Lecturey is a class-attendance app for universities. It verifies that the right student is present in the right class, using a QR code and an on-device face check. This policy explains what data we collect, why, how long we keep it, and the choices you have. It is written to align with Jordan's Personal Data Protection Law No. 24 of 2023 (PDPL).
1. Who we are
The Lecturey app is operated by Lecturey ("Lecturey", "we", "us"). We act as the data controller for the personal data described below. Your university provides your enrollment details and uses Lecturey to record attendance for its courses.
2. Data we collect
We only collect what the app needs to record attendance and keep your account secure:
- Account & identity: name, university ID number, email, course enrollment.
- Attendance records: sessions you attended, were absent from, or were excused from, with timestamps.
- Face & biometric: a numeric face template used to confirm it is you (see Section 3).
- Camera & photos: QR scans and face capture at check-in, and an optional photo you attach to an excuse request.
- Device & technical: push-notification token, app version, device type, and security logs.
We do not collect your location, contacts, or advertising identifiers, and we do not use third-party advertising or tracking in the app.
3. Face & biometric data
Face verification is how Lecturey stops one student checking in for another.
When you enroll, the app turns your face into a mathematical template (a list of numbers, a face descriptor). This template cannot be turned back into a photo of your face. At check-in the app makes a new template and compares it to your stored one to confirm it is you.
- We store the face template only, and we do not keep the camera images used to create or check it.
- Your template is used for one purpose: confirming your identity for attendance. It is never used for advertising or profiling, and is never sold.
- Liveness and anti-proxy checks ensure a live person (not a photo or another student) is present.
- Because biometric data is sensitive under the PDPL, we process it on the basis of your explicit consent, given in the app before enrollment.
- You can ask us to delete your face template at any time (Section 9).
4. How we use your data
- To record and display your attendance for your enrolled courses.
- To verify your identity at check-in and prevent proxy attendance.
- To send attendance-related notifications (reminders, absence alerts, excuse updates).
- To secure your account, enforce one active session per account, and detect misuse.
- To provide support and fix problems with the app.
5. Legal basis & consent
- Your explicit consent for processing your face/biometric template.
- Performance of the service you and your university use Lecturey for, which is recording attendance.
- Our legitimate interest in keeping the service secure and preventing fraudulent check-ins.
You can withdraw consent for biometric processing at any time; doing so removes face check-in for your account.
6. Who we share data with
We do not sell your data. We share it only with:
- Your university: attendance records and account details, so it can manage its courses.
- Push-notification providers: Apple (APNs), Google Firebase (FCM), and Expo, solely to deliver notifications.
- Our hosting provider: a Hostinger VPS that stores the data securely on our behalf.
- Authorities: only where we are legally required to.
7. How long we keep data
- When you graduate, your account and personal data, including your face template, are scheduled for deletion and are automatically and permanently deleted within 90 days of graduation.
- Your face template is also deleted any time you delete your account or withdraw biometric consent.
- Attendance records may be retained by your university for its official academic records.
- Security logs are kept for a limited period and then deleted.
8. How we protect data
- All traffic between the app and our servers is encrypted in transit (HTTPS/TLS).
- Passwords are stored only as salted one-way hashes, and we never store or see your actual password.
- Access to stored data is restricted, and the database is not exposed directly to the internet.
- Face data is stored as a non-reversible template, not as images.
9. Your rights
Subject to the PDPL, you can ask us to access, correct, or delete your data, withdraw consent for biometric processing, or object to / restrict certain processing. To do so, contact us (Section 12). Some attendance records may be retained by your university as part of its official academic records.
10. Age
Lecturey is intended for university students and staff. It is not directed at children under 16, and we do not knowingly collect their data.
11. Changes to this policy
We may update this policy as the app evolves or the law changes. We will revise the "Last updated" date above and, for material changes, notify you in the app.
12. Contact us
For any privacy question or to exercise your rights, contact us at supportlectury@gmail.com. You also have the right to lodge a complaint with the competent data-protection authority in Jordan.