Skip to content

LegalSHT 12 · PRIVACY

Your
information.

What we collect, why we have it, who can see it, and how to delete it. Written to be read, not to be skipped.

Version 2026-09-29.1 · Effective September 29, 2026

The short version

  • We collect what you type into our forms, plus which of our links you clicked to get there. We do not buy data about you, and we do not sell or rent yours.
  • Registering for an event does not put you in any public directory. That is a separate box you tick on purpose, and it is unticked by default.
  • Ember is a private directory shared with partner Purdue entrepreneurship organizations. It is not public, and event registrations are more private still: only The Anvil can see those.
  • Most of it you can handle yourself on the Your data page at anvilstartups.com/ember/account: see what our database holds under your email, download a copy, edit your Ember profile, and delete your registrations, your messages, or all of it. For anything the page does not cover, email us and we will correct or delete it.

Who we are

The Anvil is a student-led entrepreneurship organization at Purdue University. We are an independent student organization. We are not operated by Purdue University, we are not a university department, and this is not a university privacy policy. When we say Purdue students, we mean the people we serve, not who runs us.

This policy covers anvilstartups.com, including our event pages, our signup and application forms, and Ember, the founder directory described below. Questions about any of it go to TheAnvil@purdue.edu, which reaches the students who actually maintain these systems.

What we collect, and why

Almost everything we hold is something you typed into a form. The one exception is described below, and we do not track you across other websites, run advertising pixels, or build profiles from third-party sources.

Event registration
Your name and email, plus whichever of these the event asks for: phone number, year in school, major, whether you are working on a startup and what it is, dietary restrictions, and how you heard about us. We use it to plan the room, to know who to expect, and to email you about that event.
Contact form
Your name, email, the role you picked, and your message. Used to reply to you. Kept in our own system as well as emailed to us, so a message cannot be lost in one person's inbox and go unanswered.
Team application
Your name, email, phone, year, major, LinkedIn, the teams you applied to, and your written answers. Used to evaluate applications for that recruiting cycle.
Ember profile
Whatever goes in it: your name, a one-line headline, what you are building, your major and graduation year, links, what you can offer and what you are looking for. It is not public. Only The Anvil and the people at the visibility level you choose can see it; see the next section. You can edit it or delete it yourself from Your data.
Career fair registration
When a startup registers to recruit at our career fair: the contact's name, email, job title and phone number, and the company's details, such as its name, website, logo, one-liner, industry, stage, team size, location, Purdue connection, the roles it is hiring for and the majors it wants to meet, plus logistics like how many people are coming. We also note the booth fee and whether it has been paid. Used to review the registration, plan the floor, and email the contact about the fair. Once a startup is confirmed, and only if the listing box was left ticked, the company's name, website, logo, one-liner, industry, stage, location, roles, and the kinds of hires and majors it is looking for are shown on the public career fair page. The contact's details never are: only The Anvil sees them.
Signing in
Your email address, when you sign in to Your data. We use it to email you a one-time code and, once you enter that code, to find what we hold under that address. There is no password. Our database provider, Supabase, keeps a sign-in account record for the address; deleting everything from Your data removes it, and the page tells you if that last step did not go through.
Mailing list
Your email address, plus your first name if you gave us one, for example on an event form. You are on the list because you subscribed on this site, ticked "Email me about future Anvil events" when registering for an event, or asked us to add you: we brought over the list we kept before this one. We record when and how you joined, which of our emails went to you, and when you left. Used to send you news and events from The Anvil. Every email we send to the list has a link that takes you off it, and leaving needs nothing but that link.

The exception: when you register for an event we also record which link brought you there. We put a tag on our own links so we can tell an Instagram post from a newsletter from a QR code on a poster, and if you arrived by clicking a link on another site we store the name of that site, such as "linkedin.com". We store the site's name only, never the full address, because a full address can carry search terms or private group names we have no reason to hold.

This is to find out which of our own efforts actually reach people, and nothing else. It tells us that twelve people came from Instagram; it does not tell us who you are elsewhere, and it does not follow you after you leave.

We do not ask for and do not want your student ID number, your grades, your date of birth, or any government identifier. Please do not put them in a free-text box.

Who can see what

This is the most important section on the page, so it is deliberately blunt.

Ember is a private directory, not a public one. It is not readable by the open internet and it is not indexed by search engines. Access is an allowlist that The Anvil controls: a named set of people, mostly students and staff at partner Purdue entrepreneurship organizations, who have been approved individually. The database refuses to return a single record to anyone not on that list, so this is enforced by the system rather than by a setting someone could forget.

Within that, you set your own level, and it belongs to you rather than to us. You can be visible only to the partner organizations we work with, or to nobody but The Anvil while you build something quietly, and the database enforces both. There is also a level for any signed-in Purdue student, which is not switched on yet: until it is, choosing it shows you to partner organizations only, never to anyone wider. You can change your level yourself at any time on the Your data page at anvilstartups.com/ember/account. Your contact details are never a field other people browse: when somebody wants to reach you, the introduction is made by an organization, so you learn who is asking and why before anything reaches your inbox.

It is still a directory, which means the people at your chosen level can see your profile, and that group grows as the Purdue entrepreneurship community does. Treat it as a room full of founders, mentors, and organizers rather than as a private note to us. You can remove yourself at any time from Your data, and if you would rather we did it, we will the moment you ask.

