Privacy Policy
This Policy explains how UAI collects, uses, stores, shares, and protects your personal data when you use the UAI mobile application and related services. UAI is operated by Sleipnirtech Private Limited and acts as the Data Fiduciary under India's Digital Personal Data Protection Act, 2023. Questions? Write to uai@sleipnirtech.com.
1. Introduction
This Privacy Policy explains how UAI collects, uses, stores, shares, and protects your personal data when you use the UAI mobile application and related services.
UAI is a campus platform built for university and college communities in India. It brings together several campus utilities — an AI assistant, webmail, timetable, lost & found, library search, course information, learning-management-system course materials, and class attendance — in a single application.
This App is operated by Sleipnirtech Private Limited ("we", "us", "our"). For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), we act as the Data Fiduciary in respect of the personal data described below, and you (the user) are the Data Principal.
Relationship with your University. UAI uses your University login (campus single sign-on) credentials to verify your identity against your University's official systems and to access certain University services (such as your University email and learning-management system) on your behalf and at your direction. UAI is an independent, student-built platform and is not owned, operated, endorsed, or officially affiliated with any university or college. Your University's own systems (email, directory, learning-management system, library catalogue) are governed by your University's own policies, not this one.
By creating an account and using the App, you confirm that you have read and understood this Policy. Where we rely on your consent (see Section 8), you provide that consent through the clear affirmative actions described in this Policy.
2. Definitions
- Personal data — any data about an individual who is identifiable by or in relation to such data.
- Sensitive data — in this Policy we use this term for data requiring heightened protection, including biometric data, account credentials, and the contents of your email. (Biometric information is treated as "Sensitive Personal Data or Information" under India's Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.)
- Data Principal — you, the individual to whom the personal data relates.
- Data Fiduciary — the entity that determines the purpose and means of processing your personal data (us).
- Processing — any operation performed on personal data (collection, storage, use, sharing, deletion, etc.).
- Device — the phone, tablet, or computer on which you run the App.
- University — the university or college whose campus systems you connect to through the App, and whose community you belong to.
3. Summary
For your convenience, here is a short summary. The full detail is in the sections that follow, and the full detail controls.
- We use your University login to verify who you are and to fetch your University email and course data at your request.
- We store an encrypted copy of your University password because the App must repeatedly log in to your University mailbox on your behalf to fetch new mail. It is encrypted, never shown to anyone, and never sent to any third party other than your University's own login and mail servers.
- We read, store (encrypted), and index your University email so you can read, search, and ask the AI assistant about it. Your email content is processed by an AI model that we operate ourselves — your email is not sent to any third-party AI company.
- Face recognition for attendance runs entirely on your device. Your facial data (a mathematical "faceprint") is stored only on your device, is never uploaded to us or anyone else, and is deleted when you uninstall the App. Our servers only receive a yes/no "verified" result.
- We do not collect your GPS location.
- We use a small number of service providers (cloud hosting, push notifications, web search for the AI assistant, error/usage analytics). These are described in Section 10.
- You can access, correct, and delete your data, and withdraw consent. See Section 14.
4. Data we collect
We collect the categories of data below. For each we describe what it is, how we get it, and how it is protected.
4.1 Account & profile data (you provide this)
- Your University login ID (username) and, for display, your University email address (derived from your login ID).
- Full name.
- Entry / roll number (for students).
- Academic details: programme, branch/department, semester, group number, and your list of courses (for students); department and courses taught (for faculty/staff).
- Account type (student or faculty/staff).
- Optional profile photo you choose to upload.
- Optional email-priority preferences you configure (keywords/phrases you want flagged as important).
4.2 Credentials (special category — see Section 6)
- Your University login password. We store it in two protected forms: (a) a one-way securely hashed form used to verify future logins quickly, and (b) a reversibly-encrypted copy (using strong, industry-standard encryption) that the App uses to log in to your University mailbox on your behalf to fetch new mail. Neither form is ever displayed, exported, or shared with any party other than your University's own authentication and mail servers. See Section 6.1 for full detail and why this is necessary.
