Skip to content
IngeniumJoin

Ingenium

A student workshop for projects, teammates, and a shared desk.

Explore projectsPricingAboutMissionJoin our teamContact usJoin
PrivacyTermsCookiesLegal noticeAccessibilityContact

support@project-ingenium.com

Privacy

Privacy Policy

This policy explains what Ingenium stores when you use the student project board and workspace, why we store it, who else sees it, and how you can ask us to change or delete it.

It is written in plain language on purpose. It is meant to be accurate to the product as it exists today. Related rules live in the Terms of Use and the Cookie Policy.

Last updated 2 September 2026.

On this page

  • Who we are
  • What this policy covers
  • What we collect
  • How we use it and lawful bases
  • What is public
  • Processors and subprocessors
  • International transfers
  • How long we keep it
  • Sharing, selling, and advertising
  • Cookies and similar tech
  • Reliability scores and profiling
  • Children
  • Your rights (GDPR, UK GDPR, CCPA)
  • How to make a request
  • Security
  • Changes
  • Contact

1. Who we are

The controller of personal data processed through this service is the operator of Ingenium (“Ingenium,” “we,” “us”). Ingenium is an early-stage student collaboration platform. We have not published a separate registered company name or registered office on this site.

Privacy, access, correction, export, and deletion requests: privacy@project-ingenium.com, or the Contact page, as described in section 14. You can also export or delete your account from profile settings when you are signed in.

If you need a named legal entity, postal address, or data processing addendum for a campus or club contract, write to legal@project-ingenium.com before you rely on Ingenium for that purpose.

2. What this policy covers

This policy applies to:

  • The public marketing site (including browse, pricing, and these legal pages).
  • Account creation, sign-in, and profile onboarding.
  • Public project postings and people discovery.
  • Applications, interviews, and team workspaces (chat, tasks, whiteboard, progress, pitch decks).
  • Video calls that we start from the product.
  • Admin review of pitch decks and presentation requests, where that feature is used.

It does not apply to:

  • Websites or tools a teammate links to from a posting or chat.
  • The privacy practices of Daily.co, Jitsi (meet.jit.si), Supabase, Excalidraw, or other processors once data is in their systems — those vendors have their own terms and policies, which also apply.
  • Content you choose to copy out of Ingenium into email, Drive, GitHub, or anywhere else.

3. What we collect

We collect the data you give us, data created while you use the service, and a small amount of technical data needed to keep you signed in.

3.1 Account and profile

  • Email address and a hashed password (we do not store your password in plain text).
  • Date of birth, used only to check that you are at least 13 before an account is created, plus a timestamp of that check. Date of birth is not shown on public profiles.
  • Username, full name, school name, roles, and skills you type during onboarding or later edits.
  • Whether your profile is complete enough to use the home desk.
  • A platform-admin flag on a small number of operator accounts. Ordinary users cannot set this.

3.2 Projects and applications

  • Project title, description, track (portfolio or venture), duration, skills needed, and owner.
  • Applications, including screening answers and status (pending, interview, accepted, rejected).
  • Interview proposals: time, messages, confirmation or decline.

3.3 Workspace

  • Membership of a workspace after an owner accepts you.
  • Chat messages and the username shown with them.
  • Tasks, assignees, and completion state.
  • Whiteboard drawings and related state.
  • Progress-tracker state.
  • Channel names and which tools sit on each channel.
  • Pitch decks (PDF or PowerPoint) and presentation-review messages, including admin notes where a presentation request is used.

3.4 Calls

When you join a team or interview call we send your display name to the call vendor. Audio and video go to that vendor for the length of the call. We do not operate our own recording feature. The vendor’s product may still process live media. If Daily.co is not configured, the product may open a Jitsi room on meet.jit.si instead.

3.5 Notifications

We store in-app notification rows (for example: a new application or an interview update) so you can see them in the product. We do not currently send marketing email, digest email, or push notifications.

3.6 Technical data

  • Authentication cookies and session tokens, described in the Cookie Policy.
  • A short-lived first-party cookie if signup is rejected because the date of birth is under 13, so the same browser cannot immediately retry.
  • Server logs that our host or database provider may keep (IP address, timestamps, request path) for security and reliability.
  • School and skill catalog entries you type, which can be reused as suggestions for other users.

We do not currently run advertising pixels, Google Analytics, Mixpanel, PostHog, or similar product-analytics SDKs on these pages.

4. How we use it and lawful bases

If UK GDPR or EU GDPR applies to you, we rely on the bases below. More than one basis can apply to the same activity.

