OlyAdmit Privacy Policy
Effective Date: August 2, 2026
OlyAdmit LLC (operating under the "OlyAdmit" brand name, and referred to herein as "OlyAdmit," "we," "us," or "our") takes your privacy seriously, especially regarding student data. This policy outlines how we collect, protect, and handle your information.
Scope: This Privacy Policy applies to student users of the OlyAdmit platform. School and counselor access is governed by separate terms. This policy should be read alongside our Terms of Service, available at https://olyadmit.org/terms.
1. Data Collection Categories
We collect specific categories of information to provide our AI-powered counseling services:
- Age Verification & Identity Data: During registration, we collect month and year of birth client-side for age verification. (The specific day is strictly defaulted to the 1st of the month, and only the month and year are collected). If this indicates you are under 13, account creation is blocked and this data is immediately discarded without being stored.
- Mandatory Identity Verification: When platform systems detect indicators suggesting a user may be under 13, regardless of selected education path or entered age, additional identity verification is conducted through Didit (see Section 3.1). We receive limited verification data: document type, first name, last name, date of birth, age, front camera face match score, verification status, and system warnings. We store only the verification result (verified/not verified), method, and timestamp. For users 13 and older who are not flagged for additional verification, we strictly store only your first name, last initial, and age classification.
- Voluntary Age Verification: We also offer an opt-in, voluntary age verification workflow from the profile page. For users not flagged for mandatory review, this verification is non-punitive: there are no retry limits, no permanent account or device blocking, and no account deletion on failure.
- Collection Mechanisms: If you fail the initial age gate (the month/year input), device fingerprinting applies a technical block to your device for seventy-two (72) hours to prevent repeat attempts.
- Required Account Data & Authentication: We support passwordless authentication via email magic link, Google OAuth, and Discord OAuth. We offer an account linking flow allowing users to connect Google, email, and Discord credentials to a single account.
- Google OAuth: We receive your email address, display name, email verification status, profile picture URL, and Google account ID. We strictly store only your email address.
- Discord OAuth: We receive your email, username, discriminator, avatar hash, Discord user ID, and locale. We strictly store only your email address.
- Parent Email Data: If authorized by the student user, we collect a parent or guardian's email address to send automated platform updates and activity reports.
- Sensitive Educational Data: School name, weighted and unweighted GPA, grade level, education level, graduation year and term, SAT/ACT scores, classes and grades, coursework achievements, academic awards, transcripts, draft essays, recommendation letters, essay analytics, essay templates, and quick comment templates.
- College Planning Data: Academic interests (selected during onboarding), extracurricular activities, user activities, career goals, languages spoken, college preferences, college visits, search priorities, saved scholarships, application tasks and subtasks.
- Demographic and Financial Data (Optional): Residency, ethnicity, family background, special circumstances, and family income range.
- System-Generated Data: Scholarship match results and timestamps produced by our matching algorithms.
- Usage Data: Log data, device identifiers, session duration, feature usage patterns, user feedback, notifications, notification preferences, and comment mentions.
2. How We Use Your Information
OlyAdmit consolidates the use of your data into the following core purposes:
- To create, authenticate, and secure your account.
- To provide the core functioning of the AI counseling, brainstorming, and editing platform.
- To accurately match you with niche scholarships and appropriate college programs.
- To run content moderation systems, including automated sensitive content detection and crisis content detection, which triggers the delivery of immediate safety resources.
- To power the parent email system, which utilizes a dedicated data table to send authorized updates.
- To monitor platform performance, troubleshoot issues, and improve the user experience based on aggregated usage patterns.
- To communicate aggregated, de-identified platform statistics for business development purposes.
3. Third-Party Sharing and Disclosures
We will notify you at least thirty (30) days before onboarding any new sub-processor that processes personal data. An updated list of our active sub-processors is maintained in our Children's Data Retention Policy and Written Information Security Program (WISP).
3.1 Essential Service Providers
We share necessary data strictly with categories of service providers required to run the platform. All such sub-processors are bound by formal Data Processing Agreements (DPAs) to protect user data. These include:
- Cloud Infrastructure: Supabase, serving as our cloud, rate limiting, and database hosting provider.
- Enterprise AI Processing: Vercel AI Gateway, utilized for unified real-time text generation and AI analysis across all chat and essay endpoints. Vercel AI Gateway operates under a formal DPA, and we strictly route data only to specific AI models that natively guarantee Zero Data Retention (ZDR). All inference requests are routed exclusively to AWS Bedrock through single-provider routing using Vercel-managed API keys. AWS Bedrock functions as Vercel's sub-processor under the Vercel DPA; OlyAdmit has no direct contractual relationship with AWS Bedrock.
- Error Tracking & Performance Monitoring: Sentry, utilized to detect runtime software bugs. We implement custom configuration hooks that programmatically strip all personal data before any error event leaves the browser/server. Sentry Session Replay is disabled, and stripped telemetry data is automatically deleted within ninety (90) days.
- Age & Identity Verification: Didit, utilized to securely power age verification workflows. We review limited verification data and store only the verification result, method, and timestamp. OlyAdmit never receives or stores document images, physical addresses, or raw biometric media.