4.3 Email data (special category — see Section 6)
When you enable webmail, the App logs in to your University mailbox (over an encrypted connection) using your credentials and periodically fetches your incoming email. This includes:
- Email subjects and bodies.
- Sender, recipient (To/Cc) addresses, message identifiers, and timestamps.
- Attachments — the App downloads attachments and extracts their text (including via optical character recognition of images and scanned PDFs) so you can search them and ask the assistant about them.
- Links contained in certain broadcast/priority emails, which the App may fetch to extract linked-document text for search.
Email subjects, bodies, and the extracted text index are encrypted at rest. Certain routing metadata (sender/recipient addresses, message IDs, timestamps, and attachment filenames) is stored in readable form to allow display, sorting, and search. See Section 6.2.
4.4 AI assistant ("chat") data
- The questions you ask the assistant and the assistant's replies (your conversation history), and any thumbs-up/thumbs-down feedback you give.
- Conversation history is encrypted at rest and we retain only your most recent conversation threads (see Section 12).
- To answer you, the assistant may draw on your own emails, timetable, course information, your learning-management-system grades summary, and — for general questions — results from an internet search (see Sections 9 and 10).
4.5 Attendance data
- Facial data (biometric): processed and stored only on your device — see Section 6.3. Our servers store only a boolean indicating that you have completed face enrollment, plus, per attendance session, a match-confidence score and a yes/no "verified" result.
- Proximity / Bluetooth data: to confirm you are physically present in class, the App exchanges short-lived, signed tokens with nearby devices over Bluetooth Low Energy and observes nearby-device signal strength. This proximity information is used transiently and is not stored on our servers except as a single yes/no "present in room" indicator per attendance record. A per-installation device identifier is sent to our attendance server to evaluate presence; it is held only in memory and is not stored in our database. No Bluetooth exchange includes your name or login ID, and no GPS location is used (see Section 4.8).
- QR data: when marking attendance, you scan a rotating, short-lived code shown by your instructor. These codes are ephemeral and are not stored as a scan log.
- Attendance records (which class, when, verified/not) associated with your account.
4.6 Lost & Found data
- Item reports you create: item name, category, description, date, a free-text location (where the item was lost/found), a contact phone number you provide, and one or more photos you upload from your gallery.
- We compute mathematical image and text representations ("embeddings") of your photos and descriptions to match lost items with found items.
- When a high-confidence match is found, we send a push notification to the person who reported the item lost, which discloses the matching item's photo, location, reporter name, and contact number so the two people can connect. By posting a contact number you consent to it being shared in this way when a match occurs.
4.7 Device, session, and technical data
- A push-notification token (from the platform push service) so we can send you alerts.
- Device/session information used for security: platform (iOS/Android/web), app/client version, User-Agent string, IP address, an optional device public key, and a per-installation device identifier.
- Security/audit logs of authentication events (login, logout, registration, token refresh, failed/locked logins) including timestamp and IP address.
4.8 Location
- We do not collect GPS or precise geolocation. The App requests Bluetooth-related permissions (and, on some Android versions, a location permission that Android requires solely to enable Bluetooth scanning) only to support proximity-based attendance. We do not derive or store your geographic location from these.
4.9 Usage & analytics data
- We record how the App is used to keep it reliable and to understand feature usage: which features/screens and API routes are used, timestamps, session duration, request counts, platform, client version, latency, error status, and IP address. Some of this is associated with your login ID; aggregate performance metrics are kept without direct identifiers. See Section 10 for where this is processed.
4.10 Data we access but do not store
- Grades: fetched live from your University's learning-management system each time you view them and not permanently stored by us (a short-lived cache may hold them briefly to speed up display). Course materials you access may be stored to serve them to you.
- Library searches: your query is sent to your University's library catalogue and is not stored by us as search history.
- Timetable screenshots: if you upload a screenshot of your timetable, we send the image to a vision model we operate to read it, store only the extracted timetable text, and delete the image afterward.
5. How we use your data (purposes)
We use your data only for the following purposes:
- Authentication & account management — to verify your identity against your University's systems, create and secure your account, and manage sessions.
