Privacy Notice
Privacy practices with clear boundaries.
This notice explains what the current Linden Study prototype handles, why it is used, and what sensitive Boston College account information the service does not request.
1. Information the current service handles
- Mock sign-in data: the normalized @bc.edu address and sign-in time stored in this browser.
- Planning data: courses, sections, watchlists, preferences, and schedules selected in the browser.
- Community data: ratings, reviews, reports, appeals, or profile details submitted through future enabled features.
- Technical data: browser, device, IP, request, security, and error information created by hosting infrastructure.
- Communications: support, privacy, copyright, accessibility, correction, and security requests.
2. Information Linden Study does not request
Linden Study does not ask for or intentionally collect a BC password, Duo or other MFA code, Eagle ID, portal cookie, SSO token, authorization header, transcript, payment credential, or another person's private information.
Linden Study's own email-format sign-in is separate from Boston College SSO. It does not prove that a person controls the address or is currently affiliated with Boston College.
3. How information is used
Information may be used to remember local prototype access, provide search and planning features, maintain preferences, answer requests, prevent abuse, measure reliability, debug problems, comply with law, and develop the service.
Linden Study will not use this information to make an official academic, admissions, employment, or disciplinary decision.
4. Browser storage, cookies, and analytics
The current mock sign-in stores a versioned record containing the normalized email address and sign-in time in browser localStorage. The current component does not itself transmit that address to a Linden Study server. Signing out or clearing site storage removes the local record.
Hosting infrastructure may use essential cookies, operational logs, and security controls. Any future analytics, advertising, or embedded-media tool should be identified before activation, with consent requested where required.
5. Service providers and disclosure
Information may be processed by contracted hosting, email, security, analytics, and support providers; when a user directs Linden Study to share it; to protect people or the service; or when legally required.
The current prototype does not sell personal information or use it for targeted advertising. Vendor processing should be minimized and documented rather than described as if no sharing occurs.
6. Retention and deletion
Local mock sign-in data remains until sign-out or browser storage is cleared. Production retention periods must be finalized before server-side accounts, reviews, or alerts launch.
The intended baseline is deletion from active systems within 30 days of a verified request, ordinary operational logs for up to 30 days, security logs for up to 90 days, and backup purge within 90 days, unless a shorter requirement or documented legal or security hold applies.
7. Security and user choices
Linden Study intends to use HTTPS, access controls, redacted logs, rate limiting, dependency updates, and an incident-response process. No online service can promise absolute security.
Depending on applicable law, a user may request access, correction, deletion, or export of personal data, or appeal a denied request. Contact details are intentionally not invented and will be published on the Contact page when available.
8. Age, geography, and education records
The current prototype is intended for people age 18 or older in the United States and is not directed to children under 13. Broader access requires a separate legal and product review.
Linden Study is not acting as a Boston College school official unless a future written agreement expressly establishes that relationship. Users should not upload official education records.