Privacy Policy
This policy explains what Student Performance Analyser ("the Service", "we") collects, why, and how we handle it. It applies to the Service operated by CRO Technologies.
1. Who can use the Service
The Service is intended for faculty and authorised staff. Accounts are reviewed and approved by an administrator before activation.
2. What we collect
- Account details — your name, email address, college and department, supplied at registration. If you sign in with Google, we receive your name, email address and Google account identifier.
- Result data — student results fetched from the public RGPV result portal at your request (enrollment number, name, status, SGPA, CGPA and subject grades), used solely to produce the analysis you ask for.
- Sign-up origin — the IP address you register from and an approximate location (city/region/country) derived from it, shown to administrators to help vet account requests. The IP is sent to a third-party geolocation provider solely to resolve that approximate location.
- Operational logs — basic technical logs (timestamps, errors, job activity) needed to run and secure the Service.
3. How we use it
- To authenticate you and gate access to approved users.
- To run fetch jobs and generate reports, exports and trends.
- To send transactional email (verification, approval, job completion).
- To keep the Service secure and diagnose problems.
4. Result data and the RGPV portal
Result data originates from the official RGPV result portal and belongs to the respective students and to RGPV. We act as a tool that retrieves and analyses results on behalf of authorised faculty. You are responsible for using result data lawfully and only for legitimate academic purposes.
5. Sharing
We do not sell your data or share it with advertisers. Reports are private to your account unless you explicitly create a share link, which you can disable or set to expire at any time. We may disclose information where required by law.
6. Retention
Fetched results are cached for a limited period (by default 7 days) to avoid repeated requests, then re-fetched when needed. Account data is retained while your account is active. Contact us to request deletion of your account.
7. Security
Passwords are stored only as salted hashes (bcrypt). Sessions use signed cookies. We apply reasonable safeguards, but no online service can guarantee absolute security.
8. Your choices
You may request access to, correction of, or deletion of your account data by contacting us. You can stop sharing any report at any time from the report page.
9. Changes
We may update this policy; material changes will be reflected by the "last updated" date above.
10. Contact
Questions about this policy: spa@chiragrai.de.