Privacy
What this site and the club's sign-up pages collect, what the club does with it, and how to have it removed.
Last updated 21 September 2026
What this covers
This policy covers aialignmentillinois.org, the members' dashboard at dashboard.aialignmentillinois.org, and the pages the site links to for the mailing list, event RSVPs, event tickets and live polls. Student officers of AI Alignment @ Illinois run all of them.
What is collected
- Visiting the site. Vercel, the site's host, counts page views: the page, the site that sent you, your country and city, and your browser, operating system and device type. It uses no cookies, and tells visits apart with a hash of the request that is thrown away after 24 hours.
- Scanning a club QR code. The time, which code, your browser, and the rough location your network address maps to (country, region, city, postal code and network name). The address itself is never stored.
- Joining the mailing list. Your email, the time, the page or printed code that brought you, and the country, city and browser of the request. The sign-up page may also ask your browser for your location. If you allow it, that location is saved against the page or code you came from, with no email attached.
- RSVPing to an event. Your name, your email, and how many friends you might bring, with the same time, country, city and browser details. An RSVP also adds you to the mailing list. Each RSVP gets a ticket code, and checking in at the event records that code or your name, with the time.
- Voting in a live poll. Your answer, and a random ID kept in a cookie so each phone votes once.
- Applying. Applications run on Google Forms, and officers read them to make decisions and place people into tracks. Your name, email, year, major, LinkedIn, personal site, Discord username, which form you used, when you applied, and up to 420 characters of your written answers are copied into the member database, so a dashboard account made with the same address starts filled in.
- Making a dashboard account. Your name, your Illinois email, and your password, stored only as a salted scrypt hash. Then whatever you add to your profile: year, major, tracks, a short bio, LinkedIn, personal site, Discord username, a Cal.com or Calendly link, and a photo your browser shrinks to 480 pixels before it uploads. If an officer emails you a link to set your password, the club keeps only a hash of it, and it stops working once used or after seven days.
- Meeting an officer one on one. Officers keep notes on the dashboard: the date, who you met, what you said you are looking for, what they suggest you do next, and anything else worth keeping. If the call was recorded with everyone's agreement, its transcript can be kept with the notes. A note an officer deletes can be brought back for 30 days, and is erased after that the next time an officer opens the notes.
- Messaging another member on the dashboard. Messages are end-to-end encrypted: your browser seals each one before it is sent, and only you and the member you wrote to can open it. The club stores the sealed text, who wrote to whom, when each message was sent and read, and, for each browser you use the dashboard on, a public key with when that browser was first and last seen. The key that opens your messages never leaves your browser.
- Signing in. Each attempt records the email tried, your network address and a random browser ID, so repeated guessing slows down. A successful sign-in clears those records.
Who sees your profile
- The whole dashboard is for signed-in members.
- A member's profile shows only to signed-in members, and only while Open to one on ones is on.
- Your email never shows to other members. Your Discord username shows only to signed-in members.
- A profile photo loads only for signed-in members who can see that profile.
- Notes and transcripts from one on ones show only to officers, never to other members. Officers see the name and join date of every account so they can keep them, and nothing more of a profile that is hidden.
- A message can be read only by the two members in the conversation. Officers cannot read messages, including from the database. When you sign in on a new browser, your other browsers pass it your conversations, still encrypted.
How it is used
To run the club: sending the mailing list and event tickets, checking people in, reviewing applications and placing people into tracks, running the members' dashboard, keeping accounts safe, and learning which flyers and pages bring people in.
The club does not sell or rent any of it, and uses none of it for advertising.
Services that handle it
Officers see what they need to run the club. These services store or process it on the club's behalf:
- Vercel hosts the site and counts page views.
- Turso stores dashboard accounts, profiles, encrypted messages, officers' one on one notes and imported application answers.
- Cloudflare runs the mailing list, RSVP, ticket and poll pages, and stores what they collect.
- Resend sends event ticket emails, and some go out through an officer's Illinois mailbox on Microsoft.
- Google runs the application forms and the club calendar.
- Cal.com and Calendly run one on one bookings. What you enter there goes to that service and to the person you book, and the club's site receives none of it.
- Substack runs the newsletter for anyone who subscribes there.
Outside these services, the club shares personal information only when the law requires it or someone's safety depends on it.
How long it is kept
A sign-in lasts 30 days. Everything else stays until you ask for it to be removed, or until the club no longer needs it.
Your choices
- Edit or clear your profile details and photo at any time from Profile in the dashboard.
- Turn off Open to one on ones to hide your profile from other members.
- Delete your account and everything on it from Settings in the dashboard. That includes every message you sent or received, and the officers' notes from your one on ones.
- To change your name or email, leave the mailing list, or get a copy of what the club holds about you, write to mithils3@illinois.edu.
Security
Passwords are stored as salted scrypt hashes, the sign-in cookie cannot be read by scripts on the page, and every page loads over HTTPS. Messages are end-to-end encrypted, so a copy of the database does not reveal what they say. Use a password here that you use nowhere else.
Children
The site is meant for university students and is not directed at children under 13.
Changes
When this policy changes, the date at the top of this page changes with it.
Contact
Privacy questions and removal requests go to Mithil Salunkhe, Operations Lead, at mithils3@illinois.edu.