Event registrations are narrower still. Your registration is visible only to The Anvil, and only through its signed-in console. It is not shared with partner organizations, it is never shown on the event page, and the public page shows at most a count of how many spots are taken, never who took them.

These two are joined only by your explicit choice. When you register for an event you may tick a box asking to be added to Ember. It is unticked by default, ticking it is never required to attend, and even after you tick it The Anvil reviews the entry before any profile appears. Nothing you type into an event form is published automatically.

Who else can see your information

Three categories, and no others. We do not sell, rent, or trade your information, and we never will.

  • The Anvil. Event registrations and applications are readable only by The Anvil. Access is granted per account and revoked when someone leaves.
  • Partner organizations, for Ember only. Ember is built to be shared across the Purdue entrepreneurship community, so approved people at other student organizations we work with can see the profiles in it. Access is granted person by person and can be revoked. Nothing you submitted privately, such as an event registration or an application, is ever shared with them.
  • Service providers that operate the site for us, such as our database, email, and hosting providers. They process data on our instructions and are not permitted to use it for their own purposes. Ask us and we will tell you who they are.

We will also disclose information if the law actually requires it. If that ever happens and we are permitted to tell you, we will.

How long we keep it

  • Event registrations: through the event and the semester that follows, so we can measure what we ran and follow up. Then deleted or reduced to anonymous counts.
  • Team applications: through the recruiting cycle and the following academic year, so a later cohort can see who applied before.
  • Ember profiles: for as long as you want one. Delete it yourself from Your data, or ask us and it is removed.
  • Contact messages: as long as the conversation is useful, and no longer than a year after it ends.
  • Mailing list: until you unsubscribe. After that we delete your name and keep your address, marked as unsubscribed, with the dates you joined and left and which of our emails went to it. That record is what stops the address being added back by mistake. Ask and we will delete it too.

We are a student organization with turnover every year, so these are the periods we hold ourselves to rather than an automated guarantee. If you want something gone sooner, delete it yourself from Your data, or ask and we will delete it.

Your choices

Most of these you can do yourself, right away, on the Your data page at anvilstartups.com/ember/account. You sign in with your email address and a one-time code we send to it, and the page shows everything our database holds under that address. Email stays open for anything the page does not cover, and for anyone who would rather ask.

  • Attend without joining anything. Leave the Ember box unticked. You will still be registered for the event.
  • Get a copy of what we hold about you. Your data shows everything our database holds under your email and lets you download a copy, exactly as the database returns it. Team applications are not kept in that database, so they are not on the page: email us for those, or for a copy in any other form, and we will send it.
  • Correct anything that is wrong. Edit your Ember profile yourself on Your data: your name, headline, bio, major, graduation year, links, what you offer and what you are looking for, who can see you, and, if you have set it up, whether you are open to cofounder matching. The answers on a registration you already submitted cannot be edited there, only deleted. To correct one, or anything else the page does not cover, email us and we will fix it.
  • Be removed. On Your data you can leave Ember, which deletes your profile and withdraws any request to join you made at an event; delete any of your event registrations, which for an upcoming event also gives up your spot; delete messages you sent us; or delete everything at once, including your sign-in account. If you were on the mailing list, your address stays on it only as an unsubscribed record, so an old list can never add you back; ask and we will delete that too. We do not ask for a reason. The page deletes what is in our database. A message you send us is also emailed to our inbox, and a registration can be too, and the page cannot reach those copies: ask and we will delete them.
  • What is not self-serve. A startup's career fair registration is the company's booth, and it may be paid for, so it is not deleted from the page: email us. The same goes for team applications, and for access The Anvil has given you to Ember or to our console, which only The Anvil can remove.
  • Stop the email. On Your data you can stop emails about future events and take yourself off the mailing list in one step. To start again, tick the box the next time you register for an event, or subscribe on our newsletter page. Mail about an event you are registered for is not marketing and still comes; to stop it, delete that registration on Your data or ask us. Every announcement we send has an unsubscribe option too, and you can reply to any message asking to be taken off.

Anything the page does not cover goes to TheAnvil@purdue.edu. We aim to answer within a couple of weeks, which is realistic for a student team during a semester.

How we protect it

Access to event registrations is enforced by the database itself rather than by the website. Anyone not on The Anvil's allowlist reads nothing, whatever page or address they try. The Anvil signs in with one-time codes sent to email, so there are no shared passwords to leak, and removing someone from the allowlist revokes their access immediately.

Your data works the same way: a one-time code sent to your email, and no password. It only ever shows what is held under the address you proved you own by entering that code, so knowing someone's email address is not enough to see their records.

We should be honest about the limits. We are students, not a security company, and no system is perfect. We keep the amount of information we hold small on purpose, because the most reliable way to protect something is not to collect it.

Younger students

Our events and programs are intended for university students and are not directed at children under 13. We do not knowingly collect information from them. If you believe a child has submitted information to us, email us and we will delete it.

Changes to this policy

When we change this policy we update the version at the top of the page. Every event registration records the version that was on screen when it was submitted, so what you agreed to stays attached to your entry rather than being quietly replaced by a later version. If a change materially affects information we already hold, we will contact the people affected rather than relying on you to re-read this page.

Contact us

To see, download or delete what we hold under your email yourself, sign in to Your data. Anything else, including anything that page does not cover: TheAnvil@purdue.edu.

The Anvil is an independent, student-led organization at Purdue University. It is not operated by Purdue University, and its programs do not constitute university endorsement.