Buildory Privacy Policy

Effective / Last Updated: October 2026

Application: Buildory (https://buildory.online)

Contact & Data Protection: support@buildory.online · Bengaluru, Karnataka, India

Buildory (buildory.online, "we", "us", or "our") is a free collaboration platform created for student developers, engineers, designers, and creators to showcase technical projects, discover collaborators, and build together. Buildory is operated by an individual founder based in Bengaluru, Karnataka, India.

This Privacy Policy explains transparently what personal information we collect, why we collect it, how it is stored and secured, who processes it, and how you can manage or delete your data. It includes dedicated disclosures regarding data accessed through Google OAuth 2.0 services. By accessing or using Buildory, you consent to the practices described in this policy.

1. Application Purpose & Public Browsing

Buildory exists to connect student builders based on what they actually build rather than pedigree or institutional prestige. Students use Buildory to publish build logs, list project roles, find teammates for hackathons and startups, and learn collaboratively.

No Login Required for General Browsing:

Our homepage, public project showcase (/discover, /projects), builder directory (/people), and informational pages are 100% publicly viewable without creating an account or logging in. User sign-in via Google is only required when a user chooses to actively participate—such as creating a project, submitting a join request, or posting to the community feed.

2. Google User Data Policy & OAuth 2.0 Disclosures

Buildory uses Google OAuth 2.0 to offer students a safe, passwordless single sign-on experience. We adhere strictly to the principle of data minimization.

(a) Google OAuth Scopes Requested

When you sign in to Buildory with Google, we request authorization for only three standard, non-sensitive identity scopes:

  • openid: Authenticates your identity using the OpenID Connect standard.
  • https://www.googleapis.com/auth/userinfo.email (email): Provides your primary Google account email address.
  • https://www.googleapis.com/auth/userinfo.profile (profile): Provides basic profile info (display name, profile avatar URL, and Google subject ID).

(b) Specific Google User Data Accessed & Collected

Through Google OAuth, Buildory accesses and stores only the following data points:

  • Your Full Name: Used as your display name on your public builder profile and project team cards.
  • Your Email Address: Used as your unique account identifier and for sending critical transactional emails (such as project join requests and security alerts).
  • Your Profile Picture URL: Used to display your avatar icon across your profile and feed activity.
  • Unique Google Identifier (sub): A cryptographic ID used to verify your account across subsequent logins.

What We Never Access: Buildory never requests, accesses, reads, or stores your Gmail messages, Google Drive files, Google Contacts, Google Calendar events, location data, or search history. We request only identity authentication scopes.

(c) How We Use Google User Data

Google user data is used exclusively for functional, user-facing features within the application:

  • To authenticate you and establish your session.
  • To populate your builder profile display name and avatar photo.
  • To allow project creators and collaborators to identify who is requesting to join their team.
  • To send essential transactional notifications concerning your projects.

(d) Storage, Protection & Security of Google User Data

We implement comprehensive technical and organizational measures to safeguard your Google data:

  • Encryption in Transit: All communications between your browser, Google OAuth servers, and our application endpoints are encrypted using TLS 1.3 / HTTPS.
  • Encryption at Rest: Database storage is hosted by Supabase in SOC 2-compliant cloud facilities with AES-256 encryption at rest.
  • Access Controls & Row Level Security (RLS): Database-level Row Level Security policies enforce strict boundaries; users can only write to their own authorized profile and project records.

(e) Sharing, Disclosure & Sale of Google User Data

We respect your ownership of your information:

  • Zero Sale of Data: We NEVER sell, rent, monetize, or lease your Google user data or personal data to third parties, brokers, or advertisers.
  • Zero Advertising Trackers: We do NOT share Google user data with ad networks, data brokers, or recruiting firms. Buildory contains no advertising.
  • No AI Model Training: Google user data is NEVER used to train, develop, fine-tune, or improve any machine learning (ML) or artificial intelligence (AI) models.
  • Sub-processor Access: Google user data is processed solely by essential infrastructure providers (Supabase for encrypted database hosting, Cloudflare for edge routing) strictly to deliver the service.

(f) Data Retention & How to Delete Your Google User Data

We retain Google user data only for as long as your Buildory account is open:

  • Account & Data Deletion: You can permanently delete your account and all associated Google user data at any time by:
    1. Navigating to Settings within the Buildory app and selecting account deletion, OR
    2. Emailing support@buildory.online from your registered Google email address with the subject "Delete My Account & Google Data".
  • Deletion Processing Time: Upon receiving your request, your personal information, profile, and Google OAuth identifiers are permanently deleted from active production databases within 30 days. Encrypted database backups are fully purged within 90 days.
  • Revoking Google Access: You can disconnect Buildory and revoke OAuth permissions directly from your Google Account at any time via: https://myaccount.google.com/permissions.

(g) Google Limited Use Disclosure Compliance

Buildory's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. Other Information We Collect

(a) Voluntary Profile Details: You may choose to add technical skills, college or university context, graduation year, project interests, and external portfolio links (e.g. personal website or social profiles).

(b) Optional GitHub Verification: If you connect GitHub, we receive your public GitHub username, numeric ID, avatar, and public repository metadata to verify developer activity. You may disconnect GitHub at any time in Settings.

(c) User Contributions: Content you publish (project titles, summaries, progress updates, comments, and team join requests) is stored and visible to other platform users. Do not share sensitive personal information (such as passwords, phone numbers, or financial details).

(d) Technical & Security Logs: For security maintenance, rate limiting, and spam defense, our infrastructure records standard HTTP server logs (IP address, user agent, request timestamp). We do not record precise GPS location.

4. Service Providers & Sub-Processors

We work exclusively with trusted, industry-standard cloud providers:

  • Supabase Inc.: Encrypted cloud database hosting, authentication engine, and asset storage.
  • Cloudflare Inc.: Content delivery network (CDN), SSL termination, DDoS protection, and edge routing.
  • Google LLC: Identity authentication provider (OAuth 2.0).
  • GitHub Inc.: Optional builder identity verification.

5. User Rights & Regulatory Compliance

We respect the privacy rights of all users regardless of location, in alignment with India's Digital Personal Data Protection Act (DPDPA), 2023 and global privacy frameworks such as the GDPR:

  • Right to Access: View all profile data and project submissions anytime in the app.
  • Right to Rectification: Edit and update your personal details directly in Profile Settings.
  • Right to Erasure: Request permanent deletion of all data by emailing support@buildory.online.
  • Right to Data Portability: Request a digital copy of your contributions and profile information.

6. Age Restrictions & Children's Privacy

Buildory is intended for student developers and creators aged 16 and older. We do not knowingly collect personal data from children under 16. If we discover an account registered by someone under 16, we will promptly delete all associated data.

7. Contact & Privacy Inquiries

For privacy inquiries, data deletion requests, or questions regarding our Google API compliance, please contact:

Buildory Data Protection
Email: support@buildory.online
Physical Jurisdiction: Bengaluru, Karnataka, India
Website: https://buildory.online