PurposeLawful basis
Create and keep your account, sign you in, reset or change credentials when that flow exists, and show your profile to you.Contract (Art. 6(1)(b)) — we cannot run an account without this.
Check date of birth at signup so we do not create accounts for children under 13, and keep the attestation timestamp.Legal obligation (COPPA / equivalent child-protection rules) and legitimate interests in keeping under-13 users off the service.
Let you post projects, apply, message a team, use tasks and whiteboards, and upload a pitch deck.Contract.
Show public postings and public profiles on Explore / Browse so students can find teammates.Contract, and legitimate interests (Art. 6(1)(f)) in operating a student project board.
Compute a reliability badge from completed and active project counts and show it on profiles.Legitimate interests in helping students judge whether someone finishes work. You can object; see section 11.
Security, abuse prevention, debugging, and keeping the service available.Legitimate interests; legal obligation where a law requires a log or a report.
Respond to access, deletion, or other rights requests, and to Contact notes.Legal obligation (Art. 6(1)(c)) and contract.
Connect a live call through Daily.co or Jitsi.Contract. Those vendors process call media under their own terms.

Where a law requires consent (for example certain non-essential cookies in the UK/EU), we ask before setting them. The first visit opens a cookie preference centre. You can change that choice later from the Cookie Policy page. Today the cookies we set ourselves are for sign-in. See the Cookie Policy.

5. What is public

Ingenium is a directory as well as a workspace. The people directory lists only profiles that opted in. A signed-in account is not enough to browse every private profile.

  • Project postings: title, description, skills needed, track, duration, and the owner’s public profile fields.
  • People discovery for guests, search engines, and signed-in students: only profiles that opted in. Those pages may show username, full name, school, skills, roles, and reliability badge.
  • You can still open a teammate’s profile if you share a project or workspace with them, even if they did not opt in to the public directory.

The following is not shown on the public board:

  • Your email address.
  • Your password.
  • Application screening answers (visible to the project owner, and to you).
  • Workspace chat, tasks, whiteboard, pitch files, and call rooms (workspace members, and platform admins where a presentation review is in play).

Search engines and other people can copy public pages. Do not put a phone number, home address, or anything you would not put on a campus noticeboard into a public profile or posting.

6. Processors and subprocessors

We use other companies to host and run parts of the product. They process data on our instructions or, for call vendors, as independent providers of the live room.

NameWhat they doTypical data
SupabaseAuthentication, database, file storage, realtime updates.Account, profile, projects, applications, messages, tasks, whiteboard state, pitch files, notifications.
Daily.coEmbedded team and interview video rooms, when configured.Display name, live audio and video, room metadata.
8x8 Jitsi (meet.jit.si)Fallback call rooms opened in a new tab when Daily is not used.Display name, live audio and video. That site has its own cookies and terms.
Excalidraw (library)Whiteboard drawing surface in the browser.Canvas state we store in our database; the library may also keep short-lived state on your device.
Hosting provider (for example Vercel, if that is where this site is deployed)Serves the website and server actions.Request logs, IP address, pages requested.
Google Fonts pipeline via Next.jsNunito and Fraunces typefaces. Next.js usually self-hosts the files from this site at runtime.If a request is made to Google, Google may see your IP. See the Cookie Policy.

We do not currently use Stripe, an email-marketing tool, or a third-party analytics SDK in this application.

7. International transfers

Supabase, Daily.co, Jitsi, and hosting providers may process data in the United States or other countries outside the UK and European Economic Area. Where UK GDPR or EU GDPR applies, those transfers rely on the vendor’s published transfer tools (often the European Commission Standard Contractual Clauses and a UK addendum) plus the vendor’s security measures.

If you use Jitsi on meet.jit.si, you are also dealing directly with that service in whatever countries it operates.

8. How long we keep it

  • Account, profile, projects, applications, workspace content, and notifications: for as long as the account exists, and for a short period after a deletion request while we complete deletion and check we are not required to keep a record of the request.
  • Pitch files: while the related project or presentation request needs them, or until you or an authorised member remove them, or until the account that owns them is deleted.
  • Auth sessions: until you sign out or the session expires (see the Cookie Policy).
  • Server logs: according to the host and database provider’s defaults, typically days to weeks, longer if needed to investigate abuse.
  • School and skill catalog rows: these are shared suggestions. Removing your account does not always delete a school or skill string that other people also use.

After deletion we may keep a minimal record that a request was made and completed, if we need that to show we complied with the law.

9. Sharing, selling, and advertising

We share personal data only as follows:

  • With other users, as described in section 5 (public board) and inside a workspace or application you took part in.
  • With processors in section 6.
  • With platform admins, for presentation review and to operate the service.
  • If the law requires it, or to protect someone from serious harm, or to defend a legal claim.
  • If the service is transferred to a new operator, in which case we will update this policy.

