Legal

Privacy Policy

Last updated: 6 September 2026

Hajiri ("we", "us") is a student-built attendance and timetable dashboard for NSUT students. This policy explains what data we collect, why we collect it, and what control you have over it. We keep it short because there is not much to hide.

1. What we collect

To make Hajiri work, we collect the following:

  • IMS credentials. Your NSUT IMS roll number and password. These are the only way to fetch your attendance and timetable from the IMS portal.
  • Academic data fetched from IMS. Your name, branch, semester, subjects, timetable, and attendance records as returned by the IMS portal.
  • Subscription and payment records. Your plan, its start and end dates, and the Razorpay order and payment identifiers. We do not receive or store your card, UPI, or bank details. Those are handled entirely by Razorpay.
  • Referral data. Referral codes you share or use, and which accounts they connect, so rewards can be credited correctly.
  • Technical data. Basic device, browser, and usage information collected by our analytics provider (Vercel Analytics) and standard server logs. This is aggregated and not tied to your IMS identity.

2. How we handle your IMS password

Hajiri refreshes your attendance in the background so the dashboard is up to date when you open it. To do that, we must keep your IMS password on file. It is stored in encrypted form, is transmitted only over HTTPS, and is used for exactly one purpose: signing in to the IMS portal on your behalf to fetch your academic records.

We never display your password back to you, never share it with anyone, and never use it for anything other than fetching your data from IMS. If IMS rejects the saved password (for example after you change it), we stop using it and ask you to sign in again.

If you would rather not keep your password on file, you can delete your account at any time (see section 7) and it is removed along with everything else.

3. How we use your data

  • To fetch, parse, and display your attendance, timetable, and subject data.
  • To compute analytics such as attendance percentages, safe-skip counts, and trends.
  • To send you attendance and schedule notifications you have opted into.
  • To manage your Hajiri Pro subscription, trial, and referral rewards.
  • To keep the service secure, debug problems, and understand aggregate usage.

We do not sell your data. We do not use it for advertising. We do not build profiles of you for any purpose beyond running Hajiri.

4. AI-assisted parsing

Hajiri uses automated scraping and AI-assisted parsing to turn IMS pages into structured data. This processing happens on our infrastructure. Your credentials are never sent to any third-party AI model, and we do not use your personal data to train models.

5. Who we share data with

We share data only with the services needed to run Hajiri:

  • NSUT IMS portal, which receives your credentials when we fetch your records.
  • Razorpay, our payment processor, which receives the details needed to process your Pro subscription payment. Razorpay's handling of your payment data is governed by its own privacy policy.
  • Hosting and analytics providers (such as Vercel) that run our infrastructure and collect aggregate usage metrics.

We may also disclose data if required by law or to protect the rights, safety, or security of Hajiri and its users.

6. MCP and API access

If you connect an AI assistant to Hajiri through our MCP server, that assistant can read your attendance and timetable data using an access token you authorise. The token can be revoked at any time. What the assistant does with the data is governed by that assistant's own policies.

7. Retention and deletion

We keep your data for as long as your account is active. Cached IMS data is refreshed periodically and older snapshots are discarded. Payment records are retained as long as needed for accounting and to resolve disputes.

You can request deletion of your account and all associated data, including your IMS credentials, by contacting us on WhatsApp support. Deletion is completed within 7 days.

8. Cookies and local storage

We use a session cookie to keep you signed in and browser local storage to remember preferences such as pending referral codes and install prompts. We do not use advertising or cross-site tracking cookies.

9. Security

All traffic to Hajiri is encrypted with HTTPS. Credentials are encrypted at rest and access to production systems is restricted. No system is perfectly secure, so if you believe your account has been compromised, change your IMS password immediately and let us know.

10. Children

Hajiri is intended for university students and is not directed at children under 13. We do not knowingly collect data from anyone under 13.

11. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top will change when we do, and material changes will be announced in the app.

12. Contact

For privacy questions, data requests, or anything else, reach us on WhatsApp support.