Privacy Policy
Last updated: June 13, 2026
1. Introduction
myCGPA ("we," "us," "our," or "the Application") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, process, store, and safeguard your personal data when you access or use the myCGPA mobile application and related services (collectively, the "Service").
This Privacy Policy is incorporated into and forms part of our Terms and Conditions. Capitalized terms not defined herein shall have the meanings ascribed to them in the Terms and Conditions.
By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with any part of this policy, you must discontinue use of the Service immediately.
2. Information We Collect
2.1 Information You Provide Directly
We collect the following categories of personal data that you voluntarily provide when creating an Account or using the Service:
| Category | Examples |
|---|---|
| Identity Data | Full name, matriculation number, student identification number |
| Contact Data | Email address, phone number (if provided) |
| Academic Data | Course names, course codes, credit units/load, grades, semester information, CGPA history, institution name, department, level/year of study |
| Account Credentials | Password (hashed and salted; never stored in plaintext), security questions/answers (if applicable) |
| Communication Data | Messages sent to our support team, feedback, survey responses, and any other correspondence |
| Profile Data | Profile picture, display preferences, academic goals, GPA targets |
2.2 Information Collected Automatically
When you use the Service, we may automatically collect certain technical and usage data, including:
| Category | Examples |
|---|---|
| Device Data | Device model, operating system and version, unique device identifiers (e.g., IDFA, AAID), mobile network information |
| Log Data | IP address, app version, timestamps of access, pages/features accessed, time spent on features, crash logs, error reports |
| Usage Data | Feature interaction patterns, frequency of use, navigation paths, CGPA calculation history metadata |
| Location Data | Approximate geographic location derived from IP address (not precise GPS data unless explicitly granted) |
2.3 Information from Third Parties
We may receive information about you from:
- Authentication providers if you choose to sign in via third-party services (e.g., Google, Apple Sign-In).
- Your educational institution, only if you explicitly authorize such integration.
2.4 Information We Do NOT Collect
We do not knowingly collect:
- Sensitive personal data such as government-issued ID numbers, biometric data, or health information.
- Financial information or payment card details (all payments, if any, are processed by third-party payment processors).
- Data from children under the age of 13 (see Section 9).
3. How We Use Your Information
We process your personal data for the following purposes, based on the legal grounds specified:
| Purpose | Legal Basis | Examples |
|---|---|---|
| Service Provision | Contractual Necessity / Legitimate Interest | Creating and maintaining your Account; calculating, displaying, and storing your CGPA; generating academic reports and analytics |
| Service Improvement | Legitimate Interest | Analyzing usage patterns to improve features; debugging and fixing errors; optimizing performance |
| Communication | Consent / Legitimate Interest | Sending Account-related notifications; responding to support inquiries; providing updates about Service changes |
| Security | Legitimate Interest / Legal Obligation | Detecting, preventing, and investigating fraud, abuse, or unauthorized access; enforcing our Terms and Conditions |
| Legal Compliance | Legal Obligation | Complying with applicable laws, regulations, legal processes, or governmental requests |
| Marketing (if opted in) | Consent | Sending newsletters, promotional materials, and feature announcements (you may opt out at any time) |
4. How We Share Your Information
We do not sell, rent, or trade your personal data. We may share your data only as described below:
4.1 Service Providers
We may share data with trusted third-party service providers who perform functions on our behalf, including cloud hosting and storage providers, analytics and crash reporting services, email delivery services, and customer support platforms. These providers are contractually bound to process your data only on our instructions and to implement appropriate security measures.
4.2 Legal Obligations
We may disclose your data if required by law, court order, subpoena, or governmental authority, or if we believe in good faith that such disclosure is necessary to comply with legal obligations, protect our rights, property, or safety, or investigate and defend against third-party claims.
4.3 Business Transfers
In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
4.4 With Your Consent
We may share your information for any other purpose with your explicit, informed consent.
4.5 Aggregated and De-identified Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably identify you for research, statistical, or marketing purposes.
5. Data Storage and Security
5.1 Data Storage
Your data is stored on secure cloud servers. The location of these servers may vary depending on our service providers, and your data may be transferred to and processed in countries other than your country of residence. By using the Service, you consent to such transfer and processing.
5.2 Security Measures
We implement and maintain appropriate technical, administrative, and physical security measures designed to protect your personal data, including:
- Encryption: All data transmitted between the Application and our servers is encrypted using TLS (Transport Layer Security). Passwords are hashed using industry-standard algorithms (bcrypt or equivalent).
- Access Controls: Access to personal data is restricted to authorized personnel on a need-to-know basis, enforced through role-based access controls and multi-factor authentication.
- Monitoring: Automated intrusion detection and continuous security monitoring systems.
- Regular Audits: Periodic security assessments, vulnerability scans, and penetration testing.
- Data Minimization: Collection and retention of only the data necessary for the stated purposes.
5.3 No Absolute Security
No method of electronic storage or transmission over the Internet is 100% secure. While we strive to protect your data using commercially acceptable means, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your Account credentials.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our retention criteria include:
- Active Accounts: Data retained for the duration of your Account's active status.