We do not sell personal information. We do not sell student profile lists. We do not run advertising on these pages. We do not currently “share” personal information for cross-context behavioural advertising as those terms are used in the California Consumer Privacy Act (CCPA) / CPRA.

10. Cookies and similar tech

We use cookies and similar storage to keep you signed in. Details, including names, purposes, and how to block them, are in the Cookie Policy. That policy is part of this Privacy Policy.

11. Reliability scores and profiling

We compute a simple reliability summary from how many projects you have completed or are active on (counts and a star/badge label). It is shown on public profiles. It is not a credit score. Ingenium does not use it as the sole basis of an automated decision that legally produces effects concerning you (for example we do not auto-ban accounts from it).

Other students can still use the badge when they decide whether to apply or accept someone. If UK/EU GDPR’s profiling rules apply to you, you can object to this processing through Contact. If we agree, we will stop showing the badge on your profile or otherwise limit it where the product allows.

12. Children

Ingenium is aimed at students. You must be at least 13. Signup collects a date of birth and the server refuses the account before it is created if the calculated age is under 13.

We do not knowingly collect personal data from children under 13 (COPPA). If you believe a child under 13 has an account, write to privacy@project-ingenium.com. We will delete that account and related data we control.

We do not offer a parental-consent flow for under-13 users because those accounts are not allowed. If you are between 13 and 17, signup asks you to confirm a parent or guardian has reviewed the Terms, and we store the time of that confirmation. That is still self-attestation, not a verified parental consent flow.

13. Your rights (GDPR, UK GDPR, CCPA)

Depending on where you live, you may have some or all of the following rights. We will not discriminate against you for exercising them.

UK / EU

  • Access a copy of personal data we hold about you.
  • Correct inaccurate data (you can already edit much of your profile in the product).
  • Delete data (erasure), subject to the limits below.
  • Restrict or object to certain processing, including legitimate-interest processing such as the public directory or reliability badge.
  • Data portability for data you provided, in a common machine-readable format where technically feasible.
  • Withdraw consent, where we ever rely on consent (for example a future non-essential cookie).
  • Complain to a supervisory authority. In the UK that is the ICO (ico.org.uk). In the EU, complain in your member state.

California (CCPA / CPRA)

  • Right to know categories and specific pieces of personal information collected, sources, purposes, and categories of recipients.
  • Right to delete, correct, and to non-discrimination.
  • Right to opt out of sale or sharing. We do not sell or share for cross-context ads; if that changes we will say so here and offer a Do Not Sell or Share control.
  • We honour Global Privacy Control and Do Not Track in the cookie preference centre: those signals turn third-party call cookies off. We do not sell or share personal information for cross-context ads.

Categories collected, in CCPA terms, typically include identifiers (email, username), student/education information you type (school), professional information (skills, roles, project history), internet activity (use of the service, session cookies), and audio/visual information during a live call (processed by the call vendor). We do not intentionally collect government ID numbers, precise geolocation, or payment card data.

14. How to make a request

When you are signed in, profile settings include “Download my data” and “Delete my account.” You can also write to privacy@project-ingenium.com or use Contact.

  • Sign in so we can match the request to an account, or write from the email address on the account.
  • Say whether you want access, correction, export, deletion, restriction, or an objection, and any username or project title that helps us find the data.

We may need to verify you control the email. We aim to respond within 30 days (GDPR) or 45 days (CCPA), or sooner if the law requires it, and will say if we need more time.

Deletion limits: we may keep data we must keep for law, disputes, or security; we cannot delete copies other students already downloaded; public search-engine caches are outside our control; shared catalog strings may remain; call vendors may keep their own logs under their policies.

You can edit profile fields and sign out yourself from your account page. Signing out is not deletion.

15. Security

We use HTTPS, hashed passwords at the auth provider, access checks in the application, and database row-level security at Supabase. Pitch downloads use time-limited signed URLs. No method of transmission or storage is completely secure. Do not put secrets (API keys, exam answers you are not allowed to share) in chat or on a whiteboard.

If we become aware of a personal-data breach that must be notified, we will notify the relevant authority and affected users as the law requires.

16. Changes

We will update this page when the product or the law changes. The “Last updated” date at the top is the current version. If a change materially expands what we collect or who we share it with, we will also say so in the product or by email if we have a working mail channel by then.

17. Contact

Privacy requests: privacy@project-ingenium.com. Product and accounts: support@project-ingenium.com. Safety: safety@project-ingenium.com. Terms: legal@project-ingenium.com. Also Contact, the Terms of Use, and the Cookie Policy.