Privacy Policy
At Academic Vault, protecting the privacy, academic integrity, and confidentiality of university students and institutional records is fundamental to everything we engineer. Student documents, exam scripts, and academic evidence ingested through our platform are processed securely and statelessly utilizing Google Gemini Vision AI models. Document visual scans are analyzed strictly in real-time for optical character recognition, academic term extraction, course identification, and metadata tagging. No student documents, personal identifiable information (PII), or graded submissions are ever retained, indexed, or utilized by external AI systems for model training or secondary algorithmic refinement.
All persistent student records, relational databases, and private document archives are physically hosted and maintained within Supabase infrastructure located in the European Union (AWS Central EU Frankfurt, region eu-central-1). Our European data residency guarantees strict adherence to GDPR (General Data Protection Regulation) security standards. Student credentials for filtered private vaults are secured utilizing zero-knowledge cryptographic hashing (salted bcrypt/Argon2); passwords are never stored in plaintext and cannot be read, decrypted, or recovered by system administrators, faculty operators, or anyone holding access to the database. All data exchanges between client browsers and server endpoints are protected with continuous Transport Layer Security (TLS 1.3 / SSL) over Vercel edge hosting, preventing eavesdropping and tampering.
Central EU Frankfurt Storage
All structured student data, course links, and private PDF vaults are physically hosted within Supabase on AWS eu-central-1 (Frankfurt, Germany) under strict GDPR data isolation laws.
Zero-Knowledge Hashing
Student portal passwords undergo irreversible cryptographic salt-and-hash transformations. Neither administrators nor database operators have access to student passwords.
TLS 1.3 & Edge Encryption
Stateless Google Gemini Vision OCR runs without retaining user data. All web traffic is encrypted via end-to-end TLS/SSL certificates and edge-served via Vercel.