Privacy Policy
1. Overview
Admitly ("we," "us," or "our") operates the Platform at admitly.com — a college admissions planning tool for students, families, and educational counselors. This Privacy Policy describes how we collect, use, store, share, and protect personal information from users of the Platform ("you" or "your").
By using the Platform, you consent to the data practices described in this policy. If you do not agree, please do not use the Platform.
2. Information We Collect
2.1 Information You Provide Directly
| Category | Examples | Purpose |
|---|---|---|
| Account Data | Name, email address, password, profile username | Account creation & authentication |
| Academic Profile | GPA, test scores, extracurriculars, grade level, intended major | College matching & readiness scoring |
| Application Content | College essays, drafts, notes, supplemental responses | Essay review features, storage |
| College List | Target schools, application status, deadlines | Deadline tracking, dashboard |
| Communications | Messages with counselors, support tickets, feedback | Platform functionality, support |
| Payment Data | Billing information (processed by Stripe — we do not store raw card data) | Payment processing |
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, clicks, session duration, and navigation paths
- Device & Technical Data: IP address, browser type, operating system, device identifiers, and screen resolution
- Log Data: Server logs including timestamps, error logs, and access records
- Cookies & Similar Technologies: See Section 7 for details
2.3 Information from Third Parties
- OAuth Sign-In: If you sign in via Google or Apple, we receive your name, email address, and profile picture from that service
- Analytics Providers: Aggregated and anonymized usage data from tools like Google Analytics
- Counselor-Provided Data: If a counselor adds you to the platform, they may provide your name and email address
3. How We Use Your Information
We use your personal information for the following purposes:
- Providing & Improving the Platform: Operating, maintaining, debugging, and enhancing features
- Personalization: Generating college match scores, readiness indicators, and tailored recommendations
- AI Features: Processing essay content through AI models to provide feedback and suggestions (see Section 6)
- Communications: Sending service-related emails (account confirmations, deadline reminders, security alerts). We will not send marketing emails without your explicit opt-in consent.
- Customer Support: Responding to inquiries, troubleshooting, and resolving disputes
- Analytics & Research: Understanding usage patterns to improve the product (using aggregated or anonymized data where possible)
- Legal Compliance: Complying with applicable laws, regulations, and lawful requests from authorities
- Safety & Security: Detecting and preventing fraud, abuse, and violations of our Terms of Service
- Payments: Processing transactions and managing billing
We will not sell, rent, or trade your personal information to third parties for their marketing purposes.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal bases for processing your personal data are:
- Contract Performance: Processing necessary to provide the services you have requested
- Legitimate Interests: Improving the Platform, ensuring security, and communicating about service updates
- Legal Obligation: Complying with applicable laws and regulations
- Consent: Where required (e.g., marketing communications, non-essential cookies) — you may withdraw consent at any time
5. Sharing & Disclosure of Information
We do not sell your personal information. We may share your information in the following limited circumstances:
Service Providers
We share data with trusted third-party vendors who assist us in operating the Platform, including hosting providers, payment processors (Stripe), email delivery services, analytics tools, and AI infrastructure providers. These parties are contractually required to protect your data and use it only for the purposes we specify.
Counselor Access
If you use the counselor collaboration feature, your profile data, essays, and application progress may be visible to your assigned counselor(s). You consent to this sharing when you enable the feature or accept a counselor invitation.
Legal Requirements
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a legal obligation.
Business Transfers
In the event of a merger, acquisition, reorganization, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity. We will notify you via email and/or a prominent notice on the Platform prior to the transfer, giving you an opportunity to opt out.
Aggregated / De-Identified Data
We may share aggregated or de-identified data (data that cannot reasonably be used to identify you) for research, industry analysis, or product improvement purposes.
6. AI Processing & Your Content
- Essay content submitted for AI review is processed to generate feedback. We do not use your personal essays to train AI models without your explicit, separate consent.
- AI processing may involve transmission of data to third-party AI infrastructure providers (e.g., OpenAI). These providers are bound by data processing agreements and are not permitted to use your data for their own model training.
- AI-generated outputs (scores, feedback, suggestions) are stored in your account for your reference but are not shared with colleges or third parties without your action.
- You may delete your essay content at any time through your account settings.
7. Cookies & Tracking Technologies
We use cookies and similar tracking technologies to operate and improve the Platform. The types of cookies we use include:
| Type | Purpose | Can be disabled? |
|---|---|---|
| Essential | Session management, authentication, security (CSRF tokens) | No — required for Platform to function |
| Functional | Remembering preferences, language, and UI state | Yes, with reduced functionality |
| Analytics | Understanding usage patterns (e.g., Google Analytics) | Yes — via cookie preferences |
| Marketing | We do not currently use marketing or advertising cookies | N/A |
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect Platform functionality. We honor "Do Not Track" (DNT) signals from browsers where technically feasible.
