Student privacy notice
← backVersion 2026-08-13 · Responsible party: MariffB
Why this portal uses data
It creates and manages an MQTT account for class exercises, confines that account to its own topic namespace, shows the instructor whether a device reports online/offline, and supports account troubleshooting and deletion.
Data collected
- Required: chosen username, broker password and class code.
- Optional: a display name. A nickname is sufficient; a real name is not required by this portal.
- Operational: account creation date, enabled/disabled state, device online/offline status and last status time.
The portal sends the chosen password to the local Mosquitto broker to create the account, but the portal metadata store does not save that plaintext password. The browser test console connects directly to Mosquitto; credentials entered there are not submitted to the portal application. MQTT messages are processed by the broker and any Node-RED flows your instructor configures, so do not publish personal, confidential or sensitive information.
Access and disclosure
The instructor can see usernames, optional display names, creation dates, enabled state and device presence. Accounts are topic-isolated. Data is hosted on the course VPS and is not sold or used for advertising. Infrastructure providers may process server data as necessary to host and back up the service.
Retention
Accounts and portal registration metadata are scheduled for deletion after 180 days, or earlier at the end of the course when no longer needed. Encrypted backups may remain until their configured backup retention expires. MQTT messages may have different retention if an instructor's Node-RED flow stores them; ask before publishing anything beyond class telemetry.
Your choices and requests
The display name is optional. You may ask to see, correct, disable or delete your portal account and metadata by contacting ariff.lain@gmail.com. If you are under the age required by your institution to use this service independently, follow your instructor's parent/guardian or institutional authorization process before registering.
Security and incidents
Connections use TLS, accounts have per-user topic permissions, and administrative access is restricted. No online system is risk-free. Report suspected credential exposure or unexpected access promptly to ariff.lain@gmail.com; change the affected password and stop publishing until the instructor confirms it is safe.