Effective date: May 22, 2026 · Last updated: May 28, 2026
This Privacy Policy describes how Noida International University (“NIU”, “we”, “us”) collects, uses, and protects information through the NSAT (NIU Student Aptitude Test) mobile application and web platform (“the App”). By using the App, you agree to the practices described below.
We collect the following categories of information when you use the App:
| Data | Purpose | Source |
|---|---|---|
| Full name | Identify the test-taker and display on results | NoPaperForms (NPF) / Meritto application |
| Email address | Send one-time password (OTP) for identity verification | NPF application |
| Phone number | Send WhatsApp OTP for second-factor identity verification | NPF application |
| NIU Application Number | Unique identifier for login, fee verification, and test-attempt tracking | NPF application |
| Course / programme enrolled | Determine which test paper to present and categorise results | NPF application (fetched live at login) |
| Payment status | Verify application-fee payment before granting test access | NPF application (synced every 30 minutes) |
| Test responses & scores | Evaluate aptitude test performance, generate results, and produce score reports | Collected in-app during the test |
| Short-answer responses | Stored ungraded for manual review by admissions staff | Collected in-app during the test |
| FCM device token | Deliver push notifications about exam updates and results | Collected automatically from device |
| Diagnostic & crash data | Identify and fix app errors; improve stability | Collected automatically via Firebase Crashlytics (mobile only) |
| App usage & analytics events | Understand student journey flow and improve the exam experience | Collected automatically via Firebase Analytics |
| Error logs | Diagnose operational issues during the examination period | Collected automatically; persisted to Firestore for admin review |
| Device information | Exam integrity — device metadata is recorded at test start for post-exam auditing to detect irregularities | Collected automatically from device (brand, model, OS version, screen size, browser user-agent) |
| Saved test answers (periodic) | Crash recovery — your in-progress answers are saved every 30 seconds so they can be recovered if the app crashes or you lose network connectivity | Collected in-app during the test; automatically deleted after successful submission |
| App Check attestation token | Verify that requests originate from the genuine NSAT app, not from unauthorized tools or scripts | Generated automatically by the device (Play Integrity on Android, App Attest on iOS, reCAPTCHA Enterprise on Web) |
Your information is used exclusively for administering the NIU entrance examination. Specifically, we use it to verify your identity and fee payment status, send OTP codes via email and WhatsApp for secure two-factor login, deliver your aptitude test (multiple-choice and short-answer), calculate and display your test results via server-side scoring, send push notifications related to the examination, ensure exam integrity through anti-cheating measures, recover your test progress in case of technical issues, generate anonymised usage analytics to improve the app, and diagnose errors or crashes during the exam period.
We do not sell, rent, or share your personal information with any third parties for advertising or marketing purposes. The App contains no advertisements and no third-party tracking SDKs beyond those listed in Section 5.
To maintain the fairness and integrity of the examination, the App employs the following measures during the test:
| Measure | What It Does | Data Impact |
|---|---|---|
| Screenshot & screen recording blocking | Prevents capturing test content on Android devices using the operating system's secure window flag | No data collected; enforced locally on your device |
| Clipboard lockdown | Disables copy, paste, and text selection within the test interface to prevent sharing of questions or importing of answers | No data collected; enforced locally on your device |
| Device fingerprinting | Records basic device metadata (brand, model, operating system version, screen size) when you start the test | Stored in our database and retained for the admission cycle. Used only by administrators for post-exam review if irregularities are suspected |
| App Check verification | Confirms that requests to our servers originate from the genuine NSAT app, blocking unauthorized bots or scripts | Attestation tokens are generated by your device and verified server-side. No personal data is collected through this process |
| Periodic answer backup | Saves your in-progress answers every 30 seconds to enable crash recovery | Saved answers are automatically deleted upon successful test submission |
| Auto-submit safety net | If your app crashes or loses connectivity and the test time expires, our server automatically scores your most recently saved answers | Uses the same saved answers described above; results are flagged as auto-submitted for administrator review |
These measures do not access your camera, microphone, location, contacts, files, or any data beyond what is listed above. The App does not perform screen monitoring, keystroke logging, or any form of audio/video surveillance.
