Back to Home

LEGAL · DOC-PP-001

Privacy Policy

Last Updated: July 16, 2026 · Effective immediately

CampusNinja ("we," "our," or "us") operates the CampusNinja mobile application and the CampusNinja website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.

1. Information We Collect

a) Information You Provide

  • Account Information: When you sign in with Google, we receive your name, email address, and profile picture from your Google account.
  • Academic Preferences: Your selected course (B.Tech), engineering branch, and semester.
  • Order Information: When placing marketplace orders, you provide your name, email, phone number, college name, delivery address, and any uploaded files (PDFs, images).
  • Support Requests: Any messages or emails you send to our support team.

b) Information Collected Automatically

  • Device Information: Device type, operating system, platform (Android/iOS), and a unique device push notification token (FCM token).
  • Usage Data: App open events, subject views, resource downloads, marketplace interactions, and search queries (logged locally for analytics).
  • Installation Timestamp: The date and time the app was first installed on your device.

c) Information We Do NOT Collect

  • Location data (GPS, network-based)
  • Contacts or phone book data
  • Camera or microphone data
  • Payment card or financial information (all orders are Cash on Delivery)
  • Health, fitness, or biometric data
  • Advertising identifiers or cross-app tracking data

2. How We Use Your Information

  • Personalized Academic Content: To display subjects, notes, PYQs, video lectures, and syllabus relevant to your selected branch and semester.
  • Order Fulfillment: To process, track, and deliver your marketplace orders.
  • Push Notifications: To send you academic updates, new resource alerts, and order status changes.
  • Service Improvement: To understand usage patterns (anonymized) and improve the app experience.
  • Authentication: To verify your identity and maintain your session across app restarts.
  • Customer Support: To respond to your inquiries and resolve issues.

3. Authentication & Sign-In

CampusNinja uses Google Sign-In via Supabase Authentication as the sole sign-in method. When you sign in, we receive:

  • Your Google account name and email address
  • Your Google profile picture URL
  • A unique user identifier

We do not receive or store your Google account password. Authentication tokens are securely stored on your device and refreshed automatically by Supabase.

Signing in is optional. The app can be used without an account for browsing subjects, notes, and study resources. An account is required only for placing marketplace orders.

4. Push Notifications

We use Firebase Cloud Messaging (FCM) via Expo Notifications to send push notifications. When you grant notification permission, we obtain:

  • An Expo push token (for the Expo notification service)
  • A native FCM device token (for Firebase Cloud Messaging)

These tokens are stored in our Supabase database (in the device_tokens table) alongside your user ID (if signed in), selected branch, semester, and platform type.

You can disable push notifications at any time through your device's system settings. When you sign out, your device token is automatically removed from our servers.

5. Analytics

CampusNinja uses basic event tracking to understand how the app is used. Events tracked include:

  • App open events
  • Subject and resource views
  • PDF downloads
  • Marketplace interactions
  • Order creation events

Currently, analytics events are logged locally on the device for debugging purposes. Firebase Analytics JS SDK is not active in the React Native environment. No analytics data is transmitted to third-party analytics services.

We do not use any advertising identifiers, cross-app tracking, or third-party analytics SDKs that profile users.

6. Third-Party Services

We use the following third-party services, each with their own privacy policies:

Supabase

Database, authentication, file storage, and real-time data

Privacy Policy

Firebase (Google)

Cloud Messaging (FCM) for push notifications

Privacy Policy

Google Sign-In

OAuth authentication provider

Privacy Policy

Expo

App framework, OTA updates, push notification relay

Privacy Policy

We do not sell, trade, or rent your personal information to any third party. Data shared with the above services is limited to what is necessary for their operation as described.

7. Cookies & Local Storage

Mobile App: The CampusNinja mobile app uses AsyncStorage (device-local storage) to store:

  • Your academic setup preferences (branch, semester)
  • Onboarding completion status
  • Recent search history
  • Authentication session tokens
  • Installation timestamp

This data is stored locally on your device and is not transmitted to any server unless explicitly stated.

Website: The CampusNinja website may use essential cookies and local storage for session management and functionality. We do not use advertising or tracking cookies.

8. Your Rights

Under applicable data protection laws, including the General Data Protection Regulation (GDPR) and the Indian Digital Personal Data Protection Act (DPDP Act, 2023), you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request permanent deletion of your account and associated data (see Section 12).
  • Portability: Request your data in a structured, machine-readable format.
  • Withdraw Consent: Withdraw consent for data processing at any time by deleting your account or contacting us.
  • Grievance Redressal: Under the DPDP Act, you may raise a grievance with us and, if unresolved, with the Data Protection Board of India.

To exercise any of these rights, please contact us at manavgupta236@gmail.com.

9. Data Retention

We retain your personal data only for as long as necessary to provide our Service:

  • Account Data: Retained until you delete your account.
  • Order Records: Retained for up to 2 years after order completion for record-keeping and dispute resolution, then anonymized.
  • Device Tokens: Removed when you sign out, delete your account, or uninstall the app.
  • Uploaded Files: Order-related files are retained for the duration of the order lifecycle and deleted upon account deletion.
  • Local Storage: Cleared when you delete the app from your device.

10. Security

We take the security of your data seriously and implement the following measures:

  • Encryption in Transit: All data transmitted between your device and our servers uses TLS/HTTPS encryption.
  • Encryption at Rest: Supabase encrypts all stored data at rest using AES-256 encryption.
  • Row-Level Security: Supabase Row-Level Security (RLS) policies ensure users can only access their own data.
  • Secure Authentication: OAuth 2.0 via Google Sign-In with token-based session management.
  • No Password Storage: We never store user passwords; authentication is delegated entirely to Google.

While we strive to use commercially acceptable means to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

11. Children's Privacy

CampusNinja is designed for engineering college students and is not directed at children under the age of 13 (or 18 in jurisdictions where applicable). We do not knowingly collect personal information from children under 13.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us at manavgupta236@gmail.com and we will promptly delete such information.

12. Account Deletion

You can permanently delete your CampusNinja account at any time through the mobile app:

  1. Open the CampusNinja app
  2. Go to Profile tab
  3. Scroll to Help & Legal section
  4. Tap Delete Account
  5. Confirm deletion in the two-step confirmation dialog

Upon account deletion, we permanently remove:

  • Your authentication account and session
  • Your push notification device tokens
  • Your uploaded order files from cloud storage
  • Your order records (anonymized for legal compliance)

You may also request account deletion by emailing us at manavgupta236@gmail.com. Deletion requests are processed within 7 business days.

For detailed instructions, visit our Account Deletion page.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page and notify users through a push notification or in-app banner for material changes.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes acceptance of the updated policy.

14. Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us:

CampusNinja

Email: manavgupta236@gmail.com

Website: campusninja-web.vercel.app

For data protection grievances under the Indian DPDP Act, you may contact the Data Protection Board of India if your grievance is not resolved within 30 days.