Effective July 1, 2026
Privacy notice
What we collect
The waitlist collects your email address, consent timestamp, and 18+ self-attestation with timestamp and version. Optional fields include first name, college, graduation year, intended major, biggest financial concern, referral source, referral code, UTM fields, and source subreddit when supplied.
What we do not collect
The waitlist does not collect GPA, loan balances, income, Social Security numbers, financial-account credentials, bank or brokerage credentials, date of birth, government ID, exact age, or detailed personal financial data.
How we use data
We use waitlist data to send product updates, understand aggregate launch interest, manage referral attribution, and protect the form from abuse. Cloudflare Turnstile and basic rate limiting are used for bot and abuse prevention.
Analytics and logs
No analytics integration is required for this release. If analytics is added later, form-field autocapture should remain disabled and form values should not be collected. Application logs must not include email addresses, names, college names, referral text, or other personal form values.
Storage and access
Waitlist data is stored in Supabase Postgres with Row Level Security enabled. Public clients do not have read access. Inserts are handled through a server-side route after validation, rate limiting, and bot verification. Authenticated app access stores only minimal onboarding progress, consent records, and data request records; onboarding drafts and mock plans stay in browser session storage.
Export requests
Authenticated users can request a JSON export from Settings. The export covers server data only. Browser session-only onboarding drafts, mock plans, dashboard edits, and mock coach messages are not server data and are not included.
Deletion requests
Authenticated users can request deletion from Settings. The current flow deletes app progress, consent records, and the linked waitlist row; deleting the Supabase Auth identity remains a manual/admin step. If you only joined the waitlist, email privacy@example.com from the email address you used to join the waitlist, or include that email address in your request so the record can be located.