Who we are
Progsu is a programming and builders community at Georgia State University. The Progsu member platform is operated by Progsu leadership as a student organization, not by GSU itself.
What we collect
When you sign up, we collect:
- Your Google identity (email, name, avatar) for login.
- A student email at an allowlisted school domain, which we verify with a 6-digit code.
- Profile information you enter: name, school, major, class standing, graduation term, and up to six role interests.
- Optional contact info: phone, LinkedIn, GitHub, portfolio URL.
- Your resume PDF, if you upload one.
- Your consent choices (privacy, terms, age, recruiter sharing, email, SMS), with version and timestamp.
- Your event activity: RSVPs, waitlist entries, and check-ins for events you choose to engage with.
We do not collect date of birth, SSN, home address, GPA, gender, or race.
How we use it
- To run your member account.
- To let Progsu admins help you with problems (e.g. manual verification).
- To share with sponsors and recruiters Progsu works with — only if you toggle "open to recruiters" AND accept the recruiter-sharing consent.
- To operate events you participate in — RSVP confirmations, reminders, and cancellations (see Events below).
- To send marketing event and opportunity emails or text messages, if you opt in separately.
If you register for an event without an account
New in v6: you can RSVP to a Progsu event as a guest, without signing up. When you do, we store the name, email, and phone number you enter so we can send you the event details and check you in at the door.
After registering you may be asked three optional questions — your major, when you graduate, and what kind of work you are looking for. Answering is entirely optional and skipping costs you nothing; your RSVP is already complete before we ask. If you later sign in with the same email address, those answers are copied onto your member profile so you do not have to type them twice.
Guest registrations are visible to Progsu admins running the event. They are not shown to other members, and guests do not appear on the public attendee list on an event page.
Text messages
We only text you if you tick the SMS box yourself. It is never pre-ticked, and your RSVP, ticket, and event emails all work exactly the same whether you tick it or not.
We do not sell, rent, or share mobile opt-in data or consent with anyone for their own marketing. Your phone number and the fact that you opted in stay with Progsu.
Message frequency varies. Message and data rates may apply. Reply STOP to any message to stop receiving them, or HELP for help. A STOP applies to your number permanently and overrides every consent we hold — including one given on a different form or at a different event.
Events
When you RSVP to a Progsu event, we store your RSVP status, any waitlist position, and whether you checked in. Admins running the event can see this roster so they can manage capacity, run check-in, and follow up with attendees.
If you RSVP "going" to an event, you may receive a small number of operational emails related to that specific event:
- An RSVP confirmation when you sign up.
- A reminder before the event starts.
- A cancellation or reschedule notice if the event changes.
These are transactional emails tied to your participation. They are separate from the marketing email setting in your dashboard settings, and turning marketing email off does not silence event operational mail — the only way to stop those is to cancel your RSVP or skip the event.
Other members do not see your event activity by default. The member-directory section below explains the opt-in path that makes some of your profile and event history visible to peers.
Member directory and profile visibility
You can opt into a peer-visible member directory from your settings. When it's on, other Progsu members can visit progsu.app/members/<your-slug> and see a sanitized view of your profile.
Accounts created on or after 20 August 2026 start with directory visibility on, and can turn it off at any time in the same settings page. Accounts created before that date keep whatever they had already chosen; we did not switch anyone on.
Fields visible to other members:
- Your name (preferred name, or first name if none).
- Your avatar, whether from Google or uploaded by you.
- New in v4: your profile banner image, and your note — the short status line shown above your avatar. Both are optional, both are written by you, and neither is reviewed before other members see it, so treat them as public writing.
- Your one-line bio.
- School, class standing, and graduation term.
- Up to six interested roles.
- Your LinkedIn, GitHub, and portfolio links, and your Discord username, when you have added them.
- Optional: events you attended — only public, non-sensitive events with at least a handful of attendees. Private-invite events are never shown. You can turn this on or off separately.
Fields never visible to other members:
- Email addresses (Google or student).
- Phone number.
- Resume content or file path.
- Consent history or verification status.
- Admin status.
- Major and minor.
Progsu admins can still see full profile data regardless of your directory setting. Every time another member views your card we record an audit row so admins can investigate suspicious patterns. Turning off visibility hides your card from the directory and from peer URL lookups immediately; previously-recorded audit rows are retained.
