Privacy Policy & Security Standards
How CONNECT SRMAP protects student identity, enforces closed-loop campus privacy, and safeguards academic interactions.
Academic Year 2026–27 • Version 3.2CONNECT SRMAP is built exclusively for verified university students. We operate on a zero-commercial-sale privacy standard: your data is never sold, shared with advertising brokers, or exposed outside authenticated campus boundaries.
1. Student Identification & Enrollment Data
Authentication & verification criteria
To prevent impersonation and maintain trust across campus, registration requires verifiable student credentials:
- University Register Number: Acts as the primary cryptographic identifier across all services, ensuring one account per enrolled student.
- Official Institutional Email: Used exclusively for mandatory OTP authentication, security verification, and account alerts.
- Academic Records & Room Info: Class, section, hostel block, and room data are utilized only to organize timetables, room swaps, and mess updates.
2. Login Security, Rate Limiting & Lockout Rules
Brute-force protection and cryptographic standards
Passwords are never stored in plain text and are hashed using one-way bcrypt encryption. Security safeguards include:
After 4 incorrect password attempts, a warning is displayed. On the 5th attempt, the account is automatically locked for 5 minutes.
Password reset tokens expire automatically after 1 hour, are single-use only, and require email verification.
3. The Golden Privacy Rule (Chat & Connections)
Zero unsolicited contact policy
Mutual Follow Required to Chat
Direct messaging and shared media access are locked by default. Two students can only message each other after both have followed each other (Mutual Follow). If either party unfollows or disconnects, the conversation is immediately locked for both.
- Blocking Mechanics: Blocking a user terminates communication instantly, unlinks both users from followers, and removes chat visibility.
- Manual Moderation Review: Reported accounts and harassment logs are audited directly by university administrators.
4. Community Feed & Academic Resource Standards
Rules for General, Lost & Found, Requests, and Teams
- • Academic discussions and subject doubt-solving
- • Study notes, slides, and syllabus material requests
- • Genuine Lost & Found item reports
- • Hackathon, project, and event teammate recruitment
- • Commercial promotions, paid services, and marketing
- • Abusive language, hate speech, or harassment
- • False reporting or impersonation of faculty/students
- • Sharing copyright-restricted exam answer keys during tests
Attachment Policy
Files uploaded to Community Posts or Comments (PDFs, PPTs, Images) are strictly limited to 30MB per file to ensure performance stability.
5. Profile Visibility, Views & Data Control
Customizing your showcase visibility
- Private Profile Mode: Enabling Account Privacy hides your showcase, skills, and portfolio from unverified visitors until you approve their connection.
- Profile View Tracking: You can see who viewed your profile, but viewers are logged with a 1-hour cooldown to prevent spam counters.
- Search & Activity Log Control: You have full rights to inspect and clear your search history, visited links, and saved posts at any time.
6. Daily Streaks, Badges & Admin Rewards
Activity tracking and reward redemption guidelines
Daily logins are calculated using Indian Standard Time (Asia/Kolkata / UTC+05:30). Streak guidelines:
- Streak Continuity: Logging in once daily maintains your streak. Missing a full calendar day resets the active streak counter to zero.
- Admin Rewards: Prizes and perks awarded by university moderators (such as Canva Pro rewards) are tracked in your account records and cannot be transferred to other register numbers.
Questions, Concerns or Data Appeals?
If you encounter security vulnerabilities, need data clarification, or wish to report guideline breaches, contact our administration team:
© 2026 CONNECT SRMAP • All Rights Reserved
Developed by Nani Balaga