Privacy Policy
Last updated: 13 August 2026
Draft — not yet reviewed by a lawyer.This describes what Klubi genuinely does with data today, so it's a solid starting point, but it must be reviewed by a qualified professional before launch, and the placeholders marked […] filled in.
Klubi is a platform for discovering, joining and running student clubs. This policy explains what we collect, why, who can see it, and what control you have over it.
Who we are
Klubi is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For anything in this policy, contact [PRIVACY CONTACT EMAIL].
What we collect
Information you give us
- Account details — your email address, username, display name, and the school you select when signing up. Your password is stored only as a salted cryptographic hash; we never hold the password itself and cannot recover it.
- Profile information — anything you choose to add: photo, headline, bio, location, graduation year, skills, interests, LinkedIn address, and your education and experience history.
- Content you create — posts, comments, stories, polls and votes, event RSVPs, club chat messages, direct messages, and uploaded files.
- Applications— when you apply to a club or an opportunity, your answers, any cover note, and any file you attach (including a résumé) are shared with that club's leadership.
- Reports — if you report content, we keep the report, your reason, and a copy of the reported content so it can be reviewed after the original is deleted.
Information collected automatically
- Session data— when you sign in we store a hashed session token, the time it was created and last used, and your browser's user-agent string.
- Rate-limiting data — short-lived counters keyed to your account or IP address, used to block password-guessing and spam. These are deleted automatically.
- Participation records— whether you viewed or started a club's application form, and whether you checked in to an event. Clubs see these as aggregate numbers in their dashboards.
Cookies
Klubi sets one essential cookie, which holds your sign-in session. It is required for the service to function and is not used for advertising or cross-site tracking. We do not use third-party analytics or advertising cookies. Your theme preference is stored locally in your browser and never sent to us.
Why we use it
- To provide the service — showing you clubs, feeds, messages and events.
- To let club leaders review applications and manage their membership.
- To keep accounts secure — verifying your email, resetting passwords, blocking abuse.
- To enforce our terms and respond to reports of harmful content.
We do not sell your personal information, and we do not use it to train machine-learning models.
Who can see your information
- Other users — your profile, posts and comments are visible to signed-in users of Klubi. Club chat and resources are visible only to members of that club.
- Club leaders— when you apply to their club or an opportunity they posted, the club's Founder, President, Co-Presidents and Admissions Operators can see your application, its answers and attachments, and your public profile.
- Your school — if your school is registered on Klubi, its administrators see aggregate participation statistics, not individual activity.
- Service providers — we use Vercel for hosting, Supabase for the database and file storage, and Resend to send email, Supabase for the database and file storage, and Resend for sending email. They process data on our behalf under contract.
- Legal requests — we may disclose information where legally required.
How long we keep it
Account data is kept while your account exists. Sessions expire after 30 days. Password-reset links expire after one hour. Stories are deleted automatically after 24 hours. Rate-limiting counters are deleted within a day. When you delete your account, your profile, memberships, posts, comments and messages are removed.
Your rights
Depending on where you live you may have the right to access, correct, delete, or export your data, and to object to how it is used. In Klubi you can:
- Access and export— Settings → “Download my data” gives you a complete machine-readable copy.
- Correct — edit your profile at any time.
- Delete— Settings → “Delete account”.
For anything not covered by those, contact [PRIVACY CONTACT EMAIL]. You also have the right to complain to your local data-protection authority.
Children
Klubi is for people aged 18 and over at a post-secondary institution, and is not directed at children. We do not knowingly collect information from anyone under 18: the signup form offers no high-school option and asks for no date of birth. If you believe someone under 18 has created an account, contact [PRIVACY CONTACT EMAIL] and we will delete it.
Security
Passwords are hashed with a per-user salt. Session tokens are stored only as hashes and sent in cookies that scripts cannot read. Uploaded files are served through short-lived signed links. No system is perfectly secure, but if a breach affects you we will notify you as required by law.
Changes
We will update the date at the top of this page when this policy changes, and tell you in the app if the change is significant.
See also our Terms of Service.