Legal
Privacy Policy
Welcome to B-link ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application.
1. Information We Collect
1.1 Personal Information
When you register for an account, we collect:
- Your Brock University email address (@brocku.ca)
- Your chosen username and display name
- Profile information you choose to provide (bio, profile picture, courses)
1.2 Content You Create
We collect content you voluntarily post on the platform:
- Marketplace listings (items for sale, prices, descriptions, images)
- Event information (event details, locations, dates, co-hosts)
- Tutor profiles and tutoring requests
- Reports and feedback you submit
1.3 Usage Information
We automatically collect certain information about your device and how you interact with our app:
- Device information (device type, operating system, unique device identifiers)
- Usage data (features accessed, time spent, interaction patterns)
- Error logs and diagnostic data for improving app performance
1.4 Push Notifications
If you enable push notifications, we collect:
- Device push token and platform (iOS/Android)
- Notification metadata needed for delivery
Notification payloads do not include message content.
1.5 Data We Do Not Collect
We do not collect:
- Location data
- Audio recordings
2. End-to-End Encrypted Messaging (E2EE)
Your Privacy is Our Priority
We use end-to-end encryption (E2EE) for all messaging features. This means:
- Your messages are encrypted on your device before being sent
- Only you and your conversation partner can read the messages
- Our servers CANNOT decrypt or read your messages
- We do NOT have access to your message content
- Messages are decrypted only on the recipient's device
2.1 What We Store (Encrypted Messages)
For encrypted messages, we only store:
- Encrypted message content (unreadable ciphertext)
- Message metadata (sender ID, recipient ID, timestamp)
- Conversation participants and conversation IDs
- Public encryption keys for message delivery
2.2 What We CANNOT Access
Due to end-to-end encryption:
- We CANNOT read the content of your messages
- We CANNOT access shared images or files within messages
- We CANNOT decrypt messages even if legally requested
- Law enforcement CANNOT obtain message content from us
2.3 Encryption Keys
Your encryption keys are stored securely:
- Private keys are stored only on your device (in secure storage)
- We never transmit or store your private encryption keys
- Public keys are stored on our servers to enable message delivery
- If you lose your device, messages cannot be recovered (by design)
3. How We Use Your Information
We use the information we collect to:
- Provide and maintain our services
- Facilitate marketplace transactions, events, and tutoring connections
- Send you notifications about messages and event co-host invites
- Enforce our Terms of Service and community guidelines
- Investigate and prevent fraud, spam, and abuse
- Improve app performance and fix bugs
- Respond to your support requests
4. Information Sharing and Disclosure
4.1 Public Information
The following information is visible to other Brock students on the platform:
- Your username, display name, and profile picture
- Marketplace listings you post
- Events you create or co-host
- Your tutor profile (if you apply as a tutor)
4.2 We Do NOT Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4.4 Legal Requirements
We may disclose your information if required by law or to:
- Comply with legal obligations or court orders
- Protect the rights and safety of our users
- Investigate violations of our Terms of Service
Note: Due to E2EE, we cannot disclose message content even if legally requested.
5. Data Security
We implement industry-standard security measures:
- End-to-end encryption for all messages
- Secure HTTPS connections for all data transmission
- Regular security audits and updates
- Rate limiting to prevent abuse
6. Data Retention
We retain your data for as long as your account is active. When you delete your account:
- Your profile and personal information are permanently deleted
- Your listings and events are removed
- Encrypted messages are deleted from our servers
- Some data may be retained for legal compliance (e.g., violation records)
7. Your Rights and Choices
You have the right to:
- Access your personal information
- Update or correct your profile information
- Delete your account and associated data
- Export your data (contact us for data export requests)
- Opt out of non-essential notifications
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or via email. Continued use of the app after changes constitutes acceptance of the updated policy.
By using B-link, you acknowledge that you have read and understood this Privacy Policy.