1. Scope
This Privacy Policy applies to the UC Merced Hub mobile applications and the UC Merced Hub campus-map website and related support/policy pages that link to this policy (collectively, the “Service”). Some map and browsing features can be used without creating an account. Account-based and community features require additional information described below.
2. Information We Collect
A. Account and authentication information
If you create an account, we may collect information needed to create, secure, and maintain it, including:
- Your email address.
- Your username, display name, internal account identifier, or similar account information where used by the Service.
- Authentication and session information needed to sign you in and keep your account secure.
- Account status, creation/update timestamps, and other basic account records.
B. Student verification information
If you request student-only access, we may process a UC Merced school email address, verification status, and records necessary to complete or re-check the verification workflow. Verification status may be associated with your UC Merced Hub account so the Service can enable eligible student features.
C. User-generated content
If you use features that allow you to create or submit content, we collect the content and information needed to display and manage it. Depending on the feature, this may include:
- Wildlife captures or other posts you submit.
- Images, captions, descriptions, categories, timestamps, and other information you choose to include.
- A location or map position associated with a post when the feature uses or allows location information.
- The account or username associated with the post.
- Records of edits, deletion, or other actions necessary to operate the feature.
Please avoid including unnecessary personal information about yourself or other people in public or community-facing posts.
D. Safety, blocking, reporting, and moderation information
To support community safety and moderation, we may collect and store:
- Which accounts you have blocked and the account identifiers needed to apply those blocks.
- Reports you submit about content or users, including the report category/reason and identifiers for the reported content or account.
- Moderation records, such as content removal, restrictions, or other actions taken to enforce our Community Guidelines.
Your block list and report details are not intended to be displayed publicly. They may be reviewed as needed to operate safety and moderation functions.
E. Location information
The app may request device location permission to provide map positioning, walking directions, routing, or similar location-aware features. We do not use the Service to build a continuous history of your movements.
If you intentionally attach or select a location for a user-generated post, that post location may be stored with the post and may be visible to other users according to the feature’s design. This is separate from your device’s live navigation location.
F. Device, diagnostics, and usage information
We may process limited technical information needed to operate, secure, troubleshoot, and improve the Service, such as app version, device/operating-system information, request/error information, and aggregate feature usage where available.
G. Website analytics
UC Merced Hub web pages use Plausible Analytics to understand aggregate website traffic and page usage. Plausible is used as a privacy-focused web analytics service and is configured without advertising trackers on these pages.
H. AI features and AI-related information
UC Merced Hub uses OpenAI for certain optional AI features and for safety screening of community content. The information sent depends on the feature you choose to use:
- AI Search: When you choose AI Search, we send your search query and limited campus-content context needed to answer or rank results. AI Search does not intentionally send your account email, account ID, or device location unless you include that information in the text you submit.
- Wildlife AI Autofill: If you choose AI Autofill and accept the in-app disclosure, we may send up to four hosted wildlife image URLs and report context such as title, description, tags, date/time, selected location name or identifier, and related report fields to OpenAI so it can suggest a title, description, tags, or image alt text. Precise geometry is not sent for AI Autofill. Suggestions remain editable and are never published automatically.
- Content safety and moderation: Before community wildlife content is published, submitted text, image information, and related post metadata may be processed by OpenAI for safety screening. This is separate from AI Autofill and is covered by its own in-app acknowledgement.
- AI-related logs: We may retain limited AI request, response, and technical information for troubleshooting, security, abuse prevention, and service reliability. Production logging is intended to avoid unnecessary personal data and is not used for advertising.
I. Support communications
If you contact us by email, support page, Discord, or another support channel, we receive the information you choose to provide so we can respond to your request. Please do not send passwords or verification codes to support.
3. How We Use Information
We use information described above to:
- Provide maps, events, routing, search, and other core Service functionality.
- Create and manage accounts and maintain authenticated sessions.
- Verify eligibility for student-only features.
- Publish, retrieve, edit, and delete user-generated content.
- Provide optional AI Search and AI Autofill features when you choose to use them.
- Screen submitted community content for safety and enforce moderation rules.
- Apply user blocks and reduce unwanted interactions.
- Review reports, enforce community rules, prevent abuse, and protect users and the Service.
- Respond to support requests and account-deletion requests.
- Diagnose technical problems, improve reliability, and understand aggregate use of the Service.
- Protect the security and integrity of our systems.
4. Sharing, Service Providers, and Public Visibility
A. Information you make visible through the Service
User-generated content may be visible to other users. Information displayed with a post may include your username/account identity used by the feature, the content you submitted, and associated metadata such as time, category, or location. Do not post information you do not want exposed to the audience for that feature.
