Privacy Policy for DIU Question Bank
Last Updated & Effective: September 2, 20261. Introduction
Welcome to DIU Question Bank ("the App", "we", "us", or "our"), an educational application developed by FourDevs for the student community of Daffodil International University (DIU). This Privacy Policy is intended to provide transparency about how we collect, use, process, retain, and protect information when you use our mobile application and related services.
2. Information We Collect
We only collect information necessary to provide academic question archives, personalized learning features, user authentication, and app functionality:
A. User Account & Authentication Data
- Account Credentials: When you register or sign in using Firebase Authentication (Email/Password or Google Sign-In), we process your email address, display name, user ID (UID), and profile avatar.
- University Email Verification: If you voluntarily request an institutional badge, we process your university email (e.g.,
@diu.edu.bd) to send a one-time verification passcode (OTP). - Guest Users: You can browse questions without logging in. Guest data (such as offline cached papers and local reading history) is stored locally on your device in an encrypted Room database and is not transmitted to our servers.
B. User-Generated Content & Academic Data
- Question Uploads & Documents: Question papers, PDFs, and academic resources you voluntarily contribute.
- Discussion Comments & Community Interactions: Comments, solutions, reports, and questions posted in the app.
- Bookmarks, Study Progress & Points: Saved questions, download records, viewing history, streak progress, loyalty points, and level milestones synced to your account.
- Camera & Optical Character Recognition (OCR): When you use the document scanner or OCR text search, image processing is executed 100% on-device using Google ML Kit. Raw camera frames and photos are not transmitted to or stored on our servers.
C. Diagnostic, Device & Technical Data
- Device Information: Device model, OS version, app version, and system language to ensure technical compatibility.
- Analytics & Crash Data: Non-personally identifiable diagnostic events, app performance metrics, and crash logs collected through Firebase Crashlytics and Firebase Analytics.
- Advertising Identifiers: Android Advertising ID (AD_ID) used by Google AdMob to deliver relevant advertisements in accordance with your consent preferences.
3. Data Retention Policy
We retain personal and user-generated data only for as long as reasonably necessary to provide the App's services, maintain academic resources, protect the security of our services, or comply with applicable legal obligations.
| Data Category | Retention Period | Storage Location | Disposal / Purge |
|---|---|---|---|
| Account Information (name, email, UID, profile information) |
While the account is active. Following an account deletion request, associated personal account data is deleted from our active systems within 30 days, unless retention is required by law or necessary for security. | Firebase Authentication / Cloud Firestore | Permanent deletion from active systems |
| Bookmarks, Study Progress & Points | While the account remains active. | Cloud Firestore | Deleted with the associated account, subject to necessary legal/security retention. |
| Guest / Local Data | Until the user clears app data, cache, or uninstalls the App. | User's device | Deleted when local storage is cleared or the App is uninstalled. |
| Comments, Reports & Community Content | For as long as reasonably necessary to maintain the relevant academic discussion or resource. | Cloud Firestore | Deleted, anonymized, or moderated when appropriate. |
| User-Contributed Question Papers & Documents | While they are maintained as part of the academic archive. | Firebase Cloud Storage / Cloud Firestore | Removed following valid removal/takedown requests or when no longer required. |
| Analytics & Diagnostic Data | According to the retention settings configured for Firebase Analytics and Crashlytics. | Firebase | Automatically deleted or aggregated according to applicable service retention settings. |
| OCR / Camera Images | Not retained by our servers. Processed locally in device volatile memory. | Processed locally on user's device | Temporary data is released immediately after processing. |
4. User Data Deletion & Account Erasure Policy
Users have full control over their personal data and can request deletion at any time:
A. In-App Account Deletion
Users can request deletion of their account from within the App:
- Open the DIU Question Bank app.
- Navigate to Profile (My Space).
- Scroll to the bottom and select Delete Account Permanently.
- Confirm the request. We will delete the personal information associated with the account from our active systems within 30 days, except information that we are legally required or legitimately permitted to retain. User-contributed public academic resources may remain available where they do not contain personal information and are maintained as part of the community archive.
B. Manual Deletion Requests
If you no longer have access to the app, manual deletion requests received by email at diuquestionbank@gmail.com or shadhinafridi@gmail.com with your registered account details will normally be processed within 30 days after verification.
5. Third-Party Services & Integrations
Our app integrates trusted industry-standard SDKs that comply with Google Play Developer Program policies:
- Google Mobile Ads (AdMob): Used to deliver in-app advertisements. AdMob collects the Google Advertising ID (AD_ID) and diagnostic data. In the European Economic Area (EEA) and UK, user consent is gathered through the Google User Messaging Platform (UMP) before serving personalized ads.
- Google Firebase: Used for secure authentication, Cloud Firestore database, Cloud Storage, Crashlytics crash reporting, and Cloud Messaging (FCM) notifications. Data is hosted in secure Google Cloud infrastructure.
- Google Play In-App Billing: Handles in-app subscriptions and loyalty purchases. Financial and credit card information is processed securely by Google Play and is never accessed or stored by our app.
- Google ML Kit: Provides on-device optical character recognition without sending camera data over the internet.
6. Data Security & Encryption
We implement robust technical and organizational measures to safeguard your personal data:
- Encryption in Transit: All communications between the app and backend services are strictly encrypted via HTTPS / TLS 1.3. Cleartext (HTTP) traffic is strictly disabled (
usesCleartextTraffic="false"). - Encryption at Rest: Local app storage is protected using SQLCipher 256-bit AES encryption.
- Integrity Protection: Firebase App Check with Play Integrity API is enforced to prevent unauthorized API requests and tampering.
7. Children's Privacy
Our app is designed for university students and general academic learners aged 13 and above. We do not knowingly collect or solicit personal information from children under the age of 13. If we discover that a user under 13 has provided personal information, we will promptly delete it.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our app features or regulatory practices. Any updates will be published on this page with an updated "Last Updated" date. Continued use of the app after changes constitutes acceptance of the revised policy.
9. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our team at:
- Email: diuquestionbank@gmail.com
- Support Email: shadhinafridi@gmail.com
- Developer Team: FourDevs Community Team
- Website: https://diuquestionbank.app