- Providing the features you use — webmail, AI assistant, timetable, attendance, lost & found, library, courses, and learning-management-system materials.
- Fetching your University email on your behalf (requires the stored encrypted credential — Section 6.1).
- Powering the AI assistant — answering your questions using your own data and, where relevant, internet search results (Section 9).
- Matching lost and found items and notifying the relevant users.
- Sending notifications you have opted into (e.g. important-email alerts, attendance/grade/lost-&-found alerts, app updates).
- Security, fraud prevention, and abuse protection — rate-limiting, account lockout on repeated failed logins, and audit logging.
- Reliability and improvement — diagnosing errors and understanding feature usage (analytics).
- Legal compliance — complying with applicable law and lawful requests.
We do not sell your personal data. We do not use your data for third-party advertising. We do not use your email content, chat content, or biometric data to train third-party AI models.
6. Sensitive data — detailed disclosures
Because the following categories carry heightened legal and personal risk, we describe them separately and in detail. Your use of the relevant feature, together with the consents described in Section 8, constitutes your explicit consent to the processing described here.
6.1 Your University password (stored encrypted)
- The App needs to log in to your University mailbox repeatedly and automatically to fetch new mail. Standard University mail access requires your password each time. For this to work in the background, we store a reversibly-encrypted copy of your University password (using strong, industry-standard encryption), in addition to a one-way securely hashed form used for fast login verification.
- The encrypted password is used for one purpose only: to authenticate to your University's own mail server and directory on your behalf. It is never displayed, logged in readable form, exported, or transmitted to any third party.
- Encryption keys are held separately from the data. If a key is unavailable, the system fails closed (it does not fall back to storing your password in readable form).
- If you change your University password, the App detects the change on its next fetch, removes the stored encrypted copy, and stops attempting mail access until you log in again with your new password.
6.2 Your email content (stored encrypted, indexed, and AI-processed)
- With your consent, the App fetches your incoming University email and stores it so you can read, search, and query it. Email subjects and bodies and the searchable text index (including text extracted from attachments) are encrypted at rest using strong, industry-standard encryption. Routing metadata (sender/recipient addresses, message IDs, timestamps, attachment filenames) is stored in readable form to enable display, sorting, and search.
- Attachments you receive are downloaded and stored in our cloud object storage; their text is extracted (including by optical character recognition of images/scanned PDFs) and added to the encrypted search index.
- Your email is partitioned per user: access requires your authenticated session, and the App's interfaces do not expose one user's mail to another user.
- AI processing: when you ask the assistant about your email, relevant portions of your email are decrypted momentarily and provided to an AI language model that we operate ourselves. Your email content is not sent to any third-party AI provider.
- Broadcast/priority email links: for certain broadcast or high-priority emails, the App may follow links found in the email to extract linked-document text for search. This causes an outbound request to the linked website.
- Retention: stored email is retained while your account is active and is deleted when you delete your account (see Section 12).
6.3 Biometric / facial data (on-device only)
This is the most sensitive category, so we are explicit:
- Where it lives: if you choose to use face-based attendance, the App captures your face using your device camera and computes a mathematical representation of your face (a "faceprint" / embedding — not a stored photograph). This faceprint is stored only on your device, in the device's secure, encrypted storage (Android Keystore / iOS Keychain).
- It never leaves your device. Your faceprint and your face images are never uploaded to our servers or shared with anyone. Face matching happens entirely on your device.
- What our servers receive: only a boolean flag that you have enrolled a face, and, per attendance check, a yes/no "verified" result and a confidence score. No image and no faceprint.
- Consent: face enrollment is optional and initiated by you. By enrolling, you consent to on-device face processing for attendance. Marking attendance by face verification requires an enrolled faceprint; if you choose not to enroll, you will not be able to use face-based attendance and should ask your instructor about the alternative your University offers.
- Deleting your faceprint: your faceprint is stored only in your device's private, encrypted app storage. Uninstalling the App deletes your registered face from your device, together with all other app data. You can also replace it at any time by re-enrolling, which overwrites the previously stored faceprint. Note: because your faceprint never reaches our servers, deleting your UAI account does not by itself remove the copy stored on your device — uninstall the App (or re-enroll over it) to remove it from the device.
