not implemented any custom analytics dashboards; analytics data, where collected, is processed by Google under Firebase's terms.
6. Push Notifications
The Android app uses Firebase Cloud Messaging. The FCM registration token stays on your device; the app subscribes your install to a single shared notification topic. The backend does not store per-device tokens. Notifications are only shown if you grant Android's notification permission (asked once on Android 13+). You can turn notifications off at any time in your device's app settings.
7. Device & Technical Information
Standard technical data (browser/OS type [where visible to our hosts], IP address used for rate limiting and security, cache keys) is handled by the hosting providers (Netlify, Cloudflare, Google). The website stores small amounts of data in your browser for caching (service worker cache, session/local storage for search and session state) so the archive loads fast; this data stays in your browser until you clear it. No third-party advertising or tracking cookies are used.
8. Third-Party Services
- Firebase (Google) — Authentication, Firestore, Cloud Messaging, Storage/Analytics — see Google's Privacy Policy.
- Cloudflare Workers — API hosting, KV cache and rate limiting.
- Netlify — static website hosting.
- gofile.io — temporary file storage for uploaded papers.
- WhatsApp channel — external link; WhatsApp is not operated by us.
Each provider handles data under its own terms and privacy policy.
9. Data Retention
- Submitted content stays in the review queue until reviewed, then remains while the archive holds the paper (or until removed).
- Account, profile, points and feedback records stay until you ask us to remove them or until the Service is discontinued.
- Server logs and rate-limit counters are short-lived and expire automatically.
- We do not delete content merely because you close an account if it is part of the public archive (for example, a paper you contributed) — contact us if you want such material reviewed.
10. Security Practices
Access to the admin panel is protected by Firebase Authentication and Firestore security rules, and the API only accepts admin actions after verifying a signed Firebase ID token with an admin claim on the server. Firebase service-account credentials are kept only as server-side secrets (never in the site's code or public documents). No system is perfectly secure; please report suspected issues through the contact channels below.
11. Your Choices & Controls
- Browse without an account — most public archive content is visible without signing in (some features require a verified account).
- Edit profile information from your profile page.
- Stop push notifications in the Android app settings or your device's app notifications settings.
- Clear browser cache/storage to remove locally cached data.
- Ask us to review or remove your submissions/feedback (subject to Section 9).
12. Account & Data Deletion
The website and app do not currently offer a self-service "delete my account" button. To request deletion of your account or related personal data, contact us via the feedback forms or the GitHub repository (Section 15). We will verify the request and delete or anonymize what we can within a reasonable time. Purely technical measures to protect against abuse or legal requirements may still keep limited records.
13. Notification Controls
On Android, the app asks for the system notification permission once (Android 13+). You can grant or deny it, and change it later in Settings → Apps → DSMNRU PYQ → Notifications. When denied, the app still works normally; notifications simply don't appear.
14. Children's Privacy
The Service is an educational resource for students. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal data, contact us and we will take steps to delete it.
15. Changes to This Policy & Contact
We may update this policy as the Service changes. The newest version is always on this page with its "Last updated" date. Questions, requests and data-deletion requests can be sent through:
- The in-site Request PYQ / Report broken link forms (Feedback inbox),
- The WhatsApp channel linked in the footer