- Inactive Accounts: Data retained for up to twenty-four (24) months of inactivity, after which it may be automatically deleted or anonymized.
- Deleted/Terminated Accounts: Personal data deleted or anonymized within sixty (60) days of Account termination, unless a longer retention period is required by law.
- Legal Obligations: Certain data may be retained beyond the above periods to comply with legal obligations, resolve disputes, or enforce our agreements.
- Backups: Residual copies of your data may persist in encrypted backup archives for up to ninety (90) days before being permanently purged.
7. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Request correction of inaccurate or incomplete personal data |
| Erasure ("Right to be Forgotten") | Request deletion of your personal data, subject to legal retention obligations |
| Restriction | Request restriction of processing under certain circumstances |
| Data Portability | Request transfer of your data to another service provider in a structured, commonly used, machine-readable format |
| Objection | Object to processing based on legitimate interests, including for direct marketing purposes |
| Withdraw Consent | Withdraw previously given consent at any time (does not affect lawfulness of prior processing) |
| Automated Decision-Making | Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects |
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within thirty (30) days, or such shorter period as required by applicable law. We may require verification of your identity before processing your request.
If you believe our processing of your data violates applicable law, you have the right to lodge a complaint with your local data protection supervisory authority.
8. Cookies and Tracking Technologies
The Application may use cookies, beacons, tags, and similar tracking technologies to:
- Remember your preferences and authentication state.
- Analyze usage patterns and improve the Service.
- Deliver relevant content and features.
You can control certain tracking technologies through your device settings. However, disabling essential cookies or device identifiers may affect the functionality of the Service.
8.1 Analytics
We use analytics services (including but not limited to Google Analytics for Firebase or similar) to understand how users interact with the Service. These services may collect data such as your device information, IP address, and in-app activity. You can learn about Google's data practices at https://policies.google.com/privacy.
8.2 Do Not Track
We do not currently respond to "Do Not Track" (DNT) signals from web browsers, as there is no universally accepted standard for DNT. The Application is primarily mobile-based and may not be subject to DNT mechanisms.
9. Children's Privacy
The Service is not intended for individuals under the age of 13. We do not knowingly collect, use, or disclose personal data from children under 13. If we become aware that a child under 13 has provided us with personal data without verified parental consent, we will take immediate steps to delete such data from our systems. If you believe a child under 13 has provided us with personal data, please contact us immediately at [email protected].
For users between the ages of 13 and 18, we recommend that a parent or legal guardian review this Privacy Policy and supervise the use of the Service.
10. International Data Transfers
Your data may be transferred to, stored in, and processed in countries outside your country of residence, including countries that may not provide the same level of data protection as your home jurisdiction. When we transfer data internationally, we implement appropriate safeguards, including:
- Standard contractual clauses approved by relevant regulatory authorities.
- Ensuring recipients are certified under recognized data protection frameworks.
- Conducting transfer impact assessments where required.
By using the Service, you consent to such international transfers.
11. Data Breach Notification
In the event of a data breach that compromises your personal data, we will:
- Promptly investigate and contain the breach.
- Notify affected users and relevant regulatory authorities as required by applicable law, within the statutory timeframe.
- Provide details of the breach, the data affected, measures taken to mitigate harm, and recommended steps for users.
12. Third-Party Links and Integrations
The Service may contain links to third-party websites, services, or integrations that are not operated or controlled by us. This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of each third-party service you interact with. We are not responsible for the privacy practices, content, or security of third-party services.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Revise the "Last Updated" date at the top of this document.
- Provide notice through the Application or via email for material changes.
- Post the updated policy within the Application.
Your continued use of the Service after changes become effective constitutes your acceptance of the revised Privacy Policy. We encourage you to review this Privacy Policy periodically.
14. Specific Jurisdictional Provisions
14.1 Nigeria Data Protection Regulation (NDPR) / Nigeria Data Protection Act (NDPA)
If you are a resident of Nigeria, you have rights under the NDPR/NDPA, including the right to request information about our data processing activities and to lodge complaints with the Nigeria Data Protection Commission (NDPC).
14.2 European Economic Area (EEA) and United Kingdom (UK) — GDPR
If you are located in the EEA or UK, the legal bases for processing your data are as set forth in Section 3. You have the rights enumerated in Section 7, and you may lodge a complaint with your local supervisory authority.
14.3 California Residents — CCPA/CPRA
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and sell (we do not sell personal information).
- Request deletion of your personal information.
- Non-discrimination for exercising your privacy rights.
To exercise these rights, contact us at [email protected].
15. Contact Information
For any questions, concerns, requests, or complaints regarding this Privacy Policy or our data practices, please contact:
Data Protection Officer / Privacy Team
Email: [email protected]
We will acknowledge receipt of your inquiry within five (5) business days and endeavor to resolve it within thirty (30) days.
16. Acknowledgment
By using the Service, you acknowledge that you have read, understood, and agree to this Privacy Policy and our Terms and Conditions.
© 2026 myCGPA. All rights reserved.