Privacy Policy

What we collect, why, who processes it, and the rights you have over it.

1. Overview

NotCollege helps U.S. high schoolers explore non-degree career paths. We collect the minimum data needed to run the service. We do not sell user data. We do not run advertising or third-party tracking. We are not sponsored by trade schools, community colleges, apprenticeship programs, or any third party whose programs appear in our corpus.

2. Data We Collect

  • Name (the name you enter at signup — used only to address you; you may use any name or nickname)
  • Email address (required for account creation; used for email verification and password reset)
  • Password (stored as a bcrypt hash; we never see your plain-text password)
  • Account type (currently a single value: student)
  • Saved paths (the career paths you choose to save to your account; you can remove them at any time)
  • IP address and user agent (collected on login/signup attempts for rate limiting and abuse prevention; retained for 7 days then deleted)
  • First-party analytics events (aggregate usage — e.g. which pages are viewed or paths saved — recorded with a random id stored in your browser, not a tracking cookie; see Section 3)
  • Browser session data (httpOnly cookie containing your session token)
  • Error monitoring data (when the application throws an error, we capture the stack trace via Sentry, configured to mask text input and scrub PII before ingest)

3. Analytics & What We Do NOT Collect

We run our own first-party, cookieless analytics to understand aggregate product usage (page views, guided-match starts, paths saved). It uses a random identifier stored in your browser's localStorage — not a tracking cookie — and never follows you to other websites. We do not use Google Analytics or any third-party analytics/ad network.

We also do NOT collect:

  • Your date of birth (we do not verify age — NotCollege is intended for 16+ but we do not gate by age)
  • Your school name
  • Your street address or phone number
  • Precise location
  • Any cross-site tracking, advertising identifiers, or tracking pixels

4. How We Use Your Data

  • Name: to address you in the app and in emails.
  • Email: to verify your account, send password-reset links, and — only if you opt in — occasional saved-path reminder emails (off by default; unsubscribe in any message or in Settings → Privacy). We do not send other marketing email.
  • Saved paths: to show your shortlist on your dashboard and, if you create a share link, to display it to whoever you share that link with.
  • First-party analytics: aggregate product improvement only — never sold or shared, never used to build an advertising profile.
  • IP and user agent: rate limiting, abuse prevention, debugging.

5. Third-Party Data Processors

We use the following services. Each is named explicitly so you know exactly who has access to what. We do not send your data to any third-party AI service — the guided match runs on our own servers (Section 6).

  • Supabase — hosts our database and authentication. Your account and saved paths are stored in their PostgreSQL infrastructure.
  • Vercel — hosts and serves the web application. Your requests pass through their CDN and serverless functions.
  • Upstash (Redis) — stores rate-limit counters and short-term cache data. No personally identifying data stored here.
  • Resend — sends transactional and (opt-in) reminder emails. Your email address is shared with Resend at send time.
  • Sentry — monitors application errors. Session replay is disabled and request bodies are scrubbed server-side before ingest, so your input and other PII are not captured in error reports.
  • Stripe — payment processor. Currently inactive — no payment data collected.

6. How the Guided Match Works (No AI Processing)

  • The guided match is deterministic: it scores our public, BLS-verified career corpus against the answers you pick, entirely on our own servers.
  • It uses no AI model and sends nothing to any third-party AI service.
  • Your questionnaire answers and results are not stored — they exist only in your browser for the length of the session. Saving a path is a separate, explicit action (Section 2).

7. Data Retention

  • Account data (name, email, account type): retained while your account is active.
  • Saved paths: retained while your account is active; remove any at any time.
  • First-party analytics events: retained in aggregate for product analysis.
  • Login/signup attempt logs: 7 days, then deleted.
  • Webhook event logs: 90 days, then deleted.
  • Audit logs: 2 years, then deleted.
  • After account deletion: all data deleted within 30 days. Some data may persist in encrypted backups for up to 90 days before automated purge.

8. Your Rights (GDPR + CCPA)

  • Access: download all your data via Settings → Privacy → Export My Data.
  • Rectification: update your name in Settings → Profile. To change your email address, contact privacy@notcollege.app — we intentionally do not allow self-service email changes to prevent account takeover. We respond within 5 business days.
  • Erasure: delete your account via Settings → Privacy → Delete My Account (full account erasure).
  • Portability: the data export endpoint returns JSON (machine-readable).
  • Objection / Restriction: contact privacy@notcollege.app to object to or restrict specific processing.

9. Accuracy Disclaimer

  • The guided match and path pages present information from our BLS-verified corpus. They are informational only — NOT professional career counseling, legal, financial, or medical advice.
  • Wage figures come from the BLS Occupational Outlook Handbook and OEWS, documented with verification dates in our corpus. Actual wages vary by location, employer, experience, and individual circumstances.
  • Workforce Pell state status is based on publicly available sources. Verify with your state's workforce agency before enrolling in any program.

10. Children's Privacy

NotCollege is designed for users 16 and older (typical high school junior and senior age). We do not knowingly collect data from users under 13. We do not actively verify user age. Parents and guardians concerned about their child's use of NotCollege should contact privacy@notcollege.app.

11. Changes to This Policy

We will email all account holders 30 days before any material change. The current version date is shown at the bottom of this page.

12. Contact

  • Privacy requests: privacy@notcollege.app
  • General contact: hello@notcollege.app

This privacy policy was last updated: August 19, 2026.

See also our Terms of Service.