Privacy Policy
1. Who we are
SEARCH (Space and Earth Analogs Research Chapter) is a registered student organization at Purdue University, West Lafayette, Indiana. In this policy, "SEARCH," "we," "us," and "our" refer to that student organization.
SEARCH is student-run and is not an official service of Purdue University. This policy is issued by the student organization on its own behalf. It does not describe Purdue University's own data practices and does not bind the University. Purdue's own privacy notices apply to services the University operates.
For any question about this policy or about information we hold, contact us at purduesearch@gmail.com.
2. What this policy covers
This policy applies to:
- The public SEARCH website at purduesearch.github.io.
- Public forms hosted on that site, including event RSVP pages, meeting-scheduling pages, and newsletter signup.
-
Constellation, our internal project-management system for club members
(the
/clubpmsection of the site and its supporting server). - The outreach records we keep about sponsors, press contacts, partners, and alumni.
It does not cover third-party services we link to or use — such as Slack, GitHub, Google, Instagram, LinkedIn, or Purdue University systems including BoilerLink and Purdue's giving portal. Those services have their own privacy policies.
3. Information we collect
3.1 Visitors to the public website
We do not run analytics, advertising, or tracking scripts on the public website. There is no Google Analytics, tag manager, advertising pixel, or third-party behavioural tracker on our public pages. We do not set cookies for ordinary visitors.
The public site is hosted on GitHub Pages, and pages that load data or images from our own server contact that server directly. Both GitHub and our hosting provider may keep standard server logs, which typically include IP address, request time, page requested, and browser user-agent. These logs are generated by our infrastructure providers as part of delivering the site.
If we shorten or tag a link we share on social media, we count how many times that link was clicked in total. We do not associate those counts with individual people.
3.2 People who use our public forms
Some pages let anyone — including non-members — submit information to us:
- Event RSVP pages. If you RSVP to a SEARCH event as a guest, we store the name and email address you enter, along with the event and the time you responded.
- Meeting scheduling pages. If you respond to a scheduling poll using a shared link, we store the name you enter and which time slots you marked as available.
- Newsletter signup. If you subscribe, we store your email address, your name if you provide one, whether you have confirmed or unsubscribed, and a unique unsubscribe token.
3.3 Contacts recorded in our outreach records
We may hold information about you even if you have never visited this website. To manage sponsorships, press coverage, partnerships, and alumni relations, SEARCH members record contact details for people and organizations we work with or hope to work with.
These records may include:
- Name, email address, and phone number;
- Organization and job title or role;
- A category (for example sponsor, press, partner, prospective contact, or alumni) and a relationship stage;
- Free-text notes written by SEARCH members, and a log of interactions such as emails, calls, meetings, and events attended.
This information is usually obtained directly from you, from a business card or public professional profile, or from a colleague's introduction. It is visible only to SEARCH members with access to our internal system. If you would like to know what we hold about you, correct it, or have it deleted, email purduesearch@gmail.com and we will act on your request — see Your rights and choices.
3.4 Constellation member accounts
Constellation is available only to SEARCH members and is not open to the public. You sign in with your Slack account from the SEARCH workspace. When you do, we collect and store:
- Identity from Slack: your Slack user ID and handle, display name, profile photo, email address, job title if set, biography if set, and time zone.
- GitHub connection (optional): if you link a GitHub account, your GitHub username and OAuth access and refresh tokens. Those tokens are encrypted before they are stored.
- Work you do in the system: tasks you create, are assigned, or complete; comments and reactions; time you log against tasks; files and CAD parts you upload; blog drafts and revisions you author; and change requests you raise or review.
- Engagement and gamification data: experience points, "doubloons," rank, activity streaks, daily-quest and challenge progress, achievements, purchased cosmetic items, and kudos you send or receive.
- Training records: your enrolment in internal courses, your progress through them, quiz attempts, and the answers you gave.
- An activity and audit log recording actions taken in the system, who took them, and when — used to show project history and to resolve disputes about changes.
- Preferences: notification settings, quiet hours, muted projects, and interface layout choices.
3.5 Google account data
SEARCH connects one shared Google account, controlled by the club, to Constellation so the system can store and retrieve club files in Google Drive. Individual members do not connect their personal Google accounts, and we never ask members to sign in to Constellation with Google.
From that single connection we store:
- The email address of the connected club account;
- An OAuth refresh token, encrypted before storage;
- The list of permissions (scopes) that were granted, and when.
Using that connection, Constellation reads and writes club files in Google Drive — for example CAD files in our parts vault, images used in blog posts, presentation decks used in internal courses, and listings of the club project folders. See Google account data and Limited Use for the specific commitments that apply to this data.
4. How we use information
We use the information described above only to:
- Run the club's projects — assigning and tracking work, scheduling meetings, and keeping project history;
- Store and retrieve club documents, CAD files, images, and course materials;
- Send you notifications you have opted into, such as task assignments, due-date reminders, and digests, in the app and by Slack direct message;
- Organize events and know who is attending;
- Manage relationships with sponsors, press, partners, and alumni;
- Send our newsletter to people who subscribed;
- Operate the club's recognition and engagement features (points, ranks, streaks, achievements);
- Deliver internal training courses and record completion;
- Keep the system secure, investigate misuse, and fix problems.
We do not sell personal information. We do not share it with advertisers, and we do not use it for advertising.
5. Google account data and Limited Use
SEARCH's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, in relation to data obtained through Google APIs:
- We use it only to provide and improve the file-storage features described in this policy — storing and retrieving club CAD files, blog images, course decks, and project folder contents.
- We do not transfer or sell it to third parties, except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to affected users.
- We do not use it for serving advertisements of any kind, including retargeted, personalized, or interest-based advertising.
