Privacy Policy
What Dormed collects about families and student guides, why, and who else touches it.
This document is a placeholder. It has not been written or reviewed by a lawyer and is not a binding agreement. The sections below describe how Dormed intends to operate; the enforceable text will replace them before launch.
version 2026-08-draft
1.What we collect
From everyone: name, email address, and password (stored hashed by our authentication provider, never in readable form), and a phone number if one is entered in account settings.
From student guides additionally: a university email ending in .edu, the university itself, and the profile they write — major, a short written bio, interests, sports, and their availability.
From families at booking: the university, the requested major, interests and sports used to match a guide; the requested tour date and time; and a handwritten signature drawn on screen when agreeing to the liability waiver, stored as an image alongside a record of which version of the waiver was shown.
Payments: card details are entered on Stripe's own checkout page and are never seen or stored by Dormed. Dormed keeps a reference to the Stripe session and whether it was paid.
During and after a tour: messages exchanged in the in-app chat, and the star rating and written comment a family leaves afterwards.
Ordinary technical data — the session that keeps a user signed in, and server error logs.
2.How we use it
To match a family with a guide, to take payment for a tour, to let the two parties message each other and meet, to show a guide their schedule and a family their bookings, and to contact either about a specific tour.
Ratings are used to order guides in matching and to show a public star average on a guide's profile.
Dormed does not sell personal information and does not use it for advertising.
4.Service providers who process data for us
Stripe processes payments and holds the card details Dormed never receives.
Supabase hosts the database, the authentication system, and the server functions this app runs on.
Both act as processors on Dormed's behalf and under their own terms.
5.How long we keep it
Booking records, signatures and payment references are kept as the record of a transaction and of an agreement that was signed. Messages, profiles and ratings are kept while an account is open.
No retention period has been set for any category of data.
6.Children and minors
This product exists to bring a high-school student, usually under 18, onto a university campus to meet an adult stranger. That is the core of the service, not an edge case.
Accounts are held by the booking adult, not by the visiting student. The adult accompanies the student throughout the tour and remains in sight of them.
What Dormed records about the visiting student today is limited — the tour is booked around a major, interests and sports rather than a named child profile — but the tour itself brings that child into contact with an adult guide.
7.Your rights and choices
How to see what Dormed holds about you, correct it, or ask for it to be deleted, and what happens to a booking record or a signed waiver when an account is deleted.
Guides and families can already edit their own profile details in the app; there is no self-service export or account deletion yet.
8.How we protect it
Data is held in a database with row-level access rules, so an account reaches its own records and not other people's. Traffic is encrypted in transit and payments never touch Dormed's servers.
No system is perfectly secure, and this section should say what Dormed does and does not promise.
9.Contact and changes to this policy
Who to contact with a privacy question or request, and how Dormed will notify users when this policy changes.
Email support@dormed.app. In an emergency during a tour, call campus security or 911 first.