Privacy Policy & Data Security

Last updated: September 2026 • PESU OAuth2 Identity Service

1. Zero-Exposure Credential Policy

When authenticating through Sign in with PESU in standard Identity mode, your password is transmitted over TLS to authenticate directly against the university mobile service. Once authentication succeeds, your password is immediately purged from memory and is never written to disk or database logs.

2. Delegated Credential Vault

Certain applications require delegated access to execute campus services on your behalf. These applications must explicitly declare delegated capabilities and require your affirmative consent on the authorization screen. In this mode, your credentials are encrypted using AES-256-GCM envelope encryption with unique per-row Data Encryption Keys (DEKs) wrapped by a master key.

3. Data Minimization & Scopes

We adhere strictly to data minimization principles. Applications only receive the specific claims you grant:

  • openid: Opaque user identifier (usr_...).
  • profile: Name, PRN, SRN, program, branch, semester, section, and campus.
  • email: Official university email address (only if granted).
  • phone: Contact phone number (only if granted).
4. User Control & Consent Revocation

You retain absolute sovereignty over your permissions. You can inspect all active applications in your Settings and instantly revoke any authorization. You can also delete your entire vault document at any moment.