Policy Update History
A dated record of what changed in our Terms and Privacy Policy, and why
We update our Terms of Service and Privacy Policy whenever CAX's actual features or data practices change, so the published policy always reflects what the platform really does. This page is a plain-language history of those updates for reference — the documents above remain the binding legal text.
Blocking, reporting, and automatic screening of game chat
CAX now has proper safety tools: you can block someone, report a post, comment, account or chat message, and mute a player inside a game room. These tools create records, and one of them changes something we had previously promised, so both documents were updated rather than left to cover it by implication.
- Blocking now exists, and it works in both directions. Blocking someone hides their posts, comments, and profile from you — and yours from them. They are not told, no notification reaches them, and nothing visibly changes on their side. We store only who blocked whom and when, we use it for nothing except the hiding, and the record is deleted the moment you unblock them from Settings → Blocked accounts.
- Reporting is now available on comments, accounts, organization posts, and game chat, not just on posts. A report records who filed it, who it is about, and the reason. Reports are anonymous to the person reported — but not to us, because we cannot judge whether a report is being made in good faith without knowing who made it.
- We changed a promise about in-game chat, and want to be direct about it. We previously said game chat is deleted when the room closes. That is still true for every message nobody reports. But a reported message is now copied into the report along with a few messages either side of it, and that copy outlives the room. We made this change because a report showing one line with no context cannot be judged fairly — but it does mean the old blanket statement was no longer accurate, so we replaced it rather than leave it standing.
- Game chat is now screened automatically. Messages are checked against a list of prohibited terms before they reach the room; a message that matches is refused and never delivered or stored. It happens as the message passes through, no human reads your chat as part of it, and refused messages are not logged. The screening runs on the game server rather than in the app, so it applies equally to players on the standalone Business Game app.
- Voice and text chat are private-room only. This was already how the game worked, but it was not written down. Quick-match rooms have both switched off, so nobody can talk to you in a game unless you shared a room code with them.
- The Terms no longer tell you to email us about game conduct. That instruction was written when reporting in the app did not exist. Text messages can now be reported directly. Voice still needs an email, because voice is not recorded and there is nothing for a report to point at — that limitation is unchanged and is stated plainly.
- Deleting your account leaves reports about you in place. Your blocks and the reports you filed are deleted with your account. Reports other people filed about you are kept as part of our safety record, and we would rather say so than let you find out from the omission.
The Business Game: voice chat, a separate game service, and players from outside CAX
The Arcade now includes the Business Game, a property-trading board game played live against other people. It works differently from everything else on CAX in three ways that genuinely affect your privacy, so both documents were updated to describe it honestly rather than leave it to the general wording.
- Game rooms include voice chat, so the app now asks for your microphone. Your device joins a room's voice channel muted, and no audio leaves your device until you unmute yourself. Voice is streamed directly between players as it happens — we do not record, store, or transcribe any of it, and none of it is ever written to our servers. You can decline microphone permission entirely and still play; the game is fully playable without voice.
- The game runs on its own service, with its own database. It is ours, not an outside company's, but it is a separate system from the main platform, so the Privacy Policy now has a section devoted to it. It lists exactly what CAX passes over when you open the game — your CAX user ID, email, display name, and profile picture — and, just as importantly, what it does not: your college, your verification status, your ID card, your posts, and your payment history never leave CAX.
- You will be playing with people who are not CAX students. Room codes work between CAX and the standalone Business Game app, which is the point — you can play with friends who do not have CAX. It also means a game room is not the campus-only space the rest of CAX is. In a room, those players can see your in-game username, company name, and avatar, and can hear you if you unmute. They cannot see your CAX profile, college, or email. Our previous promise that your content is only visible to verified students from your university was accurate everywhere else on the platform, and would not have been accurate here, so we wrote the exception down instead of leaving it implied.
- Deleting your CAX account now also deletes your game record. Because the game keeps its own database, we made it explicit that account deletion clears your player record and match history there too, not just on the main platform.
- In-game text chat is not kept. Messages exist for the length of the match so someone joining late can catch up, and are deleted when the room closes.
- The conduct rules apply in game rooms, including in voice. Because voice is live and unrecorded, we cannot go back and review what was said — so if someone is abusive, leave the room and report them with the room code and roughly when it happened. We act on those reports the same way we act on reports about posts.
- Competitive play now has plain expectations. Leaving a match forfeits it and a match ends automatically after two minutes of lost connection — both deliberate, both now written down. Match results and in-game currency have no monetary value and cannot be redeemed for anything outside the game.
Verification, security, and payments overhaul
Backend authentication and student verification were substantially rebuilt. This update brought both legal documents in line with how the platform actually works:
- Verification is now two-tier. Students who sign up with their institutional (university-domain) email are verified automatically — no ID card is requested at all. Students signing up with a personal email now go through a manual review track: they submit a photo of their student ID card and select their college, and an administrator approves or rejects it.
- Corrected data retention claims. The previous policy stated uploaded ID card images were auto-deleted within 24 hours. That is no longer accurate: the encrypted image, an image hash, and a hashed (non-reversible) student ID number are now retained permanently to detect the same document being reused across multiple accounts and prevent fraud. This is a real change in how long the data is kept, not just wording.
- Renewal changed from every 6 months to once a year. Manually verified accounts previously had to re-verify every 180 days. Verification now expires annually on a fixed date (July 19, Asia/Kolkata), with a 30-day grace period of uninterrupted access afterward.
- Removed the "3 rejected attempts = permanent block" rule. This limit no longer exists in the system; users can resubmit corrected documentation after a rejection.
- Added optional two-factor authentication (TOTP) as an account security option.
- Documented event payment processing via Razorpay or manually submitted UPI screenshots, including that CAX never stores card, UPI PIN, or bank credentials.
- Broadened "User Content" language to explicitly cover newer platform features — bookmarks, and game activity such as Bingo and Arcade — that didn't exist when the policy was first written.
Initial publication
The first published versions of the CAX Terms of Service and Privacy Policy, covering student eligibility and email-domain verification, the original ID-card verification and 24-hour deletion process, code of conduct, content licensing, liability, and data rights.