Privacy Policy

Last updated

This policy explains what information UniPath collects, why we need it, who can see it, and the choices you have. We have tried to keep it short and clear. If anything is unclear, just ask.

1.The short version

  • UniPath helps schools, counsellors, students and parents manage university applications.
  • We collect what the service needs: your account, your school work for applications, and messages you send in the app.
  • We don't sell your information, we don't show ads, and we don't build marketing profiles.
  • Your school's counsellors and admins can see students' application work. Other students cannot.
  • Analytics only run if you say yes in the cookie banner.
  • You can ask to see, fix, download or delete your information at any time: yuldashovulugbek0@gmail.com.

2.Who we are and our role

“UniPath”, “we” and “us” mean the team that runs the UniPath service at unipath.cc. You can reach us at yuldashovulugbek0@gmail.com.

When a school uses UniPath, the school decides which students, parents and staff are invited and what the service is used for. For that school data, the school is in charge (the “controller”) and we process it on the school's behalf. If you are a student or parent at a school, you can contact your school or us, and we will work with the school to answer you.

For our own website and operations (for example sign-in security, demo requests, billing, analytics and support), we are in charge of the data.

3.What we collect

Account details

  • Name, email address, role (student, counsellor, school admin or parent) and school.
  • Your password, which is stored only as a secure hash by our sign-in provider. We can't read it.
  • A profile photo, if you add one.

Profile and application information (mostly students)

  • Optional personal details such as date of birth, gender, phone number, and a parent's name, email and phone.
  • Academic information: grades, test scores, graduation year, activities, honours, olympiads and interests.
  • Universities, programs and scholarships you save or apply to, with deadlines and application status.
  • Essays and their earlier versions, comments on essays, uploaded documents (such as transcripts or certificates), your CV and your portfolio.
  • Results from practice tools: mock exams, flashcards, the career interest (Holland) test, work preferences and the university-fit quiz.

Communication

  • Chat messages between students, parents and school staff, meeting notes, announcements and in-app notifications.
  • Recommendation requests: the teacher's name and email, and the letter they submit through their private link.
  • Demo requests from our website: your name, email, school, role, school size and message.

Connections you choose

  • If you publish your portfolio to GitHub or Vercel, we store an access token and your account username for that service so we can deploy it for you. You can revoke this access at any time in your GitHub or Vercel settings, or ask us to delete it.

Billing (schools only)

  • When a school pays, Stripe handles the card. We keep the Stripe customer ID, the school's name and the payer's email. We never see full card numbers.

Usage and technical information

  • Activity events linked to your account, such as “essay submitted”, “application status changed”, “message sent” or “mock exam submitted”. We use these to run and support the service.
  • A count of AI requests per student, so we can apply the weekly limit (see section 5), and a count of web searches per person, so we can apply a daily limit.
  • Page views and page speed, only if you accept analytics cookies.
  • Standard server logs kept by our hosting providers, such as IP address, browser type and time of request, used for security and fixing errors.

4.How we use it, and why we're allowed to

What we doLegal reason
Run your account and the features you use: applications, essays, documents, chat, meetings, practice tools, reports.To provide the service to you and your school (contract), and the school's legitimate interest in supporting its students.
Send service emails: invitations, password resets, recommendation requests and important notices.Contract.
Keep UniPath secure, prevent misuse and fix errors.Legitimate interests, and legal obligations.
Understand which pages are slow or unused (Vercel Analytics and Speed Insights).Your consent, which you can withdraw at any time.
Bill schools that subscribe.Contract and legal obligations (tax and accounting).
Answer demo requests and support questions.Legitimate interests, or steps before a contract.

We do not sell personal information, use it for advertising, or make decisions about you by automated means that have legal or similarly serious effects. University suggestions and fit scores in UniPath are guidance only.

5.AI features

Students can use two AI helpers: essay feedback and the essay assistant. Each request can include up to 8,000 characters, and each student can make up to 10 requests in any 7 days. When you use them, we send the essay title and the text you chose to an AI provider to produce a reply. We don't send your name or email with it.

Counsellors, school admins and parents don't have AI features. Our two platform administrators use AI tools to research and maintain the university catalogue. They don't send student records to these tools. New university information is checked by an administrator before it goes live.

The AI providers we use are Groq, Google (Gemini) and OpenRouter (which passes the request to the company that hosts the model). If one is unavailable, the request goes to the next. Each provider processes the text to create the reply and may keep it for a short time under its own terms, for example to detect abuse. Please don't put health details or other very sensitive information into text you send for AI feedback.

6.Who can see your information

  • You. You can see your own profile and work.
  • Your school's counsellors and school admins can see the students at their school: profiles, applications, essays, documents, reports and messages sent to them. This is how they guide you. If your school has no counsellor, a school admin or teacher with a staff account guides you instead and sees the same things.
  • Linked parents can see their own child's profile and progress, such as applications, deadlines and meetings. Parents can't see other students.
  • Other students can't see your profile details. If you opt in as an alumni mentor, students at your school can see the mentor details you share.
  • Teachers writing a recommendation see only the request sent to them.
  • Other schools never see individual records. If a school turns on shared insights, only anonymous totals are shared, and any group smaller than 5 students is hidden.
  • The public can see your portfolio only if you publish it. You can unpublish it at any time.
  • UniPath's platform administrators can access data when needed to support schools, keep the service safe, or when the law requires it.

