Privacy Policy
Privacy Policy for Varia
Effective Date: 27/08/2025
Last Updated: 27/08/2025
Varia (“Varia,” “we,” “our,” or “us”) provides a socio-study app that lets students access free study materials, receive real-time campus event notifications, get AI-assisted study help, create personalized timetables, and share educational content. This Privacy Policy explains what we collect, why we collect it, how we use and share it, and the choices you have.
1) Who we are & scope
This policy applies to the Varia mobile app and any services that link to it.
2) Minimum age
Varia is intended for users aged 16 and above. We do not knowingly collect personal data from anyone under 16. If you believe a user under 16 has provided personal data, contact us and we will delete it.
3) Information we collect
We collect:
A. Account & profile data (you provide):
Name (or display name), email, password (hashed), optional profile photo, university/program info you add, verification/badge status.
B. Content you upload (you choose to share):
Educational materials (e.g., documents, links, media) and event notifications you post.
Note: Varia does not provide a comments feature at this time.
C. Timetable & preferences (you provide):
Courses, schedules, reminder settings, notification preferences, theme (light/dark).
D. AI assistance inputs (you provide):
The text you type into the AI study helper (e.g., questions or prompts). We take steps to minimize personal data in prompts.
E. App usage & diagnostics (collected automatically):
Device and app identifiers, basic device info, crash logs, performance and interaction events (e.g., which screens are used), approximate region (derived from IP), push notification token.
What we do not collect by default:
Contacts, precise GPS location, SMS, call logs, or microphone/camera data (unless you explicitly use a feature that needs the camera—for example, to upload a photo).
4) Why we collect it (how we use data)
Provide core features: account, study materials, event notifications, timetables, AI study help.
Personalize experience: recommendations, saved preferences.
Notifications: send campus/event alerts and study reminders you enable.
Safety & integrity: prevent spam, abuse, and violations of our terms.
Analytics & quality: fix crashes, improve performance, measure feature usage.
Legal compliance: meet legal, regulatory, and audit requirements.
We do not sell personal data. We do not show third-party advertising at this time.
5) AI processing
When you use AI study help, your prompt (and minimal context needed to answer it) may be processed by our trusted AI service provider(s) to generate a response. We instruct providers not to use prompts to train their general models unless they already offer strong contractual restrictions. Avoid including sensitive personal information in prompts.
6) When we share information
We may share limited data with:
Service providers/Processors: hosting, cloud storage, analytics/crash reporting, push notifications, and AI processing—only to operate the app, under contracts that limit use.
Other users: when you choose to share educational materials or event posts (visibility you select).
Legal & safety: if required by law, subpoena, or to protect the rights, safety, or security of users, the public, or our services.
Business transfers: if we undergo a merger, acquisition, or asset sale, your information may be transferred under this same policy.
We do not share your personal data with third parties for their independent marketing.
7) Data retention
Account & profile: kept until you delete your account or we deactivate for inactivity per our policies.
Shared content (materials/events): kept until you delete it or your account; residual copies may remain in backups for a limited period.
Diagnostics/logs: typically retained for up to 12–24 months, then aggregated or deleted.
We may retain data longer if required by law, to resolve disputes, or enforce agreements.
8) Your choices & rights
You can:
Access & update profile information in the app.
Manage notifications in system settings and in-app.
Delete content you’ve uploaded.
Request account deletion (in-app if available, or by emailing us).
Data requests: contact us to request a copy of your personal data, correction, restriction, or objection where applicable by law (e.g., NDPR/GDPR-style rights).
9) Security
We use reasonable administrative, technical, and organizational measures (e.g., encryption in transit, hashed passwords, access controls). No system is 100% secure; please use a strong, unique password and keep your device updated.
10) International transfers
If we transfer data across borders, we use lawful mechanisms (e.g., contractual clauses) and safeguard your information in line with this policy.
11) Third-party services
Varia may link to or integrate with third-party services used to deliver features (e.g., video or news content). Your use of those services is governed by their own policies and terms.
If Varia surfaces YouTube content via YouTube API Services, your use is also subject to YouTube Terms of Service and Google Privacy Policy, and you can revoke access any time via your Google account permissions.
12) Changes to this policy
We may update this policy from time to time. If changes are material, we will notify you via the app or email and indicate the new “Last Updated” date.
13) Contact us
Questions or requests about privacy?
Email: Our Email
Address: 2, Bashiru Demu Close, Abule Osorun, Ibese, Ikorodu
Appendix: Google Play Data Safety summary (for your form)
Collected: Name/email, profile photo (optional), university info (optional), user content you upload (materials/events), app activity, device IDs, diagnostics/crash logs, push token.
Not collected: Contacts, precise location, SMS/call logs.
Purposes: App functionality, account management, content sharing (you choose), notifications, analytics, fraud prevention, security, compliance.
Data handling: No sale; no third-party advertising; shared with processors under contract; retention as above; security controls in place.
Plain-English explanation of each section (what it means & why it’s here)
1) Who we are & scope
Sets the legal “what this policy covers” and who to contact. Google Play reviewers also look for reachable contact details.
2) Minimum age (16+)
You asked to raise the threshold. This aligns with stricter regions (GDPR default is 16). We block use by under-16s and provide a removal path if we discover such data.
3) Information we collect
Breaks data into clear buckets so users (and Play’s Data safety form) can see what’s in/out.
We explicitly state no comments feature yet.
We exclude sensitive device data (contacts, precise GPS, SMS, etc.) unless a feature truly needs it.
We call out that AI prompts are user-provided text, so users avoid pasting personal data.
4) Why we collect it
Maps each category to purposes allowed by Play (functionality, personalization, notifications, security, analytics, compliance). Also states no data selling and no third-party ads right now.
5) AI processing
Explains that prompts may be sent to an AI provider to generate answers, and that we aim to minimize personal data in those prompts. This transparency prevents surprises for users and reviewers.
6) When we share information
Limits sharing to processors (hosting, analytics, push, AI), other users only for content you choose to publish, legal reasons, and business transfers. Clarifies no marketing sharing.
7) Data retention
Gives practical timeframes (you can adjust). Play wants to see that you don’t store diagnostics forever and that users can delete accounts/content.
8) Your choices & rights
Explains user controls (edit profile, toggle notifications, delete content, delete account). Mentions rights similar to GDPR/NDPR without over-promising jurisdictional specifics.
9) Security
States reasonable safeguards (encryption in transit, hashed passwords, access controls), without guaranteeing perfect security.
10) International transfers
Covers cross-border hosting/processing using standard contractual protections—useful if providers are outside your country.
11) Third-party services
Acknowledges integrations (e.g., video/news). If you use YouTube Data API, you must reference YouTube Terms and Google Privacy Policy and tell users they can revoke access in Google account settings.
12) Changes to this policy
Lets you update the policy and explain how you’ll notify users.
13) Contact us
Required for trust and for users to exercise rights (e.g., deletion).
Appendix (Play Data Safety)
A quick map to help you fill Google Play’s form consistently with this policy.
Comments
Post a Comment
Add a comment