- Transient images: during capture, your camera briefly writes image files to your device's private app storage for processing. These files are never uploaded to us or anyone else. They remain in the App's private storage on your device until the operating system reclaims the space, or you clear the App's storage or uninstall the App — which deletes them together with your registered face and all other app data.
7. Permissions we request
- Camera — to scan attendance QR codes, capture your face for on-device attendance, and (optionally) take a profile photo.
- Photo library / gallery — to let you pick a timetable screenshot, a lost-&-found item photo, or a profile photo.
- Bluetooth (scan/advertise/connect) — for proximity-based attendance verification.
- Notifications — to send you the alerts described in this Policy.
- Location (Android only, where required) — requested solely because some Android versions gate Bluetooth scanning behind a location permission; we do not collect your location.
You can decline or later revoke permissions in your device settings; some features will not work without the relevant permission.
8. Legal basis and consent
Under the DPDP Act, we process your personal data on the basis of your consent and, where applicable, for legitimate uses permitted by law (such as security and compliance).
- Your consent is obtained through clear affirmative actions: creating an account, enabling a feature (e.g. webmail, face attendance), granting a device permission, or submitting content (e.g. a lost-&-found report).
- Your consent is specific (tied to the purposes in Section 5), informed (this Policy), free, and unambiguous.
- You may withdraw consent at any time (Section 14). Withdrawing consent will stop the related processing going forward and may disable the related feature; it does not affect processing already carried out.
9. Automated processing and AI
- The App uses artificial-intelligence models to: answer your questions in the assistant; read timetable screenshots and email attachments (OCR); classify emails (e.g. urgency, schedule changes); and match lost-&-found items.
- Text and vision AI inference runs on infrastructure we operate. Your email and chat content are not sent to any third-party AI provider.
- Web search for the assistant is the exception: for general (non-personal) questions, the assistant may send your search query (not your emails or personal records) to a third-party internet search provider to retrieve public information (see Section 10). It may also fetch the content of public web pages in the results.
- These automated features assist you; they are not used to make legal or similarly significant decisions about you without a human in the loop. AI output can be inaccurate — see Section 18.
11. International data transfers
Some of our providers may store or process data on servers located in or outside India. Where personal data is transferred outside India, we do so in accordance with the DPDP Act and applicable transfer restrictions, and we take reasonable steps to ensure a comparable level of protection. We aim to host personal data within India where practicable.
12. Data retention
We keep personal data only as long as needed for the purposes in this Policy or as required by law:
- Account & profile data — retained while your account is active; deleted on account deletion.
- Credentials (encrypted) — retained while your account is active; the encrypted password copy is removed if you change your University password or delete your account.
- Email content — retained while your account is active and deleted when you delete your account.
- Chat/assistant history — only your most recent conversation threads are retained (older threads are automatically deleted); short-term conversation memory expires within hours.
- Lost & Found items and images — retained until you delete the item or your account.
- Attendance records — retained as institutional records; because attendance is an official University requirement, these records are not deleted on account deletion.
- Sessions & security/audit logs — retained for a limited period for security, then deleted; expired login sessions and refresh tokens are swept automatically.
- Usage/analytics records — retained for a limited operational period and then deleted or aggregated into anonymous statistics.
- On-device biometric faceprint — stored only on your device and deleted when you uninstall the App (or when you re-enroll over it); it is not stored on, or controlled by, our servers.
University-owned records. Certain records generated through your University's systems — in particular attendance records and learning-management-system-derived academic data — may be considered records of your University and may be retained even after you delete your UAI account, where we are required to preserve them or where they belong to the institution.
13. Security
We implement reasonable technical and organisational safeguards, including:
- Encryption at rest of email subjects/bodies and the search index, stored passwords, and AI conversation history, using strong, industry-standard encryption with support for key rotation. These systems fail closed (they refuse to store readable copies if encryption keys are unavailable).