7.Service providers we use

We use these companies to run UniPath. They may only use your information to provide their service to us.

ProviderWhat for
SupabaseDatabase, sign-in and file storage. Our database is hosted in Tokyo, Japan.
VercelWebsite hosting. Vercel Analytics and Speed Insights only with your consent.
Google (Gmail) and ResendSending service emails such as invitations and password resets.
StripePayments from schools.
Groq, Google (Gemini), OpenRouterAI essay feedback for students, and admin catalogue tools.
TavilyThe web search boxes in the app (for example on the research and activities pages). Only the words you search for are sent.
GitHub, VercelPublishing your portfolio, only if you connect your account.

We may also share information if the law requires it, to protect someone's safety, or as part of a sale or merger of UniPath (in which case this policy keeps applying).

8.International transfers

Our users live in many countries, and our providers store and process data in other countries, including Japan (our database), the United States and the European Union. When we move personal information out of the UK or EU, we rely on safeguards such as adequacy decisions or the standard contractual clauses our providers offer. You can ask us for details.

Schools in Central Asia and Mongolia

Many of our schools are in Kazakhstan, Uzbekistan, Kyrgyzstan, Tajikistan and Mongolia. When a school there uses UniPath, its students' information leaves the country and is stored abroad (see above). Please know:

  • Consent comes first. These countries' data laws generally need clear consent before personal information is collected or sent abroad, and for a child that consent usually comes from a parent or guardian. The school collects this consent before it invites a student (see Students under 18).
  • Data storage rules. Kazakhstan and Uzbekistan have rules that can require their citizens' personal information to be stored on servers inside the country. UniPath does not store data in Kazakhstan or Uzbekistan today. Before using UniPath, a school there should check with its own legal adviser whether and how these rules apply to it.
  • Keep it small. Schools can leave optional fields (such as date of birth or phone numbers) empty, and students only upload the documents their applications need.

If your school needs more detail about where data is stored, email yuldashovulugbek0@gmail.com.

9.How long we keep it

  • Account and school data: while the account is active and the school uses UniPath. When a school stops using UniPath or asks us to delete its data, we delete it, usually within 30 days.
  • Deleted accounts: when an account is deleted, its profile and the student work linked to it are removed. Messages the person sent in shared conversations may stay visible to the other people in that conversation.
  • Backups: deleted data can remain in encrypted backups for a short time until they are replaced automatically.
  • Billing records: as long as tax and accounting law requires.
  • Demo requests and support emails: up to 2 years, unless you ask us to delete them sooner.
  • Cookies: see the Cookie Policy.

10.Students under 18

Most students on UniPath are secondary-school students, so many are under 18. We take extra care:

  • UniPath is only for students aged 13 or older. If we learn that a child under 13 has an account, we delete it.
  • Students join by invitation from their school. There is no public sign-up. The school is our customer and agrees to our terms for its students.
  • Where the law requires a parent's permission (for example, under 16 in some EU countries, and for children in Kazakhstan, Uzbekistan and Mongolia), the school gets it before inviting the student. To make this easy, we offer a short parent consent form that schools can print or save as a PDF, give to parents, and keep on file.
  • Parents can be invited with their own account to follow their child's progress, and can ask their school or us to see, correct or delete their child's information.
  • We don't show ads, sell data, or use students' information for marketing. AI use by students is limited as described in section 5.

11.Your rights

Depending on where you live (for example under the GDPR in the EU or UK GDPR), you have the right to:

  • get a copy of your information;
  • correct information that is wrong;
  • ask us to delete your information;
  • limit or object to how we use it;
  • receive your information in a common format to take elsewhere;
  • withdraw consent at any time, such as for analytics cookies.

To use any of these rights, email yuldashovulugbek0@gmail.com from the address on your account. We may need to confirm who you are. We reply within one month. If your account belongs to a school, we may pass your request to the school and help them answer it.

If you are not happy with our answer, you can complain to your data protection authority, for example the ICO in the UK or the authority in your EU country.

12.Deleting your account

To delete your account, ask your school's counsellor or admin, or email yuldashovulugbek0@gmail.com. We will confirm the request and delete the account and its data as described in section 9. If you only want to stop sharing your portfolio, you can unpublish it yourself on your portfolio page.

13.How we protect it

  • All traffic uses HTTPS encryption.
  • Database rules make sure each person can only read the records their role allows.
  • Documents are kept in private storage, not on public links.
  • Only a small number of staff can access the systems, and only when needed.

14.Changes to this policy

We will update this page when our practices change and change the date at the top. If a change is important, we will tell schools and signed-in users before it takes effect.

15.Contact

For any privacy question or request, email yuldashovulugbek0@gmail.com.

Questions? Email yuldashovulugbek0@gmail.com.