গোপনীয়তা নীতি
মদন মোহন গ্রন্থাগার (Madan Mohan Library) — ওয়েবসাইট, Android অ্যাপ, কোষাগার অ্যাপ ও Discord বট · সর্বশেষ হালনাগাদ: ২৭ সেপ্টেম্বর ২০২৬ · সব নীতি · English below
এই নীতি মদন মোহন গ্রন্থাগারের সব ডিজিটাল সেবার জন্য প্রযোজ্য: ওয়েবসাইট madanmohanlibrary.org, ওয়েব অ্যাপ app.madanmohanlibrary.org, Google Play-এর “মদন মোহন গ্রন্থাগার” Android অ্যাপ (ডেভেলপার: Mishuk Adhikari), কোষাধ্যক্ষদের “কোষাগার” অ্যাপ (treasury.madanmohanlibrary.org) এবং গ্রন্থাগারের Discord বট “জ্ঞানবন্ধু”। এখানে বলা আছে আমরা কী তথ্য সংগ্রহ করি, কেন, কোথায় রাখি, কার সঙ্গে ভাগ করি, কতদিন রাখি, এবং আপনি কীভাবে তা দেখতে, বদলাতে বা মুছতে পারেন।
সংক্ষেপে: আমরা শুধু গ্রন্থাগার পরিচালনার জন্য প্রয়োজনীয় তথ্য রাখি। কোনো তথ্য বিক্রি করি না, বিজ্ঞাপন দেখাই না, অ্যানালিটিক্স বা ট্র্যাকিং টুল ব্যবহার করি না। চেক-ইনের সময় নেওয়া অবস্থান সঙ্গে সঙ্গে দূরত্বে বদলে ফেলে দেওয়া হয়। অ্যাকাউন্ট যেকোনো সময় মুছে ফেলা যায় —
কীভাবে, আর কী মুছে যায়।
১. আমরা কী তথ্য সংগ্রহ করি ও কেন
সদস্য নিবন্ধন ও প্রোফাইল
- নাম, লিঙ্গ, জন্ম তারিখ, মোবাইল নম্বর (নম্বরটি নিজের, অভিভাবকের না অন্যের), ইমেইল (ঐচ্ছিক), পেশা ও তার বিবরণ, ভোটার আইডি বা জন্মনিবন্ধন নম্বর (নিজের বা অভিভাবকের), পাসওয়ার্ড, প্রোফাইল ছবি, পরিচয়পত্রের ছবি ও ঐচ্ছিক অতিরিক্ত ডকুমেন্ট, ব্যবহৃত রেফারেল কোড, এবং নীতিমালায় সম্মতি দেওয়ার সময়।
- কেন: আপনার পরিচয় যাচাই করে সদস্যপদ অনুমোদন, সদস্য আইডি তৈরি, এবং আপনার সঙ্গে যোগাযোগ। পাসওয়ার্ড একমুখী হ্যাশ করে রাখা হয় — কেউ তা পড়তে পারে না।
- প্রশাসকরা আপনার পদবী, ভূমিকা ও চাঁদার পরিমাণ নির্ধারণ করেন। ফোন নম্বর ও ইমেইল অন্য সদস্যদের কাছ থেকে লুকিয়ে রাখার বিকল্প আছে।
কে কী দেখতে পান
- অনুমোদিত সদস্যদের নাম, ছবি, পদবী ও পেশা গ্রন্থাগারের পাবলিক “নিবন্ধিত সদস্যবৃন্দ” পাতায় সবার জন্য দেখানো হয়।
- লগ ইন করা সদস্যরা অন্য সদস্যদের নাম, সদস্য আইডি, পদবী, ছবি এবং — আপনি লুকিয়ে না রাখলে — ফোন নম্বর ও ইমেইল দেখতে পান।
- যিনি আপনাকে রেফার করেছেন, তিনি নিবন্ধন যাচাইয়ের জন্য আপনার আবেদনের তথ্য (পরিচয়পত্রের নম্বর ও ছবিসহ) দেখতে পান। গ্রন্থাগারের প্রশাসকরা সদস্য ব্যবস্থাপনার জন্য সব তথ্য দেখতে পান।
