Privacy policy
What the Union holds on you, why it holds it, and how to make it stop.
Last updated 11 August 2026
What this covers
The AUC Student Union — the elected student body of the American University in Cairo, and in this policy “the SU”, “we”, “us” — runs the AUC SU mobile app for iOS and Android and the website at aucsu.org. This policy covers both, and the shared systems behind them.
It covers what the SU's own systems hold. It is not a statement about what the University holds on you as a student: your grades, your registration and your AUC account belong to AUC and to AUC's own policies, and the SU cannot read any of them.
The SU is the controller of the data described here. Write to sutech@aucegypt.edu with anything about it.
What we collect
Every row below exists because a feature you used needed it. There is no background collection, and nothing here is gathered speculatively for a use we have not thought of yet.
| What | Where it comes from | Why we hold it |
|---|---|---|
| Name, AUC email address, profile picture | Your AUC Google account, at sign-in | To identify the account and address you by name |
| Student ID, major, graduation year, phone, gender | You, when you set the account up. Only the ID is required | The SU Card is issued against your ID; the rest tells a service which student it is serving |
| Points balance and the ledger behind it | Earned at SU events, spent in the SU Market | To run the points system and show you where a number came from |
| RSVPs and door check-ins | You, when you RSVP or are scanned in at an event | Headcount, entry, and crediting the points for attending |
| Cases you file, every message in them, and the photos and documents attached | You | So the SU can answer you, and so the thread survives being handed to someone else |
| Files you upload to SU Notes | You | To review them and publish them to the library |
| Form responses, recruitment applications, and redemption records | You | To process the thing you applied for or claimed |
| A push token per device | Your device, once you allow notifications | It is the address a notification is delivered to. Nothing about you is in it |
| Session and request data — a signed session token, the platform, the app version | Your device, on every request | To keep you signed in, serve the right build, and diagnose faults |
There is no advertising in the app and no third-party analytics or tracking SDK in it. We do not build advertising profiles, we do not track you across other apps or websites, and we do not sell, rent or trade personal data to anyone, for any price.
The permissions the app asks for
Each one is asked for at the moment it is needed rather than at launch, and each one can be refused without losing the rest of the app. You can change your mind at any time in your phone's settings.
| Permission | What it is for | If you say no |
|---|---|---|
| Camera | Scanning an SU QR code — a door screen at an event, a form on a poster — taking a profile picture, and attaching a photo to a case | Everything else still works; only the scanner stops |
| Photos | Choosing a file to upload to SU Notes, a profile picture, or an attachment for a case | Use the camera instead, or skip the upload |
| Location | Centring the partner map on you so the nearest vendors are the ones you see first. Your position is used on the device to draw the map — it is never sent to us and never stored | The map stays centred on campus |
| Notifications | Telling you a case has been answered, or carrying an SU announcement | Nothing else changes; you read replies in the app instead |
How we use it
- To sign you in, keep you signed in, and show you the services you are entitled to.
- To run the things you asked for: your card, your points, your RSVPs, your cases, your uploads, your applications.
- To answer you — a reply to a case, an email back, a notification that one has landed.
- To keep the platform working and honest: finding faults, stopping abuse, and protecting the accounts of other students.
- To count. How many students came to an event, how many notes a course has — aggregate figures the SU plans on, holding nothing that points back at a person.
We do not make automated decisions about you that carry a legal or similarly significant effect. A person decides whether an application succeeds, whether a note is published, and what a case is worth.
Filing a case anonymously
Tell Rep lets you file anonymously, and the switch does what it says: the SU member handling your case sees the case and your messages, and does not see your name, your picture or your account.
It is anonymous to the SU, not untraceable, and you should know the difference before you rely on it. The case stays linked to your account in the database, because that link is the only reason a reply has somewhere to arrive. Exactly one principal — the SU's own break-glass administrator account — can resolve that link, and it exists for safety and abuse matters. No handler, chair or officer can.
The other limit is in your own hands: a handler reads what you type. Name yourself in the message and the anonymity ends there.
Who else touches it
Only the companies that run the pipes, and only with what the pipe carries. Each is bound to use it for the service they provide us and nothing else.
| Who | What reaches them | Why |
|---|---|---|
| Your AUC email address, and the fact that you signed in | Google Sign-In is how the app knows you are an AUC student | |
| Expo | A device push token, and the text of a notification while it is being delivered | It runs the push service the app registers with, and ships the app's over-the-air updates |
| Apple and Google | A device push token and the notification itself, at the last step | APNs and FCM are the only routes onto a phone's lock screen |
| OpenStreetMap and Google Maps | Map tiles your device asks for while a map is open | To draw the partner map. The request comes from your device, not from us |
| Our hosting and storage providers | Everything above, at rest | The database, the API, and the private bucket the uploaded files sit in |
| The American University in Cairo | Only what a specific matter requires | Where the SU must escalate something — safety, misconduct — or where a service is run jointly with the University |
Beyond these, we disclose nothing — unless a law or a lawful order requires it, or a person's safety turns on it.
How long we keep it
- Your account, profile and points ledger last as long as you keep the account.
- Cases and their attachments are the record of what the SU was asked and what it answered, and are kept while your account exists.
- Notes published to the library outlive your account, because other students are relying on them. On deletion they are detached from you and stop carrying your name.
- A push token is deleted when you sign out, turn notifications off, or the device stops accepting them.
- Backups are rotated, and a copy can persist in one for up to thirty days after deletion.
Your choices
You can read your own record under Profile in the app or at aucsu.org/profile, correct anything you entered there, turn notifications off in Settings, and withdraw any OS permission in your phone’s settings without losing the account.
You can ask us for a copy of everything we hold on you, ask us to correct it, or ask us to delete the account outright — write to sutech@aucegypt.edu from the AUC address you sign in with, and we answer within seven days. What deletion removes and what it leaves behind is set out on the support page.
Signing in is itself the choice: everything the SU holds on you begins with an account you opened and ends with one you can close.
How it is protected
Traffic runs over HTTPS. Your session token is held in the device's own secure keystore rather than in ordinary app storage. Uploaded files sit in a private bucket that is never public and is served only through the API, to a signed-in student. Inside the SU, access is fenced by rank and committee — a member sees the cases and the records their position reaches, and no more.
No system is perfect, and we will not pretend otherwise. If you think an account has been reached by someone else, or you have found a weakness in ours, write to sutech@aucegypt.edu and we will treat it as urgent.
Children
The app is for enrolled AUC students and can only be entered with an @aucegypt.edu account, so it is not directed at children and we do not knowingly collect anything from one. If you believe a child's data has reached us, tell us and we will remove it.
Changes to this policy
When the platform changes what it collects, this page changes with it and the date at the top moves. Anything material — a new category of data, a new recipient — is announced in the app rather than left here to be discovered.
Contact
Privacy, the app, and anything technical: sutech@aucegypt.edu. The Union’s general inbox: su@aucegypt.edu.
By post: The Student Union, The American University in Cairo, AUC Avenue, P.O. Box 74, New Cairo 11835, Egypt.