Privacy Policy

Last updated: July 2026

This policy explains how the Project RISHI @ UC Berkeley member dashboard (the “Dashboard”) collects, uses, stores, and shares information. It applies to members who sign in to the Dashboard. The public pages of our website do not require an account and do not collect personal information beyond standard web traffic and analytics.

Who we are

Project RISHI @ UC Berkeley is a registered student organization at the University of California, Berkeley. We are the controller of the information described here. You can reach us at sachitkumar2025@gmail.com.

Who can access the Dashboard

The Dashboard is private to our club. Only email addresses on our member roster can sign in; the roster is checked on our server every time someone logs in, so it cannot be bypassed from a browser. When you leave the club, an officer removes you from the roster and your access ends.

What we collect

From your Google account

When you sign in with Google we receive your name, email address, and your Google account identifier. We use these only to identify you as a club member and to display your name in the Dashboard. Signing in uses basic, non-sensitive permissions only; it does not give us access to your Gmail, your Calendar, your Drive, or your contacts.

Information the club records about you

  • Roster information — your name, club email, project team, phone number (if provided), and the roles you hold (for example lead, exec, VP). Roles determine what you can do in the Dashboard.
  • Contact details in the Member Directory — your name, role, project team, contact email, and phone number. Every signed-in member can view the directory. You can edit your own contact email and phone at any time; doing so changes only the directory listing and never the email you log in with.
  • Profile photo — only if you upload one.

Information created as you use the Dashboard

  • Tasks and events — titles, descriptions, dates, tags, who assigned them and to whom, completion status, and a full activity history of each item (created, submitted, approved, returned, reminder sent, edited, archived).
  • Task submissions and comments — any note or link you submit to complete a task, when you submitted it, and comments you or others leave on a task.
  • Chat messages — the direct messages and group-chat messages you send through the Dashboard, the members included in each conversation, and emoji reactions. Messages are stored so conversations persist between sessions.
  • Notifications — a record of the notifications shown to you in the Dashboard, which mirror the emails we send you.
  • Announcements and newsletters — their content, who sent them, who received them, and whether you have read them.
  • Newsletter subscriptions — if you subscribe through the signup on our public site, we store the email address you provide. This is the only item here that applies to non-members.

Google Calendar access (optional)

Connecting your Google Calendar is optional and off by default. If you choose to connect it, we request the calendar.events permission so we can add the tasks and events assigned to you in the Dashboard to your own Google Calendar.

This sync is strictly one-way (Dashboard → your calendar). We only create and update the events our app created. We never read, list, or import your existing calendar events, and your personal calendar is never shown to other members. You can disconnect at any time from Settings, which stops syncing and removes the events we added, or revoke access directly in your Google Account settings. We request calendar.events rather than the broader calendar permission because managing events is all we need.

Gmail send access (optional)

So the Dashboard can send email on the club’s behalf, an authorized officer connects club Google accounts using send-only permission (the gmail.send scope). This permission can only send messages — it can never read, view, modify, or delete mail in the connected account.

The club uses two separate connected accounts:

  • an announcements account, for officer-composed announcements and newsletters; and
  • a notifications account, for automated task and event notifications, due-date reminders, and manual reminders (“nudges”) sent by a task’s assigner.

Members may also optionally connect their own Google account to send messages they personally author. The tokens that permit sending are stored securely on our server and are never exposed to the browser or shared with other members.

Background notifications (optional)

If you allow browser notifications, we store a push subscription for that browser or device so we can deliver Dashboard notifications and new chat messages even when the site isn’t open. You can turn this off at any time in your browser or device settings, which stops the notifications and lets us discard the subscription. Subscriptions that your browser reports as expired are deleted automatically.

Google Sheets copies

To keep records the club can work with outside the Dashboard, we copy certain Dashboard data into private Google Sheets owned by the club:

  • a directory sheet, containing each member’s name, role, project team, contact email, and phone number;
  • a task sheet, containing tasks, who assigned and received them, status, due dates, submission notes and links, and submission history; and
  • a roster sheet, containing each member’s login email, name, project team, phone number, and roles. Officers edit this sheet to add or remove members and change roles, and the Dashboard reads it back, so this sheet controls who can sign in.

These sheets are not public. They are shared only with the club account and with a Google service account that our server uses to write to them. Access is controlled by the club through Google Drive sharing settings. If you are a member, please be aware that your contact details and task activity appear in these sheets, and that anyone the club shares a sheet with can see them.

How information is stored and protected

Dashboard data is stored in a secured Postgres database (Supabase) that is reachable only by our server using a private service key. Row-level security is enabled on every table, so no public or browser-side key can read them. Access tokens for Google Calendar, Gmail sending, and the Sheets service account are stored server-side only and never touch your browser. Traffic to the site is encrypted in transit (HTTPS).

We are a volunteer, student-run organization. We take reasonable measures to protect your information, but no system can be guaranteed perfectly secure.

How we use it

We use the information above only to run the club:

  • to let you sign in and to decide what you can do in the Dashboard;
  • to assign, track, and complete club work, and to coordinate events;
  • to send you notifications, reminders, announcements, and newsletters;
  • to let members contact one another through the directory and chat; and
  • to keep club records that outlive any single semester’s officers.

We do not sell your information, use it for advertising, or use it to train machine-learning models.

Who we share it with

We share information only with the service providers needed to run the Dashboard, and with other club members where that is the point of the feature (for example, the directory and chat). Our providers are:

  • Vercel — hosting and analytics;
  • Supabase — database;
  • Google — sign-in, and (only where you or an officer connected it) Calendar, Gmail sending, and Google Sheets.

We may also disclose information if required by law or to protect the safety of our members.

Google API disclosure

Project RISHI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the Google Calendar (calendar.events) and Gmail send (gmail.send) permissions described above, use them solely to provide those features to the member who granted them, and do not transfer that data to others except as necessary to provide the feature, for security purposes, or to comply with applicable law. We do not use Google user data for advertising, and we do not allow humans to read it except where you explicitly ask us to, where it is necessary for security, or where required by law.

Data retention

We keep Dashboard data for as long as it is needed to run the club, since past tasks, events, and chapter history are part of our records. When you leave the club or ask us to, we remove your roster entry and your account information, and your access ends. Content you created that was shared with others (such as tasks, comments, or messages sent in a conversation) may remain visible to those members unless you ask us to remove it. Disconnecting a Google integration deletes the stored token for it.

Your choices and rights

  • Your contact details — edit your directory email and phone yourself, from the directory page or Settings.
  • Google Calendar — connect or disconnect at any time in Settings, or revoke access in your Google Account.
  • Gmail sending — if you connected your own account, disconnect it at any time in Settings.
  • Background notifications — turn them off in your browser or device settings.
  • Chat — delete a conversation from your own list at any time.
  • Newsletter — unsubscribe using the link in any newsletter email.
  • Access, correction, or deletion — email us at the address above and we will help.

Eligibility

The Dashboard is intended for members of Project RISHI @ UC Berkeley, who are university students and generally 18 or older. It is not directed to children, and we do not knowingly collect information from anyone under 13.

Changes

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above, and, where appropriate, announced in the Dashboard.

Contact

Questions about this policy, or a request about your data? Email sachitkumar2025@gmail.com.