CS Attendance System App logo

Legal · Privacy

Privacy Policy

CS Attendance System App — the attendance system.

Last Updated
31 Jul 2026
App
CS Attendance System App

This policy explains what CS Attendance System App collects, why, and how it's protected. CS Attendance System App is an academic tool built for students, faculty, teaching assistants, and administrators to manage enrollment, attendance, coursework, and timetables — it carries no advertising and does not sell personal data.

01

Scope & who we are

This Privacy Policy applies to the CS Attendance System App mobile application and the backend service it connects to. It is operated for use by enrolled students, faculty, teaching assistants, and administrative staff.

By creating an account or signing in with credentials issued by the department, you agree to the collection and use of information as described here.

02

Information we collect

Account & profile information

  • Full name, university email address, and password (stored only as a salted bcrypt hash — we never see or store your plaintext password)
  • Registration/roll number, role (student, faculty, teaching assistant, or admin/coordinator), and where applicable, degree program, batch, and section
  • Profile picture, if you choose to add one

Academic records

  • Course enrollments, sections, and class timetables
  • Attendance records
  • Assessment and assignment submissions, and grades
  • Survey responses you submit
  • Teaching-assistant assignments and notices/announcements you view

Authentication & device data

  • Session tokens (short-lived access and refresh tokens), held in your device's encrypted secure storage (Android Keystore-backed)
  • If you enable biometric sign-in: a device-generated cryptographic public key and a device identifier, registered to your account

Technical & server log data

Like most web services, our server automatically logs standard request metadata — IP address, timestamp, and app version/platform — for security, abuse prevention, and troubleshooting. We do not use this data for advertising or behavioral profiling.

Files

Course materials or documents you download or upload (for example, an assignment submission) are handled through Android's document picker, at a location you choose. We only access files you explicitly select or that you download from within the app.

03

Device permissions

CS Attendance System App requests the following Android permissions. We request nothing beyond what these features require, and the app contains no advertising or tracking SDKs.

INTERNET / ACCESS_NETWORK_STATE
Required to communicate with the attendance system server — signing in, syncing courses, attendance, and grades.
READ / WRITE_EXTERNAL_STORAGE
Legacy permission for Android 12 and earlier; used only to save or open course files you choose. On Android 13+, file access instead goes through the system document picker, which needs no broad storage permission.
USE_BIOMETRIC / USE_FINGERPRINT
Optional. Powers fingerprint/face sign-in as a faster alternative to your password. Verification happens on-device; see the biometric note above.
VIBRATE
Haptic feedback for in-app interactions and alerts.
04

How we use it

  • To authenticate you and maintain your session securely
  • To operate core attendance system functions: enrollment, timetables, attendance, assessments, grading, surveys, and notices
  • To maintain the academic records the department is required to keep
  • To detect, prevent, and investigate fraud, abuse, or security incidents
  • To diagnose crashes and technical issues and keep the service reliable

We do not use your data for advertising, and we do not build behavioral or marketing profiles from it.

05

Who can see your data

Access is role-based and scoped to what each role needs to do its job:

  • Students see their own profile, enrollments, attendance, grades, and submissions.
  • Faculty & teaching assistants see records for the sections and courses they are assigned to teach or assist.
  • Admins & coordinators can access department-wide records as needed to administer the program (enrollment management, semester setup, reporting).
06

Sharing & third parties

We do not sell your personal data, and the app does not integrate any advertising or third-party analytics SDKs. Data is processed on infrastructure operated for CS Attendance System App. We only disclose data:

  • Within the university, to staff with a legitimate academic administration need for it;
  • To infrastructure providers (e.g. hosting and database providers) strictly to operate the service, under confidentiality obligations, and never for their own marketing purposes;
  • When required by law, regulation, or a valid legal process.
07

Storage & security

  • All traffic between the app and our server is encrypted in transit (HTTPS/TLS).
  • Passwords are hashed with bcrypt; we cannot recover your original password.
  • Sign-in uses short-lived JWT access tokens plus a longer-lived refresh token, stored only in your device's encrypted secure storage — never in plain preferences or logs.
  • Biometric sign-in uses asymmetric cryptography (ES256): the private key is generated and stays inside your device's secure hardware and is never exportable or transmitted.

No method of transmission or storage is 100% secure, but we apply industry-standard safeguards appropriate to an academic records system.

08

Data retention

We retain account and academic data for as long as your account is active and as required by the university's academic record-keeping obligations (for example, transcripts and grade records may need to be retained after you graduate or leave, independent of your app account). Session tokens and biometric keys are removed from your device as soon as you sign out or disable biometric sign-in. To request for data deletion, send your query to [email protected]

09

Your rights & choices

  • Access & correction — view your profile and records in-app; for corrections to official academic records, contact your department/registrar or app support.
  • Biometric opt-out — disable biometric sign-in any time from Profile settings; this deletes the on-device key immediately.
  • Deletion — request removal of your account and personal data as described in the next section.
10

Account & data deletion

CS Attendance System App does not currently have an in-app "delete account" button. To request deletion of your account and associated personal data, email us — we handle every request individually rather than through an automated flow:

  1. 1Email [email protected] from your registered university email address, with the subject line "Account Deletion Request".
  2. 2Include your full name and registration/roll number so we can locate the correct record.
  3. 3We will confirm receipt and complete the request within 30 days.
11

Children's privacy

CS Attendance System App is intended for enrolled university students, faculty, and staff, and is not directed at children. We do not knowingly collect personal information from children.

12

Changes to this policy

We may update this policy as the app evolves. Material changes will update the "Effective" date at the top of this page, and where appropriate, we'll notify users in-app.

13

Play Data Safety reference

A quick-reference summary of this policy, matched to the categories Google Play's Data Safety form asks for. Use it as a starting point when completing the form in Play Console — always confirm against your current build.

Data categoryCollectedShared with 3rd partiesPurpose
NameYesNoAccount management, app functionality
Email addressYesNoAccount management, authentication
User IDsYesNoAccount management, app functionality
Photos (profile picture)OptionalNoApp functionality (personalization)
Other personal info (registration no., role, academic records)YesNoApp functionality (academic administration)
Device or other IDsOptional (biometric users only)NoAuthentication
App activity / app interactionsYesNoApp functionality, analytics (internal only)
Financial infoNoNo
LocationNoNo
Health & fitnessNoNo
MessagesNoNo

Other form answers

  • Is all user data encrypted in transit? Yes — HTTPS/TLS throughout.
  • Do you provide a way for users to request data deletion? Yes — see Account & data deletion above; link this page's URL in that field.
  • Data collection is required or optional? Name, email, password, and registration number are required (account creation). Profile picture and biometric enrollment are optional.
  • Committed to the Play Families Policy / target children? No — this app targets university students and staff, not children.
14

Contact

Questions, corrections, or data requests relating to this policy:

CS Attendance System App
[email protected]