Last updated 16 August 2026
This page explains, in plain terms, what cgpa.store stores about you, what other people can see, who else touches your data, and how to get it deleted. It covers the site at cgpa.store and the installable app version of it.
If you are not signed in, nothing you type is sent to us. Your courses, scores and grading scale stay in your own browser's local storage, and clearing your browser data removes them. The same is true of your theme choice and any prompts you have dismissed.
You only create a record on our side when you choose to sign up.
Tied to your account, we hold:
New accounts start on the Ranked setting, which lists you on the public leaderboard. To everyone except you, the leaderboard shows only your name, avatar, department and position. Your actual CGPA is removed on the server before the page is ever sent to another visitor.
Your profile page at /u/your-id is also public. On Ranked it shows your name, avatar, department, rank and the month you joined. If you switch to Public, it additionally shows your CGPA, degree classification, semester breakdown, CGPA trend and your weekly timetable including venues. On Hidden you are off the leaderboard entirely and your profile is private.
When a public profile link is shared, a preview image is generated for it, and services such as WhatsApp, X or Facebook may cache that preview on their own systems. Public profiles are also listed in our sitemap so search engines can find them. You can change your visibility at any time in your profile, but content already cached elsewhere is outside our control.
Friends see each other's name, avatar, department and relative ranking. They do not see each other's CGPA.
Department averages are only shown once at least three students in that department have opted in, so a figure can never describe a single person.
When you create a share link for a timetable, we save a snapshot of it under a short random address. Anyone who has that address can open it without logging in, and the snapshot does not expire on its own. Only share the link with people you want to have it, and email us if you want a snapshot removed.
If you turn on push notifications, your browser gives us a subscription that points at your browser vendor's push service, run by Google, Mozilla, Apple or Microsoft depending on the browser you use. Reminders travel through that service, which means the contents, such as a class name or a deadline title, pass through it. Turning notifications off in your profile deletes the subscription, and we also drop subscriptions that the push service reports as dead.
We use Vercel Web Analytics to count page views. It does not use cookies and does not build a profile of you. It records the page visited, the referring site, and coarse details such as country, browser and device type.
We keep the list of processors short and unglamorous:
We do not sell your data, we do not share it with advertisers, and there is no social login, so no third-party identity provider is involved.
The site administrator can look up accounts by name, email or department and can see an account's email, department, privacy setting, grading scale, saved CGPA and join date. Administrators can also send a notification to subscribed devices. This access exists to run and moderate the service, not to browse it.
Messages you send through the chat button go to the administrator by design, alongside your name and email so they know who they are replying to. Please do not put passwords or anything else sensitive in them.
Account data stays until the account is deleted, and that includes your support conversation, which either you or the administrator can have removed sooner. Password reset links expire after one hour and are deleted after use. Push subscriptions last until you turn notifications off or the push service reports the device as gone. Shared timetable snapshots stay until they are removed on request.
You can edit your name, department, avatar, grading scale and privacy setting at any time from your profile, change your password there, and turn notifications off from the same page.
There is no self-service delete button yet. To have your account and everything attached to it removed, or to ask for a copy of what we hold, email info@kingsworks.space from the address on the account. Deletion removes your user record, scores, timetable, deadlines, friend connections, support messages, push subscriptions and shared timetable snapshots.
Passwords are hashed with bcrypt. Sessions are signed tokens rather than anything readable. Changing or resetting your password signs your other devices out. Password reset links are single use, expire within an hour, and are stored only as a hash, so even a database copy could not be turned into working links.
No service can promise perfect security. Use a password you have not used elsewhere, and tell us if something looks wrong with your account.
The site is built for university students and is not directed at children under 13. We do not knowingly keep data from them. If you believe a child has created an account, email us and we will remove it.
If this policy changes in a way that matters, the date at the top changes with it, and material changes will be flagged in the app. Continuing to use the site after a change means the updated policy applies.
Questions, corrections, deletion requests and complaints all go to info@kingsworks.space. See also the Terms of Service.