Legal

Privacy Policy

Last updated 3 August 2026 · Effective 3 August 2026

1. Who we are

walkdeeznust (the "app") is built and operated by Ahmad Hassan, an individual developer based in Islamabad, Pakistan ("we", "us", "our"). We are the data controller for the personal information described in this policy.

This policy explains what the app collects, why, who it goes to, and what control you have over it. It covers the walkdeeznust mobile app and this website. It is written to be read, not to be survived — if any part of it is unclear, email us and we will explain it and fix the wording.

2. Who can use the app

walkdeeznust is a closed campus app. You sign in with a Google account, and the app only admits accounts whose email domain belongs to NUST. If your email is on any other domain, sign-in stops there and no profile is created for you.

This means everyone you can see in the app, and everyone who can see you, holds a verified NUST email address.

3. The waitlist

The form on our home page is part of this website, not the app. Joining the waitlist does not create an account, does not put you on the map, and does not sign you into anything.

  • What we take. Your university email address, the department it belongs to, and the country the request came from. The department is worked out from the domain — an address ending seecs.edu.pk means SEECS — and you can correct it before you send. We do not store your IP address.
  • What it is for. Counting how many people are waiting in each department, so we know which one to open next, and writing to you once, on the day yours opens. That is the entire use.
  • What we will not do. No newsletter, no reminders, no "we miss you". We do not share the list, sell it, or load it into a marketing tool. Joining is not consent to anything else.
  • Where it sits. In a database attached to this website, hosted by Cloudflare and separate from the app's own database. If you later create an account, the two are not linked.
  • Getting off it. Email us and we will delete your entry — see your rights. We delete the whole list once every department is open and it has no purpose left.

Our legal basis for holding this is your consent, given by sending the form, and you can withdraw it at any time by asking us to remove you.

4. What we collect

We collect what the app needs to put two people on the same footpath, and nothing beyond it. There is no analytics SDK, no crash-reporting service, and no advertising code in the app.

CategoryWhat exactlyWhy
Google account details Your name, your email address, and your Google profile photo, passed to us by Google when you sign in. To create your account, confirm you are a NUST student, and show other walkers who you are.
Profile Display name, department, a short bio (up to 160 characters), the topics you pick, and your conversation style. To match you with someone who wants to talk about the same thing.
Location Your device's precise coordinates, while you are marked available or on a walk. See section 5. To place you on the campus map and let you meet.
Invites and walks Who you invited or were invited by, the topic, the optional note (up to 150 characters), the meeting point you agree on, and the walk's start and end times. To run the invite and rendezvous, and to show you your own history.
Walk chat Messages sent inside a walk session. These are end-to-end encrypted. See section 6. To let two people find each other before the walk starts.
Ratings Your scores on four dimensions after a walk, an optional highlight, an optional tag, and an optional private comment. The private comment is never shown to the person you rated. To compute a walker score and tier, and to surface safety problems.
Safety signals Any walk flagged with "Felt unsafe" after a rating. To investigate what went wrong and act on it.
Support correspondence Emails you send us and the address you send them from. To answer you and keep a record of the issue.

5. Location data

Location is the most sensitive thing the app handles, so it gets its own section and plain sentences.

  • Only while the app is open. The app requests "while using the app" location permission and never requests background location. When the app is not in the foreground, your device stops giving it location, and the app stops sending any.
  • Only while you say you're free. Location is sent while you are marked available, and during an active walk. Turn availability off and the app stops sending location and erases the coordinates it was holding for you.
  • Other people see your actual position on a map. This is the point of the app and we will not soften it: while you are marked available, other signed-in NUST students see a pin at your real location on the campus map, and during a walk your walking partner sees you move. If you do not want to be visible, do not mark yourself available.
  • You go stale on your own. If your position has not been updated for five minutes, you disappear from everyone else's map automatically — closing the app or losing signal is enough.
  • We do not keep a location history. Your position is a single field that is overwritten as you move and emptied when you go offline. There is no trail, no archive, and nothing to export. The only coordinates that persist are the meeting point you and your partner agreed on, stored with that walk.

6. Walk chat

Chat exists only inside a walk session — there is no inbox and no way to message someone you are not currently walking with.

  • End-to-end encrypted. Each device generates its own key pair for the session and publishes only the public half. Both phones independently derive the same AES-256-GCM key. The private key never leaves your device and the derived key never touches the network, so we cannot read your messages and neither can our database provider.
  • Destroyed with the walk. When the walk session ends, the messages are wiped by the database itself. Nothing is archived.
  • Because we cannot read chat, we cannot investigate a report based on its contents. If something is said in chat that worries you, take a screenshot before the walk ends and email it to us.

7. What we never collect

  • Gender. The app has no gender field, no gender filter and no gender inference. It is not collected, stored or displayed anywhere, by design.
  • Background location. Never requested, never collected.
  • Contacts, calendar, microphone, camera roll beyond a photo you deliberately choose.
  • Advertising identifiers. There is no advertising or tracking code in the app, and we do not track you across other apps or websites.
  • Payment details. The app is free and has no payments.
  • Health, biometric or financial data.
  • Third-party analytics or crash reporting. No SDK of that kind is in the app. This website — not the app — counts visitors with a cookieless tool that cannot identify you; see section 10.

We do not sell or rent personal information, and we never have.

8. Why we use your information

  • To create and secure your account and confirm you are a NUST student.
  • To show you people nearby who are also free, and show you to them.
  • To run invites, agree a meeting point, and route you to it.
  • To compute your walker score and tier from ratings.
  • To operate safety features — unsafe flags, and investigating them.
  • To answer you when you contact support.
  • To comply with law and enforce our Terms of Service.

