Privacy
TrackCDC holds academic records, so this page says plainly what is collected, where it is kept, and what is never done with it.
Last updated 21 August 2026
What is stored
When you create an account, we store:
- Your name, email address and profile picture, as your provider supplies them.
- Which provider you signed in with, and the account id it gave us.
- Your academic profile: roll and registration numbers, college and school, CGPA, SGPA per semester, backlog count, branch, Class 10 and 12 percentages, phone, and anything optional you add — exams, certifications, awards, projects, links, profile photo.
- Applications you track, including text you paste into the announcement parser.
- Notes in the question memory bank, the document metadata in your vault, and the actual files (resumes, transcripts, etc.) you choose to upload.
Everything above is what you typed or uploaded. Nothing is collected in the background: no analytics, no advertising, no third-party tracking scripts anywhere in the page.
Where it lives
Your profile, applications, and logs are stored on a MongoDB database we operate, reachable only by the TrackCDC server. Your browser never talks to the database directly, and the credentials for it exist only on the server.
Files you upload to the Document Vault are stored in a private, secure S3-compatible cloud storage bucket (Supabase Storage / Cloudflare R2). These files are completely private and cannot be accessed publicly; the application retrieves them on-demand using secure, temporary presigned URLs that expire automatically after 15 minutes.
Your workspace is stored in one record keyed to your account. Requests are authorised from your session cookie rather than anything the page sends, so one account cannot ask for another's data.
Signing in
Sign-in is handled by Google or GitHub. You enter your password on their site, never here, so TrackCDC never receives one and has none to store or lose.
When you sign in we keep the provider's name, the account id it gives us, your verified email address, your display name and your avatar URL. We discard the provider's access and refresh tokens as soon as sign-in completes — we cannot read your Gmail, your repositories, or anything else in those accounts, and we never ask for permission to.
Your provider learns that you signed in to TrackCDC, in the same way it would for any site you use it on.
Showcase mode
The demo tour from the landing page creates no account and writes nothing to the database. It runs entirely in your browser on sample data. If you only ever use showcase, we hold nothing about you.
The announcement parser
Text you paste into the parser is processed by JavaScript in your own browser — it is not sent to a server, and not to any AI provider. Only the structured result is saved, and only once you choose to track it.
What we never do
- Sell or share your data with anyone.
- Send it to advertisers, analytics providers, or hiring companies.
- Contact your placement cell, or act on your behalf anywhere.
- Read your workspace except where it is unavoidable for support, and only if you ask for help.
Deleting your data
There is no self-serve delete button yet — an honest gap rather than a policy. Until there is, ask via the developer page and the account and workspace will be removed.
Known gaps
Stated here rather than left for you to discover — see Data & security for the detail:
- No self-serve export or delete yet — ask and it will be done by hand.
- Account recovery depends on your Google or GitHub account. Lose access to that and we cannot restore your workspace.