Loading...
Loading...
Effective Date: August 12, 2026
OlyAdmit LLC (operating under the "OlyAdmit" brand name, and referred to herein as "OlyAdmit," "we," "us," or "our") takes your privacy seriously, especially regarding student data. This policy outlines how we collect, protect, and handle your information.
Scope: This Privacy Policy applies to student users of the OlyAdmit platform. School and counselor access is governed by separate terms. This policy should be read alongside our Terms of Service, available at https://olyadmit.org/terms-of-service.
We collect specific categories of information to provide our AI-powered counseling services:
Age Gating & Identity Data: During registration, we collect month and year of birth client-side for age gating. (The specific day is strictly defaulted to the 1st of the month, and only the month and year are collected). If this indicates you are under 13, you are asked to confirm the birth date is correct before proceeding; only if you confirm is account creation blocked and this data immediately discarded without being stored. Mandatory Identity Verification: When platform systems detect indicators suggesting a user may be under 13, regardless of selected education path or entered age, additional identity verification is conducted through Didit (see Section 3.1). We receive limited verification data: document type, first name, last name, date of birth, age, front camera face match score, verification status, and system warnings. We store only the verification result (verified/not verified), method, and timestamp. For users 13 and older who are not flagged for additional verification, we strictly store only your first name, last initial, and age classification. Voluntary Age Verification: We also offer an opt-in, voluntary age verification workflow from the profile page. For users not flagged for mandatory review, this verification is non-punitive: there are up to five (5) retry attempts per session, no permanent account or device blocking, and no account deletion on failure. Collection Mechanisms: If you confirm an under-13 birth date at the initial age gate (the month/year input), device fingerprinting applies a technical block to your device for seventy-two (72) hours to prevent repeat attempts. Required Account Data & Authentication: We support passwordless authentication via email magic link, Google OAuth, and Discord OAuth. We offer an account linking flow allowing users to connect Google, email, and Discord credentials to a single account. Google OAuth: We receive your email address, display name, email verification status, profile picture URL, and Google account ID. We strictly store only your email address. Discord OAuth: We receive your email, username, discriminator, avatar hash, Discord user ID, and locale. We strictly store only your email address. Parent Email Data: If authorized by the student user, we collect a parent or guardian's email address to send automated platform updates and activity reports. Sensitive Educational Data: School name, weighted and unweighted GPA, grade level, education level, graduation year and term, SAT/ACT scores, classes and grades, coursework achievements, academic awards, transcripts, draft essays, recommendation letters, essay analytics, essay templates, and quick comment templates. College Planning Data: Academic interests (selected during onboarding), extracurricular activities, user activities, career goals, languages spoken, college preferences, college visits, search priorities, saved scholarships, application tasks and subtasks. Demographic and Financial Data (Optional): Residency, ethnicity, family background, special circumstances, and family income range. System-Generated Data: Scholarship match results and timestamps produced by our matching algorithms. Usage Data: Log data, device identifiers, session duration, feature usage patterns, user feedback, notifications, notification preferences, and comment mentions.
Biometric age verification through Didit is not required to create a standard OlyAdmit account. It is triggered only when platform systems detect indicators that a user may be under 13 after account creation, as a COPPA safeguard. The purpose is age verification only; it is not used for academic fraud prevention, ghostwriting detection, or ongoing identity monitoring. For users 13 and older who are not flagged, no biometric data is collected and only your first name, last initial, and age classification are stored.
OlyAdmit consolidates the use of your data into the following core purposes:
To create, authenticate, and secure your account. To provide the core functioning of the AI counseling, brainstorming, and editing platform. To accurately match you with niche scholarships and appropriate college programs. To run content moderation systems, including automated sensitive content detection and crisis content detection, which triggers the delivery of immediate safety resources. To power the parent email system, which utilizes a dedicated data table to send authorized updates. To monitor platform performance, troubleshoot issues, and improve the user experience based on aggregated usage patterns. To communicate aggregated, de-identified platform statistics for business development purposes.
We will notify you at least thirty (30) days before onboarding any new sub-processor that processes personal data. An updated list of our active sub-processors is maintained in our Children's Data Retention Policy and Written Information Security Program (WISP).
