Privacy
This policy explains what Ingenium stores when you use the student project board and workspace, why we store it, who else sees it, and how you can ask us to change or delete it.
It is written in plain language on purpose. It is meant to be accurate to the product as it exists today. Related rules live in the Terms of Use and the Cookie Policy.
Last updated 2 September 2026.
The controller of personal data processed through this service is the operator of Ingenium (“Ingenium,” “we,” “us”). Ingenium is an early-stage student collaboration platform. We have not published a separate registered company name or registered office on this site.
Privacy, access, correction, export, and deletion requests: privacy@project-ingenium.com, or the Contact page, as described in section 14. You can also export or delete your account from profile settings when you are signed in.
If you need a named legal entity, postal address, or data processing addendum for a campus or club contract, write to legal@project-ingenium.com before you rely on Ingenium for that purpose.
This policy applies to:
It does not apply to:
We collect the data you give us, data created while you use the service, and a small amount of technical data needed to keep you signed in.
When you join a team or interview call we send your display name to the call vendor. Audio and video go to that vendor for the length of the call. We do not operate our own recording feature. The vendor’s product may still process live media. If Daily.co is not configured, the product may open a Jitsi room on meet.jit.si instead.
We store in-app notification rows (for example: a new application or an interview update) so you can see them in the product. We do not currently send marketing email, digest email, or push notifications.
We do not currently run advertising pixels, Google Analytics, Mixpanel, PostHog, or similar product-analytics SDKs on these pages.
If UK GDPR or EU GDPR applies to you, we rely on the bases below. More than one basis can apply to the same activity.
| Purpose | Lawful basis |
|---|---|
| Create and keep your account, sign you in, reset or change credentials when that flow exists, and show your profile to you. | Contract (Art. 6(1)(b)) — we cannot run an account without this. |
| Check date of birth at signup so we do not create accounts for children under 13, and keep the attestation timestamp. | Legal obligation (COPPA / equivalent child-protection rules) and legitimate interests in keeping under-13 users off the service. |
| Let you post projects, apply, message a team, use tasks and whiteboards, and upload a pitch deck. | Contract. |
| Show public postings and public profiles on Explore / Browse so students can find teammates. | Contract, and legitimate interests (Art. 6(1)(f)) in operating a student project board. |
| Compute a reliability badge from completed and active project counts and show it on profiles. | Legitimate interests in helping students judge whether someone finishes work. You can object; see section 11. |
| Security, abuse prevention, debugging, and keeping the service available. | Legitimate interests; legal obligation where a law requires a log or a report. |
| Respond to access, deletion, or other rights requests, and to Contact notes. | Legal obligation (Art. 6(1)(c)) and contract. |
| Connect a live call through Daily.co or Jitsi. | Contract. Those vendors process call media under their own terms. |
Where a law requires consent (for example certain non-essential cookies in the UK/EU), we ask before setting them. The first visit opens a cookie preference centre. You can change that choice later from the Cookie Policy page. Today the cookies we set ourselves are for sign-in. See the Cookie Policy.
Ingenium is a directory as well as a workspace. The people directory lists only profiles that opted in. A signed-in account is not enough to browse every private profile.
The following is not shown on the public board:
Search engines and other people can copy public pages. Do not put a phone number, home address, or anything you would not put on a campus noticeboard into a public profile or posting.
We use other companies to host and run parts of the product. They process data on our instructions or, for call vendors, as independent providers of the live room.
| Name | What they do | Typical data |
|---|---|---|
| Supabase | Authentication, database, file storage, realtime updates. | Account, profile, projects, applications, messages, tasks, whiteboard state, pitch files, notifications. |
| Daily.co | Embedded team and interview video rooms, when configured. | Display name, live audio and video, room metadata. |
| 8x8 Jitsi (meet.jit.si) | Fallback call rooms opened in a new tab when Daily is not used. | Display name, live audio and video. That site has its own cookies and terms. |
| Excalidraw (library) | Whiteboard drawing surface in the browser. | Canvas state we store in our database; the library may also keep short-lived state on your device. |
| Hosting provider (for example Vercel, if that is where this site is deployed) | Serves the website and server actions. | Request logs, IP address, pages requested. |
| Google Fonts pipeline via Next.js | Nunito and Fraunces typefaces. Next.js usually self-hosts the files from this site at runtime. | If a request is made to Google, Google may see your IP. See the Cookie Policy. |
We do not currently use Stripe, an email-marketing tool, or a third-party analytics SDK in this application.