গ্রন্থাগারের কার্যক্রম
- গ্রন্থাগার কক্ষে চেক-ইন ও চেক-আউটের সময়, ইভেন্টে নিবন্ধন ও উপস্থিতি, বই ধার ও ফেরত, পয়েন্ট, কোন বিজ্ঞপ্তি পড়েছেন, এবং অ্যাপে আপনার নোটিফিকেশন।
- কেন: গ্রন্থাগার পরিচালনা, পয়েন্ট ও স্বীকৃতি দেওয়া, এবং আপনাকে প্রাসঙ্গিক খবর জানানো।
অবস্থান (লোকেশন)
- অ্যাপ বা ওয়েব অ্যাপে গ্রন্থাগার কক্ষে চেক-ইন বা চেক-আউট (অথবা কক্ষ খোলা) করার মুহূর্তে, আপনার অনুমতি নিয়ে, ফোনের সুনির্দিষ্ট অবস্থান (precise location) একবার নেওয়া হয়।
- সার্ভার সেটিকে গ্রন্থাগার থেকে দূরত্ব (মিটারে) ও অবস্থানের নির্ভুলতায় বদলে নেয়; অক্ষাংশ-দ্রাঘিমাংশ (latitude/longitude) সঙ্গে সঙ্গে ফেলে দেওয়া হয়, কোথাও সংরক্ষণ করা হয় না। কেন: চেক-ইনটি গ্রন্থাগারেই হচ্ছে কি না যাচাই করা।
- অ্যাপ পটভূমিতে (background) কখনো অবস্থান নেয় না, এবং অবস্থান অন্য কোনো কাজে ব্যবহার বা কারও সঙ্গে ভাগ করা হয় না। অনুমতি যেকোনো সময় ফোনের সেটিংস থেকে বন্ধ করা যায়।
চ্যাট ও ফোরাম (Discord)
- অ্যাপের চ্যাট ও ফোরাম আসলে গ্রন্থাগারের Discord সার্ভারের চ্যানেল। অ্যাপ থেকে পাঠানো বার্তা ও সংযুক্ত ফাইল আপনার নাম ও ছবিসহ Discord-এ পোস্ট হয় এবং সেখানেই থাকে; আমাদের সার্ভারে শুধু বার্তার আইডি ও বার্তাটি যে আপনার পাঠানো — এই যোগসূত্র রাখা হয়।
- চ্যাট ও ফোরামের নোটিফিকেশনের জন্য প্রেরকের নাম ও বার্তার প্রথম ১৪০ অক্ষর পর্যন্ত রাখা হয়।
- Discord অ্যাকাউন্ট যুক্ত করলে আপনার Discord আইডি, ব্যবহারকারীর নাম, প্রদর্শিত নাম ও ছবি রাখা হয়, আপনাকে গ্রন্থাগারের Discord সার্ভারে যুক্ত করা হয় এবং পদবী অনুযায়ী রোল দেওয়া হয়। Discord-এ রাখা বার্তার ক্ষেত্রে Discord-এর নিজস্ব গোপনীয়তা নীতিও প্রযোজ্য।
- কোনো কনটেন্ট বা সদস্যকে রিপোর্ট করলে রিপোর্টটি (কী, কেন, এবং প্রাসঙ্গিক লেখার অংশ) প্রশাসকদের পর্যালোচনার জন্য রাখা হয়। কাউকে ব্লক করলে সেই তালিকা রাখা হয়, যাতে তাঁর বার্তা আপনাকে দেখানো না হয়।
রক্তদান
- রক্তদাতা হিসেবে নিবন্ধন করলে: নাম, বয়স, লিঙ্গ, ওজন, রক্তের গ্রুপ, ফোন ও বিকল্প ফোন নম্বর, ঠিকানা ও এলাকা, শেষ রক্তদানের তারিখ, স্বাস্থ্যগত সমস্যা ও তার বিবরণ, এবং কখন রক্ত দিতে পারবেন।
