BPSC RankLab

Privacy

Working draft

Working draft

This is an initial product-stage privacy notice for BPSC RankLab. It is structure-only and does not commit final legal language. A legal review will be required before public launch. The categories below describe, at a high level, the kinds of data this product expects to handle when each feature ships.

What we collect

Account data

Information you provide when you create an account, including the email address or phone identifier you sign up with. We do not request profile fields beyond what is required to authenticate today.

Authentication and session data

Records used to keep you signed in safely: peppered password hash, session identifiers used by the application server, idle and absolute session expiry, and audit rows that record successful and failed authentication attempts so we can investigate abuse.

Delivery and audit data

Bounded records that the product writes when it queues a verification email or a password-reset email. The delivery outbox is append-only and does not store the message body or the full recipient address; it stores audit-safe metadata so the operator can investigate delivery problems without reading student data.

Future learning data

When practice, mains evaluation, current affairs, and progress features ship in later packages, they will generate per-student learning data. Each future package will name the data shape it adds in its own design doc and validation report before it ships.

How we use it

We use account data to identify you, authentication data to keep you signed in safely, and delivery/audit data to ensure verification and password-reset emails reach you. We do not sell student data. We do not run any advertising network on the site.

Who we share it with

Today the product uses one transactional email delivery provider for verification and password-reset emails. Provider integration details will be named in the privacy notice updates that ship alongside each relevant feature package.

How long we keep it

Retention timelines for each data category will be specified in the final privacy notice. As of today the product retains account, authentication, and delivery/audit data indefinitely so the operator can investigate access concerns.

Your rights

Rights of access, correction, and deletion will be described in the final privacy notice. You can stop using the service at any time by not signing in.

How to contact us

A dedicated privacy contact will be added once it is operator-approved. See the contact support page for current guidance.