B. Service providers
We use service providers to operate specific parts of the Service. Depending on the feature you use, these providers may process information on our behalf:
- OpenAI: used for AI Search, optional wildlife AI Autofill, and community-content safety screening as described above.
- Supabase: used for account authentication, database records, user content, reports, blocks, sessions, and related application data.
- UC Merced Hub image hosting: wildlife images may be uploaded to a separate image-upload and hosting service so they can be displayed in posts and made available to AI Autofill or moderation when you use those features.
- Plausible Analytics: used for aggregate analytics on UC Merced Hub web pages.
- Hosting, email, mapping, routing, content-delivery, and security providers: used as needed to deliver and protect the Service.
These providers may process information only as needed for the services they provide to UC Merced Hub. Their own terms and privacy practices may also apply to information they process.
C. Legal, safety, and security reasons
We may disclose information when reasonably necessary to comply with law, respond to valid legal process, protect users or the public, investigate abuse or security incidents, or protect the rights and integrity of UC Merced Hub.
D. No sale of personal information
UC Merced Hub does not sell personal information or user posts for advertising purposes.
5. Data Retention and Deletion
We retain account information for as long as your account is active or as reasonably necessary to provide the Service. User posts and related information are retained while they remain part of the Service unless you delete them, your account is deleted, they are removed through moderation, or limited retention is reasonably necessary for safety, security, dispute resolution, or legal compliance.
Post and image deletion
When you delete a wildlife post, we remove the post record and the associated wildlife image files stored by our image-hosting service, subject only to limited retention that is reasonably necessary for safety, security, abuse prevention, dispute resolution, or legal compliance.
Account deletion
You can initiate deletion of your account from within the app. If you cannot access the app, you can also use the external account-deletion instructions on our Support page.
When an account-deletion request is completed, we delete or de-identify data associated with the account that is no longer needed to operate or protect the Service, including account information, student-verification state, user posts, associated hosted wildlife image files, block relationships, and active sessions, subject to the limited exceptions below.
AI and operational logs
We may retain limited AI request, response, and technical information for troubleshooting, security, abuse prevention, moderation integrity, and service reliability. Access is limited to operational needs, and we seek to minimize or redact personal information where practical. We retain this information only for as long as reasonably necessary for those purposes or as required by law.
Limited retention for safety or legal reasons
We may retain limited records when reasonably necessary for security, fraud or abuse prevention, moderation integrity, dispute resolution, or legal compliance. For example, a minimal record related to a serious abuse report or enforcement action may be retained to prevent repeat abuse. We aim to minimize or de-identify retained information where practical.
6. Your Choices and Controls
- Location: You can control location permission through your device settings. Some navigation features may not work without it.
- AI Autofill: AI Autofill is optional. Before the first wildlife AI Autofill transfer, the app asks you to accept a disclosure explaining that your wildlife photos and report details will be sent to OpenAI for suggestion generation. You can revoke this permission from Settings → Privacy & Safety → AI Autofill Data Sharing; the app will ask again before a future transfer.
- AI Search: AI Search is optional and runs only when you choose to submit an AI search query.
- Posts: Where the Service provides a delete option, you can remove content you created, including associated hosted wildlife images as described above.
- Blocking: You can use available blocking controls to hide or prevent content/interactions from blocked users as implemented by the Service.
- Reporting: You can report objectionable content or users through the available in-app reporting controls.
- Account deletion: You can initiate account deletion in the app or use the external deletion instructions on the Support page.
- Support: You may contact us at [email protected] with privacy or data questions.
7. Security
We use reasonable administrative and technical measures designed to protect information and limit access to what is needed to operate the Service. No internet-connected service can guarantee absolute security. You are responsible for keeping your account credentials secure and should not share verification codes or passwords.
8. Children’s Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to the Service, contact us so we can review and address the issue.
9. Third-Party Links and Content
The Service may link to university pages, community sites, Discord, social platforms, map/data sources, or other third-party services. Their privacy practices are governed by their own policies, not this Privacy Policy.
10. Changes to This Policy
We may update this Privacy Policy as the Service changes. When we make material updates, we will post the revised policy on this page and update the “Last updated” date. Where appropriate, we may also provide notice within the app or ask for renewed permission before a materially different data-sharing use.
11. Contact Us
Questions about privacy, account deletion, or data handling can be sent to:
- Email: [email protected]
- Support: campusmap.ucmercedhub.com/support/
- Community Guidelines: campusmap.ucmercedhub.com/community_guidelines/