- রক্তের অনুরোধে: রোগীর নাম ও রোগীর সঙ্গে সম্পর্ক, হাসপাতাল, জেলা ও থানা, যোগাযোগের নম্বর, রক্তের গ্রুপ, কবে লাগবে, রোগীর অবস্থা ও বিবরণ। এতে অন্য মানুষের (রোগী বা আত্মীয়ের) তথ্য থাকতে পারে — তাঁদের সম্মতি নিয়েই দিন।
- কেন: প্রয়োজনের সময় দ্রুত উপযুক্ত রক্তদাতা খুঁজে দেওয়া। রক্তের অনুরোধ গ্রন্থাগারের সদস্য ও দাতাদের দেখানো হয় (অ্যাপ, ওয়েবসাইট ও Discord-এ) এবং উপযুক্ত দাতাদের নোটিফিকেশন পাঠানো হয়। দাতাদের যোগাযোগের নম্বর ও স্বাস্থ্যসংক্রান্ত তথ্য শুধু গ্রন্থাগারের রক্তদান ব্যবস্থাপকরা দেখতে পান এবং তা শুধু রক্তদানের উপযুক্ততা বিচারে ব্যবহার হয়।
কোষাগার (আর্থিক হিসাব)
- কোষাধ্যক্ষরা “কোষাগার” অ্যাপে চাঁদা, অনুদান, খরচ ও ধার-দেনার হিসাব রাখেন — কার কাছ থেকে কত টাকা, কবে, কে গ্রহণ করেছেন। অনুদানদাতা চাইলে নাম গোপন রাখা বা অঙ্ক না দেখানোর বিকল্প আছে। সদস্যরা নিজের চাঁদার হিসাব অ্যাপে দেখতে পান।
লগ-ইন, নোটিফিকেশন ও ডিভাইস
- লগ-ইনের টোকেন, ব্রাউজার সেশন (IP ঠিকানা ও ব্রাউজারের তথ্যসহ), লগ-ইন লিংক, এবং পাসওয়ার্ড রিসেটের কোড।
- “Google দিয়ে প্রবেশ” ব্যবহার করলে: আপনার Google অ্যাকাউন্টের আইডি ও যাচাই করা ইমেইল — শুধু আগে থেকে থাকা সদস্য অ্যাকাউন্টের সঙ্গে মেলাতে। আমরা আপনার Google পাসওয়ার্ড, পরিচিতি বা অন্য কোনো Google তথ্য পাই না।
- পুশ নোটিফিকেশনের জন্য: Android অ্যাপে Firebase Cloud Messaging টোকেন; ব্রাউজারে পুশ সাবস্ক্রিপশন (ব্রাউজারের তথ্যসহ) এবং কোন ধরনের নোটিফিকেশন চান সেই পছন্দ।
- ক্যামেরা শুধু আপনি নিজে ছবি তুলতে চাইলে ব্যবহার হয়, এবং ছবিটি আপনি জমা দিলে তবেই আপলোড হয়।
- অ্যাপ অফলাইনে কাজ করার জন্য কিছু তথ্যের কপি আপনার ফোনে রাখে; অ্যাপ আনইনস্টল করলে তা মুছে যায়।
যোগাযোগ ও প্রযুক্তিগত তথ্য
- আমরা SMS ও ইমেইলে নিবন্ধনের খবর, পাসওয়ার্ড রিসেটের কোড, লগ-ইন লিংক, স্মরণ-বার্তা ও বিজ্ঞপ্তি পাঠাই; পাঠানো SMS-এর নম্বর, লেখা ও পৌঁছানোর ফল একটি খাতায় রাখা হয়।
- ওয়েব সার্ভার প্রতিটি অনুরোধের IP ঠিকানা, ব্রাউজারের তথ্য ও সময় লগে রাখে। সার্ভারে কোনো ত্রুটি ঘটলে তার বিবরণ ত্রুটির লগে (error log) রাখা হয় এবং প্রশাসকদের একটি Discord চ্যানেলে পাঠানো হয়; তাতে কখনো কখনো সংশ্লিষ্ট সদস্যের ইমেইল, ফোন নম্বর বা অ্যাকাউন্টের আইডি থাকে। আমরা কোনো বিজ্ঞাপন, অ্যানালিটিক্স বা ট্র্যাকিং টুল ব্যবহার করি না।