- We do not use it to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
- We do not allow humans to read it, except: with the explicit consent of the account holder for specific files; where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data has been aggregated and anonymized for internal operations. Ordinary access to files stored in the club Drive by SEARCH members is access to the club's own documents by the club's own members.
The permissions we request are limited to what the features above require. An administrator can disconnect the club's Google account from Constellation at any time, which deletes the stored refresh token from our database. Access can also be revoked at any time from the Google account permissions page.
6. Automated and AI processing
Constellation includes optional features powered by Google's Gemini API — for example drafting task descriptions, answering questions about a project, suggesting deadlines, generating course material, and assisting with blog drafts.
When a member uses one of these features, relevant content is sent to Google's Gemini API to produce a response. Depending on the feature, that content can include task titles and descriptions, project details, milestone and blocker information, recent project activity, and the display names of members involved. It may also include a document or image a member deliberately submits for analysis.
This processing is governed by Google's terms for that API. As stated above, data obtained from Google Workspace APIs is not used to train generalized AI or machine learning models. AI-generated output is suggestion only; it is reviewed by a member before it is acted on, and it is not used to make automated decisions that have legal or similarly significant effects on anyone.
7. How information is shared
We share information with the service providers that make the club's systems work. We do not sell personal information to anyone.
| Service | What it handles |
|---|---|
| Slack | Member sign-in, identity and profile details, notification direct messages, and club discussion. |
| GitHub | Hosting of the public website, and — for members who link an account — code activity such as commits and pull requests shown against tasks. |
| Google Drive | Storage of club files, CAD parts, blog images, and course decks under the club's own Google account. |
| Google Gemini API | Processing of content submitted to the optional AI features described in section 6. |
| Oracle Cloud | Hosting of the Constellation server and its database. |
We may also disclose information where we are required to do so by law, or where it is necessary to protect the rights, safety, or property of SEARCH, our members, or others.
Some information is public by design: blog posts we publish, the names of post authors, and other content we choose to put on the public website.
8. Cookies and local storage
The public website does not set cookies and does not use tracking technologies.
When you sign in to Constellation as a member, we use two things on your device:
- A session cookie, which keeps you signed in between page loads.
- An authentication token in your browser's local storage, used as a fallback for browsers that block cross-site cookies. It expires after seven days, and it can be invalidated earlier if you sign out or if an administrator revokes access.
Both exist only to keep you signed in. Neither is used to track you across other websites. Clearing your browser's site data removes both and signs you out.
9. How long we keep information
- Member accounts and project history are kept while you are a member and afterwards as part of the club's project record, so that the history of who did what on a project stays intact. You can ask us to remove or anonymize your personal details — see below.
- Outreach contact records are kept while the relationship is relevant to the club, and are deleted on request.
- Newsletter subscriptions are kept until you unsubscribe. We keep a record that an address unsubscribed so we do not contact it again.
- Event RSVPs and scheduling responses are kept as part of the record of that event or meeting.
- The Google refresh token is kept until an administrator disconnects the account or access is revoked, at which point it is deleted from our database.
Because SEARCH is a student organization with changing leadership, we review stored data periodically and remove what is no longer needed.
10. Security
- Traffic to the website and to the Constellation server is encrypted in transit using HTTPS.
- OAuth tokens — including GitHub tokens and the Google refresh token — are encrypted before they are written to our database.
- Constellation is restricted to signed-in SEARCH members, and administrative functions are limited to club leadership.
- Access to the underlying server and database is limited to the members who maintain the system.
No system is completely secure. We cannot guarantee absolute security, but we will notify affected people without undue delay if we become aware of a breach that presents a meaningful risk to them.
11. Your rights and choices
Whoever and wherever you are, you may ask us to:
- Tell you what we hold about you;
- Correct information that is wrong or out of date;
- Delete your information, or anonymize it where a project record needs to remain intact;
- Stop contacting you, including removing you from our outreach records entirely.
Email purduesearch@gmail.com with your request. We aim to respond within 30 days. We may need to confirm your identity before acting on a request, so that we do not disclose someone else's information.
Newsletter: every newsletter includes an unsubscribe link, which takes effect immediately and requires no explanation.
Constellation notifications: members can change notification settings, set quiet hours, and mute projects from their profile.
Depending on where you live, you may have additional statutory rights — for example under the EU or UK General Data Protection Regulation, or under state privacy laws in the United States — including rights of access, correction, deletion, portability, and the right to object to certain processing. We honour the requests above for everyone regardless of location, and we do not sell personal information or share it for cross-context behavioural advertising.
12. Children's privacy
SEARCH's services are intended for university students, staff, and adult collaborators. Constellation is restricted to club members. We do not knowingly collect personal information from children under 13.
SEARCH runs outreach and educational activities that may involve minors. Where that happens, information about participants is handled through the school, event organizer, or Purdue University program running the activity, and is not collected through this website. If you believe a child has given us personal information directly, contact purduesearch@gmail.com and we will delete it.
13. International users
SEARCH operates in the United States, and the services we use store and process information in the United States. If you are outside the United States, submitting information to us means it will be transferred to and processed in the United States, where data-protection law may differ from that of your country.
14. Changes to this policy
We may update this policy as the club's systems change. When we do, we will revise the "Last updated" date at the top and increment the version number. If a change materially affects how we handle personal information, we will give notice — for members, in Constellation or by Slack message; for newsletter subscribers, by email.
15. Contact us
Questions, requests, or concerns about this policy or about information we hold:
SEARCH — Space and Earth Analogs Research Chapter
Purdue University, West Lafayette, Indiana, USA
Email: purduesearch@gmail.com
Web: purduesearch.github.io/contact