EGO-Works · Mahalai

Privacy and account deletion

Last updated · 27 September 2026

Privacy notice

Operator and contact

Mahalai is operated by EGO-Works. For support, privacy questions, or account and data deletion requests, contact [email protected].

Information Mahalai handles

Account creation uses your email address and authentication data through Supabase Auth. Your profile can include your school, faculty, student or staff status, entry year, nickname, and avatar. Enrollment verification handles submitted documents, their type and review status, and limited extracted text such as a name and student or admission number when found.

Mahalai handles posts, comments, photos, polls and votes, marketplace details, reports and appeals, support requests and attachments, chat messages and photos, friend and group relationships, timetable blocks, GPA course entries, and notification preferences that you create or provide. It stores device push tokens when you enable notifications, plus operational timestamps, moderation decisions, reports, and administrator actions.

Purposes and visibility

These records support sign-in, school membership, profiles, school feeds, chat and notifications, timetable and GPA tools, support, moderation, report handling, and prevention of duplicate enrollment-proof approvals.

Posts are limited to members of the same school and are anonymous by default. Posters can choose to show their nickname and avatar. Comments use anonymous labels, but the service processes account identifiers internally. Anonymous one-to-one chats can be opened from posts and comments; those rooms hide participant identity in the participant-facing view and disable photo sending. Friend chats and group chats are visible to their participants.

Accepted friends can see current-semester class names and locations for timetable blocks marked as classes. Other personal blocks show only day and time. Group timetable comparisons show busy/free time. A timetable image shared in a chat is visible to that chat's participants.

Enrollment documents and support requests are restricted to the submitting user and authorized administrators in the app. Chat messages and attachments are available to conversation participants and authorized report handling. Administrators can review reported or moderated content and enrollment documents.

Providers and external processing

  • Supabase provides authentication, database, storage, realtime updates, and server functions.
  • Google Cloud Vision receives enrollment documents for OCR and post images for OCR and safety review.
  • Google Vertex AI receives post/comment text and related context for moderation, and can receive attached post images and OCR text.
  • OpenAI is used by a legacy moderation route for submitted school-board names that reach its keyword check.
  • Expo Push receives device push tokens and notification payloads, which can contain short chat/comment previews. Android delivery is configured with Firebase Cloud Messaging.
  • Resend can receive administrator email addresses and generic moderation/legal-request alerts. The reviewed email body does not include reported content.

For questions about external processing or a privacy request, contact [email protected].

Retention currently configured

A daily scheduled job is configured to delete reviewed proof files 90 days after review, and clear extracted name/number candidates and per-submission document hashes after that period. The submission metadata row remains. A separate duplicate-prevention claim retains an HMAC identity key and approved-document hash while the account exists.

Orphaned proof files become eligible for cleanup after one day. Support attachments become eligible after their support request is deleted and they have been orphaned for one day. A failed job or missing storage credentials can delay cleanup; these are configured schedules, not verified deletion guarantees.

Original moderation text snapshots, report/moderation snapshots, and post-image OCR text have 90-day purge rules subject to active legal holds. Soft-deleted posts and comments are eligible for deletion after 90 days unless held. Administrator-role audits, moderation events, and legal-request records have no general automatic expiry in the reviewed migrations. These application cleanup schedules do not guarantee simultaneous erasure of service-provider logs or backups.

Account and data deletion

Request in the app

Go to Profile → Settings → Delete account. The current flow asks for your password and calls the server-side account deletion function.

Request by email without installing the app

Contact [email protected] with the subject “Mahalai account and data deletion request”. Specify whether you want your account deleted, specific content containing personal information removed, or both. Provide the account email address and, for a content request, a link or enough detail to locate the content. Do not send your password or enrollment documents.

The EGO-Works operating team receives these requests and verifies account ownership before processing them. For a request about specific content, include a link or other details that allow the team to locate it. You can also ask privacy questions at the same address.

What the current account deletion function does

It removes the authentication account and profile-linked information, including private profile, timetable, group memberships, bookmarks, proof-submission rows, and the student-identity duplicate-prevention claim.

Posts, comments, likes, votes, and chat messages remain with a newly generated account identifier. This does not remove personal information written in text or contained in photos, and does not prove that all retained records are anonymous. One-to-one chat rooms are removed when both former participants no longer have accounts; otherwise messages remain for other participants. Reports and appeals may remain without the deleted reporter's account reference.

Current limitation: account deletion does not automatically remove surviving content, media, or chat history. If retained content includes your personal information, you can request its removal by email. Existing content has no fixed automatic expiry through the account deletion function. We do not describe replacing an account identifier as removal of all personal information from text, photos, or message history.