- লগ-ইন ছাড়া পূরণ করা পাবলিক ফর্মে (যেমন অনুষ্ঠানের নিবন্ধন) আপনার দেওয়া নাম, ফোন নম্বর ও উত্তর রাখা হয়।
২. কোথায় রাখা হয় ও কারা প্রক্রিয়া করে
- আমাদের নিজস্ব সার্ভার: সব ডাটাবেস ও অ্যাপ্লিকেশন।
- Cloudflare: ওয়েবসাইটের সব ট্রাফিক সুরক্ষা ও গতির জন্য Cloudflare-এর নেটওয়ার্ক হয়ে আসে; প্রোফাইল ছবি, পরিচয়পত্রের ছবি, ডকুমেন্ট ও বইয়ের প্রচ্ছদ Cloudflare R2-তে রাখা হয় এবং cdn.madanmohanlibrary.org থেকে অনুমান-অযোগ্য ঠিকানায় দেখানো হয়; ডাটাবেস ব্যাকআপের একটি কপিও R2-তে থাকে; কিছু ফর্মে বট ঠেকাতে Cloudflare Turnstile ব্যবহার হয়।
- Google: Android অ্যাপে পুশ নোটিফিকেশন পাঠাতে Firebase Cloud Messaging, এবং ঐচ্ছিক “Google দিয়ে প্রবেশ”। ব্রাউজারের পুশ নোটিফিকেশন আপনার ব্রাউজারের নির্মাতার (যেমন Google, Mozilla, Apple) পুশ সেবা দিয়ে পৌঁছায়।
- Discord: চ্যাট ও ফোরাম; প্রশাসকদের জন্য বটের স্বয়ংক্রিয় নোটিশ (নিবন্ধন, অনুমোদন, প্রশাসকের হাতে সদস্য মোছা, রক্তের অনুরোধ ইত্যাদি — নাম, সদস্য আইডি, ফোন নম্বর [লুকানো রাখলে আংশিক] ও ইমেইলসহ; আপনি নিজে অ্যাকাউন্ট মুছলে নোটিশে থাকে শুধু নাম ও সদস্য আইডি); সার্ভারের ত্রুটির খবর; Discord যুক্ত থাকলে পাসওয়ার্ড রিসেটের কোড Discord বার্তায়; এবং ডাটাবেস ব্যাকআপের দৈনিক আর্কাইভ।
- Resend: ইমেইল পাঠানো।
- sms.net.bd: বাংলাদেশে SMS পাঠানো।
এই সেবাদাতারা শুধু উপরের কাজের জন্য তথ্য প্রক্রিয়া করে। আমরা কোনো তথ্য বিক্রি বা ভাড়া দিই না, বিজ্ঞাপনে ব্যবহার করি না, এবং কোনো AI বা মেশিন লার্নিং মডেল প্রশিক্ষণে ব্যবহার করি না। আইনত বাধ্য হলে, অথবা কারও জীবন রক্ষায় প্রয়োজন হলে, যথাযথ কর্তৃপক্ষকে তথ্য দেওয়া হতে পারে।
৩. নিরাপত্তা
সব সংযোগ HTTPS-এ এনক্রিপ্ট করা, এবং পাসওয়ার্ড হ্যাশ করে রাখা হয়। গ্রন্থাগারের অ্যাপ ও ওয়েবসাইটে পরিচয়পত্রের ছবি ও ডকুমেন্ট শুধু আপনি, আপনার রেফারকারী ও প্রশাসকরা দেখতে পান; ফাইলগুলোর ঠিকানা অনুমান করা যায় না।
৪. কতদিন রাখা হয়
- অ্যাকাউন্ট ও প্রোফাইলের তথ্য: অ্যাকাউন্ট যতদিন আছে। অনুমোদন না পাওয়া নিবন্ধন বাতিল হলে তা ফাইলসহ সঙ্গে সঙ্গে মুছে যায়।
- অ্যাপের নোটিফিকেশন: ৬০ দিন পর স্বয়ংক্রিয়ভাবে মুছে যায়।
- পাসওয়ার্ড রিসেটের কোড: ১০ মিনিট। ব্রাউজার সেশন: ২ ঘণ্টা নিষ্ক্রিয় থাকলে শেষ (“মনে রাখুন” বেছে নিলে দীর্ঘতর)। অ্যাপের লগ-ইন: লগ আউট বা অ্যাকাউন্ট মোছা পর্যন্ত।
