Privacy Policy

Last updated: 5 October 2026

Effective date: 5 October 2026

1. Overview

KGP Placement Form Tracker ("the Extension", "the Service", "we", "us") is a browser extension that helps IIT Kharagpur students organise placement and internship notices, deadlines and application links. It is paired with a licensing and payment service that supports PRO, a community tracker that shares a limited set of notice-derived information between users, and this website.

Operator. The Service is operated by the developer of KGP Placement Form Tracker, an independent project based in India. That developer is the data fiduciary (controller) responsible for the processing described in this policy, and can be contacted using the details in Section 18.

This Privacy Policy explains what information we process, why we process it, where it is stored, who it is shared with, how long we keep it, and what choices you have.

We have deliberately designed the Service so that most of the data it touches stays in your own browser and never reaches our servers. That is not true of all of it. This policy states precisely which information leaves your device and which does not, and Section 5 describes the community tracker in full, because it is the one part of the Service that publishes information beyond you.

2. Summary

  • Your ERP credentials are never collected. We do not ask for, receive, or store your IIT KGP ERP username, password, or OTP.
  • Most notice content stays in your browser. The notice subject line, the full notice text, the notice identifier, and your completion checkboxes are stored only on your device and are never uploaded.
  • A limited set of notice-derived fields is shared publicly. The Extension contributes the company name, the opportunity type, the deadline we derive from the notice, any application-form links found in it, and the notice's posting time, to a community tracker that anyone can read without an account. This happens automatically once you have opened the Extension and it has read notices from the ERP notice board, and it then continues in the background. See Section 5.
  • We collect your email address only when you purchase PRO or use PRO licence recovery.
  • We do not store payment credentials. Card, UPI, net-banking and CVV details are handled entirely by our payment provider. We never see them.
  • We do not sell your data and we do not use it for advertising, profiling, or behavioural tracking.

3. What Stays on Your Device

The following is stored in your browser's local extension storage and is not transmitted to us:

  • Notice records. For notices the Extension captures from the ERP notice board: the notice identifier, the notice subject, the full notice text (up to 1,500 characters per notice), the raw posting string, the company name, and the opportunity type.
  • Derived information. The deadlines and application-form links the Extension estimates from those notices, and a merged view combining your own notices with the community tracker's records.
  • Your completion checkboxes and your PRO "Done" tracking state.
  • Your installation identifier and installation secret. These are stored on your device so the Extension can authenticate to our licensing service.
  • Your PRO state. Whether PRO is active, the signed entitlement token described in Section 13, and the time PRO was last checked. The entitlement token contains a licence identifier, your installation identifier, and issue and expiry times. It does not contain your email address.
  • Cached community records downloaded from the community tracker, and internal sync status information.
  • Your email address, temporarily. If you use PRO recovery, the address you enter is held in local storage while the one-time code is being verified, and is deleted once recovery completes, is cancelled, or after 55 minutes, whichever is first. The one-time code itself is never stored.

The Extension uses local extension storage only. It does not use synchronised browser storage, so this data is not copied to your browser account or to any other device. Locally stored data is removed when you uninstall the Extension or clear your browser data. We cannot access it, and we cannot delete it for you, because we never receive it.

4. What Leaves Your Device

We want to be exact about this, so the list below is complete rather than illustrative.

Contributed to the community tracker. When the Extension has notices to contribute, it sends the following fields to our servers, which store them and publish them to all users. Only records that are new, or whose posting time is more recent than the record we already hold, are sent; the Extension does not re-upload your notice history on every sync:

  • the company name;
  • the opportunity type (placement or internship);
  • the deadline the Extension estimated from the notice text;
  • the application-form and related links found in the notice, up to ten per notice;
  • the notice's posting time.

Not contributed. The notice subject line, the full notice text, and the notice identifier are never uploaded. They remain on your device.

Sent to authenticate you. Your installation identifier and installation secret are sent to our licensing service whenever the Extension checks or restores a licence, and when it contributes records, so that the service can confirm the request comes from a registered installation. Your installation identifier also appears in the address of the hosted checkout page you open; the installation secret is passed in a part of the address that browsers never send to a server.

Your email address. Sent only if you buy PRO or use PRO recovery. On recovery it is sent to our email-verification provider to issue and confirm a one-time code, and it reaches our licensing service inside the signed credential that proves you verified that address. See Sections 7 and 11.

Your IP address and request timing. Received by our servers on every request, including requests that carry no other information, because a server necessarily sees the address it is answering. Used to enforce rate limits and prevent abuse. See Sections 8 and 12.

