Privacy Policy

Last updated: February 2025

1. Introduction

IITD OAuth ("Service") is the unified authentication system operated by DevClub, IIT Delhi. This Privacy Policy explains how we collect, use, and protect your personal information when you use our Service.

2. Information We Collect

When you authenticate through IITD OAuth, we may collect the following information:

  • Name, email address, and Kerberos ID (from IIT Delhi authentication)
  • Entry number, department, and user category
  • Profile information you voluntarily provide (hostel, mobile number, date of birth, social media links, bio)
  • Information from linked external accounts (Google, GitHub) such as email and display name
  • Authentication tokens and session data necessary for the Service to function

3. How We Use Your Information

Your information is used for the following purposes:

  • Authenticating your identity and providing single sign-on access to IITD services
  • Sharing authorized profile information with third-party applications you explicitly approve via OAuth consent
  • Maintaining and improving the security and reliability of the Service
  • Communicating important updates about your account or the Service

4. Data Sharing

We only share your information with third-party applications when you explicitly authorize it through the OAuth consent flow. The specific data shared depends on the scopes requested by the application and approved by you. We do not sell your personal information to third parties.

5. Data Security

We implement industry-standard security measures to protect your data, including encrypted communications (TLS), secure token handling, and access controls. Authentication tokens are signed using RSA keys and have defined expiration periods.

6. Data Retention

Your account data is retained for as long as your account is active. Authentication tokens and authorization codes are automatically expired and cleaned up. You may request deletion of your optional profile information at any time by updating your profile settings.

7. Your Rights

You have the right to:

  • View and update your personal information through your profile settings
  • Manage connected external accounts (Google, GitHub)
  • Revoke access granted to third-party applications
  • Request information about the data we hold about you

8. Contact

If you have questions or concerns about this Privacy Policy, please contact us at devclub@iitd.ac.in.