Your data is stored in Google Cloud Firestore, hosted in the asia-south1 (Mumbai) region. We use industry-standard security measures including encrypted data transmission (HTTPS/TLS), hashed OTP codes (SHA-256) with automatic expiry and attempt limits, server-side test scoring to prevent answer-key tampering, role-based Firebase security rules restricting data access, and channel-specific OTP storage to prevent verification conflicts.
Student identity data (name, email, phone, course) is fetched live from the NoPaperForms CRM API during your session. Only your application number, payment status, test results, and attempt records are persisted in the App’s database. OTP codes are hashed before storage and automatically expire after 10 minutes with a maximum of 5 verification attempts per code.
The App uses Firebase App Check to verify that all requests to our backend services originate from the genuine NSAT application. On Android, this uses Google Play Integrity; on iOS, Apple App Attest; and on Web, Google reCAPTCHA Enterprise. These services generate device attestation tokens that are verified server-side but do not collect additional personal information.
The App uses the following third-party services, each governed by their own privacy policies:
| Service | Provider | Purpose |
|---|---|---|
| Firebase (Firestore, Cloud Functions, Cloud Messaging, Crashlytics, Analytics, Remote Config, Auth, App Check) | Google LLC | Database, serverless backend, push notifications, crash reporting, usage analytics, feature flags, and admin authentication |
| NoPaperForms / Meritto CRM API | NoPaperForms Pvt. Ltd. | Student application data, fee status verification, and lead details |
| SMTP (Gmail) | Google LLC | Sending email OTP verification codes |
| Twilio WhatsApp API | Twilio Inc. | Sending WhatsApp OTP verification codes for second-factor authentication |
No data is shared with advertising networks, data brokers, or any other third parties beyond those listed above. Your phone number is shared with Twilio solely for the purpose of delivering the WhatsApp verification code; it is not retained by Twilio beyond the delivery of the message.
The App uses Firebase Analytics to understand general usage patterns (such as screen views, login funnels, and session duration) and Firebase Crashlytics to collect crash reports for improving app stability. These services may collect device identifiers, app usage data, and crash logs. This data is processed by Google in accordance with their privacy policy and is used solely for improving the App.
Firebase Remote Config is used to manage exam-day operational settings (such as the exam window schedule and maintenance mode) without requiring an app update. Remote Config does not collect personal data.
The App uses Firebase Cloud Messaging (FCM) to send push notifications about examination schedules, updates, and results. Your device token is collected for this purpose and associated with topic subscriptions based on your school/course. You may disable push notifications at any time through your device settings.
Administrators access the App using Firebase Authentication (email and password). Admin accounts, roles (admin or superadmin), and course-access assignments are stored in Firestore. Admin activity may be logged for audit purposes. Admin data is not shared externally.
The App collects structured error and informational logs to help diagnose issues during the examination period. These logs may include your application number, timestamps, and error details. Logs are stored in Firestore and are accessible only to administrators. Log data is retained for the duration of the admission cycle and deleted thereafter.
Test results, attempt records, and short-answer responses are retained for the duration of the admission cycle (academic year 2026–27). OTP records are automatically deleted after 10 minutes. Student sync data is refreshed every 30 minutes and reflects the current state of the NPF CRM. Application logs are retained for the admission cycle. After the admission cycle concludes, test data and logs may be archived or deleted in accordance with NIU’s records policy. Device fingerprint records are retained for the same duration as test results. Saved answer backups are automatically deleted upon successful test submission; any remaining backups are cleared within 24 hours of the test window closing.
You may request access to the personal data we hold about you, request correction of inaccurate data, request deletion of your data (subject to academic record-keeping requirements), and opt out of push notifications via your device settings. To exercise any of these rights, contact us using the details below.
The App is intended for prospective university students. We do not knowingly collect information from children under the age of 13. If you believe a child under 13 has provided us with personal information, please contact us so we can delete it.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the App after changes are posted constitutes your acceptance of the revised policy.
If you have questions about this Privacy Policy or your personal data, please contact:
Noida International University
Plot No. 1, Sector 17A, Yamuna Expressway
Greater Noida, Gautam Buddha Nagar
Uttar Pradesh 203201, India
Email: admissions@niu.edu.in
Website: niu.edu.in