- Frontend Hosting & Analytics: Vercel, utilized for secure edge-network hosting and platform analytics under a standard DPA.
- Transactional Email: Resend, utilized for system emails (welcome emails, counselor invitations, parent activity reports) under a formal DPA. Counselor invitations are one-time transactional communications; the recipient email exists only in Resend logs and is not persisted in OlyAdmit's database.
3.2 Independent Controllers
Certain third-party integrations operate as independent data controllers:
- Authentication Providers: Google OAuth and Discord OAuth act as independent controllers. Data sharing is governed by your direct consent with those providers, and no DPA is required for this controller-to-controller transfer.
- Payment Processing: Stripe handles payment processing for counselor subscriptions and operates as an independent controller for payment card data under strict PCI DSS compliance.
3.3 Sensitive Data and AI Transmission
To provide accurate counseling, specific data is transmitted to our AI provider (Vercel AI Gateway). This includes relevant, conditionally transmitted profile context, which may contain sensitive demographic categories (ethnicity, family background, and residency). Additionally, a unified cross-page chat history utilizing a five-message rolling window is transmitted to Vercel AI Gateway. All chat history is filtered to remove sensitive-category messages prior to transmission. We explicitly do not transmit your first name, last initial, school name, or birthday.
3.4 Content Moderation Logs
To ensure platform safety, automated moderation events are recorded in a secure moderation_deflection_logs table within a private schema. These logs capture the moderation category triggered and are retained strictly on a rolling 12-month schedule solely for safety compliance, after which they are securely deleted.
3.5 No Sale of Data
OlyAdmit does not "sell" your personal information, nor do we "share" it for cross-context behavioral advertising. We may disclose your data if explicitly required to do so by a valid subpoena, court order, or other lawful legal process.
4. COPPA Compliance (Children Under 13)
OlyAdmit strictly complies with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect, maintain, or use personal information from children under 13 years of age. If a user indicates they are under 13, account creation is blocked. If an account is suspended pending age verification and the process remains unresolved or incomplete, the account and all associated data are automatically deleted after seventy-two (72) hours. If we discover that a user under 13 has successfully created an account, we will immediately delete that account and all associated personal data from our systems.
5. Illinois BIPA Compliance (Biometric Data)
5.1 Biometric Data Collection
When age verification is required through Didit, facial geometry data (a biometric identifier) is collected to verify your age. This collection is governed by the Illinois Biometric Information Privacy Act (BIPA). Before any biometric data is collected, you will be presented with a clear written consent form detailing:
- The specific biometric data being collected (facial geometry scan)
- The purpose of collection (age verification to comply with COPPA)
- The retention period and destruction timeline
- Your rights under BIPA
5.2 Data Retention and Destruction
OlyAdmit: We never receive, store, or have access to your biometric data, facial images, or government ID documents. We only receive the verification result (verified/not verified), method, and timestamp. No biometric identifiers are retained by OlyAdmit.
Didit: Biometric data is processed on Didit's secure infrastructure and is immediately destroyed after verification is complete. Didit retains verification result data only as long as necessary for their operational requirements, as detailed in their privacy policy. Biometric identifiers are not retained beyond the verification process.
5.3 Your BIPA Rights
Under the Illinois Biometric Information Privacy Act, you have the right to:
- Know what biometric data is being collected and stored
- Know the purpose of collection
- Provide written consent before collection (satisfied through our electronic consent modal)
- Request deletion of biometric data from Didit directly
- File a private right of action for violations (statutory damages of $1,000-$5,000 per violation)
5.4 Consent and Revocation
Your consent for biometric data collection is entirely voluntary. You may decline this verification, though your account will remain suspended and may be deleted after 72 hours per COPPA requirements. If you accept, you may withdraw consent at any time by deleting your account, which will remove all associated data from our systems. You may also contact Didit directly to request deletion of biometric data from their systems.
6. AI Processing and Data Protection
6.1 Zero-Retention Processing
We utilize commercial enterprise APIs governed by strict data processing agreements. Our integration with Vercel AI Gateway routes to underlying providers with appropriate data retention policies. Your data is not used to train or fine-tune public foundational models.
6.2 Two-Model Architecture and Transmitted Data
OlyAdmit utilizes a dual-model architecture powered by Vercel AI Gateway, with all inference served exclusively through AWS Bedrock via single-provider routing. The llama-3.1-8b model handles Atlas endpoints (lower reasoning effort), while the gpt-oss-120b model powers the Athena essay editor (medium reasoning effort). We conditionally transmit relevant portions of your profile context to these models to provide personalized advice. This may include graduation year, GPA, interests, ethnicity, family background, residency, test scores, recent grades, activities, career goals, and current date metadata, strictly if relevant to your current prompt. We never transmit your first name, last initial, school name, or birthday.
6.3 Athena Essay Editor Scope
The Athena essay editor covers all essay types, including Common App, college supplementary, and scholarship applications. It applies dynamic, type-specific evaluation criteria and word limit parameters. Essay content, alongside your profile context, is transmitted to Vercel AI Gateway for analysis. The platform also runs query relevance detection and crisis content detection on all essay pathways, including cached responses.
