R
← Back to supervisors

RUNIPS / PRIVACY

Privacy Notice

This notice follows the transparency principles of the EU General Data Protection Regulation (GDPR). It explains what RunIPS processes, why, where and for how long, and how you can exercise your data rights. Public anonymity does not mean that the service processes no internal data or that nobody could ever infer a contributor’s identity.

Effective and last updated: 26 August 2026

1. Controller and scope

The controller is the RunIPS project operator, an independent, non-commercial student project. RunIPS is not affiliated with, endorsed by, or speaking for Waseda University. Contact the controller through the in-site Contact page; privacy, access, correction, export, objection, restriction, and erasure requests can all be submitted there.

RunIPS uses the core GDPR requirements as its data-protection baseline for every user and applies the mandatory requirements where the GDPR legally governs a user or processing activity. This notice is not a claim of government certification or absolute compliance status.

2. Data we process

  • Account and authentication data: a random internal ID, identities, sessions, and sign-in times for anonymous accounts. If Google sign-in is enabled later and you actively choose it, this also includes basic authentication details such as email address and display name.
  • Contribution data: supervisor ratings, research pressure, six supervision ratings, choose-again answer, tags, written comment, student level, relationship, primary communication language, and posting and editing times. You must actively choose each context field, including the available “Not disclosed” choice; a written comment may contain 0–2,000 characters.
  • Community contribution data: topic type, title, body, category, tags, replies, quotation links, status, accepted reply, duplicate-topic link, the author’s internal account link, and posting, editing, and last-activity times.
  • Interaction and contact data: review votes, topic subscriptions, in-site notifications, content reports, Contact submissions, optional reply details, handling status, and relevant timestamps.
  • Operational and security data: IP address, request path without the query string, browser or device information, request time, errors, and security events. Language preference and sign-in sessions are also stored in your browser.
  • Travel Guide query data: when you actively search, RunIPS processes the origin airport, FUK or KKJ destination, departure date, fixed economy-cabin setting, and query time. Passport country, ticket arrangement, and baggage plan are used only in the browser to generate the transfer screen; they are not sent to the flight-search interface or linked to an account.
  • RunIPS does not ask for special-category data. Do not include your own or another person’s health, political, religious, biometric, sexual-life, exact-movement, student-number, contact, unpublished-research, private-chat, or other private or sensitive information in a review, topic, or reply.

3. Purposes and GDPR lawful bases

  • Performance of our service agreement (Article 6(1)(b)): creating and maintaining the account you request; storing, publishing, and letting you manage your reviews, Community topics, and replies; and automatically following a topic and generating in-site notifications when you create that topic or post a reply. You can unfollow at any time on the topic page. We cannot provide these functions without an account and the necessary contribution data. Specific review-context values and a written review are not required.
  • Legitimate interests (Article 6(1)(f)): moderating and managing public content, linking duplicate topics, preventing duplicate submissions and abuse, investigating security incidents, maintaining backups, diagnosing faults, handling feedback, and improving a non-commercial student guide. We consider necessity and the rights of contributors, repliers, reviewed people, and others affected before relying on these interests; you may object through Contact.
  • Legal obligation (Article 6(1)(c)): retaining or disclosing the minimum necessary records when applicable law requires it, responding to valid legal process, and meeting data-protection or security duties.
  • Steps at your request (Article 6(1)(b)) or legitimate interests (Article 6(1)(f)): responding to a Contact request you choose to make. Optional reply details are used only for that request.
  • Performance of the travel search you request (Article 6(1)(b)): submitting the minimum route, date, and cabin criteria to the flight-search service and returning same-day flights, connection patterns, and indicative prices. RunIPS cannot provide live search without these query fields; passport, ticket, and baggage answers are not necessary for that search.
  • If RunIPS later considers processing records from a WeChat group or another source that did not provide the data directly to us, we will determine and document the applicable lawful basis before processing begins, assess necessity and rights, and provide the transparency information required by GDPR Article 14 where applicable. This notice does not mean that an import feature is already enabled.

4. Public display, anonymity limits, and automation

  • A public review may show ratings, the choose-again answer, tags, posting time, context you actively disclose, and a voluntary comment. The public view omits your name, email address, account ID, and internal user ID.
  • Community topic titles, bodies, categories, tags, statuses, replies, and timestamps are public worldwide and may be read, linked to, or copied. The public view omits internal account IDs. Subscriptions and in-site notifications are visible only to the relevant account and authorised operators.
  • A small number of authorised RunIPS operators may access internal records for operations, backups, security investigations, moderation, reports, or rights requests. Contact submissions go only to a private inbox.
  • A distinctive event, date, research topic, or writing style may still let someone familiar with the situation infer a contributor or third party. Omit identifying detail and do not use Community as a private communication channel. No online service can promise absolute security or impossible re-identification.
  • If a group-chat knowledge project is introduced later, raw records may be held only in restricted private staging for a documented short human-review period. Publication will be limited to anonymised, rewritten Q&A that has passed human review, never raw chat, sender identifiers, or unrelated personal information. If a rewritten item still presents a re-identification risk, we will continue to treat it as personal data.
  • RunIPS does not sell personal data, use advertising profiles or third-party behavioural analytics, or make automated decisions with legal or similarly significant effects.