- অফলাইনে জমা থাকা চেক-ইন: প্রক্রিয়ার পরপরই মুছে যায়; যেগুলো প্রক্রিয়া করা যায়নি, সেগুলো ৭ দিন পর।
- ওয়েব সার্ভারের লগ ও ত্রুটির লগ: ১৪ দিন। Discord-এ পাঠানো ত্রুটির খবর স্বয়ংক্রিয়ভাবে মোছা হয় না।
- ডাটাবেস ব্যাকআপ: সার্ভারে প্রায় ৭ দিন; Cloudflare R2-তে একটিমাত্র কপি, যা প্রতি রাতে বদলে যায়; প্রশাসকদের ব্যবহারের একটি Discord ব্যাকআপ চ্যানেলে দৈনিক কপি, যা স্বয়ংক্রিয়ভাবে মোছা হয় না। ব্যাকআপ শুধু সার্ভার বিপর্যয়ের পর সেবা ফিরিয়ে আনতে ব্যবহার হয়।
- রক্তদানের ইতিহাস, রক্তের অনুরোধ, আর্থিক হিসাব ও SMS-এর খাতা: গ্রন্থাগারের রেকর্ড হিসেবে স্থায়ীভাবে থাকে। অ্যাকাউন্ট মুছলে এগুলোর সঙ্গে আপনার অ্যাকাউন্টের যোগসূত্র মুছে যায়।
- অ্যাকাউন্ট মোছার সময় কোনো বই ফেরত দেওয়া বাকি থাকলে: সেই ধারের রেকর্ড আপনার নাম ও মোবাইল নম্বরসহ, বই ফেরত আসা পর্যন্ত।
- Discord-এ পাঠানো বার্তা Discord-এ থাকে, যতক্ষণ না আপনি বা প্রশাসকরা তা মোছেন।
৫. আপনার অধিকার ও পছন্দ
- অ্যাপ বা ওয়েবসাইটের প্রোফাইল থেকে নিজের তথ্য দেখা ও সংশোধন করা, এবং ফোন নম্বর ও ইমেইল লুকিয়ে রাখা।
- Discord সংযোগ যেকোনো সময় বিচ্ছিন্ন করা; কোন ধরনের পুশ নোটিফিকেশন পাবেন তা বেছে নেওয়া; ফোনের সেটিংস থেকে অবস্থান, ক্যামেরা ও নোটিফিকেশনের অনুমতি বন্ধ করা।
- আপত্তিকর কনটেন্ট বা সদস্যকে অ্যাপ থেকে রিপোর্ট ও ব্লক করা।
- অ্যাকাউন্ট মুছে ফেলা: অ্যাপে “আরও” পাতা (উপরে ডান কোণে নিজের ছবিতে চাপ দিয়ে) → অ্যাকাউন্ট মুছে ফেলুন, ওয়েবসাইটের প্রোফাইল পাতা থেকে, অথবা ইমেইল করে। কী মুছে যায় আর কী থাকে, বিস্তারিত: madanmohanlibrary.org/policies/account-deletion।
- নিজের তথ্যের একটি কপি পেতে, অথবা কোনো তথ্য সংশোধন বা মুছতে চাইলে ইমেইল করুন — ৭ দিনের মধ্যে উত্তর দেওয়া হবে।
৬. শিশুদের গোপনীয়তা
গ্রন্থাগারের সদস্যপদ সব বয়সীদের জন্য খোলা, তাই সদস্যদের মধ্যে শিশু ও কিশোরও আছে। ১৮ বছরের কম বয়সীদের নিবন্ধন অভিভাবকের জ্ঞাতসারে হওয়া উচিত — নিবন্ধন ফর্মে নিজের বদলে অভিভাবকের মোবাইল নম্বর ও পরিচয়পত্রের নম্বর দেওয়া যায়, এবং প্রতিটি নিবন্ধন একজন সদস্য বা প্রশাসক যাচাই করে অনুমোদন দেন। শিশুদের কাছ থেকে অন্য সদস্যদের চেয়ে বেশি