SSMBulletin

Privacy Policy

Effective August 21, 2026 · ssmbulletin.org

SSMBulletin is a campus bulletin board for NCSSM: events, announcements, organization pages, and course spaces in one feed. This policy explains what the app collects, why it collects it, who can see it, and how to get it removed. It describes what the software actually does, not what a template says it might.

Download this policy as a PDF

1. Who runs SSMBulletin

SSMBulletin is an independent, student-run project. It is not operated, hosted, or endorsed by the North Carolina School of Science and Mathematics, and it is not a school system of record. NCSSM does not send this app grades, transcripts, class rosters, or disciplinary records, and nothing posted here becomes part of your school file. Course spaces are grouped by course code because students type that code in, not because the app is connected to the registrar.

Questions, corrections, and requests about your data go to garner27d@ncssm.edu.

2. Who can create an account

Accounts are limited to people with an NCSSM email address. Signing in goes through Google, restricted to the ncssm.edu domain. That gate is the app’s main safety feature: it keeps the board to people on campus.

SSMBulletin is built for high school students aged 13 and over and is not directed to children under 13. If you believe a child under 13 has an account, write to the address above and it will be removed.

3. What the app collects

Account and profile

  • Your NCSSM email address, taken from the account you sign in with.
  • Your display name, handle, profile photo, and bio, all of which you supply and can change.
  • Your role (student, faculty, or staff) and, for student addresses, your graduation year. Both are read from the shape of your email address rather than asked for.

What you post and do

  • Events and announcements you create: titles, descriptions, images, links, locations, and deadlines.
  • Comments, space threads and replies, and upvotes.
  • RSVPs, event star ratings, organization memberships, join requests, and invitations.
  • Reports you file about someone else’s content.

Notifications and delivery

  • If you turn on push notifications, the subscription your browser issues: a delivery endpoint and the keys needed to encrypt a message to it.
  • Your notification preferences and your digest setting (daily, weekly, or off).
  • Two random tokens generated for your account: one that makes your personal calendar feed work, and one that makes the unsubscribe link in digest email work.

Diagnostics

  • When something breaks: the error message, the technical stack trace, the page path, your browser’s user agent string, and your user ID, so the bug can be found and fixed.
  • Bug reports you file yourself, with whatever description you write.

4. What the app does not do

  • No analytics, tracking pixels, session recording, or advertising. There are no third-party trackers in this app, of any kind.
  • No location tracking. An event’s location is text a person typed, never a reading from your device.
  • No sale of data, ever, and none of it is shared for advertising.
  • No profiling and no AI training. Your activity is not used to build a behavioral profile or to train machine learning models.

On IP addresses: SSMBulletin does not log or use them, but the services that keep the app online (its web host and Supabase) record them briefly as ordinary server operation and abuse prevention, the same as any website.

5. Cookies

Cookies do one thing here: keep you signed in. Supabase Auth sets a session cookie that identifies your browser to the app and refreshes as you use it. Delete it and you are signed out. There are no advertising, analytics, or cross-site cookies, so there is nothing here to opt out of.

6. How the information is used

  • To show you the board, the spaces, and the organizations you belong to.
  • To attribute what you post to you, so that posts on a shared board come from a real, reachable person.
  • To send the notifications you asked for: push, the in-app inbox, and the digest email.
  • To generate your personal calendar feed.
  • To enforce the rules: moderation, handling reports, and suspending or muting accounts that abuse the board.
  • To find and fix bugs, and to keep the app running.

7. What other people can see

Signed-in members of the community can see:

  • Your profile: name, handle, photo, bio, role, and graduation year.
  • Your NCSSM email address on your profile page. This is deliberate, so every post traces to someone reachable. It is shown one profile at a time and is not available as a list, a directory, or an export.
  • Anything you post: events, announcements, comments, space threads and replies, and the organizations you belong to.
  • Your RSVP to an event, on that event’s attendee list.

Star ratings are shown only as an average and are not attributed to you individually.

Images are public. Profile photos, org logos, banners, and post images are stored in a public bucket, so anyone holding the file’s URL can open it without signing in. Treat an uploaded image as public even when the post around it is not.

A small number of administrator accounts can additionally see moderation reports, bug reports, and error logs, and can suspend, mute, or delete accounts and content.

8. Who else handles your data

The app relies on a few outside services, each handling only what it needs. None of them is an advertising company, and none receives your data for its own marketing.

ServiceWhat it handles
SupabaseThe database, sign-in, and file storage. App data lives here.
GoogleOnly if you choose Google sign-in, to confirm your ncssm.edu identity.
ResendDelivers digest email. Receives your address and the message.
Browser push servicesRoute push notifications to your device. Message contents are encrypted before they leave the app.
Web hostServes the pages and runs the scheduled jobs.

9. How long things are kept

This part is unusual and worth reading. SSMBulletin deletes posts permanently, on a schedule. There is no archive, no trash can, and no grace period.

ContentDeleted
EventsOnce the event ends
Announcements with a deadlineOnce the deadline passes
Announcements with no deadlineSeven days after posting
Error logsAfter 30 days
Everything elseWhen you delete it, or when you delete your account

A cleanup job runs every 15 minutes. When a post goes, everything attached to it goes with it: comments, RSVPs, tags, and star ratings included. None of it is recoverable, so save anything you want to keep before it expires. Your profile, space posts, and organization memberships stay until you remove them or delete your account.

10. Your controls

  • Edit or clear your name, photo, and bio at any time from your profile.
  • Tune notifications by category, and set the digest to daily, weekly, or off. Every digest email also carries a one-click unsubscribe link.
  • Turn off push in the app or in your browser’s site settings.
  • Delete your account yourself, under Profile, then Account settings. Deletion is immediate and takes your profile, posts, comments, space activity, RSVPs, and notifications with it. An organization where you are the only owner is deleted along with your account, so hand ownership to someone else first if it should survive you.
  • Ask for a copy of your data, or ask for something to be corrected or removed, by writing to garner27d@ncssm.edu.

One caution about your calendar feed: its URL contains a secret token, and anyone you give that URL to can see the events you have RSVP’d to. Share it only with your own calendar app. There is currently no way to rotate that token from inside the app, so if it leaks, write to the address above.

11. Security

  • Every query runs as you. The database enforces row-level security, so a mistake in the interface cannot hand you someone else’s data.
  • Traffic is encrypted with HTTPS.
  • Administrative keys stay on the server and never reach the browser.
  • Your calendar and unsubscribe tokens are readable by the server alone, never by other students.

No system is perfectly secure, and this one is maintained by a student rather than a security team. If you find something that looks wrong, please report it to garner27d@ncssm.edu instead of testing it further.