Loading...
Loading...
Last Updated: August 12, 2026
OlyAdmit treats student privacy as a first-class design requirement. We collect only the information needed to deliver AI college counseling, scholarship matching, and essay feedback. We do not sell personal information, do not share it for cross-context behavioral advertising, and contractually prohibit our sub-processors from using user data to train public AI models.
The platform is built around passwordless authentication, Row Level Security (RLS), age-differentiated sessions, and a three-consent architecture for the Terms of Service, Privacy Policy, and AI Data Processing Agreement. We honor Global Privacy Control (GPC) signals and do not use third-party advertising trackers or cookies.
We share personal data only with the third-party service providers required to operate the platform. All sub-processors are contractually bound by Data Processing Agreements (DPAs) that require comparable privacy and security safeguards. We will notify users at least 30 days before onboarding any new sub-processor that handles personal data.
| Sub-Processor | Role | Data Shared / Processed | DPA / Safeguards | Retention |
|---|---|---|---|---|
| Supabase | Cloud database, authentication, rate limiting | Account profiles, educational data, usage logs, consent records | DPA in force through ToS (effective 2026-08-01); SOC 2 Type II; SCCs for EU/UK/Swiss; 48-hour breach notice | Duration of account; routine encrypted backups overwritten within 90 days |
| Vercel AI Gateway | Enterprise AI routing and inference | Conditionally transmitted profile context and essay/chat content after sensitive-category filtering | DPA in force; Zero Data Retention (ZDR) enforced by model selection; all inference routed exclusively to AWS Bedrock through single-provider routing using Vercel-managed API keys | No retention; not used for model training |
| AWS Bedrock | Underlying AI provider (Vercel sub-processor) | Same as Vercel AI Gateway; OlyAdmit has no direct contractual relationship | Covered under the Vercel DPA; contractually prohibited from retaining prompts, storing outputs, or using data for model training | No retention; not used for model training |
| Vercel | Frontend hosting and platform analytics | Website assets, request/response data, aggregated analytics | Base DPA in force through ToS; Vercel Pro active; SOC 2 Type II; edge network with HSTS and DDoS protection | Per DPA; Vercel Analytics is disabled when a GPC signal is detected |
| Sentry | Error tracking and performance monitoring | Error events after personal data is programmatically stripped by beforeSend hooks; Session Replay is disabled | DPA v5.1.0 in force; SOC 2 Type II | 30 days under the active Sentry plan |
| Didit | Age and identity verification | Facial geometry and government ID are processed on Didit infrastructure; OlyAdmit receives and stores only the verification result, method, and timestamp | DPA in force (2026-07-16); COPPA-compliant age verification; biometric data never transmitted to or retained by OlyAdmit | Didit destroys biometric data within 30 days; OlyAdmit result retained for account duration |
| Resend | Transactional email delivery | Email addresses for welcome emails, counselor invitations, and parent activity reports | DPA in force through ToS; EU-U.S. Data Privacy Framework certified; SCCs for UK/EU transfers | 90 days post-account termination |
| Zoho Mail | Business email hosting | Emails sent to privacy@olyadmit.org and hello@olyadmit.org | DPA in force through ToS (submitted 2026-08-06) | Per Zoho Mail terms |
Some third parties operate as independent data controllers, meaning they determine the purposes and means of their own processing. No DPA is required for controller-to-controller transfers.
| Provider | Role | Data Shared | Why No DPA |
|---|---|---|---|
| Google OAuth | Authentication provider | Email address, display name, email verification status, profile picture URL, and Google account ID. OlyAdmit strictly stores only your email address. | Independent controller governed by Google's Privacy Policy and your direct consent |
| Discord OAuth | Authentication provider | Email, username, discriminator, avatar hash, Discord user ID, and locale. OlyAdmit strictly stores only your email address. | Independent controller governed by Discord's Privacy Policy and your direct consent |
| Stripe | B2B payment processing (counselor subscriptions) | Payment card data for counselor subscriptions, when B2B payments are live | Will operate as an independent controller for payment card data under PCI DSS. A DPA has not yet been executed because B2B payments are not yet live; DPA is pending. |
OlyAdmit uses a dual-model architecture powered by Vercel AI Gateway, with all inference served exclusively through AWS Bedrock using single-provider routing:
Both models natively guarantee Zero Data Retention (ZDR). We conditionally transmit only the profile context that is relevant to your current feature or prompt. This may include graduation year, GPA, interests, residency (for college and scholarship matching contexts), test scores, recent grades, activities, career goals, and current date metadata.
We explicitly do not transmit the following to any AI model: first name, last initial, school name, birthday, email, ethnicity, family background, finances, or other unnecessary personal identifiers. Chat history uses a five-message rolling window, and sensitive-category messages are filtered before transmission. Your data is never used to train or fine-tune public foundational models.
OlyAdmit does not use third-party advertising cookies or cookie-based behavioral tracking. We use only essential session cookies required for authentication and security. Vercel Analytics is used for lightweight platform performance monitoring and is automatically disabled when a Global Privacy Control (GPC) signal is detected on either the client or the server.
OlyAdmit is hosted and operated in the United States. By creating an account, you consent to the transfer and processing of your information in the United States. Our core sub-processors maintain Standard Contractual Clauses (SCCs), participate in the EU-U.S. Data Privacy Framework, and/or provide equivalent transfer safeguards for international data flows.
Depending on your location, you have the right to know, access, correct, delete, port, and limit the use of your personal data. OlyAdmit extends these rights to all users globally. We aim to respond to verifiable requests within 45 days.
You may delete your account at any time. Account deletion triggers an immediate hard-delete of personal data, essays, and chat content from production databases. Deleted-account audit records are retained for 12 months solely to document COPPA and GDPR compliance, after which they are securely deleted. Routine encrypted backups are overwritten within 90 days.
To exercise your rights or ask questions, email privacy@olyadmit.org. For the full legal framework, please review our Privacy Policy and Terms of Service.