Skip to content

Privacy

Privacy notice

Last updated: October 10, 2026

What the app keeps

KemonPoray uses Google sign-in. The app requests the OpenID and email scopes. It stores keyed HMAC digests of your email and Google account subject, not the raw email address or Google subject. Those digests identify your private account and help keep the same account when you sign in again.

Your account also has a generated handle. If you rate, the rating is linked in the private database to your account ID and a target-specific voter hash. Your selected university and department are stored with the account. You choose these yourself, and they become permanent after saving.

If the address you sign in with is on your university's email domain list, the app also stores that domain (for example du.ac.bd) and marks the account as verified. The local part of the address is never stored, and the domain is never published: a verified review shows only the words "Verified student".

Google sign-in confirms control of a Google account. It does not confirm that you attend a university or prove your student status. A verified tick means the sign-in address domain is on the university's list; staff, alumni, and shared addresses share those domains, so it is not proof of enrollment.

What visitors can see

Public pages show rating totals, scores, tags, and aggregate trends. They do not show your Google email, Google account ID, internal account ID, or generated handle beside a rating. Authorized operators with database access can link ratings to the private pseudonymous account record. Read the anonymity explanation for the distinction.

Cookies and technical data

The app uses an HttpOnly session cookie to keep you signed in and a short-lived HttpOnly cookie while Google sign-in is in progress. It also processes limited network information for rate limits and abuse controls. Do not put private information in a professor rating.

Vercel hosts the app. Vercel Analytics and Speed Insights are enabled for usage and performance measurement. Supabase hosts the PostgreSQL database, and Upstash Redis supports application caching and rate limits. Google handles the sign-in step. These providers process information under their own terms and privacy practices.

Access and account changes

The university and department cannot be changed after the first valid save. The current app has no self-service account deletion. Signing out clears the browser session but does not delete the account or ratings.

The app limits database access and does not publish account identifiers with ratings. No online service can promise that stored data will never be exposed, so please rate only if you accept that operators with authorized database access can see the private account link.