5. Recipients, location, and international transfers

The application, PostgreSQL database, and authentication service are self-hosted on Tencent Cloud International infrastructure in Singapore. The relevant infrastructure operator may process data as a processor only as needed for computing, networking, security, and support. Anonymous supervisor reviews and Community topics and replies are made available to the public worldwide.

Live Travel Guide searches use SerpApi, LLC in the United States. The RunIPS backend sends only origin, FUK or KKJ, date, economy setting, and RunIPS’s own API credential; it does not forward the browser IP address, account ID, passport, ticket, or baggage answers. SerpApi queries Google Flights on RunIPS’s behalf and states that search parameters and results may remain retrievable through its Search Archive for up to 31 days. After you open a Google Flights or ITA Matrix link, your browser contacts that third party directly under its own terms and privacy policy.

Singapore is outside the European Economic Area. For transfers governed by GDPR Chapter V, Tencent Cloud International’s current Data Processing and Security Agreement incorporates, where applicable, the European Commission’s 2021/914 controller-to-processor Standard Contractual Clauses (SCCs, Module 2), with security measures and subprocessor arrangements. The agreement is linked in the official references below. If another processor is added, we will establish an applicable transfer mechanism first and update this notice.

The outbound flight query is designed to be data-minimised, contain no direct identifier, and remain unlinked to a RunIPS account. If a query nevertheless constitutes personal data in its particular context and GDPR Chapter V applies, RunIPS will stop that personal-data transfer unless an applicable transfer safeguard is in place; a provider’s general security or compliance claim does not replace a required legal mechanism.

6. Retention and account erasure

  • Accounts, supervisor reviews, Community topics and replies, votes, and reports remain until you delete the account, separately delete content, or they are no longer needed to provide the service, except for the minimum required by a valid legal obligation. Creating a topic or posting a reply automatically follows that topic. The follow record remains until you unfollow on the topic page, the topic is deleted, or you delete the account; a notification remains only while needed to provide and manage that feature.
  • Contact submissions remain until the request and reasonable follow-up are complete. We review necessity periodically and delete or de-identify submissions that are no longer needed.
  • If a group-chat knowledge project is introduced later, raw files and unpublished candidates will remain in private staging only for a documented short period needed for human review. Raw files will be deleted when that batch is completed or abandoned. The actual review period and processing detail will be published before processing begins.
  • Application access logs are retained for no more than 14 days. Minimum records isolated for an active security investigation or legal duty remain only until that purpose is complete.
  • Travel Guide results are cached in server memory for no more than 10 minutes, are not written to the RunIPS database, and disappear when the service restarts. A cache key contains only airports, date, currency, and cabin—not an IP address, account, or passport. SerpApi states that a completed search may remain retrievable through its Search Archive for up to 31 days; its own policy governs that retention.
  • The database is backed up daily with a rolling retention of no more than 14 days. Live deletion is immediate. Residual backup copies expire through rotation and are not used to restore a deleted account or republish content.
  • A signed-in user can submit the self-service form on the Account and data page. Erasure removes the authentication account, identities, sessions, reviews, review votes, Community subscriptions, notifications and reports, still-linked Contact submissions, and authentication audit entries identifiable by account ID. For your Community topics and replies, it removes the author link and user-supplied title, body, and other content. If a record must remain to preserve another person’s reply structure, it becomes a “deleted” placeholder with no user content, author identity, or internal account ID. Topic or reply record numbers and timestamps may remain where needed to preserve thread references.

7. Your GDPR rights

  • Where the relevant conditions apply, you may request access and a copy, rectification, erasure, restriction, and portability. You may also object to processing based on legitimate interests.
  • Delete the current account directly on the Account and data page or use Contact for another request. To protect others, we may reasonably verify the account or record ownership. Verification may be limited after an anonymous session is lost.
  • If you believe that a Q&A item derived from a future group-chat project concerns you, is inaccurate, or can still identify you, use Contact to request source information, correction, or erasure. We will handle the request under applicable law and reasonably available verification without requiring you to identify yourself on a public page.
  • Where GDPR applies, we ordinarily respond to a valid request within one month. A lawful extension may apply to complex or numerous requests, in which case we will explain why.
  • You may complain to the data-protection authority where you habitually live or work, or where the alleged infringement occurred. Making a request or complaint will not reduce your service rights.

8. Security, changes, and contact

We use HTTPS, least privilege, row-level database permissions, a private feedback inbox, controlled backups, and log rotation to reduce risk. If recipients, purposes, or other practices materially change, we will update this page and its effective date before the change takes effect. Use the Contact page for any privacy or data question.