Growbinar — Privacy Policy
This will be updated before public launch
Effective Date: September 30, 2025
1. Information We Collect
Personal Data
- Account registration details: name, email address, college, role (mentor/mentee), and profile information.
Usage & Analytics
- App usage metrics (login timestamps, session duration, feature usage, crash reports) for product improvement.
Google Data (when you connect your Google account)
When you choose to connect your Google account and grant permission, we may access the following Google Calendar data depending on the scopes you accept:
- Scope:
https://www.googleapis.com/auth/calendar (Full calendar access)
- Examples of data accessed: calendar titles, event start/end times, descriptions, attendees' email addresses, conferencing links (e.g., Google Meet), reminders and event metadata.
We only request minimum scopes necessary to deliver calendar features (scheduling, reminders, adding sessions to your calendar). We clearly describe why each scope is required during the OAuth consent flow.
2. How We Use Your Information
- To provide the service: match mentors and mentees, schedule sessions, send reminders, and enable calendar synchronization.
- To communicate: system notifications, session reminders, and support responses.
- To improve the product: aggregated analytics and crash reporting.
For Google Calendar data: we use calendar information only to create and sync session events, show upcoming sessions inside the app, and (with your consent) include session links or reminders. We will not use Google Calendar data for advertising or to build user profiles without your explicit consent.
3. Data Sharing & Third Parties
- We do not sell your personal data.
- We may share limited profile information (name, selected fields) between mentors and mentees to enable mentorship.
- We may use third‑party processors (video conferencing, analytics, hosting). Any processor we use is contractually required to protect your data and only process it for the purposes we direct.
- If we share Google Calendar data with a third party (e.g., a conferencing provider), we will disclose that in‑app and require contractual safeguards.
4. Data Retention & Deletion
- We retain personal and calendar data only as long as necessary to provide services and for legitimate business purposes (e.g., fraud prevention, legal compliance).
- If you request deletion of your account, we will disable your account immediately and delete user‑linked calendar data from our servers within 30 days unless otherwise required by law.
- If you want earlier deletion of Google data we have stored, contact us at the support email below — we will verify the request and remove stored Google user data promptly.
5. Security
We apply industry‑standard technical and organizational measures to protect data (encrypted in transit via TLS; encryption at rest where applicable; access controls; regular security reviews). Access to production data is limited to authorized personnel only.
6. Your Rights & Choices
- Disconnect Google account / revoke access: You may remove Growbinar from your Google Account by going to Google Account > Security > Third‑party apps with account access and removing Growbinar. Revoking access may disable calendar sync features.
- Access, correction, or deletion: Email us at [email protected] with your request and we will respond within 30 days.
- Marketing opt‑out: You may opt out of promotional emails by following the unsubscribe link in the email.
7. Google OAuth & Verification Notes
- Our OAuth consent screen lists all requested Google scopes and provides clear, accurate justification for each scope.
- Our demo video (submitted to Google during verification) demonstrates the OAuth consent flow, shows how calendar scopes are used in‑app, and provides example test accounts for the reviewer.
- Our Privacy Policy is hosted on the same domain as our app homepage and is linked from the OAuth consent screen.
8. Children’s Privacy
Our services are not targeted at children under 16. If we learn we have collected personal information from a child under the allowed age without consent, we will delete it.
9. Changes to this Policy
We may update this policy; the newest effective date will be posted at the top.
10. Contact Us
For questions about privacy, verification, or to request data access/deletion, contact: [email protected]