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services, comply with legal obligations, resolve disputes, and enforce our agreements.
- Active accounts: Data retained for the duration of your account
- Deleted accounts: Most personal data deleted within 30 days of account deletion; some data may be retained longer to comply with legal, tax, or regulatory obligations
- AI-processed content: Deleted upon user request or account deletion
- Logs & analytics: Retained in aggregated or anonymized form for up to 24 months
- Payment records: Retained for 7 years for tax and regulatory compliance
9. Security
We implement industry-standard technical, administrative, and physical safeguards to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit using TLS/HTTPS
- Encryption of sensitive data at rest
- Access controls and authentication requirements for internal systems
- Regular security assessments and vulnerability testing
- Secure password hashing (we never store plaintext passwords)
10. Children's Privacy (COPPA)
The Platform is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13 without verifiable parental consent.
Users between the ages of 13 and 17 must have parental or guardian consent to use the Platform. If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us at privacy@admitly.com. We will promptly delete such information upon verification.
11. Student Data & FERPA
Admitly recognizes that some users may be students whose educational records are protected under the Family Educational Rights and Privacy Act (FERPA). In cases where Admitly operates as a "school official" with a "legitimate educational interest" under FERPA (e.g., when providing services to a school or institution), we:
- Use student data solely to provide and improve the Platform services contracted by the school
- Do not disclose student education records to unauthorized third parties
- Do not use student data for advertising or marketing unrelated to the educational service
- Provide schools and institutions with the ability to request deletion of student data
- Comply with applicable state student data privacy laws
Individual students using the Platform independently (not through a school) are not subject to FERPA in the same manner, but their data is protected under this Privacy Policy.
12. Your Privacy Rights
Depending on your location, you may have the following rights with respect to your personal information:
🔍 Access
Request a copy of the personal data we hold about you.
✏️ Correction
Request correction of inaccurate or incomplete personal data.
🗑️ Deletion
Request deletion of your personal data ("right to be forgotten"), subject to legal obligations.
📦 Portability
Receive your data in a structured, machine-readable format.
🚫 Objection
Object to processing of your data for certain purposes, including direct marketing.
⏸️ Restriction
Request restriction of processing in certain circumstances.
↩️ Withdraw Consent
Where processing is based on consent, withdraw it at any time.
📋 Opt-Out
Opt out of marketing emails at any time via the unsubscribe link or account settings.
To exercise any of these rights, please contact us at privacy@admitly.com. We will respond to verified requests within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.
13. California Residents — CCPA Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request information about the categories and specific pieces of personal information we have collected, the sources, purposes, and third parties with whom we have shared it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale: Admitly does not sell personal information. However, you may submit a "Do Not Sell or Share My Personal Information" request at privacy@admitly.com.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
- Right to Correct: You may request correction of inaccurate personal information.
- Sensitive Personal Information: We do not use or disclose sensitive personal information for purposes beyond those permitted by the CPRA.
To submit a California privacy request, contact privacy@admitly.com or use your account settings. We will verify your identity before processing requests.
14. International Data Transfers
Admitly is based in the United States. If you access the Platform from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. These countries may have data protection laws that differ from those in your country.
For transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) adopted by the European Commission, or other legally recognized transfer mechanisms. By using the Platform, you consent to this transfer, processing, and storage of your information.
15. Third-Party Services
The Platform may contain links to third-party websites and may integrate with third-party services. This Privacy Policy does not apply to those external services. We encourage you to review the privacy policies of any third-party services you use in connection with the Platform.
Key third-party services we use include:
- Stripe — Payment processing (Stripe Privacy Policy)
- Google Analytics / Google Tag Manager — Usage analytics (Google Privacy Policy)
- OpenAI — AI-powered features (OpenAI Privacy Policy)
- Google / Apple OAuth — Authentication (subject to their respective privacy policies)
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and, where required by law, provide notice via email or a prominent in-Platform notification.
We encourage you to review this policy periodically. Your continued use of the Platform after the effective date of any changes constitutes acceptance of the updated policy.
17. Contact Us & Data Protection Officer
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Admitly Privacy Team
Email: privacy@admitly.com
General Support: support@admitly.com
Website: admitly.com
If you are located in the EEA or UK and have unresolved concerns, you have the right to lodge a complaint with your local supervisory authority (e.g., your national Data Protection Authority).