We share necessary data strictly with categories of service providers required to run the platform. All such sub-processors are bound by formal Data Processing Agreements (DPAs) to protect user data. These include:
Cloud Infrastructure: Supabase, serving as our cloud, rate limiting, and database hosting provider. Enterprise AI Processing: Vercel AI Gateway, utilized for unified real-time text generation and AI analysis across all chat and essay endpoints. Vercel AI Gateway operates under a formal DPA, and we strictly route data only to specific AI models that natively guarantee Zero Data Retention (ZDR). All inference requests are routed exclusively to AWS Bedrock through single-provider routing using Vercel-managed API keys. AWS Bedrock functions as Vercel's sub-processor under the Vercel DPA; OlyAdmit has no direct contractual relationship with AWS Bedrock. Error Tracking & Performance Monitoring: Sentry is integrated and only transmits events when the SENTRY_ENABLED environment variable is set to "true". Custom beforeSend hooks programmatically strip all personal data before any error event leaves the browser or server. Sentry Session Replay is disabled, and stripped telemetry data is retained for thirty (30) days under the current Sentry plan. Age & Identity Verification: Didit, utilized to securely power age verification workflows. We review limited verification data and store only the verification result, method, and timestamp. OlyAdmit never receives or stores document images, physical addresses, or raw biometric media. Frontend Hosting & Analytics: Vercel, utilized for secure edge-network hosting and platform analytics under a standard DPA. Transactional Email: Resend, utilized for system emails (welcome emails, counselor invitations, parent activity reports) under a formal DPA. Counselor invitations are one-time transactional communications; the recipient email exists only in Resend logs and is not persisted in OlyAdmit's database. Business Email: Zoho Mail, utilized for business email addresses (privacy@olyadmit.org, hello@olyadmit.org). The Zoho Mail DPA is in force through the Zoho Terms of Service (submitted 2026-08-06).
Certain third-party integrations operate as independent data controllers:
Authentication Providers: Google OAuth and Discord OAuth act as independent controllers. Data sharing is governed by your direct consent with those providers, and no DPA is required for this controller-to-controller transfer. Payment Processing: Stripe will handle payment processing for counselor subscriptions once B2B payments are live. Stripe will operate as an independent controller for payment card data under PCI DSS compliance. A DPA has not yet been executed because B2B payments are not live; DPA is pending.
To provide accurate counseling, specific data is transmitted to our AI provider (Vercel AI Gateway). This includes relevant, conditionally transmitted profile context, which may include residency for college and scholarship matching contexts only. Ethnicity and family background are stored for scholarship matching but are not transmitted to AI models. Additionally, a unified cross-page chat history utilizing a five-message rolling window is transmitted to Vercel AI Gateway. All chat history is filtered to remove sensitive-category messages prior to transmission. We explicitly do not transmit your first name, last initial, school name, or birthday.
To ensure platform safety, automated moderation events are recorded in a secure moderation_deflection_logs table within a private schema. These logs capture the moderation category triggered and are retained strictly on a rolling 12-month schedule solely for safety compliance, after which they are securely deleted.
OlyAdmit does not "sell" your personal information, nor do we "share" it for cross-context behavioral advertising. We may disclose your data if explicitly required to do so by a valid subpoena, court order, or other lawful legal process.
OlyAdmit strictly complies with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect, maintain, or use personal information from children under 13 years of age. If a user confirms an under-13 birth date, account creation is blocked. If an account is suspended while awaiting age verification and the process remains unresolved or incomplete, the account and all associated data are automatically deleted after seventy-two (72) hours. If we discover that a user under 13 has successfully created an account, we will immediately delete that account and all associated personal data from our systems.
When age verification is required through Didit, facial geometry data (a biometric identifier) is collected to verify your age. This collection is governed by the Illinois Biometric Information Privacy Act (BIPA). Before any biometric data is collected, you will be presented with a clear written consent form detailing:
The specific biometric data being collected (facial geometry scan) The purpose of collection (age verification to comply with COPPA) The retention period and destruction timeline Your rights under BIPA
OlyAdmit: We never receive, store, or have access to your biometric data, facial images, or government ID documents. We only receive the verification result (verified/not verified), method, and timestamp. No biometric identifiers are retained by OlyAdmit.