কোনো তথ্য নেওয়া হয় না, এবং ১৮ বছরের কম বয়সীদের Discord যুক্ত করতে হয় না। Google Play-এর Android অ্যাপটি শিশুদের লক্ষ্য করে তৈরি নয়; ১৩ বছরের কম বয়সী সদস্যরা অভিভাবকের তত্ত্বাবধানে অ্যাপ ও ওয়েবসাইট ব্যবহার করবেন। অভিভাবক ইমেইল করে সন্তানের তথ্যের কপি চাইতে, তা সংশোধন করাতে বা সন্তানের অ্যাকাউন্ট মুছে ফেলতে বলতে পারেন — ৭ দিনের মধ্যে ব্যবস্থা নেওয়া হবে।
৭. এই নীতির পরিবর্তন
নীতি বদলালে এই পাতার হালনাগাদের তারিখ বদলে যাবে; বড় কোনো পরিবর্তন হলে অ্যাপের বিজ্ঞপ্তিতেও জানানো হবে।
৮. যোগাযোগ
মদন মোহন গ্রন্থাগার · ইমেইল: [email protected] · ওয়েবসাইট: madanmohanlibrary.org · Google Play ডেভেলপার: Mishuk Adhikari
Privacy Policy
Madan Mohan Library (মদন মোহন গ্রন্থাগার) — website, Android app, Koshagar app and Discord bot · Last updated: 27 September 2026 · All policies
This policy covers every digital service of Madan Mohan Library: the website madanmohanlibrary.org, the web app app.madanmohanlibrary.org, the “মদন মোহন গ্রন্থাগার” Android app on Google Play (developer: Mishuk Adhikari), the treasurers’ “কোষাগার” (Koshagar) app (treasury.madanmohanlibrary.org) and the library’s Discord bot “জ্ঞানবন্ধু”. It explains what we collect, why, where it is kept, who we share it with, how long we keep it, and how you can see, change or delete it.
In short: we keep only what running the library needs. We never sell data, show no ads, and use no analytics or tracking tools. The location taken at check-in is turned into a distance and thrown away immediately. You can delete your account at any time —
how, and what is deleted.
1. What we collect and why
Membership registration and profile
- Name, gender, date of birth, mobile number (and whether it is yours, a guardian’s or someone else’s), email (optional), occupation and details, national ID or birth registration number (yours or a guardian’s), password, profile photo, an image of your ID card and an optional extra document, the referral code you used, and when you accepted the library’s policies.