6.4 Internal Use
OlyAdmit will not use your personal data or uploaded essays to train our own internal AI models without your explicit consent.
6.5 Consent Versioning and AI Processing
We utilize a three-consent architecture with version tracking to manage privacy, terms, and AI processing agreements. This includes a targeted consent update flow (such as when minors transition to adults). During account creation, users provide standalone, explicit consent to the processing of their data by Vercel AI Gateway for real-time text generation. Users may withdraw this consent by deleting their account.
7. Counselor Integration and FERPA Notice
7.1 Three-Tier Sharing Framework
If you actively choose to link your account with a school counselor via a "Counselor Code," you participate in a three-tier sharing model:
- Limited View: High-level progress metrics and milestone completion data are shared automatically.
- Mixed View: Selected sensitive content, such as specific draft essays, is shared alongside your progress metrics when explicitly initiated by you.
- Full View: Complete visibility into your profile and materials is granted to the counselor.
7.2 Revocation and FERPA
This connection is voluntary and can be downgraded or revoked at any time. We cannot retrieve data exported prior to revocation. OlyAdmit operates strictly as a direct-to-student consumer platform; we do not act as a "school official" as defined under the Family Educational Rights and Privacy Act (FERPA).
8. Strict Confidentiality and Security
Your data is secured at the database level using Row Level Security (RLS) policies. No human reads your personal data, essays, or chat history unless you explicitly open a technical support ticket, are subject to age verification review, or unless required to respond to a verified legal obligation. In the event of a confirmed data security incident, we will notify affected users without undue delay, and no later than 72 hours after verification.
9. Cookies, Tracking, and Global Privacy Controls
9.1 Essential Cookies, Analytics, and Lifecycle
We use standard cookies and lightweight analytics tools (Supabase built-in analytics and Vercel Analytics) to maintain session security, authenticate users, and monitor platform performance. Cookie lifecycles are strictly managed to align with our authentication and session expiration protocols. We do not use third-party advertising trackers.
9.2 Session Timeout Policies
To protect account security, user sessions are subject to automatic expiration:
- Minors (13–17): 24 hours of active use, or 30 minutes of idle time.
- Adults (18+): 7 days of active use, or 1 hour of idle time.
9.3 Global Privacy Control (GPC) and DNT
OlyAdmit commits to honoring Global Privacy Control (GPC) signals. We implement both client-side (navigator.globalPrivacyControl) and server-side (Sec-GPC header) detection, both of which automatically disable Vercel Analytics when triggered. Furthermore, our baseline practices natively satisfy "Do Not Track" (DNT) goals, as we utilize zero third-party advertising trackers and strictly prohibit the sale or sharing of your data.
10. State-Specific Privacy Rights
Depending on your state of residence, you are granted specific rights regarding your personal data. OlyAdmit extends these core rights globally:
- Rights to Know, Correct, Delete, and Limit Use: You may request to access, port, correct, or delete your data, or limit the use of sensitive information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- Authorized Agents: You may designate an authorized agent to make a privacy request on your behalf.
- Minors Under 16: OlyAdmit's existing baseline protections—which outright prohibit the sale or sharing of user data—inherently satisfy the opt-in requirements for minors under 16 in California, Virginia, Colorado, and Connecticut.
- Processing Timelines & Appeals: We commit to responding to verifiable data rights requests within 45 days. If we decline a request, you may appeal by replying directly to the denial email.
11. Account Deletion and Data Retention
11.1 Account Deletion
You may terminate your account at any time. Upon confirmation, all active personal data, chat histories, and essays will be immediately and permanently deleted from production databases.
11.2 Audit Records and Backups
To satisfy GDPR and COPPA documentation requirements, a compliance record of the deletion is retained in a secure audit log (deleted_accounts_audit) for twelve (12) months on a rolling basis, after which it is securely deleted. Data stored in routine encrypted backups is overwritten within our 90-day retention cycle. We reserve the right to retain specific data if required by a legal hold or subpoena, and will notify you of such extended retention to the extent permitted by law.
11.3 Anonymized Data
We may retain completely de-identified, aggregated usage data for internal performance analysis.
12. International Users and Data Transfers
OlyAdmit is operated, processed, and hosted in the United States. By creating an account, you consent to the transfer of your information to the United States. While OlyAdmit does not target users in the European Union or the United Kingdom, our core sub-processors (Supabase, Vercel AI Gateway, and Resend) maintain Standard Contractual Clauses (SCCs) and/or participate in the EU-U.S. Data Privacy Framework to provide international transfer safeguards at the infrastructure level. OlyAdmit reserves the right to restrict access from jurisdictions where compliance is not commercially feasible.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by sending an email to the address associated with your account or by providing a prominent notice on the platform at least thirty (30) days before the changes take effect. If you do not agree with the updated policy, you may delete your account before the effective date. Continued use of the platform after the effective date constitutes acceptance of the updated Privacy Policy.
14. Contact Information
To exercise your data rights, submit an appeal, or ask questions, please contact us at privacy@olyadmit.org or through the Help Center within the OlyAdmit application.