Didit: Biometric data is processed on Didit's secure infrastructure in the European Union (AWS infrastructure). Didit retains the facial image, facial geometry, and any document images for thirty (30) days from the date of verification. After that period, Didit destroys or permanently renders unrecoverable all biometric identifiers and biometric information. Didit retains the non-biometric verification result, method, and timestamp only as long as necessary for operational requirements. The complete retention and destruction policy is set forth in Section 14 of this Privacy Policy.
Under the Illinois Biometric Information Privacy Act, you have the right to:
Know what biometric data is being collected and stored Know the purpose of collection Provide written consent before collection (satisfied through our electronic consent modal) Request deletion of biometric data from Didit directly File a private right of action for violations (statutory damages of $1,000-$5,000 per violation)
Voluntary age verification offered from your profile page is entirely optional, and declining it does not affect your account. Mandatory identity verification triggered by under-13 detection is required to continue using the account; if you decline or fail that verification, your account will remain suspended and will be deleted after 72 hours in accordance with COPPA. If you accept, you may withdraw consent at any time by deleting your account, which will remove all associated data from our systems. You may also contact Didit directly to request deletion of biometric data from their systems.
We utilize commercial enterprise APIs governed by strict data processing agreements. Our integration with Vercel AI Gateway routes to underlying providers with appropriate data retention policies. Your data is not used to train or fine-tune public foundational models.
OlyAdmit utilizes a dual-model architecture powered by Vercel AI Gateway, with all inference served exclusively through AWS Bedrock via single-provider routing. The llama-3.1-8b model handles Atlas endpoints (lower reasoning effort), while the gpt-oss-120b model powers the Athena essay editor (medium reasoning effort). We conditionally transmit relevant portions of your profile context to these models to provide personalized advice. This may include graduation year, GPA, interests, residency (for college and scholarship matching contexts), test scores, recent grades, activities, career goals, and current date metadata, strictly if relevant to your current prompt. Ethnicity and family background are not transmitted to AI models. We never transmit your first name, last initial, school name, or birthday.
The Athena essay editor covers all essay types, including Common App, college supplementary, and scholarship applications. It applies dynamic, type-specific evaluation criteria and word limit parameters. Essay content, alongside your profile context, is transmitted to Vercel AI Gateway for analysis. The platform also runs query relevance detection and crisis content detection on all essay pathways, including cached responses.
OlyAdmit will not use your personal data or uploaded essays to train our own internal AI models without your explicit consent.
We utilize a three-consent architecture with version tracking to manage privacy, terms, and AI processing agreements. This includes a targeted consent update flow (such as when minors transition to adults). During account creation, users provide standalone, explicit consent to the processing of their data by Vercel AI Gateway for real-time text generation. Users may withdraw this consent by deleting their account.
If you actively choose to link your account with a school counselor via a "Counselor Code," you participate in a three-tier sharing model:
Limited View: High-level progress metrics and milestone completion data are shared automatically. Mixed View: Selected sensitive content, such as specific draft essays, is shared alongside your progress metrics when explicitly initiated by you. Full View: Complete visibility into your profile and materials is granted to the counselor.
This connection is voluntary and can be downgraded or revoked at any time. We cannot retrieve data exported prior to revocation. In our direct-to-student consumer service, OlyAdmit does not act as a "school official" as defined under the Family Educational Rights and Privacy Act (FERPA). When a school district enters into a separate Student Data Processing Agreement with OlyAdmit LLC, the district may, for FERPA purposes, designate OlyAdmit as a school official with a legitimate educational interest for the limited purpose of that B2B service.
Your account, application history, essays, milestones, and all planning data belong to you and remain under your control. If a linked counselor's account is suspended, lapses, or is deleted for inactivity, your account and data are not affected. You may continue to use the platform independently or connect a different counselor at any time. Counselor account suspension or deletion only revokes that counselor's access to data you have chosen to share; it does not delete, freeze, or lock your student account or any student-owned records.
Your data is secured at the database level using Row Level Security (RLS) policies. No human reads your personal data, essays, or chat history unless you explicitly open a technical support ticket, are subject to age verification review, or unless required to respond to a verified legal obligation. In the event of a confirmed data security incident, we will notify affected users without undue delay, and no later than 72 hours after verification.
We use standard cookies and lightweight analytics tools (Vercel Analytics) to maintain session security, authenticate users, and monitor platform performance. Cookie lifecycles are strictly managed to align with our authentication and session expiration protocols. We do not use third-party advertising trackers.
