Privacy Policy

Version of September 28, 2026

This policy explains what data EduFinder processes, why, and what choices you have. It describes how the portal actually works.

1. About this policy

This policy explains how EduFinder, run by the portal operator ("we"), handles data. It applies to everyone who uses the portal, with or without an account.

You can browse, search and view institutions without an account. Favorites you save as a guest are stored only in your own browser (local storage).

2. Account data

If you create an account, we store:

  • your email address, phone number, or both
  • an optional public display name
  • your role on the portal
  • the portal language you last used, so that notifications reach you in that language
  • records of which version of the Terms of Use and Privacy Policy you accepted and when
  • your notification preferences and in-app notifications
  • favorites you save while signed in

3. Sign-in codes

Accounts are passwordless. When you sign in or create an account, we send a one-time numeric code to your email address or phone number. The code expires after a few minutes and can be used once; attempts and requests are limited.

We store only a keyed hash of each code, never the code itself, and codes are deleted after they expire. If your account has both an email address and a phone number, both sign in to the same account. Changing or removing a sign-in identifier requires verification, and we send security notices about such changes.

4. Sessions

When you sign in, we keep a session record on our servers with your IP address, your browser's user-agent string and the time of your last activity. A session ends after 24 hours without activity. If you choose "keep me signed in", it lasts up to 30 days without activity and never more than 90 days.

In account settings you can see your active sessions, with the approximate browser or device, approximate IP address and last activity, and sign out other sessions. Session records are removed when they expire, when you sign out or when a session is revoked.

5. Cookies

The portal uses only the following cookies. It does not use advertising or analytics cookies.

  • a strictly necessary session cookie that keeps you signed in
  • a security token cookie that protects forms against cross-site request forgery (CSRF)
  • a language-preference cookie, set when you choose a language

6. Reviews and photos

Reviews with a 1–5 star rating and photos of institutions are checked by portal administrators before publication. Public reviews show your display name, or a neutral label if you have not set one. Your email address and phone number are never shown publicly.

Uploaded images are processed, and we store only re-encoded copies without embedded metadata such as location (EXIF) data.

You can withdraw your reviews and delete your photos at any time. When a review is withdrawn, the institution's rating is recalculated.

7. Notifications

We send in-app and email notifications about moderation decisions, access changes and account-security events. You can switch off non-essential categories in account settings; security notices cannot be switched off.

8. Administration and audit

Portal administrators moderate content and manage account roles. Institution representatives manage institution profiles, and their changes are moderated. Administrative actions are recorded in an internal audit log.

9. Maps and place search

Maps and place search use Google Maps and Google Places. When you open a map or use location search, Google's scripts load in your browser and Google processes data under its own terms.

10. Downloading your data

In account settings you can download a machine-readable (JSON) copy of your account data: your profile and identifiers, favorites, reviews and their versions, photo metadata, managed institutions, notification preferences, consent records and the security history of your account.

11. Deleting your account

You can delete your account yourself in account settings; this requires a fresh one-time code. Other sessions are signed out immediately. For 7 days you can cancel the deletion by signing in again.

An institution representative cannot delete the account while they are the only manager of an institution, and the last portal administrator cannot delete their account.

After the 7-day period:

  • favorites, notifications, preferences, sessions and pending one-time codes are deleted
  • unpublished review drafts are deleted
  • all your photos, including the image files, are deleted
  • published reviews remain public but are anonymized, shown as by a "Deleted user" and no longer linked to your account
  • administrative audit records are kept without contact details

12. Children

The portal is intended for parents, guardians and other adults. Accounts are intended for adults, and children should not create accounts. Please do not include personal data of children, such as names or identifying photos, in reviews or photos.

13. Updates and contact

We may update this policy. Each updated version gets a new version date shown on this page. New accounts accept the current version when they are created, and we keep a record of which version was accepted and when.

If you have questions about this policy or your data, please reach us through the contact options published on the portal.