- Encryption in transit (TLS) for connections between the App, our servers, your University's servers, and our service providers.
- On-device protection of biometric data using the device's hardware-backed secure storage.
- Per-user access controls — the App's interfaces are designed so that you access only your own data; identity is always established from a verified session token.
- Access controls, rate-limiting, account lockout on repeated failed logins, and audit logging of authentication events.
No system is perfectly secure. While we work hard to protect your data, we cannot guarantee absolute security, and you use the App at your own risk to that extent (see Section 18). If we become aware of a personal-data breach affecting you, we will notify you and the Data Protection Board of India as required by the DPDP Act.
14. Your rights
Subject to applicable law (including the DPDP Act), you have the right to:
- Access — obtain a summary of the personal data we process about you and how.
- Correction & updating — correct inaccurate or incomplete data (you can edit much of your profile in-app).
- Erasure / deletion — request deletion of your personal data and account (see below).
- Withdraw consent — for any processing based on consent.
- Grievance redressal — raise a complaint with our Grievance Officer (Section 17).
- Nominate — nominate another individual to exercise your rights in the event of your death or incapacity.
- Escalate — complain to the Data Protection Board of India if you are not satisfied with our response.
How to exercise your rights. Use the in-app controls where available, or contact us at uai@sleipnirtech.com. We will respond within the timeframes required by law. We may need to verify your identity before acting.
Account deletion. You can delete your data from our side by deleting your account. On deletion we remove your personal data across our systems — including your profile, stored (encrypted) credentials, stored email and attachments, chat history, lost-&-found items and images, device tokens, and sessions — subject to (a) shared broadcast emails, which are removed once no user references them, (b) records we must retain for legal or security reasons, and (c) university-owned records described in Section 12. Your registered face (faceprint) is stored only on your device, not on our servers; it is deleted when you uninstall the App (or when you re-enroll over it).
15. Children and minors
The App is intended for members of a university/college community and is designed for use by individuals 18 years of age or older. Under the DPDP Act, an individual under 18 is a child, and processing a child's data generally requires verifiable parental/guardian consent. If you are under 18, please do not use the App without your parent's or legal guardian's consent, and have them contact us at uai@sleipnirtech.com. If we learn that we have collected a minor's data without the required consent, we will delete it.
16. Third-party services and links
The App connects to your University's systems and the third-party services described in Section 10, and the AI assistant may surface links to external websites. Those services and websites are governed by their own privacy policies, which we do not control. We encourage you to review them. In particular, your use of your University's own systems is subject to your University's policies.
17. Grievance Officer and contact
If you have questions, requests, or complaints about this Policy or your data, contact:
- Grievance Officer: Deepak Batra
- Email: uai@sleipnirtech.com
We will acknowledge and address grievances within the timeframes required by applicable law. If handling biometric or large volumes of sensitive data causes us to be classified as a Significant Data Fiduciary under the DPDP Act, we will appoint a Data Protection Officer based in India and publish their contact details here.
18. Disclaimers and limitation of liability
- The App is provided "as is" and "as available" without warranties of any kind, express or implied, to the maximum extent permitted by law.
- AI output may be inaccurate, incomplete, or out of date. The AI assistant, email classification, timetable/attachment reading, and item matching are automated and may make mistakes. Do not rely on them for decisions with legal, academic, financial, medical, or safety consequences without independent verification. In particular, attendance verification and any grade/schedule information should be confirmed with official University sources.
- We are not responsible for the availability, accuracy, or policies of your University's systems or other third-party services, or for content the assistant retrieves from the internet.
- To the maximum extent permitted by law, we shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, arising from your use of the App.
- Nothing in this Policy limits any rights you have under the DPDP Act or other mandatory law, or excludes liability that cannot lawfully be excluded.
19. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and notify you within the App or by another reasonable means. Your continued use after an update means you accept the revised Policy (except where fresh consent is required by law, which we will obtain).
20. Governing law
This Policy is governed by the laws of India, and the courts at New Delhi shall have jurisdiction, subject to any mandatory provisions of the DPDP Act and the authority of the Data Protection Board of India.