Privacy Policy

Last updated: 19 April 2026

1. Who we are

MyUniReviews ("we", "us", "our") is an independent student-run platform for rating and reviewing university professors in Australia. This policy explains how we handle your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. What information we collect

  • Your university email address
  • Username and password (stored as a secure hash)
  • Your institution selection
  • Reviews and ratings you submit
  • Votes and reports you make
  • Your IP address and last login timestamp (for security)

We only collect information that is reasonably necessary to operate the platform (APP 3).

3. How we use your information

  • To create and manage your account
  • To verify that you are a current university student
  • To display your reviews (anonymously if you choose)
  • To send you a one-time email verification link
  • To moderate content and enforce our community guidelines
  • To investigate reports of policy violations

We will not use your information for any secondary purpose without your consent (APP 6).

4. Disclosure of your information

We do not sell, rent, or share your personal information with third parties except:

  • Resend — our email delivery provider, used solely to send verification emails. Their servers may be located outside Australia (APP 8 disclosure).
  • Where required by Australian law or a court order.

5. Data security

We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access (APP 11). Passwords are hashed using bcrypt and are never stored in plain text. All API communication uses HTTPS in production.

6. Your rights

Under the Privacy Act 1988, you have the right to:

  • Access the personal information we hold about you (APP 12)
  • Correct inaccurate information (APP 13)
  • Delete your account — available from your dashboard at any time
  • Anonymity — you may submit reviews anonymously (APP 2)

When you delete your account, your personal details are permanently removed. Your reviews are anonymised and retained to preserve the integrity of the platform.

7. Data retention

We retain your personal information for as long as your account is active. If you delete your account, personal data is removed immediately. Anonymised review content may be retained indefinitely.

8. Notifiable data breaches

In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme.

9. Complaints

If you believe we have breached the Australian Privacy Principles, you may contact us first to resolve the matter. If unsatisfied, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10. Changes to this policy

We may update this policy from time to time. Continued use of the platform after changes constitutes acceptance of the updated policy.