To protect account security, user sessions are subject to automatic expiration:
Minors (13–17): 24 hours of active use, or 30 minutes of idle time. Adults (18+): 7 days of active use, or 1 hour of idle time.
OlyAdmit commits to honoring Global Privacy Control (GPC) signals. We implement both client-side (navigator.globalPrivacyControl) and server-side (Sec-GPC header) detection, both of which automatically disable Vercel Analytics when triggered. Furthermore, our baseline practices natively satisfy "Do Not Track" (DNT) goals, as we utilize zero third-party advertising trackers and strictly prohibit the sale or sharing of your data.
Depending on your state of residence, you are granted specific rights regarding your personal data. OlyAdmit extends these core rights globally:
Rights to Know, Correct, Delete, and Limit Use: You may request to access, port, correct, or delete your data, or limit the use of sensitive information. Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights. Authorized Agents: You may designate an authorized agent to make a privacy request on your behalf. Minors Under 16: OlyAdmit's existing baseline protections—which outright prohibit the sale or sharing of user data—inherently satisfy the opt-in requirements for minors under 16 in California, Virginia, Colorado, and Connecticut. New York City (NYCDPA): For users 13-17, we provide age-appropriate disclosures, default privacy settings, data minimization, and restrictions on profiling for college and scholarship matching. We use automated systems for scholarship matching, college recommendations, and admissions probability estimates; these tools are advisory and do not determine your access to educational opportunities. We honor Global Privacy Control signals and do not use youth data for targeted advertising. California Age-Appropriate Design Code (AADC): Although the AADC is not currently in effect, we voluntarily align with its design principles for users under 18, including default privacy settings, data minimization, transparent AI and matching, and avoiding dark patterns. Processing Timelines & Appeals: We commit to responding to verifiable data rights requests within 45 days. If we decline a request, you may appeal by replying directly to the denial email.
You may terminate your account at any time. Upon confirmation, all active personal data, chat histories, and essays will be immediately and permanently deleted from production databases.
To satisfy GDPR and COPPA documentation requirements, a compliance record of the deletion is retained in a secure audit log (deleted_accounts_audit) for twelve (12) months on a rolling basis, after which it is securely deleted. Consent records, version timestamps, and IP addresses at the time of consent are retained for 60 months from the date of consent. Data stored in routine encrypted backups is overwritten within our 90-day retention cycle. We reserve the right to retain specific data if required by a legal hold or subpoena, and will notify you of such extended retention to the extent permitted by law.
We may retain completely de-identified, aggregated usage data for internal performance analysis.
OlyAdmit is operated, processed, and hosted in the United States. By creating an account, you consent to the transfer of your information to the United States. While OlyAdmit does not target users in the European Union or the United Kingdom, our core sub-processors (Supabase, Vercel AI Gateway, Resend, Didit, and, when SENTRY_ENABLED is true, Sentry), along with Zoho Mail for business email, maintain Standard Contractual Clauses (SCCs) and/or participate in the EU-U.S. Data Privacy Framework to provide international transfer safeguards at the infrastructure level. OlyAdmit reserves the right to restrict access from jurisdictions where compliance is not commercially feasible.
We may update this Privacy Policy from time to time. We will notify you of material changes by sending an email to the address associated with your account or by providing a prominent notice on the platform at least thirty (30) days before the changes take effect. If you do not agree with the updated policy, you may delete your account before the effective date. Continued use of the platform after the effective date constitutes acceptance of the updated Privacy Policy.
OlyAdmit directs users to Didit, Inc. for biometric age verification. OlyAdmit does not itself collect, store, or retain biometric identifiers or biometric information. Didit retains biometric verification data, including the facial image, facial geometry, and any document images, for thirty (30) days from the date of verification. After that period, Didit destroys or permanently renders unrecoverable all such biometric data. OlyAdmit stores only the non-biometric verification result (verified or not verified), the method used, and the timestamp of the verification. OlyAdmit's retained verification data is destroyed when the account is deleted or when required by law. This destruction timeline complies with the Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14/1 et seq.: the initial purpose for collecting biometric data (age verification) is satisfied at the moment of verification, and the thirty (30) day retention period is well within the three-year outer limit that BIPA otherwise requires from the individual's last interaction with the entity.
To exercise your data rights, submit an appeal, or ask questions, please contact us at privacy@olyadmit.org or through the Help Center within the OlyAdmit application.