Privacy Policy
Last updated: October 10, 2026 • Effective for all FYPMate services
1. Introduction
FYPMate ("we," "our," or "the platform") is dedicated to protecting student privacy while facilitating academic collaboration. This Privacy Policy outlines how your personal information is collected, stored, protected, and processed when using our Final Year Project (FYP) partner discovery and AI idea validation tools.
Academic Scope: FYPMate is an educational technology solution designed for university students (primarily Pak-Austria Fachhochschule: Institute of Applied Sciences and Technology, PAF-IAST) to assemble competent FYP groups and benchmark project viability.
2. Information We Collect
We collect only the information necessary to provide peer matching and academic validation services:
2.1 Institutional Account Data
- Full name and university email address (
@paf-iast.edu.pk) retrieved via Microsoft Azure AD. - Student registration number, academic department, and current semester.
2.2 Profile & Technical Skills
- Bio, technical skill proficiencies, and project interests.
- Portfolio hyperlinks (e.g., GitHub, LinkedIn, personal website).
- Availability status (Available, Busy, Away).
2.3 Communication & Proposal Data
- Direct messages and chat history exchanged between students on the platform.
- Teammate connection requests and group formation invitations.
- Project proposal drafts and abstracts submitted to the AI FYP Idea Validator.
3. How We Use Your Information
- Authentication & Verification: Confirming genuine university student enrollment.
- Peer Teammate Matching: Allowing fellow students to discover partners with complementary skill sets.
- Real-Time Messaging: Powering instant communication between students who mutually accept chat requests.
- AI Feasibility Benchmarking: Evaluating proposed project ideas across Novelty, Technical Feasibility, Timeline, and Hardware constraints.
4. Communications Policy & Administrative Audit
Student Safety, Anti-Harassment & Moderation Standards
Messages sent across FYPMate are transmitted over encrypted TLS channels and stored securely in our PostgreSQL database. Because FYPMate is an official academic collaboration tool governed by university codes of conduct, communications are not end-to-end encrypted.
To protect students from cyber-harassment, threats, blackmail, academic misconduct, or fraud, authorized platform administrators maintain read-only access to conversation history. Such access is strictly restricted to:
- Investigating formal reports or complaints of harassment, abusive language, or inappropriate conduct filed by a student.
- Inquiring into reports of academic fraud, intellectual property theft, or violation of institutional project guidelines.
- Resolving critical technical errors or verifying system integrity under audit logging.
Administrators do not engage in arbitrary or casual surveillance of student communications. Every administrative access event is logged for accountability.
5. Data Sharing and Third Parties
We do not sell, rent, or monetize student personal information. Data is shared exclusively under these terms:
- With Fellow Students: Your public profile information (name, skills, bio) is visible to authenticated students seeking partners.
- Infrastructure Providers: Supabase (PostgreSQL database & authentication) and Microsoft Azure (OAuth Single Sign-On).
- Legal & Institutional Compliance: When required by university disciplinary committees or law enforcement in cases of criminal threats or legal subpoenas.
6. Security & Storage
- Data is hosted in PostgreSQL databases secured with SSL encryption in transit and at rest.
- Authentication session tokens are stored in secure,
httpOnlycookies. - Row-Level Security (RLS) policies restrict database read/write access to authenticated user scopes.
7. Student Rights & Account Deletion
Students have full access to view, modify, or request deletion of their profile data at any time via the Settings dashboard. Upon formal account deletion request, user identification data is purged within 30 days, except where retention is required for active academic dispute resolution.
8. Contact & Administration
For questions or concerns regarding this policy, contact the platform development and administration team: