Privacy Policy & Data Protection Disclosure

    MyExamMate Privacy Policy

    Effective Date: 25th September 2026 • Last Updated: 25th September 2026

    Domain: https://myexammate.org

    MyExamMate ("MyExamMate", "we", "us", or "our") provides educational technology services that help students and members of educational communities access examination timetables, academic resources, past papers, tutorials, study tools, and related services.

    This Privacy Policy explains what information MyExamMate collects, how we use it, how it may be shared with service providers, how long different categories of information may be retained, and the choices available to users. By using MyExamMate, you acknowledge the practices described in this Privacy Policy.

    1. Who We Are

    MyExamMate is an educational technology platform operated by:

    If you have questions about this Privacy Policy or how your information is handled, please contact us using the contact information above.

    2. Information We Collect

    The information we collect depends on how you use MyExamMate across our core features.

    2.1 Account and Authentication Information

    When you create or use an account, we may collect your email address, first name, last name, profile image, password information (stored as a securely generated password hash), email verification status, Google account details (when using Google Sign-In), OAuth provider identifiers, and account modification metadata. We do not store your raw Google OAuth access or refresh tokens.

    Google OAuth Scope & Usage Disclosure

    When Google Sign-In is used, Google provides MyExamMate with information associated with the requested OpenID, email, and profile scopes, which may include your email address, name, and profile image.

    2.2 Academic and Student Information

    Depending on platform usage, you may provide or generate academic information including: institution, school/academic unit, programme, year of study, student ID, academic year, course codes, course titles, examination dates/times/venues, timetable notes, personal timetables, study plans, and course preferences.

    2.3 Timetable Information

    MyExamMate processes examination timetable information supplied by users, schools, administrators, or uploaded documents. This includes course codes, titles, exam dates, times, venues, and notes. Personal timetables are linked to registered user accounts and retained until expired or manually removed.

    2.4 Educational Resources and User-Submitted Content

    Users may submit or interact with materials such as past examination papers, lecture files, resource titles, descriptions, links, reports, favourites, WhatsApp group links, and submission notes. Content submitted may be visible to other users where designed for open access. You must not submit confidential, private, or copyrighted content without authorization.

    2.5 Tutorial, Peer-Learning & Support Data

    For tutorial features, we process tutor name, contact details (email/phone), tutorial locations/times, attendance logs, topics, session notes, and invitations. Contact/support requests are transmitted primarily by email, with technical logs retaining transmission error states.

    2.6 Push Subscriptions & Commerce

    Push subscriptions store endpoint URLs, encryption keys (p256dh), authentication secrets, and browser-provided expiration information. In-app notification records have a separate, 1-day expiry lifecycle. For donations or merchandise, payments are processed by our payment provider (ModemPay); MyExamMate does not collect or store raw payment card credentials.

    Type / KeyLifetime / ScopePurpose & Storage Mechanism
    mem_session Cookie~30 DaysEssential HTTP-only, Secure (production) cookie used for maintaining authenticated user sessions.
    Browser Local StoragePersistent / Client-sideStores temporary timetables, search history, Mates chat history, and study preferences locally on your device.
    Google & Vercel AnalyticsProvider StandardProcesses page paths, event tracking, and performance telemetry to monitor application stability.

    3. Technical and Security Information

    We automatically log IP addresses, browser User-Agent strings, authentication session timestamps, and HTTP request headers for security auditing. For authenticated sessions, MyExamMate stores a securely hashed session token rather than the raw token.

    4. Cookies, Local Storage & Analytics

    See the table above for a full breakdown.

    5. How We Use Information

    We process collected data to deliver services, operate infrastructure, and enhance security:

    Service Delivery
    To generate personalized timetables, provide past papers, facilitate tutorial sessions, deliver notifications, and render MEM-AI responses.
    Maintenance & Operations
    To diagnose platform errors, prevent automated abuse, enforce platform rules, and maintain audit records.
    Communications
    To send account verifications, password resets, timetable alerts, resource updates, and transaction confirmations.

    6. Artificial Intelligence and MEM-AI

    MyExamMate provides AI-driven functionality powered by Google Gemini and custom microservices.

    AI Processing & Data Privacy Protocol

    For timetable recommendations and PDF extraction, MyExamMate sends relevant course details or uploaded document contents to Google Gemini using server-side API credentials. MyExamMate does not intentionally pass user account identifiers inside Gemini prompt payloads. Uploaded unauthenticated documents should not contain private personal details. AI responses are generated automatically and should be verified against official institutional timetables.

    7. Third-Party Service Providers

    We work with trusted third-party vendor platforms to supply infrastructure and core operations:

    ProviderService ProvidedData Handled
    Google ServicesSign-In, Gemini AI, AnalyticsOAuth credentials, profile info, AI prompt payloads, web metrics.
    CloudinaryMedia & File Storage CDNUploaded study papers, documents, and profile images.
    ModemPayPayment GatewayTransaction metadata, order amounts, and billing contacts.
    VercelApplication Hosting & TelemetryHTTP request logs, IP addresses, and telemetry metrics.

    8. When Information May Be Shared

    We do not sell personal information. Disclosures are limited to service providers operating on our behalf, educational institutions (where requested by platform features), legal compliance requests, or security investigations into platform abuse.

    9. Public and Community Content

    Submitted past papers, resource metadata, WhatsApp group links, and tutor profiles are intended for community access and will be visible to other platform users. Exercise discretion before sharing sensitive information.

    10. Data Retention Schedules

    See the table below for full retention details:

    Data CategoryRetention Period
    Active Auth Sessions / Cookies~30 days (unless revoked earlier)
    OAuth State Tokens15 minutes
    Password Reset Tokens2 hours
    Email Verification Tokens24 hours
    In-App Notifications1 day (auto-expiry)
    Push SubscriptionsUp to browser termination (cleaned on delivery errors)
    Past PapersIndefinite (or until administrative removal)
    ResourcesResource records are retained according to their configured expiry; records with a 30-day expiry are purged daily by an automated cleanup job. Associated Cloudinary files are not automatically deleted and may persist independently of database record removal.
    Donations & Merch OrdersIndefinite
    System Security & Audit LogsRetained for security, administrative, operational, and accountability purposes. The AuditLog model includes an intended 2-year expiry field, but no automated cleanup is currently enforced.
    Tutorials & Tutor InvitesIndefinite (tutor invites expire after 7 days)
    Pending Offline Messages48 hours (auto-purge)

    11. Account Deletion and Data Requests

    MyExamMate currently provides administrative account deactivation and data scrubbing. Upon request, administrators deactivate user accounts and sanitize personal identifiers, retaining only mandatory historical records (e.g., audit trails, transactions). To request account deletion or data correction, contact: contact@myexammate.org.

    12. Your Privacy Rights

    Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal data. Rights are subject to account ownership verification to safeguard against unauthorized access.

    We process personal data based on: (a) performance of requested educational services, (b) legitimate operational and security interests, (c) compliance with legal mandates, and (d) user consent where applicable.

    14. Children's Privacy

    MyExamMate is an educational tool for student communities. We do not implement age verification for children under 13 and do not knowingly collect personal information from children under 13 without required legal parental consent.

    15. International Data Processing

    Some service providers used by MyExamMate may process information outside The Gambia. The specific location and applicable privacy practices of those providers are governed by their respective policies and terms.

    16. Data Security & Cryptography

    Security Architecture Summary

    We deploy robust safeguards including: Argon2 password hashing, cryptographic hashing for auth tokens, SameSite HTTP-only cookies, role-based access control (RBAC), environment secret management, and rate-limiting on selected API endpoints (authentication and contact forms).

    Security vulnerabilities should be reported responsibly to: contact@myexammate.org.

    17. Data Breaches & Incident Response

    In the event of a security incident affecting personal data, MyExamMate will assess the breach and notify affected users and regulatory bodies within legally mandated timeframes.

    18. Changes to This Privacy Policy

    Updates will be posted to this page with a revised "Last Updated" date. Material changes will be accompanied by additional platform notices where applicable.

    19. Contact Us

    Notice: This document outlines current data practices for MyExamMate. As technical architecture, third-party integrations, or legal requirements evolve, this document will be updated accordingly.