Privacy Policy
Last Updated: 2026-08-31
This Privacy Policy explains how The CollegeR ("we," "us," "our") collects, uses, and protects your information — with special care for the data of students under 18.
1. Information We Collect
- Account information: name, email, and role (student/parent). For students, we also collect date of birth — used only to verify the student is 13 or older at registration. We do not retain or use the date of birth for any other purpose.
- Profile information: grade, intended major, GPA, test scores, and family code.
- Content you create: tasks, activities, college lists, essays, documents, and assessment answers.
- Usage data: how you interact with the app, collected to improve the service.
2. How We Use Your Information
- To provide and personalize your roadmap, recommendations, and reminders.
- To connect family members via a shared family code.
- To send transactional emails (alerts, OTP codes) and, with consent, notifications.
- To secure the platform and prevent abuse.
3. Data Minimization
We collect only the information necessary to provide the service. We do not ask for more than we need, and we avoid collecting sensitive details (such as Social Security numbers) unless strictly required for a feature you choose to use.
4. No Sale of Personal Information
We do not sell your personal information to anyone, for any purpose. We do not share your personal information for cross-context behavioral advertising.
5. AI and Your Data
- Some features use artificial intelligence to generate suggestions (for example, college matches or essay feedback). Your content is processed by our AI providers only to generate the response for you in that moment.
- We do not use your personal information, essays, documents, or conversation data to train AI models. Your inputs are never added to a training dataset.
- AI providers are contractually restricted from retaining or training on your data.
6. Sharing Your Information
- Within your family: members sharing a family code can see shared roadmap and activity data.
- Community: posts you publish to the Parent's Circle are visible to other members.
- Service providers: we use trusted providers (for example, AI and email infrastructure) to operate features. They process data only as needed to provide the service and are bound by confidentiality obligations.
Sub-processors
We use the following categories of sub-processors to operate features you use:
- AI providers: OpenAI, Google, and Anthropic process the text, essays, documents, and conversation content you submit to AI-powered features (college matches, essay feedback, advisor chats) only to generate the response for you in that moment. They are contractually restricted from retaining your data or using it to train models.
- Payments: Stripe and Wix Payments ("Base44 Payments") process card and subscription payments. We receive a transaction record but never your full card number.
- Email & infrastructure: the Base44 platform handles transactional email (OTP, alerts, parent briefings) and data storage.
- Inbound data sources: we fetch public data (college stats, scholarship listings, maps, videos) into the app; these do not send your personal data out. Cross-border note: some sub-processors are located in the United States. Where your data leaves your region, we rely on Standard Contractual Clauses (or an equivalent transfer mechanism) as the lawful basis for the transfer.
7. Children's Privacy (COPPA)
- The CollegeR is designed for students in grades 6–12 and their families. We comply with the Children's Online Privacy Protection Act (COPPA).
- Students under 13 may not create an account on their own. A parent or guardian must create the family account in their own name and provide verifiable consent before any information is collected from a child under 13.
- At registration, students must enter their date of birth. If the date of birth indicates the student is under 13, self-registration is blocked and no account or data is created — the student is directed to have a parent set up the family account instead.
- For students under 13, parents can review, correct, or delete their child's data at any time from Settings. A parent may revoke consent, which triggers deletion of the child's personal information from our systems.
- We do not condition a child's participation in an activity on disclosing more information than is reasonably necessary.
- We do not collect geolocation data, photos, or contact lists from students.
8. Data Retention
We keep your data while your account is active. You can request deletion of your data, and we will remove it within a reasonable period. For students under 13, a parent may request deletion at any time.
9. Your Privacy Rights
- Depending on your location, you may have rights under laws like the CCPA (California) or GDPR (EU/UK) to access, correct, delete, or restrict the processing of your personal information, and to opt out of any "sale" or "sharing."
- To exercise these rights, use the in-app data tools or contact us at privacy@thecolleger.com. We will respond within the timeframe required by applicable law.