Requests to the ERP on your behalf. The Extension reads the notice board from the IIT KGP ERP using the session you have already established, and may request up to four pages of the notice board so that it has a complete picture of current notices. Those requests go only to the ERP's own addresses, and are the reason the Extension can show you notices you are entitled to see. The Extension does not submit forms, does not apply for anything on your behalf, does not alter anything in the ERP, and does not read pages outside the notice board.

5. Community Tracker and Shared Data

This section describes the part of the Service that publishes information to other people, and it is worth reading in full.

What it is. The community tracker combines the fields listed in Section 4 from many users into a single shared list, so that a student who has not yet opened a particular notice can still see that the opportunity exists, when it closes, and where to apply.

It is public. The shared list is readable by anyone who requests it. There is no login, no account, and no restriction to IIT Kharagpur students. If you contribute a record, you should assume it is visible to the general public, not only to other users of the Extension. Records may be indexed, cached, or copied by third parties once published, and we cannot retrieve copies that others have made.

When contribution happens. Nothing is contributed merely because the Extension is installed. Contribution requires two things: that you have opened the Extension at least once, which registers it with our service, and that the Extension has read placement or internship notices from the ERP notice board through your existing session. Until you have used the Extension on the notice board, there is nothing for it to contribute.

Once both are true, the Extension sends new and changed records in the background, periodically, without any further action from you, and it may do so while the popup is closed. It reads notices only when the ERP notice board is loaded in your browser.

Stopping contribution. There is currently no in-app setting that turns contribution off. If you uninstall the Extension, the installation credentials and the cached notices held in your browser are removed, and no further records are contributed from that installation. Uninstalling does not withdraw records that were already contributed and published, because those records are not linked to your installation in our database and we cannot identify which of them came from you. If you want particular records removed, contact us as described in Section 15.

Shared records are not linked to you in our database. When we store a contributed record we store only the five fields listed in Section 4. We do not store your installation identifier, your email address, or any other identifier alongside it, so the published list does not say who contributed what. The contribution request itself is authenticated, and your installation identifier and IP address are processed for that purpose as described in Sections 4 and 12, but they are not part of the published record.

We do not verify shared records. They are contributed by many different users, and the deadline is estimated by the Extension from the wording of a notice by pattern matching, which is not always accurate. Shared records may be incomplete, out of date, or wrong, and a user could contribute a record that is deliberately false. Do not rely on the community tracker as your only source for a deadline, and always confirm against the original notice before relying on it. We may remove records at any time.

Institutional content. The information contributed is derived from notices on your institute's notice board. The Extension is not affiliated with IIT Kharagpur, and nothing in this policy authorises you to republish institutional material. Your use of the ERP, and any use you make of notice content, remains subject to the rules and policies that govern those systems. See Section 19.

6. Information We Collect

Beyond the contributed records described above, we collect the minimum needed to operate PRO licensing, process payment, prevent abuse, and provide support.

  • Email address. Provided by you at checkout when purchasing PRO, or when you verify your address to restore PRO on a new browser or device. Used to associate the licence with you, to restore PRO, to contact you about your purchase, and to provide support.
  • Installation identifier. A randomly generated, pseudonymous identifier created when the Extension is first set up. It is not derived from your device, your account, or your hardware, and it contains no personal information. It is used to link a browser installation to a licence, and it is stored in our rate-limit records while those records exist.
  • Installation secret. A randomly generated credential that authenticates your installation to our licensing service. We store it only as a one-way SHA-256 hash. The original value is never stored on our servers and cannot be recovered from the hash.
  • Email-verification account identifier. When you verify your email address, our provider creates a sign-in record for that address and returns an identifier to us. We store that identifier alongside the licence so that a licence can be reattached to the account that proved ownership of the address.
  • IP address. Processed for a limited period to enforce rate limits and prevent abuse such as automated registration or licence-restoration attempts. It is stored only as part of rate-limit counters, and it is not used for profiling, advertising, or tracking.
  • Order and payment metadata. The order reference, amount, currency, payment status, the payment provider's transaction reference, and associated timestamps. This is a record of the transaction, not of your payment instrument.
  • Licence status and timestamps. Whether a licence is pending, active or revoked, the number of installations it may be linked to, when it was created and activated, when it was last verified, and when each linked installation was last seen.

Licence status can be checked by email address. If you enter an email address at checkout or in the PRO recovery flow, the Service checks whether that address already holds an active PRO licence, so that you are not charged twice. This means that someone who knows or guesses an email address can learn whether it holds a PRO licence. The check reveals nothing else, it is rate limited, and it is performed only for the address that was typed, but you should be aware of it.