Who can see that you are going to an event
New in v5: event pages show the people who are going. If your directory visibility is on, your name and avatar can appear in that group, and your face links to your member card.
Event pages are public, so this group is visible to anyone with the link, not only to signed-in members. This is the one place your directory profile is shown to people outside Progsu, and it is worth reading twice before you leave visibility on:
- It shows the same name and avatar the member directory already shows. No new field about you becomes visible.
- What is new is the link between you and a specific event — that you are going, or that you attended.
- Only a handful of faces are shown; everyone else is part of the total count, unnamed.
- Draft, cancelled, and private-invite events never show an attendee list to anyone who could not already see the event.
Turning off directory visibility in your settings removes you from this group immediately, on past and upcoming events alike. You stay in the total count, because the count is just a number of people. If you would rather RSVP without appearing anywhere, turn visibility off before you RSVP.
Attendees from events we ran before this platform existed are included in the total count only. We imported those guest lists from our previous event tool; those people never created an account here and are never named on an event page.
RSVP announcements in our Discord
New in v7: when you RSVP to an event, we post a short announcement in the Progsu Discord server. It names you by first name and last initial — "Natasha K." — along with the event you are going to and how many people are going in total.
Everyone in the Progsu Discord can read that channel. This is a different audience from the rest of the platform, so it is worth being specific about what is and is not in it:
- Your full last name, email address, phone number, and profile details are never posted. Neither is your avatar.
- Events marked sensitive, private-invite events, and unpublished drafts are never announced at all, to anyone.
- If you registered as a guest without an account, the same rule applies to you: first name and last initial, nothing else you typed into the form.
- We post when you RSVP, when you land on a waitlist, and when you cancel an RSVP you had. We do not post anything else about you.
Campaign links. If you reached the event through one of our short links — a QR code on a flyer, a link in a class announcement — the announcement also names which one. This is the only place we connect a person to the campaign that reached them. Our database deliberately does not store that connection: it counts how many people a flyer brought, and it has nowhere to record which people. The Discord announcement is the exception, it is not written down anywhere else, and it exists so that whoever put up the poster knows it worked.
If you would rather not appear in that channel, tell a Progsu officer and we will stop announcing your RSVPs. There is no toggle for this in your settings yet.
Shared event history with other members
There is a separate opt-in toggle for showing events you and another member both attended. When you and another member have both turned it on, each of you can see:
- A count of events you both attended that meet our anonymity threshold (enough other attendees were present that knowing you were both there doesn't narrow the field).
- The names of specific events — but only if the event was public, non-sensitive, and cleared the same threshold.
"Attended" means you both actually checked in, not just that you RSVP'd yes. Private-invite events are never included, even in the aggregate count. Events marked sensitive by an admin are never shown by name.
We record an audit row each time another member views your shared event history. Turning the toggle off hides future views; audit rows of past views are retained so admins can investigate abuse.
Recruiter sharing
If you opt in, the recruiter CSV can include your name, preferred name, google email, student email, phone, school, major, minor, class standing, graduation term, role interests, LinkedIn/GitHub/portfolio links, and a 15-minute signed link to your current resume.
We do not sell your data. You can withdraw consent at any time from your dashboard settings. CSVs already downloaded before you withdraw remain out of our reach — regenerating the export will exclude you immediately.
How we protect it
- All data is stored in Supabase Postgres with row-level security policies denying cross-user reads.
- Resumes live in a private storage bucket; download links are short-lived signed URLs.
- Admin exports are recorded in an audit log with the acting admin, the export ID, and row count.
- OTP codes are hashed (bcrypt) before storage and never logged.
Retention and deletion
We keep your data while you're an active member. If you request deletion, Progsu will process it within 30 days. Consent rows are retained (with name and email redacted) so we can prove what you agreed to at what time.
Your rights
You can view, edit, or ask to delete your data by emailing Progsu leadership or using the settings page. If you're in a jurisdiction with stronger rights (GDPR, CCPA), we will honor them even though our users are primarily in Georgia, USA.
Changes to this policy
If we make a material change, we'll prompt you to re-accept the new version the next time you sign in. Minor cleanups are applied silently with a new version number.
Contact
Email Progsu leadership at hello@progsu.com with any privacy questions.