We do not build advertising profiles and we do not make decisions with legal or similarly significant effects about you by automated means. Your walker score affects nothing outside the app.

Where the UK GDPR or EU GDPR applies, we rely on:

  • Performance of a contract — to provide the app you asked for: matching, invites, walks and ratings.
  • Consent — for device location access, which you grant at the OS level and can revoke at any time.
  • Legitimate interests — to keep the service secure and prevent abuse, balanced against your rights.
  • Legal obligation — where we must retain or disclose something by law.

10. Who we share it with

Personal information goes to these places and nowhere else:

  • Other NUST students using the app — your display name, photo, department, bio, topics, conversation style, walker tier, and your position on the map while you are available.
  • Your walking partner — additionally your live position during the walk, the meeting point, and your chat messages, which only the two devices can decrypt.

And to these service providers, who process data on our behalf:

ProviderWhat it doesWhat it sees
Supabase Database, authentication and realtime sync. Everything in section 3 except chat contents, which are encrypted before they reach it.
Google Sign-in. That you signed into walkdeeznust, and it supplies your name, email and photo.
Mapbox Map tiles, meeting-point search and walking directions. Your device's IP address and the map area or search term requested. Mapbox is not told who you are.
OpenStreetMap contributors The underlying map data. Nothing about you — this is data we consume, not a service we send you to.
Cloudflare Hosting for this website, and the waitlist database. Standard web request logs, and the waitlist entries described in section 3. The app does not route through it.
Umami Visitor counts for this website only. Not present in the app. Page visited, referrer, and general device and country, derived from your IP address and then discarded. Umami sets no cookies, does not identify you, and does not follow you to other sites.

We may also disclose information:

  • For legal reasons — where required by law or court order, or to protect the rights, safety or property of our users or the public.
  • In a business transfer — if the app is ever transferred to another operator, and we will tell you before your information becomes subject to a different policy.

11. Store privacy labels

This is how the above maps onto the Apple App Store's privacy labels and Google Play's Data safety form, published here so the two always agree with each other and with the app.

Data typeApple labelPlay Data safety
Precise location Collected · linked to you · App Functionality · not used for tracking Collected and shared with other users · required · in transit encryption · deletable
Name, email Collected · linked to you · App Functionality Collected · required · in transit encryption · deletable
Photo Collected · linked to you · App Functionality Collected · optional · in transit encryption · deletable
User content — bio, notes, topics, ratings Collected · linked to you · App Functionality Collected · optional · in transit encryption · deletable
In-app messages Collected · linked to you · App Functionality Collected · end-to-end encrypted · deleted automatically when the walk ends
User ID Collected · linked to you · App Functionality Collected · required · in transit encryption · deletable
Diagnostics, usage, advertising data Not collected Not collected

Nothing in the app is used for tracking as Apple defines it, and no data is shared with third parties for advertising or analytics under either store's definitions.

12. How long we keep it

  • Account and profile — for as long as your account is open.
  • Current location — held as a single value that is overwritten as you move and cleared when you stop being available. Not archived.
  • Walks, invites and meeting points — for as long as your account is open, because they are your history.
  • Chat messages — deleted when the walk session ends.
  • Ratings — for as long as your account is open, since your walker score is computed from them.
  • Safety flags24 months after the account is deleted, so repeat behaviour can be identified.
  • Waitlist entries — until your department opens and we have written to you, or until you ask us to remove you, whichever is sooner. The list is deleted outright once every department is open.
  • Support email24 months.

When you delete your account we delete or anonymise your personal information within 30 days, except where we must keep something to meet a legal obligation or to resolve an outstanding safety report.

13. Your rights

Depending on where you live, you may have the right to:

  • access a copy of the personal information we hold about you;
  • correct information that is inaccurate or incomplete;
  • delete your personal information;
  • object to or restrict certain processing;
  • withdraw consent at any time, including location permission;
  • receive your data in a portable, machine-readable format;
  • complain to a data protection authority.

To exercise any of these, email hello@walkdeeznust.com from the address on your account. We will respond within the period applicable law requires — generally one month. If you are in the UK you may complain to the Information Commissioner's Office; in the EU, to your local supervisory authority.

California residents: we do not sell or share personal information as the CCPA/CPRA define those terms, and we will not discriminate against you for exercising your rights.

14. Deleting your account

You can delete your account and its data at any time. Full instructions are on the account deletion page, which also lists exactly what is removed and what is briefly retained.

15. Security

Traffic between the app and our database is encrypted in transit. Access to rows in the database is enforced per-user by row-level security policies, not just by app code. Walk chat is end-to-end encrypted, so neither we nor our database provider can read it. Access to production data is limited to the developer named in section 1.

No system is perfectly secure and we will not claim otherwise. If a breach affects your rights we will notify you and the relevant regulator as the law requires.

16. Age requirement

You must be at least 17 years old to use walkdeeznust. The app arranges in-person meetings between people who have not met, and it is not designed or intended for children. We do not knowingly collect personal information from anyone under 17. If you believe someone under 17 has an account, email hello@walkdeeznust.com and we will remove it.

17. International transfers

The app's database and authentication are hosted by Supabase in the region configured for our project, and this website is served by Cloudflare's global network. If you use the app from the UK or EEA, your information may be processed outside it. We rely on appropriate safeguards such as Standard Contractual Clauses where that is the case.

18. Changes to this policy

We will update this policy as the app changes, revise the "last updated" date above, and for significant changes tell you in the app or by email before they take effect.

19. Contact us

  • Email: hello@walkdeeznust.com
  • Operator: Ahmad Hassan, individual developer
  • Location: Islamabad, Pakistan · postal address on request, and as filed in our store developer accounts