Alumnet
Privacy Policy
Alumnet is a private network for verified members of educational institutions. This policy explains what information Alumnet collects, why, who can see it, and the choices you have. Alumnet is operated by Weld (“we”, “us”).
The short version: we collect what is needed to verify that you belong to an institution and to run the network. We do not sell your personal data. Alumnet shows a small number of sponsored posts; every member sees the same ones, and they are never chosen using your data.
1. Information we collect
Information you give us
- Account details: your email address and your full name. You sign in with one-time codes sent to your email; Alumnet has no passwords. Any email address works; it does not have to be one issued by your institution.
- Profile details: optionally a profile photo, a nickname and a short bio. We resize your photo before it is uploaded, which also removes location data stored in the image file. You can change or remove any of these at any time.
- Institution details: the institutions you join or request to join, and optionally your program, class year and role (for example student, alumni, faculty or staff).
- Verification documents: if you upload a document to prove your affiliation (such as a transcript or an ID), we store the file and its type so staff at that institution can review it. If you instead choose to verify with an institutional email, we show the address you sign in with to that institution's staff administrator as your proof.
- Content and activity: the groups you create or join, the people you follow, your messages, reactions, attachments and voice notes, and your profile tags such as skills.
- Reports: problem reports you send us, and requests to register a new institution (including the contact name and email you provide).
- Partner details: if you apply to publish on Alumnet as a publisher or advertiser, the organisation name and role you apply with, and the posts you submit, with any photo or video attached to them, including ones that are not approved or are later removed.
Information collected automatically
- Sign-in session: a session cookie that keeps you signed in. It is required for the service to work.
- Error diagnostics: when something breaks, technical details about the error (for example the page and the error message) are sent to our error-monitoring provider. We configure it not to collect personal identifiers such as IP addresses, and we strip sign-in codes and encryption keys from these reports.
- Administrative records: when institution staff approve or reject a member, a document or a group, we record who made the decision and when, for accountability. When you change your name, we keep a record of the earlier name and the date.
We do not use advertising trackers, and Alumnet does not currently use any analytics service. We do not record which partner or sponsored posts you were shown, or whether you opened a link in one.
2. How we use your information
- To verify your affiliation with an institution and show your verification level.
- To run the network: groups, following, messaging, notifications and search.
- To send you sign-in codes and essential service emails.
- To keep Alumnet secure, prevent abuse, and investigate reports.
- To find and fix bugs.
- To review applications from publishers and advertisers, and each post they submit.
3. Who can see your information
- Members of your institutions can see your profile: your name, photo, nickname, bio, verification level, skills and groups, and can find you in search. They see your role, program and class year only for the institutions you both belong to. Alumnet does not show your profile to people outside the institutions you belong to, or to the public.
- Staff administrators of an institution can see your membership request and any verification documents you submit to that institution, in order to review them. They can also see the names you have previously used on Alumnet. Administrators of other institutions cannot.
- Messages are visible to the members of that conversation. The text of direct (one-to-one) messages is end-to-end encrypted: it is encrypted on your device and we cannot read it. Group messages, announcements, attachments and voice notes are not end-to-end encrypted; they are protected by access controls so that only conversation members can read them.
- Alumnet's site owner reviews requests to register new institutions, including the contact details submitted with them, and reviews partner applications and the posts partners submit.
- Partners (publishers and advertisers) cannot see your profile, your institutions, your groups or your messages, and cannot find you in search. They are not told who saw their posts.
We do not sell or rent your personal data. We share it only with the service providers below, when the law requires it, or to protect the safety of our members.
4. Partner and sponsored posts
Your home feed includes posts from partners: organisations that Alumnet has approved as publishers or advertisers. Partners do not belong to an institution. Alumnet reviews every partner, and every post, before it is shown.
- Posts from advertisers are labelled Sponsored and name the organisation that paid for them. Posts from publishers are labelled Alumnet partner.
- Every member is shown the same partner and sponsored posts. We do not choose them using your profile, your institution, your activity or anything else about you.
- We do not give partners any personal data, and we do not record which posts you saw.
- A post may include a photo or a video. These are stored and delivered by Alumnet, not by the partner, so viewing or playing one sends nothing to the partner. Videos do not play until you start them.
- A post may link to a partner's own website. If you follow the link, that website receives the usual information any site receives from a visitor, such as your IP address, and its own privacy policy applies. We add nothing to the link that identifies you.
- If you are a partner, the organisation name on your account is shown to every member on each of your posts.
5. Service providers
Alumnet relies on these providers, who process data on our behalf:
- Supabase: database, sign-in and file storage (servers in the United States).
- Vercel: hosting for the Alumnet website.
- Resend: delivery of sign-in code emails.
- Sentry: error monitoring.
- Expo: delivery of the Alumnet mobile app and its updates.
Because these providers operate in the United States, your information is stored outside Rwanda, in the United States.
6. Information stored on your device
- The sign-in session cookie described above.
- Your light or dark theme preference, stored only in your browser.
- The private key for your end-to-end encrypted messages, stored in your browser or your phone's secure storage. It never leaves your device. If you clear your browser data or change devices, you lose access to earlier direct-message history on that device, and we cannot recover it for you.
7. How long we keep information
We keep your information for as long as your account exists. When you delete a message, its text is removed immediately.
You can delete your account yourself at any time, from the Account section of your profile. Deletion is immediate and permanent. It removes your profile and photo, your memberships, the verification documents and emails you submitted, every message, attachment and reaction you sent, your direct conversations in full (including the other person's side of them), your follows and notifications, and the records institution staff kept about decisions on your membership and documents. We keep no copy and no record that the account existed.
Two things remain after deletion:
- Things that belong to other people or to an institution, such as a group you created or a decision you made as a staff administrator. They stay, with your name removed from them.
- Technical logs kept by the service providers listed above, such as records of requests and of sign-in emails sent. We cannot erase these ourselves. They are kept for a short period set by each provider and then deleted automatically.
Because nothing is kept, a deleted account cannot be restored, and after deletion we have no data from it to give you. If you want a copy of your data, ask for it before you delete your account.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict how we use it. You can delete your account yourself, as described in section 7. To make any other request, contact us using the details below. You may also have the right to complain to your local data protection authority; in Rwanda, that is the National Cyber Security Authority (NCSA). We will respond to requests within 30 days.
9. Security
We protect your information with encrypted connections, access rules that limit each person to the data they are allowed to see, and end-to-end encryption for direct messages. No system is perfectly secure, so we cannot guarantee absolute security.
10. Age
Alumnet is intended for people aged 16 or older. If you believe someone younger has created an account, please contact us and we will remove it.
11. Changes to this policy
If we make material changes, we will update the effective date above and tell members in the app or by email before the changes take effect.
12. Contact
Questions or requests about this document: telimberedivin@gmail.com. Signed-in members can also use Report a problem in the website's More menu.