- Why: to verify who you are before approving membership, to create your member ID, and to contact you. Passwords are stored only as a one-way hash that nobody can read.
- Administrators set your designation, roles and membership fee. You can hide your phone number and email from other members.
Who can see what
- Approved members’ name, photo, designation and occupation are shown to everyone on the library’s public “registered members” page.
- Signed-in members can see other members’ name, member ID, designation, photo and — unless you hide them — phone number and email.
- The member who referred you can see your application (including your ID number and ID image) in order to verify it. The library’s administrators can see everything needed to manage members.
Library activity
- Library Room check-in and check-out times, event registrations and attendance, books borrowed and returned, points, which announcements you have read, and your in-app notifications.
- Why: to run the library, award points and recognition, and keep you informed.
Location
- When you check in to or out of the Library Room (or open the room) in the app or web app, the app asks for your permission and takes your device’s precise location once.
- The server turns it into a distance from the library (in metres) and an accuracy figure; the latitude and longitude are discarded immediately and never stored. Why: to confirm that the check-in is happening at the library.
- The app never collects location in the background, and location is not used for anything else or shared with anyone. You can turn the permission off at any time in your phone’s settings.
Chat and forum (Discord)
- The app’s chat and forum are channels of the library’s Discord server. Messages and attachments you send from the app are posted to Discord under your name and picture, and live there; our server keeps only the message ID and the fact that you sent it.
- For chat and forum notifications we keep the sender’s name and up to the first 140 characters of the message.
- If you link your Discord account, we keep your Discord ID, username, display name and avatar, add you to the library’s Discord server and give you roles that match your designation. Discord’s own privacy policy also applies to what is stored on Discord.
- If you report content or a member, the report (what, why, and the relevant excerpt) is kept for the administrators to review. If you block someone, the block list is kept so their messages are hidden from you.
Blood donation
- If you register as a blood donor: name, age, gender, weight, blood group, phone and alternate phone, address and area, last donation date, any medical condition and its details, and when you are available.
- In a blood request: the patient’s name and your relationship to them, hospital, district and thana, contact number, blood group, when it is needed, the patient’s condition and a description. This can include other people’s (the patient’s or a relative’s) information — please share it only with their consent.
- Why: to find a suitable donor quickly when blood is needed. Blood requests are shown to the library’s members and donors (in the app, on the website and on Discord), and suitable donors are notified. Donors’ contact numbers and health information are visible only to the library’s blood-donation managers and are used only to judge whether someone can donate.
Treasury (Koshagar)
- Treasurers record membership fees, donations, expenses and loans in the Koshagar app — who paid how much, when, and who received it. Donors can choose to stay anonymous or not to have the amount shown. Members can see their own membership fee account in the app.
Sign-in, notifications and your device
- Sign-in tokens, browser sessions (including IP address and browser details), login links and password reset codes.
- If you use “Sign in with Google”: your Google account ID and verified email, used only to match an existing member account. We never receive your Google password, contacts or any other Google data.
- For push notifications: a Firebase Cloud Messaging token in the Android app; in a browser, the push subscription (with browser details) and which kinds of notification you want.
- The camera is used only when you choose to take a photo, and the photo is uploaded only if you submit it.
- The app keeps a copy of some data on your phone so it works offline; uninstalling the app removes it.
Messages and technical data
- We send registration updates, password reset codes, login links, reminders and announcements by SMS and email; for SMS, the number, text and delivery result are kept in a log.
- The web server logs each request’s IP address, browser details and time. When something goes wrong on the server, the details are written to an error log and sent to an administrators’ Discord channel; they sometimes include the email, phone number or account ID of the member involved. We use no advertising, analytics or tracking tools.
- Public forms you fill in without signing in (for example, an event sign-up) keep the name, phone number and answers you give.
