Last updated: 31 August 2026 · Version 1.3
StudentHub (“we”, “us”, “the app”) is a companion app for university students in Hungary: it brings together your class timetable, your school’s learning systems (Neptun, Canvas, Moodle), a student marketplace, local deals, and a roommate finder. This policy explains, in plain language, what personal data we process, why, who we share it with, how long we keep it, and the rights and controls you have. Please read it together with our Terms of Service and the consent you give when you create an account.
StudentHub is operated as an independent student project. For the purposes of the EU General Data Protection Regulation (GDPR) and Hungarian data‑protection law, we are the data controller for the data described here. You can reach us at privacy@senerdag.site for any privacy question or to exercise your rights.
| Category | Examples | Where it comes from |
|---|---|---|
| Account & identity | Name, email, hashed password, sign‑in method (email or Google), optional date of birth, optional profile photo | You, at sign‑up / in Settings |
| Student verification | University, Neptun code, and, only if you choose to submit one, a student‑ID photo | You / your Neptun login |
| Academic data | Timetable, courses, grades, GPA, upcoming deadlines; from Neptun also programme, enrolment year and gender | Neptun / Canvas / Moodle, read with your own login |
| Roommate card | Bio, budget, move‑in date, lifestyle tags, photos, approximate area (district / rounded distance) | You, if you post a card |
| Messages | Chat messages you send to other users, marketplace enquiries | You |
| Safety | Reports you file, users you block, and the outcome of automated content checks | You / automated screening |
| Diagnostics | Crash reports, and, only if you choose to attach them to a feedback report, recent app logs | Your device |
| Device & technical | Push‑notification token, app version, and basic server logs (e.g. IP address, timestamps) needed to run and secure the service | Your device / automatically |
We do not use advertising trackers, and we do not build advertising profiles about you.
Connecting a school system is entirely optional. When you do, you log in to your school’s own site inside the app. We never see or store your Neptun / Canvas / Moodle password. During that single logged‑in session we read only the data your own account already shows you, so we can display your grades, GPA, timetable and deadlines.
Your detailed academic records are kept on your device. Only a small summary, your Neptun code, programme, faculty, enrolment year, GPA, per‑semester averages and gender, is saved to your StudentHub profile so it survives a phone change and powers verification and the roommate finder. Neptun’s access is deliberately short‑lived (it requires two‑factor login each time), so there is no background access to your school account. You can disconnect at any time, which removes the on‑device data.
The roommate finder helps students find flatmates. It is not a dating service. To keep it safe:
Messages you send are stored so they can be delivered and shown in your conversations. Marketplace and roommate listings you post are visible to other signed‑in students. To keep the community safe, we act on reports and may review reported content, remove listings or photos that break our community rules, and suspend accounts that abuse the service. Blocking is symmetric: once either person blocks the other, neither appears to, nor can message, the other.
Automated screening. Photos and listing text are checked automatically before they are published, to catch sexual content, violence and other material that breaks our rules. Some of those checks run on our own servers; image checks, and some text checks, are performed by Sightengine acting as our processor: the image or text is sent for analysis and we receive back a score. Results are used only for moderation, never to profile you, and a decision that affects your content can always be reviewed by a person if you ask.
Deleting a conversation removes it for you only. The other participant keeps their own copy, which we continue to store on their behalf until they delete it too. We are not able to remove a message from someone else's account, and messages may be retained where they are needed to investigate a report.
We do not sell your data. We rely on a small set of service providers (processors) to run StudentHub:
| Provider | Purpose | Data involved |
|---|---|---|
| Google Firebase Cloud Messaging | Deliver push notifications | Device push token, notification content |
| Google Sign‑In | Optional “Continue with Google” login | Your Google email & name (only if you use it) |
| Google Firebase Crashlytics | Crash and error reporting, so we can fix faults | Crash diagnostics, device model/OS, and your user ID |
| Sightengine | Automated moderation of photos and listing text | The image or text being checked |
| Resend | Transactional email (verification codes, notifications) | Your email address, message content |
| OpenStreetMap / Nominatim | Turn an area you type into a location | The area text you enter |
| European Central Bank / Frankfurter | Currency conversion | None (no personal data) |
| BKK (Budapest transit) | Public transport times, where available | None (no personal data) |
| Our hosting provider (EU) | Run the database and API | All server‑side data above |
We may also disclose data where required by law, or to protect the rights and safety of our users.
Our servers and database are located in the European Union. Some providers (e.g. Google Firebase / Sign‑In) may process limited data outside the EU; where they do, they rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
All traffic is encrypted in transit (HTTPS/TLS). Passwords are stored only as salted hashes, never in plain text. Student‑ID photos are held in private storage and are accessible only to you and, for verification, authorised staff. Access to production systems is restricted. No system is perfectly secure, but we work to protect your data and to limit what we collect in the first place.
We aim to respond to any rights request within 30 days.
StudentHub is intended for university students. The roommate finder is restricted to users aged 18 and over. We do not knowingly collect data from anyone below the age required by applicable law; if you believe a child has provided us data, contact us and we will remove it.
We may update this policy from time to time; the “last updated” date and version above will change. For material changes we will notify you in the app. Continuing to use StudentHub after an update means you accept the revised policy.
Questions, requests, or complaints: privacy@senerdag.site. We’ll do our best to help.