Supabase, Daily.co, Jitsi, and hosting providers may process data in the United States or other countries outside the UK and European Economic Area. Where UK GDPR or EU GDPR applies, those transfers rely on the vendor’s published transfer tools (often the European Commission Standard Contractual Clauses and a UK addendum) plus the vendor’s security measures.
If you use Jitsi on meet.jit.si, you are also dealing directly with that service in whatever countries it operates.
After deletion we may keep a minimal record that a request was made and completed, if we need that to show we complied with the law.
We share personal data only as follows:
We do not sell personal information. We do not sell student profile lists. We do not run advertising on these pages. We do not currently “share” personal information for cross-context behavioural advertising as those terms are used in the California Consumer Privacy Act (CCPA) / CPRA.
We use cookies and similar storage to keep you signed in. Details, including names, purposes, and how to block them, are in the Cookie Policy. That policy is part of this Privacy Policy.
We compute a simple reliability summary from how many projects you have completed or are active on (counts and a star/badge label). It is shown on public profiles. It is not a credit score. Ingenium does not use it as the sole basis of an automated decision that legally produces effects concerning you (for example we do not auto-ban accounts from it).
Other students can still use the badge when they decide whether to apply or accept someone. If UK/EU GDPR’s profiling rules apply to you, you can object to this processing through Contact. If we agree, we will stop showing the badge on your profile or otherwise limit it where the product allows.
Ingenium is aimed at students. You must be at least 13. Signup collects a date of birth and the server refuses the account before it is created if the calculated age is under 13.
We do not knowingly collect personal data from children under 13 (COPPA). If you believe a child under 13 has an account, write to privacy@project-ingenium.com. We will delete that account and related data we control.
We do not offer a parental-consent flow for under-13 users because those accounts are not allowed. If you are between 13 and 17, signup asks you to confirm a parent or guardian has reviewed the Terms, and we store the time of that confirmation. That is still self-attestation, not a verified parental consent flow.
Depending on where you live, you may have some or all of the following rights. We will not discriminate against you for exercising them.
Categories collected, in CCPA terms, typically include identifiers (email, username), student/education information you type (school), professional information (skills, roles, project history), internet activity (use of the service, session cookies), and audio/visual information during a live call (processed by the call vendor). We do not intentionally collect government ID numbers, precise geolocation, or payment card data.
When you are signed in, profile settings include “Download my data” and “Delete my account.” You can also write to privacy@project-ingenium.com or use Contact.
We may need to verify you control the email. We aim to respond within 30 days (GDPR) or 45 days (CCPA), or sooner if the law requires it, and will say if we need more time.
Deletion limits: we may keep data we must keep for law, disputes, or security; we cannot delete copies other students already downloaded; public search-engine caches are outside our control; shared catalog strings may remain; call vendors may keep their own logs under their policies.
You can edit profile fields and sign out yourself from your account page. Signing out is not deletion.
We use HTTPS, hashed passwords at the auth provider, access checks in the application, and database row-level security at Supabase. Pitch downloads use time-limited signed URLs. No method of transmission or storage is completely secure. Do not put secrets (API keys, exam answers you are not allowed to share) in chat or on a whiteboard.
If we become aware of a personal-data breach that must be notified, we will notify the relevant authority and affected users as the law requires.
We will update this page when the product or the law changes. The “Last updated” date at the top is the current version. If a change materially expands what we collect or who we share it with, we will also say so in the product or by email if we have a working mail channel by then.
Privacy requests: privacy@project-ingenium.com. Product and accounts: support@project-ingenium.com. Safety: safety@project-ingenium.com. Terms: legal@project-ingenium.com. Also Contact, the Terms of Use, and the Cookie Policy.