2. Where it is kept and who processes it
- Our own server: all databases and the application.
- Cloudflare: all website traffic passes through Cloudflare’s network for security and speed; profile photos, ID images, documents and book covers are stored in Cloudflare R2 and served from cdn.madanmohanlibrary.org at unguessable addresses; one copy of the database backup is kept in R2; Cloudflare Turnstile blocks bots on some forms.
- Google: Firebase Cloud Messaging delivers push notifications to the Android app, and “Sign in with Google” is optional. Browser push notifications are delivered by your browser maker’s push service (such as Google, Mozilla or Apple).
- Discord: chat and forum; the bot’s automatic notices for administrators (registrations, approvals, members removed by an administrator, blood requests and so on — with name, member ID, phone number [partly masked if you keep it hidden] and email; when you delete your own account the notice carries only your name and member ID); server error reports; password reset codes by Discord message if your account is linked; and the daily archive of database backups.
- Resend: sends email.
- sms.net.bd: sends SMS in Bangladesh.
These providers process data only for the purposes above. We never sell or rent data, never use it for advertising, and never use it to train AI or machine-learning models. We may disclose information to the appropriate authorities if the law requires it or if it is needed to protect someone’s life.
3. Security
All connections are encrypted with HTTPS, and passwords are stored hashed. In the library’s app and website, ID images and documents are visible only to you, your referrer and the administrators, and the files’ addresses cannot be guessed.
4. How long we keep it
- Account and profile data: for as long as the account exists. A registration that is rejected is deleted immediately, with its files.
- In-app notifications: deleted automatically after 60 days.
- Password reset codes: 10 minutes. Browser sessions: end after 2 hours of inactivity (longer if you choose “remember me”). App sign-ins: until you log out or delete your account.
- Check-ins queued offline: deleted as soon as they are processed; ones that could not be processed, after 7 days.
- Web server logs and error logs: 14 days. Error reports sent to Discord are not deleted automatically.
- Database backups: about 7 days on our server; a single copy on Cloudflare R2 that is replaced every night; daily copies in a Discord backup channel used by the administrators, which are not deleted automatically. Backups are used only to restore the service after a server failure.
- Blood donation history, blood requests, treasury records and the SMS log: kept permanently as library records. Deleting your account removes their link to your account.
- A book still out when you delete your account: that loan record, with your name and mobile number, until the book is returned.
- Messages posted to Discord stay on Discord until you or the administrators delete them.
5. Your rights and choices
- See and correct your details from your profile in the app or on the website, and hide your phone number and email.
- Unlink Discord at any time; choose which kinds of push notification you receive; turn off location, camera and notification permissions in your phone’s settings.
- Report objectionable content or members, and block members, from the app.
- Delete your account: in the app, tap your photo at the top right to open “আরও” (More) → “অ্যাকাউন্ট মুছে ফেলুন” (Delete account); from your profile page on the website; or by email. What is deleted and what is kept is set out in full at madanmohanlibrary.org/policies/account-deletion.
- Email us for a copy of your data, or to have anything corrected or deleted — we reply within 7 days.
6. Children’s privacy
Library membership is open to all ages, so some members are children and teenagers. Anyone under 18 should register with a parent’s or guardian’s knowledge — the registration form takes a guardian’s mobile number and ID number in place of the member’s own, and every registration is checked and approved by a member or an administrator. We collect nothing more from children than from other members, and members under 18 do not have to link Discord. The Android app on Google Play is not designed for or directed at children; members under 13 should use the app and website under a parent’s or guardian’s supervision. A parent or guardian can email us to get a copy of their child’s data, have it corrected, or have the child’s account deleted — we act within 7 days.
7. Changes to this policy
If this policy changes, the “last updated” date on this page changes with it; significant changes are also announced in the app.
8. Contact
Madan Mohan Library · Email: [email protected] · Website: madanmohanlibrary.org · Google Play developer: Mishuk Adhikari