- If you are under 18, a parent or guardian may exercise these rights on your behalf.
10. Security
We use reasonable safeguards. No system is perfectly secure, but we work to protect your information.
11. Payment Information
- When you purchase a subscription or marketplace item, payment is processed by our payment processors (Stripe and Wix Payments / "Base44 Payments"). We receive a record of the transaction (amount, date, product) but we do not store your full card number or CVV — those are handled solely by the processor.
- Providers receiving payouts may submit payout instructions (e.g., PayPal email, bank details). These are stored securely and used only to process payouts.
12. Sensitive Documents
- The Application Vault and related features let you upload documents such as transcripts, report cards, test scores, essays, passports, I-20s, bank statements, and tax returns.
- These documents are stored privately and are only visible to you and members of your shared family. We use them to populate your roadmap, extract scores/GPA, and generate reminders. We do not share uploaded documents with third parties except as needed to provide the feature you requested.
- International students: immigration documents (passport, I-20, visa) are collected solely to power the Visa Co-Pilot checklist and are not shared with third parties.
13. Cookies, Local Storage, and Your Consent
- We use essential local storage to keep you signed in and remember your preferences (e.g., theme, acknowledged notices, tour completion). This is strictly necessary for the app to function and does not require consent.
- We use optional analytics to understand how the app is used and improve it. Analytics is off by default; we only turn it on when you accept it via the consent banner shown on your first visit (or in Settings → Privacy & Cookies).
- We do not use third-party advertising cookies or cross-context behavioral advertising cookies.
- You can change your choice, or clear local storage from your browser settings, at any time. Withdrawing consent stops analytics from that point forward.
14. GDPR (EU/UK/EEA) and LGPD (Brazil)
- Lawful basis: where you are in the EU, UK, or EEA, we process your personal data on the basis of your consent (for analytics and non-essential storage), contract (to provide the service you signed up for), and our legitimate interests (security and fraud prevention).
- EU/UK representative: [EU/UK representative — to be provided by operator]. You may contact them or our DPO ([DPO / privacy officer — to be provided by operator]) for EU/UK privacy matters.
- International transfers: when your data is processed by sub-processors outside your region (notably in the US), we rely on Standard Contractual Clauses approved by the European Commission, or an equivalent lawful transfer mechanism.
- Data Protection Officer: [DPO / privacy officer — to be provided by operator].
- Rights: EU/UK users have the right to access, rectify, erase, restrict, port, and object to the processing of their data, and to withdraw consent at any time without affecting processing carried out before withdrawal. You may lodge a complaint with your local data protection authority.
- LGPD (Brazil): Brazilian users have equivalent rights under the Lei Geral de Proteção de Dados, including access, correction, deletion, portability, and revocation of consent. Complaints may be filed with the Autoridade Nacional de Proteção de Dados (ANPD) at www.gov.br/anpd.
15. Error Logging and Security Monitoring
- To keep the app stable and secure, we capture frontend error logs when something crashes. These logs may include your user id, the page route, and your browser user-agent — but never your password or uploaded document contents.
- Error logs are stored within the app's infrastructure and are visible only to administrators for debugging. They are retained for a limited period and then automatically deleted.
- We do not use a third-party error-tracking SDK (e.g., Sentry) that would send this data externally.
16. CCPA / CPRA and "Do Not Sell or Share"
- California residents: we do not sell your personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of. You can review your rights and our commitments on our Do Not Sell or Share page.
- To exercise any privacy right, use the in-app data export or contact us at privacy@thecolleger.com.
17. Changes to This Policy
We may update this Privacy Policy. Changes take effect on the effective date listed above. Continued use means you accept the updated policy.
18. Contact
Questions about this Privacy Policy or your data? Contact us at privacy@thecolleger.com or by mail at [Business postal address — to be provided by operator]. EU/UK users may also contact our representative at [EU/UK representative — to be provided by operator].
