1. Introduction
Welcome to mHostel ("the Application"), a hostel-management platform operated by Mpower AI ("we", "us", or "our"). This Privacy Policy explains how we handle information when you use the Application's student, warden, and administrator portals. By accessing or using the Application, you agree to this Privacy Policy. If you do not agree, please do not use the Application.
2. Application Overview
mHostel is a cloud-based hostel-management application designed for colleges, universities, and hostel operators. The Application provides separate mobile portals for:
- 🎓 Students: To view room and bed allotments, request gate passes, track daily attendance, raise complaints, and view announcements.
- 🛡️ Wardens: To review and approve/reject gate pass requests, resolve complaints, mark and monitor daily attendance, and access block logs.
Each institution operates as an isolated tenant, ensuring institutional data separation.
3. Device Permissions & Mobile Data Access
The Application requires an active internet connection and may request minimal device permissions solely to provide core features:
- 📁 Storage & File Access: Used solely when you choose to select or upload supporting document attachments or image receipts for gate pass requests or complaint reports.
We do not request camera access, and we do not access your storage in the background or for any purpose unrelated to your explicit requests.
4. Information We Collect
We do not independently collect personal data from users. All user accounts and associated data are created and managed by your respective college or hostel administration through the admin portal. The following information is stored as part of your institutional account:
- Account credentials: Email address or roll number, and password (the password is stored in encrypted/hashed form).
- Profile information: Name, gender, date of birth, role (student/warden/administrator), roll or employee number, course, branch, institution affiliation, and profile photograph.
- Guardian & contact information: Parent/guardian names, parent/guardian phone numbers, and residential postal address.
- Hostel & residence data: Building, floor, room and bed allotment, academic year of stay, booking records, gate-pass details (reason, destination, departure/return times, emergency contact), and complaints you raise.
- Attendance & biometric data: Daily attendance records with check-in/check-out times, a facial photograph captured at allotment, and attendance events reported by biometric or face-recognition devices operated by your institution (device enrollment identifier, roll-number mapping, and scan timestamps).
- Fee & payment data: Fee amounts and status, and offline payment details you submit (payment mode, bank name, transaction reference number, and uploaded receipts). The Application does not process card payments and does not store card numbers or banking passwords.
All of the above data is provided and managed by your hostel administration, not collected directly from you by this Application for its own purposes.
5. How We Use Information
The information associated with your account is used solely to:
- Authenticate your identity and provide secure access to the Application;
- Allot rooms and beds and manage hostel occupancy;
- Record and report attendance, including biometric/face-scan attendance operated by your institution;
- Process gate-pass requests and record fee payments;
- Receive and resolve complaints and service requests; and
- Send announcements, absentee/parent alerts, and one-time passcodes for login and password reset.
6. Authentication & Cookies
The Application uses cookie-based authentication to maintain your login session. When you log in, a secure authentication token (JWT) is stored as a browser cookie. This cookie is used solely to keep you logged in during your session, verify your identity for each request to the server, and determine your access level and permissions. Password reset uses a one-time passcode delivered to your registered email and/or phone number.
7. Data Storage & Security
All data is stored securely on our servers using industry-standard practices:
- Data is stored in a secure PostgreSQL database with tenant-level isolation (each institution's data is separated);
- Uploaded files (photographs, receipts, documents) are stored as private objects on secure cloud storage and accessed only through time-limited signed links;
- Passwords are never stored in plain text; they are hashed using secure algorithms;
- All communication between your browser and our servers is encrypted via HTTPS; and
- Access to data is restricted based on user roles and institutional boundaries.
8. Data Sharing
We do not sell, trade, or share your personal data with any third parties for their own use. Your data is accessible only to you (through your own login), your hostel administration, and authorized wardens or staff for hostel-related purposes.
To operate the Application, limited data is processed by trusted service providers acting on our behalf and under confidentiality obligations — namely our cloud database and file-storage providers, and the email and SMS gateways used to deliver alerts and one-time passcodes. Where your institution syncs student identity records from its own student-information system, that data is exchanged under the institution's authority. We may disclose information only if required by law, regulation, or legal process.
9. Children's & Minor's Privacy
The Application is intended for college and university students (typically 17 years and older) and staff. Where a resident is a minor, the account is provisioned by the institution, and processing of resident data is conducted under institutional authority and student/parent consent obtained by the institution as required by law.
10. Your Rights
As a user of this Application, you have the right to:
- View your personal and hostel data through the Application;
- Request your hostel administration to correct any inaccurate data;
- Request removal of your account through your hostel administration;
- Withdraw consent for biometric/face-linked processing; and
- Portability: Request a copy of your data from your hostel administration.
Since user accounts are managed by your institution, requests for data correction or deletion should be directed to your hostel administration.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date. Your continued use of the Application after changes take effect constitutes acceptance of the updated Policy.
Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
For institution-specific data inquiries, please contact your hostel administration directly.