Student privacy notice

← back

Version 2026-08-13 · Responsible party: MariffB

Why this portal uses data

It creates and manages an MQTT account for class exercises, confines that account to its own topic namespace, shows the instructor whether a device reports online/offline, and supports account troubleshooting and deletion.

Data collected

The portal sends the chosen password to the local Mosquitto broker to create the account, but the portal metadata store does not save that plaintext password. The browser test console connects directly to Mosquitto; credentials entered there are not submitted to the portal application. MQTT messages are processed by the broker and any Node-RED flows your instructor configures, so do not publish personal, confidential or sensitive information.

Access and disclosure

The instructor can see usernames, optional display names, creation dates, enabled state and device presence. Accounts are topic-isolated. Data is hosted on the course VPS and is not sold or used for advertising. Infrastructure providers may process server data as necessary to host and back up the service.

Retention

Accounts and portal registration metadata are scheduled for deletion after 180 days, or earlier at the end of the course when no longer needed. Encrypted backups may remain until their configured backup retention expires. MQTT messages may have different retention if an instructor's Node-RED flow stores them; ask before publishing anything beyond class telemetry.

Your choices and requests

The display name is optional. You may ask to see, correct, disable or delete your portal account and metadata by contacting ariff.lain@gmail.com. If you are under the age required by your institution to use this service independently, follow your instructor's parent/guardian or institutional authorization process before registering.

Security and incidents

Connections use TLS, accounts have per-user topic permissions, and administrative access is restricted. No online system is risk-free. Report suspected credential exposure or unexpected access promptly to ariff.lain@gmail.com; change the affected password and stop publishing until the instructor confirms it is safe.