Privacy Policy
Last updated: 2 August 2026 · session cookie disclosure, legal-disclosure section, third-party links
1. Who we are
Ministry of Exchange is operated by Nikshala AI, the parent company, with Ministry of Exchange operating as a sister product under the Nikshala AI family. Contact for privacy questions: nd@nikshala.com.
2. What data we collect
- Account information: name, email, hashed password. Password is stored hashed via bcrypt; we never see or store your plaintext password.
- Case & visa details: the country, host university, host city, home university, home city, duration, start date, and process stage you enter into Northstar. Optional: persona questionnaire answers (traveler type, primary purpose, budget tier, cohort visibility choice).
- WhatsApp number: collected as a required field at signup so accepted matches can contact you off-platform. Same privacy gating as before — WhatsApp is only revealed to peers with whom you have a mutually-accepted connection. It is never displayed on match cards, cohort feeds, discovery surfaces, or any unauthenticated context.
- Cohort profile: if you opt in to peer matching, your first name / chosen display name, host city, program, and a short bio you write yourself.
- Messages: direct messages and cohort group messages you send through the Platform, stored to enable the messaging feature to function. We do not have standing access to read your private conversations. If you or another user reports a specific conversation for a safety concern (e.g. harassment, spam, impersonation), that specific reported conversation becomes visible to our admin team for review, and only after a report has been filed. We log every admin review of a reported conversation.
- Assembly coordination data: trips, arrivals, roommate posts, and social plans you create or join.
- Telemetry: aggregate page-view events (path, device class, timestamp) to understand which products are being used. We do NOT track individual keystrokes, mouse movement, or session recordings.
- Documents: if you attach a document URL to your case (e.g. a PDF you host elsewhere), we validate the URL is a normal http/https address to a public host and store the URL. We do not fetch or store the file itself.
3. Why we collect it
To provide the service — build your visa timeline, match you with peers, coordinate group plans, and give you an accurate packing list. Telemetry is used only in aggregate to improve which products get built next.
4. What we don’t do
- We do not sell, rent, or trade your personal data to third parties. Ever.
- We do not read your private messages by default — only a specifically reported conversation becomes visible to our admin team, and only after a report is filed.
5. GDPR rights (EU/EEA users)
- Access: you can see all of your data in-product — your case, Cohort profile, messages, and Assembly participation are all readable to you within the app.
- Correction: you can edit your case, profile, and Cohort details at any time from the relevant pages.
- Deletion: you can delete your account from the Dashboard. Deletion is a soft-delete with a 14-day reversible grace period, after which all your personal data is permanently removed by our automated hygiene process. Cohort messages you sent are anonymized so remaining participants can still read the thread coherently, but nothing identifies you.
- Portability: for a portable export of your data in a machine-readable format, email nd@nikshala.com.
6. Data retention
- Active accounts: we retain your data as long as your account is active and for as long as needed to provide the service.
- Deleted accounts: 14-day soft-delete grace period, then permanent removal by our automated hygiene job.
- Telemetry (page_events): aggregate page-view events are automatically pruned after 90 days by the same hygiene job.
- Login attempts: login-attempt records used for brute-force protection are pruned after 30 days.
7. Third-party processors
We use the following third parties to run the service. Each is bound by their own privacy terms:
- MongoDB Atlas — primary data storage (accounts, cases, messages, telemetry).
- Resend — transactional email delivery (welcome, match, request, and Concierge confirmation emails). Resend receives only the recipient email address and the email content we send.
- Frankfurter.app — currency conversion (Northstar visa fees, Cost Estimator). Frankfurter receives no user data - only currency pair queries.
- Emergent Labs — hosting and deployment infrastructure.
8. Third-party links
The Platform links to third-party services for travel search (e.g. flight and bus search providers such as Ryanair, FlixBus, and Omio). We are not responsible for the privacy practices, security, or content of these external sites. Once you leave our Platform via one of these links, their own privacy policy and terms apply, not ours.
9. Legal disclosure
In addition to the uses described above, we may disclose information where required to do so by law, a valid court order, or a legally binding request from a competent authority. We do not disclose data to law enforcement or any third party beyond what is legally required.
10. Cookies and tracking
We use a session cookie/token to keep you logged in between visits. This is required for the Platform to function and cannot be disabled while remaining logged in. Beyond this, our aggregate usage tracking (described above) does not use third-party advertising cookies.
Technical detail for the curious: the login token is an httpOnly, SameSite=Lax cookie. We do not run advertising cookies, cross-site trackers, or third-party analytics scripts like Meta Pixel. The aggregate page-view telemetry we do collect runs entirely on our own backend and never leaves our servers, with one narrow exception: we send anonymous pageview signals to Google Analytics 4 (measurement ID G-4WYTMH56W7) so we can see which products are getting used at a funnel level. GA4 receives page paths and a per-browser client ID; we do not send it your name, email, WhatsApp, messages, or any case detail.
11. Security
- Passwords are stored as bcrypt hashes.
- Authentication uses JWT (HS256) with an httpOnly cookie fallback.
- Login attempts are rate-limited to protect against brute force.
- User-supplied URLs (e.g. document attachments) are validated to block internal IP ranges and non-http(s) schemes.
12. Children
The Platform is for users aged 18 and above. We do not knowingly collect data from children under 18. If you believe a child under 18 has created an account, email us and we will delete it.
13. Changes to this policy
We may update this policy. We will make reasonable efforts to notify active users of material changes.
14. Contact
For any privacy question — access, correction, deletion, portability, or general concern — email nd@nikshala.com or call +91 82639 07201.