7. In-App Purchases

PRO is a one-time in-app purchase that unlocks additional features within the Extension. To provide a purchase you have asked for, we necessarily process:

  • the email address you supply, so the licence can be attached to you and recovered if you change browser or device;
  • the installation identifier, so the purchased licence can be activated on the installation you are using;
  • transaction metadata returned by the payment provider, so we can confirm that payment succeeded and that the correct amount was charged.

We do not receive your card, UPI or banking credentials at any point. The purchase is completed on infrastructure operated by the payment provider, and payment authentication is performed by your bank or payment app.

We confirm payment with the payment provider directly and independently of your browser. A payment is only treated as successful, and a licence only activated, when the payment provider notifies us with a cryptographically signed message that we verify and that confirms the correct amount for the correct order.

8. Why We Are Allowed to Process Your Data

Where the law requires us to have a legal basis for processing, we rely on the following:

  • Performance of a contract for the email address, installation identifier, order records and licence records that are necessary to sell you PRO, activate it, and restore it later.
  • Our legitimate interests in preventing fraud, abuse and unauthorised access, in keeping the Service secure and available, and in operating the community tracker so that students do not miss opportunities. We process IP addresses and rate-limit counters, security-relevant request information, and the contributed tracker records on this basis.
  • Compliance with legal obligations for records we are required to keep, such as accounting and tax records.

Where we rely on legitimate interests, you have the right to object. See Section 15. We do not rely on consent for any of the processing described in this policy, and we do not carry out advertising, profiling, or behavioural tracking, so there is no consent of that kind for you to withdraw.

9. Where Your Data Is Stored and International Transfers

On your device. The information listed in Section 3 is stored in your browser's local extension storage. This data stays on your device and is removed if you uninstall the Extension or clear your browser data.

On our servers. The information listed in Sections 4 and 6 is stored in a managed database operated on our behalf by our hosting provider. It is not stored on your device alone, because licence recovery, payment confirmation and the community tracker require it.

International transfers. Our hosting, database, email-verification and payment providers are global service providers, and the information described in this policy may be stored and processed outside India, including in jurisdictions whose data-protection laws differ from those of your own country. By using the Service, you understand that this transfer takes place. We select providers that commit to contractual and technical protections for the data they handle on our behalf.

Infrastructure logs. Our hosting provider records technical information about requests to the Service and to this website, such as the IP address, the time, and the path requested, for security, operational and diagnostic purposes. These logs are retained by the provider for a limited period and are used to keep the Service working and to investigate abuse.

10. Cookies and Local Storage

This website does not set cookies of its own, and we do not use analytics, advertising, or tracking cookies anywhere in the Service.

The hosted checkout page loads the payment provider's own software in order to take a payment. That software may set its own cookies or equivalent storage, and it is governed by the payment provider's own privacy policy rather than this one. No such technology is used on the rest of the Service.

The Extension stores information using your browser's local extension storage, as described in Section 3. That storage is not a cookie, is not transmitted to us, and is not shared with other websites.

11. Third-Party Service Providers

We use a small number of processors. Each receives only what is necessary for its function.

  • Payment processing (Cashfree). Receives the order reference, the order amount, the email address you provide, and the installation identifier, in order to process the payment. Payment credentials you enter are provided directly to the payment provider and its banking partners, not to us. Their handling of your data is governed by their own privacy policy.
  • Email verification and sign-in (Supabase). When you verify your email address to restore PRO, your address is used to create a sign-in record, to send a one-time code, and to confirm that you control that address. A user identifier is returned to us so the licence can be linked to the verified address.
  • Hosting, database and logs (Cloudflare). Our licensing service, the community tracker, this website, and the database that holds the information described in Sections 4 and 6 all run on Cloudflare infrastructure, which therefore processes that data on our behalf and records the infrastructure logs described in Section 9.
  • Other users and the public. The contributed tracker records described in Section 4 are published to everyone who requests them. This is the only respect in which information you cause to be processed is disclosed beyond our processors, and it is described in full in Section 5.

We do not sell, rent, or trade your personal information. We do not share it with advertisers or data brokers, and we do not permit our processors to use it for their own marketing. We may disclose information where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims.

