Privacy note

This tool is student-run — not an official INSEAD system. Last updated July 2026.

Who controls this data

Rahul Gupta, an incoming INSEAD MBA student (Jan 2027 intake), operates this tool independently. Questions or data requests: use the manage link in a Connector email or email rahul.gupta27D@insead.edu.

What's collected and why

Name, personal email (optional), INSEAD email, WhatsApp number (optional), country, timezone, one-line bio, optional detailed profile description, optional LinkedIn profile URL and sharing choice, match frequency, matching-mode preference, chosen interest tags, optional custom interest text, and private product feedback are collected to verify membership, compute introductions, coordinate meetings, protect the service, and send transactional email. The service also records limited short-lived keyed rate-limit and signup-diagnostic buckets, delivery events, meeting choices and outcomes, and operational audit events. Custom interests are stored separately and are not used for match scoring until mapped into the shared taxonomy.

Legal basis

Your explicit consent, given at signup. You can withdraw ordinary participation by deleting your data.

Who sees your data

A current batchmate you're matched with sees your name, bio, optional detailed profile description, shared-interest context, and verified INSEAD email. Your LinkedIn profile link is shown to current matches only when you explicitly choose to share it. Your WhatsApp number is disclosed only if you explicitly share it for that match. Your personal email is not disclosed to your counterpart. The operator and the processors below handle only the data needed to run the Connector.

Up to three conversation starters may be generated deterministically from profile information you supplied directly to the Connector. They do not affect matching and the Connector does not scrape, download, or infer content from your LinkedIn profile.

Your verified INSEAD inbox remains the primary notification channel. If you separately verify a personal email and opt in, the Connector may send an additional copy of match and meeting notifications there. You can disable that optional channel without affecting matching or INSEAD delivery. A bounce, complaint, or provider suppression disables the personal channel until you verify it again.

Automated matching

Matching uses the mode you select. Fully random ignores interests; Balanced and Interest-first use normalized interest relevance. Timezone is not used to rank people. You can change your mode or pause participation.

Where it's processed

No data is sold or used for advertising. Providers may process data across borders under their contractual safeguards. This limited 27D cohort test has not yet received independent legal review; qualified privacy review is planned before the service expands beyond this test.

Microsoft calendar delivery confirms that an invitation was created; it does not prove that either person attended. Each participant separately records Happened, Rescheduled, Cancelled, or No-show from the dashboard after the meeting. Those self-reports, not passive Microsoft attendance monitoring, are what the owner cockpit displays.

Retention and deletion

Signup diagnostics contain a one-way keyed email bucket, a processing stage, timestamps, and—when available—a profile reference. They do not store confirmation links, tokens, message bodies, raw provider payloads, or network addresses, and are deleted after seven days.

Availability grids and bridge options are private scheduling inputs, not profile fields shown to your match. They are deleted when an open window expires, seven days after a terminal cycle, or after a stalled window becomes stale. Expired Microsoft authorization state is also removed. A monitored daily purge records aggregate deletion counts only.

Ordinary data is kept until you delete it or the active program ends. Permanent deletion removes your identity row and ordinary profile-linked contact, confirmation, recovery, matching, delivery, scheduling, meeting, provider-token, and identifiable admin-history data from the live application database in one transaction. Shared match and meeting records involving you are removed. No email hash, deletion tombstone, or rejoin block remains. You can sign up later as a completely new member.

The Connector cannot recall copies already delivered to an inbox. Resend retains email data for 30 days under its documented standard retention, and encrypted provider backups may persist until their normal backup-expiry cycle; backup copies are not available as live profiles.

Microsoft connection tokens are encrypted and stored only after optional consent. You may disconnect after any future event organized through that connection and any unresolved provider operation has been completed or cancelled; this guard prevents the Connector from losing the ability to cancel an event it created. Disconnecting then deletes local access and prevents future use. You can also remove the Connector from your Microsoft account's app-consent page. Meetings already delivered to calendars or retained by Microsoft are outside the live Connector database.

A confidential safety report is deliberately separated from ordinary profile data. Its narrative and identity snapshot are encrypted, visible only through the MFA-protected and audited owner cockpit, and retained for no more than 12 months after case closure unless a documented legal or safety hold applies. Deleting an ordinary profile does not silently delete an open safety case. A report alone never automatically suspends another member.

Written confidential safety reports are available. File attachments remain disabled until the private malware scanner and its operational response process have passed the release gate.

Legal review required before expansion: processor, backup, international-transfer, safety-retention, lawful-basis, and data-subject-right wording must be reviewed by a qualified privacy professional before the service expands beyond this limited cohort test.

Your dashboard

Dashboard links in Connector emails are valid for seven days. One-time recovery links are valid for 30 minutes. Anyone to whom you forward an active link may be able to use it, so treat Connector emails as private. A newly redeemed recovery link invalidates older dashboard links for the profile.

Your rights

Aggregate stats

The public stats page shows counts only — never names, contact details, or safety-case content.