Skip to content
StudErn

StudErn legal

Privacy Policy

What we collect, why we collect it, who else sees it, and what happens when you ask us to delete it.

Effective 31 July 2026

StudErn (“StudErn”, “we”, “us”) operates a platform connecting students in Bangladesh with paid short-term work, internships, and micro-projects. This policy describes exactly what personal data the platform collects and processes, in plain terms tied to what the product actually does — not a generic template. If a section doesn’t apply to how you use StudErn (for example, you’ve never used the recruiter side), it still applies to anyone who does.

This document describes the system as built for the StudErn pilot. It has not been reviewed by a lawyer. If you are evaluating StudErn for a purpose where that matters — commercial use, handling payment data at scale, or operating in a jurisdiction with its own data protection law — have it reviewed before relying on it.

1. Who this covers

Anyone with a StudErn account: students and job seekers (“applicants”), recruiters and company administrators, and platform administrators. Registration requires you to be at least 18 years old — the system checks your date of birth against this at sign-up and will not create an account for anyone younger.

2. What we collect

Account and profile

  • Name, username, date of birth, gender
  • Email address or phone number, and its verification status
  • Your password, stored as a cryptographic hash — we never store or can retrieve the plain-text version
  • Current job title and employer, if you choose to add them
  • Education history, skills, work experience, projects, and achievements you add to build your profile or CV

If you sign in with Google, LinkedIn, or GitHub

We receive the identifier and basic profile information the provider shares under its own consent screen (typically your name, email, and profile photo URL). We do not receive your password for that provider, and we cannot see anything else in that account.

The free CV builder

The CV builder at /cv/works without an account: your draft is saved in your browser’s local storage on your own device, not on our servers, until you choose to import it into an account (or never do). If you import it, the fields become part of your profile as described above.

Company and recruiting data

If you create or join a company, we collect the company’s name, description, industry, size, logo, and any links you add, along with which team members have which permissions. Job and internship postings you create are stored along with their requirements, and are visible to any applicant browsing the platform.

Applications and the hiring pipeline

When you apply to a posting, we store your application, any cover message, and its progress through the hiring stages (applied, screening, shortlisted, interview, offer, hired, rejected, or withdrawn). Recruiters at the company you applied to can see this; other applicants cannot. Any private note a recruiter adds about your application is visible only to that company’s team — it is never included in the messages you receive.

Payments

Paid job postings are processed through bKash. We store the transaction amount, currency, status, and a reference ID bKash gives us — we do not receive or store your bKash PIN, full account number, or other wallet credentials; that information stays with bKash. See our Refund Policy for how payments are handled after the fact.

Technical and security data

  • IP address and a device fingerprint (derived from your browser/device characteristics), used to detect suspicious sign-ins and enforce rate limits on login and registration attempts
  • Session and authentication records, including when and roughly from where you signed in
  • System logs of account-level actions (profile changes, password changes, deletion requests) for security auditing

3. Cookies and local storage

StudErn’s frontend is a static site with no server-rendered pages, so it does not use traditional server-set cookies for authentication. Instead, your sign-in token and a few preferences (which company you’re currently managing, your light/dark theme choice, an in-progress CV draft) are kept in your browser’s local storage, on your device only. Signing out, or clearing your browser’s site data, removes them.

We use Cloudflare’s privacy-respecting web analytics on the marketing pages, which is cookieless by design and does not track you across other sites. If your browser has tracking protection enabled, you may see this beacon blocked in your browser console — that’s expected and doesn’t affect anything the platform does.

4. Who we share data with

WhoWhat they receiveWhy
A company you apply toYour profile, application, and any documents you attachSo they can evaluate your application
Google / LinkedIn / GitHubNothing beyond the standard OAuth handshakeOnly if you choose to sign in that way
bKashPayment amount and your bKash number, entered directly into bKash’s own checkoutTo process a paid job posting

We do not sell personal data, to anyone, ever.

5. How long we keep it

We keep your data for as long as your account is active. If you request deletion, see the Data Deletion Policyfor the full 30-day process — the short version is that deletion is requested immediately but the data isn’t actually purged until the grace period ends, specifically so a mistaken or emotional deletion request can be undone.

Three things outlive account deletion, by design: financial transaction records (kept for accounting and tax compliance, with your personal identifiers removed once the account is purged), security audit logs (kept with the account reference removed, so the record of “an account did X at time Y” survives without identifying whose account it was), and a minimal, one-way fingerprint of your contact plus your deletion date, kept for 6 years for legal and fraud-prevention purposes and then permanently erased in its own right. None of these can be used to identify you, contact you, or reconstruct your profile. See the Data Deletion Policy for the full detail on each.

6. Your rights

  • Access — your full profile is visible to you at any time in your dashboard.
  • Correction — edit your profile, education, skills, and other records directly; contact us for anything you can’t self-serve.
  • Deletion — request it from your profile settings. See the Data Deletion Policy.
  • Portability — download your ATS-formatted resume as a PDF at any time from your dashboard.

7. Security

Passwords are never stored in plain text. API access is rate-limited to slow down credential stuffing and brute-force attempts. Uploaded images are re-encoded server-side before storage, which strips metadata and defeats several classes of image-based attack. We do not consider this an exhaustive security statement — if you find a vulnerability, please report it to [email protected] before disclosing it publicly.

8. Changes to this policy

If this policy changes materially, we’ll update the effective date at the top of this page. We won’t narrow your rights retroactively without telling you first.

9. Contact

Questions, requests, or complaints about how your data is handled: [email protected].