12. How Long We Keep Data

  • Licence, order and installation records are retained while your licence is active and afterwards, so that PRO can be restored, so that we can resolve payment disputes, and so that we can meet accounting and tax obligations. We delete records on request as described in Section 15, except where we are required to retain them, such as records of a completed payment that we must keep for accounting purposes.
  • Installation secret hashes are retained for as long as the corresponding installation record exists, and are deleted with it.
  • Rate-limit counters, including IP addresses and installation identifiers, are short-lived. Each counter is reset when its window expires, which happens within hours. Because a counter is reset in place rather than deleted, a row can remain in the database after its window has ended until it is next overwritten. Such a row contains the key itself (which is the IP address or installation identifier), the last counter value, and the window start time. It contains nothing else.
  • Email-verification accounts held by our verification provider are retained until deletion is requested.
  • Contributed tracker records contain no identifier of the person who contributed them, and are retained while they remain useful to the community tracker. We may remove any record at any time.
  • Locally stored data remains on your device until you clear it or uninstall the Extension. We have no ability to delete it for you, because we never receive it.

13. Security

We take technical measures to protect the data we hold:

  • All communication with our service uses HTTPS.
  • Installation secrets are stored only as SHA-256 hashes, so a disclosure of our database would not yield usable credentials.
  • PRO entitlement is proven with a token signed using an asymmetric key, and valid for up to six hours. The signing key exists only on our servers and is never distributed. This means a user cannot forge PRO access by editing the Extension or its local storage, and a token cannot be replayed on a different browser, because the installation it was issued for is part of what is signed.
  • Payment confirmation is verified cryptographically. We check the signature on the payment provider's notification, reject notifications that are not recent, and confirm independently with the provider that the payment succeeded, belongs to the correct order, and covers the correct amount, before activating anything.
  • Requests are rate-limited to limit automated abuse.
  • We never hold payment credentials, so there is nothing of that kind for us to lose.

No system is perfectly secure, and we cannot guarantee absolute security. We have designed the Service to hold as little sensitive data as possible for that reason. If we become aware of a breach that affects your personal data, we will notify you and the relevant authority where the law requires us to do so.

14. Automated Decisions and Profiling

Whether PRO is active is determined automatically, by checking a licence record against your installation. This is a straightforward entitlement check. We do not build profiles of you, we do not use your data for advertising or behavioural analysis, and we do not make automated decisions that produce legal effects or similarly significant effects concerning you.

15. Your Rights and Choices

Subject to applicable law, you may:

  • request access to the personal data we hold about you;
  • request correction of inaccurate data;
  • request deletion of your personal data, where we are not required to retain it;
  • request a copy of the personal data you provided to us, in a structured, commonly used format;
  • object to processing that we carry out on the basis of our legitimate interests, including the contribution of records to the community tracker, and request that we restrict certain processing;
  • withdraw any consent you have given, where processing is based on consent; and
  • complain to a supervisory authority. In India, this is the Data Protection Board of India. You may also complain to the authority responsible for data protection in your own country.

To exercise any of these rights, contact us using the details in Section 18 and tell us what you want. We will respond within 30 days. We may ask you to confirm that you control the email address associated with a licence before acting on a request, so that we do not disclose or delete data at the request of someone else.

Two limits are worth stating plainly. Deleting your email address may make it impossible to restore a PRO licence, because that address is how a licence is matched to you. And we cannot delete, correct or export the notice data held in your browser, because we never receive it — that data is under your control alone.

16. Eligibility and Children

The Service is intended for students and members of the IIT Kharagpur community who are capable of entering into a binding contract. It is not directed at children. If you are below the age of majority in your jurisdiction, please use the Service only with the involvement of a parent or guardian.

We do not knowingly process the personal data of children, and we do not carry out behavioural monitoring or behavioural advertising directed at children.

17. Changes to This Policy

We may update this Privacy Policy to reflect changes to the Service or to legal requirements. The "Last updated" date at the top will change when we do. Where a change materially affects how we handle your information — for example, a new category of data, or a new kind of sharing — we will describe it on this page. If you do not agree with a revised policy, you should stop using the Service and uninstall the Extension.

18. Contact and Grievances

For any privacy question, data request, or complaint, including concerns about how your personal data has been handled, contact:

fineprintdev@gmail.com

Grievance Officer: the developer of KGP Placement Form Tracker, at the email address above.

We acknowledge complaints within 48 hours and aim to resolve them within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India or to the supervisory authority in your own country.

Please include enough detail for us to identify your request, such as the email address associated with your purchase. Do not send us your ERP password, OTP, UPI PIN, card number, or CVV — we will never ask for them.

19. Independent Project

KGP Placement Form Tracker is an independent software project. It is not an official IIT Kharagpur service, website, application, or institute-endorsed product, and it is not operated by IIT Kharagpur. This Privacy Policy concerns the Extension and its services only. Your use of institutional systems remains governed by the policies of those systems, and references to IIT Kharagpur and its ERP are made only to describe the environment in which the Extension is intended to operate.