Privacy Policy
How Denkard collects, uses, and protects your information.
Last updated October 2, 2026
Denkard is a University of Toronto life-sciences club running a resource-sharing site for our members. This policy explains what account and activity information we collect when you use denkard.ca, why we collect it, who inside the club can see it, and the choices you have.
1. Information We Collect
- Account info: the email address you sign in with (any address, confirmed by an emailed link), your username, and, if you set one, your password, stored only as a salted one-way hash we can't reverse.
- UofT email: if you verify one, your @utoronto.ca or @mail.utoronto.ca address and when you verified it. This is what unlocks study resources and full event details.
- Google account info: if you sign in with Google: your email address, name, profile photo, and Google's internal account identifier ("sub"), provided by Google Sign-In.
- Passkeys and two-step verification: if you add a passkey, its public key, a name for it, and when it was added and last used. Passkeys never send us your fingerprint, face, or device PIN: those stay on your device. If you turn on two-step verification, we store that it's on, plus one-way hashes of your backup codes and of each emailed sign-in code.
- Session data: your IP address, browser/device (user-agent string), and session timestamps (created, last active, expiry), so you can stay signed in and so we can detect misuse.
- Course selections: the UofT courses you choose under "My Courses", used to personalize the calendar and resources you see.
- Activity log: a record of logins, logouts, changes to your course selections, which published resources you've downloaded and when, and any admin action taken on your account (e.g. a role change or a forced sign-out), each with the IP address and browser used.
- Newsletter signup: if you subscribe to our mailing list, just the email address you give us. This doesn't require an account and isn't linked to one, even if you use the same address for both.
We also keep an aggregate download count on each published resource (e.g. "downloaded 42 times") so we know which resources are actually useful. That count is a running total tied to the resource itself, not to any individual account: it doesn't say who downloaded it.
We don't collect payment information, and we don't run analytics or advertising trackers of any kind.
2. How We Use It
- Authentication: to know who you are and keep you signed in for up to 30 days.
- Personalization: your course selections drive what shows up on the calendar and resources pages when you filter by "My Courses".
- Access to resources and event details: a verified UofT email lets you download and preview study resources and see full event details. Your account works without one (including Denkard Games), with previews of the rest.
- Security and moderation: the activity log and session records let club admins recognize misuse and revoke a compromised or misbehaving account's active sessions without touching its role.
3. Who Can See Your Data
Club admins have access to an admin dashboard that shows, for every registered user, their email address, display name, role, join date, and last login time. Admins can also open a full activity history for any account, including which resources they've downloaded and when, along with the IP addresses and browser information tied to each logged event. Separately, the admin file manager shows the aggregate download count for each resource; that view doesn't identify who downloaded it.
Admins can also see whether your UofT email is verified (and which address), which ways you sign in (password, Google, passkeys), and whether two-step verification is on. To help someone who's locked out, an admin can remove a UofT verification or turn off two-step verification on an account; both are recorded in that account's activity log.
This is more visibility than a typical club membership list, so we want to be upfront about it: signing in gives club admins meaningful visibility into your account activity. This access exists to run the club's admin functions (managing roles, publishing resources, and responding to account misuse) and isn't used for anything else.
4. How Long We Keep It
- Session cookies expire automatically after 30 days.
- Emailed links expire after 1 hour and two-step sign-in codes after 10 minutes. Expired ones are deleted within a day.
- Passkeys and backup codes are kept until you remove them, turn off two-step verification, or delete your account.
- Activity log entries (including individual download records) are purged automatically after 30 days: a scheduled job deletes anything older every day.
- Course selections and your account record are kept for as long as your account exists. If you delete your account (see "Your Choices" below), they're deleted with it.
- A resource's aggregate download count is kept for as long as that resource stays published: it isn't tied to your account, so deleting your account doesn't change it.
- Newsletter emails are kept until you unsubscribe, using the link included in every email we send.
5. Third Parties
We share data with a few service providers who process it on our behalf, under their own privacy and security terms:
- Google: handles sign-in (the account info described above) and provides the club's public event calendars. The site reads events directly from the club's own public Google Calendars using a service credential; this doesn't involve your personal Google Calendar or any other Google data of yours.
- Cloudflare: hosts the site and stores the database and uploaded resource files that power it.
- Resend: sends the account emails we need to send on your behalf (email confirmation and UofT verification links, password reset links, two-step sign-in codes, and security notices such as "your sign-in email was changed"), using the email address on your account, and sends newsletter updates to whoever has subscribed to our mailing list.
We don't sell your data or share it with anyone else.
6. Cookies
The site sets one cookie, denkard_session, an HttpOnly cookie that keeps you signed in for up to 30 days. A few short-lived cookies are also set for a few minutes during the sign-in process itself: while you go through Google sign-in, while you enter a two-step verification code, and while you use a passkey. None of them are used for analytics or advertising, and the site doesn't set any third-party tracking cookies.
7. Your Choices
- Review your data: your course selections are always visible on the My Courses page. You can also download a full copy of everything tied to your account (your profile, course selections, active sessions, passkey names, and complete activity log) as a JSON file from your account page at any time.
- Manage how you sign in: from your account page you can change your sign-in email or UofT email, add or remove a password, link or unlink Google, add or remove passkeys, and turn two-step verification on or off.
- Delete your account: you can permanently delete your account from your account page. This removes your sessions, course selections, and activity log, and anonymizes the record of any admin actions you took on other accounts. Club resources you uploaded or organized stay published, since that content belongs to the club, but are no longer attributed to you. (If you're the only remaining admin, promote another admin first, since the sole admin account can't be deleted.)
- Unsubscribe from the newsletter: every newsletter email includes an unsubscribe link that removes your email from the list immediately, no sign-in required.
8. Contact
Questions about this policy or your data? Email us at denkarduoft@gmail.com.