Legal
Privacy Policy
Last updated: May 2, 2026
1. Who we are
Iranian Students & Friends Network (“we,” “us,” “the network”) operates iranian-students.org and its regional subdomains. We are an independent, volunteer-run community project — not a registered corporation. This policy explains how we handle your information.
This deployment operates independently. It maintains its own member database, administrative team, moderators, governance, and chapters — entirely separate from any sister community platform. While our technical code and infrastructure are shared with affiliated projects, no member accounts, profiles, posts, messages, or personal data are exchanged between deployments. Your presence here creates no account, profile, or data footprint on any other platform.
If you want to participate in a sister community platform, you can sign up there separately and at your own choice — it is a distinct account with its own credentials, its own data, and its own settings. Volunteering as a moderator, chapter leader, or in any other role on a sister platform is also entirely your own choice and is managed by that platform's team, not ours. Nothing is automatic or cross-enrolled.
2. Information we collect
- Account data — email address, hashed password, account type, country, state, and optional chapter.
- Profile data — name, nickname, organization, research area, bio, links, mentoring preferences, and privacy settings you choose.
- Content — posts, messages, civic items (petitions, polls, statements), and reports you submit.
- Usage data — pages visited, timestamps, and basic request metadata collected by our hosting provider (DigitalOcean).
3. How we use your information
- Provide and operate the platform: authentication, profiles, messaging, feeds, and chapter directories.
- Enforce moderation standards and respond to abuse reports.
- Send account-related communications (approval status, security alerts).
- Improve the platform based on aggregated, non-identifying usage patterns.
We do not sell your data. We do not serve ads. We do not share your information with third parties for marketing purposes.
4. Data storage and security
Data is stored in PostgreSQL on DigitalOcean. Passwords are hashed with scrypt and a unique random salt. Session tokens use HMAC-signed JWTs stored in HttpOnly cookies. We use timing-safe comparisons to prevent timing attacks.
4a. Community Support information
When you use Community Support features (Application Fee Support, Funds & Scholarships, Discussions, Cities & Universities guides, Free Classes & Teaching, Business Sponsorships, Startup & Angel Network, Community Projects, and similar) we may additionally process: opportunity submissions and the support requests / offers you create; matches between requests and offers and the participants in those matches; private documents you upload (e.g. redacted receipts, fee-waiver proofs, pitch decks marked private, project evidence) — stored privately and accessible only to you and platform moderators with a legitimate review reason; community-verification actions you take on funding opportunities or guides; saved funds and reminder dates; discussion threads and replies you post (including upvotes you give); city and university guides you contribute or edit; class enrollments and (for minors) guardian-consent records; sponsorship campaign submissions and sponsor recognition data; startup and investor profile fields you publish; introduction requests between founders and investors; community project submissions including external fundraising URLs and proof updates; privacy data requests you submit; and moderation flags raised by safety scans on your submissions. Sensitive support requests default to a private visibility level until matched. Moderators may access submissions to review safety, verification, or reports.
Upload only what is necessary. Redact passport numbers, national ID numbers, full dates of birth, home addresses, bank details, card details, and unrelated personal information before uploading. We do not intentionally collect or store card numbers, CVV codes, bank passwords, OTP codes, crypto private keys, or payment account credentials.
You can submit privacy data requests (access, correction, deletion, restriction, or portability) at /privacy/data-requests. For immediate self-service, see Settings → Account → Download my data and Settings → Account → Delete account.
5. Your privacy controls
- Show or hide your real name (use a nickname instead).
- Show or hide your email address from other members.
- Control who can message you: everyone, followers only, or no one.
- Choose whether your profile appears in your chapter directory.
6. Cookies
We use a small number of cookies: one for your session token and one for your language preference. We do not use tracking cookies, analytics cookies, or third-party advertising cookies.
7. Data retention and account deletion
Your account and content remain stored while your account is active. You can delete your account at any time, immediately, from Settings → Account → Delete account. Deletion requires you to re-enter your password and takes effect right away — there is no recovery period and no waiting list. See How to delete your account for step-by-step instructions.
After deletion, your account is marked deleted in our database and cannot be signed into. Your posts, messages, and other content you authored may remain attributed to your former username so that conversations you participated in stay readable for other members; request full content removal by emailing privacy@iranian-students.org. Aggregated, non-identifying statistics may be retained indefinitely.
If you only want a break, use Settings → Account → Deactivate instead — your profile is hidden and posts are paused, and you can reactivate any time by signing back in. Your data stays intact.
8. Your rights
- Access and correction — view and edit most of your personal data yourself from Settings.
- Portability / data export — download a machine-readable JSON file of your data (account, profile, posts, comments, messages, likes, bookmarks, follows, civic votes, notifications, and more) at any time from Settings → Account → Download my data. No request or email needed.
- Deletion — delete your account yourself, immediately, as described in section 7.
- Additional questions — for anything not exposed in Settings (e.g., data you want removed that was authored by someone else about you), email privacy@iranian-students.org.
If you are in the EU/EEA, you have additional rights under GDPR including the right to lodge a complaint with a supervisory authority. Data export and deletion above already implement the GDPR rights to access, portability, and erasure.
9. Children
This platform is intended for individuals aged 16 and older. We do not knowingly collect data from anyone under 16.
10. Changes to this policy
We may update this policy as the platform evolves. Material changes will be noted at the top of this page with an updated date. Continued use of the platform after changes constitutes acceptance.
11. Contact
Questions about this policy? Email privacy@iranian-students.org