Last updated September 6, 2026
Privacy Policy
This Policy explains what AcademicPilot processes, what remains only in your browser, who receives data, and how to exercise your privacy rights.
CV versions, saved advisors, admissions checks, application tracker records, and outreach drafts are stored in your browser. When you deliberately run an AI feature, the content required for that request is transmitted for processing as described below.
1. Data controller
海口龙华区沃展铭信息咨询工作室(个体工商户)Entity type: individually owned business registered in China
Registered business location: 海南省海口市龙华区龙桥镇昌荣村60号215室 (Room 215, No. 60, Changrong Village, Longqiao Town, Longhua District, Haikou, Hainan, China)
Privacy and support email: support@academicpilot.com
Data Protection Officer: Not applicable
2. Personal information we process
2.1 Information you provide
- Account information: email address, authentication identity, account status, plan, Terms acceptance, and Google basic profile information when you choose Google sign-in. Authentication is handled by Supabase; AcademicPilot does not receive your Google password or store your raw account password.
- Application content: research descriptions, advisor or program information, CV content, research ideas, and outreach drafts that you enter or upload.
- URL content: URLs you submit and publicly accessible page text retrieved at your request.
- Support communications: messages, attachments, feedback, and other information you send to our support mailbox.
- Payment information: order identifier, product, amount, currency, payment status, credits granted, and limited payment-method summary. Full payment-card numbers are handled by Waffo Pancake and are not stored by AcademicPilot.
2.2 Information processed automatically
- Usage and credit records: feature used, model, token counts, credits charged or refunded, request status, timestamps, and technical errors.
- Security information: IP address, browser identifier, CAPTCHA result, authentication events, and rate-limit signals. Where described in our anti-abuse system, email, identity, IP, and browser signals are stored as keyed hashes rather than raw values.
- Operational logs: request timestamps, network metadata, deployment logs, and performance or error records generated by hosting and service providers.
3. Browser-local information
CV drafts and versions, saved advisor lists, advisor search state, admissions checks, application tracker records, outreach versions, and outreach chat history are stored in browser local storage rather than our application database. They remain on that browser until you delete them or clear browser storage. Switching devices or browsers, using private browsing, or clearing site data can make them unavailable unless you exported them.
Browser-local content is transmitted to our server only when needed for an action you initiate, such as AI generation, editing, URL checking, or payment/account operations.
4. How and why we use information
| Purpose | Basis |
|---|---|
| Provide accounts, AI tools, credits, and payments | Perform our contract |
| Process support and service requests | Contract and legitimate interests |
| Prevent duplicate trials, fraud, spam, and attacks | Legitimate interests and legal obligations |
| Maintain reliability, troubleshoot, and measure costs | Legitimate interests |
| Send verification, security, billing, and policy notices | Contract, legitimate interests, and legal obligations |
| Meet tax, accounting, dispute, and regulatory duties | Legal obligations |
We do not sell personal information and do not use your application content for targeted advertising. We do not currently send marketing messages without a separate opt-in.
5. AI processing
When you run an AI feature, the input required for that request passes through our Vercel-hosted server and is sent to OpenAI. Depending on the feature, input may include your current block or draft, CV text, advisor or program information, retrieved public webpage text, research interests, and your instruction. We use this content to return the requested result, secure the request, and diagnose failures. We do not add the full AI prompt or generated document to our application database, and we do not use it to train our own models.
Advisor and admissions research may use OpenAI background processing so a long search can continue while your browser polls for completion. OpenAI temporarily stores the response state needed for polling, currently for approximately ten minutes. AcademicPilot stores only task metadata such as the response identifier, status, model, request hash, and credit event; it does not store the underlying research description or admissions notes in the task record.
OpenAI and infrastructure providers may process limited content and logs under their applicable terms, privacy commitments, and retention controls. Do not submit information you are not authorized to process or information unnecessary for the requested result.
6. Local storage and similar technologies
AcademicPilot uses browser storage for authentication sessions, language preferences, anti-abuse identifiers, and your locally saved application work. These technologies are necessary or functional; we do not currently use advertising cookies. Cloudflare Turnstile may process device and network signals to distinguish people from automated abuse. Google Fonts may receive ordinary request metadata when fonts load from its servers.
7. Service providers and disclosure
We disclose only the information reasonably required for the following providers to perform their services:
- Vercel: website hosting, serverless processing, delivery, and operational logs.
- Supabase: authentication, account profiles, usage, credits, payment records, and security controls.
- OpenAI: AI request processing and output generation.
- Cloudflare: Turnstile CAPTCHA and abuse prevention.
- Waffo Pancake: checkout, payment-card processing, tax handling where applicable, payment events, and refunds.
- Resend: delivery of authentication email initiated through Supabase.
- Zoho Mail: support mailbox and customer communications.
- Google: optional Google sign-in and web-font delivery.
We may also disclose information when required by valid law or legal process, to protect users and the Service, during a corporate transaction subject to continued safeguards, or with your consent. Payment-card data is processed by Waffo Pancake and does not pass through AcademicPilot servers.
8. Security
We use HTTPS encryption in transit, Supabase authentication and row-level access controls, server-side API secrets, signed payment webhooks, rate limits, CAPTCHA, and hashed anti-abuse identifiers. Access is restricted according to operational need. No online system is completely secure, so you should protect your credentials and avoid storing unnecessary sensitive information. Where required by law, we will notify affected users and competent authorities of a qualifying breach within the applicable deadline.
9. Retention
| Category | Retention |
|---|---|
| Browser-local application documents | Until you delete them or clear browser storage |
| Account, usage, and credit records | While active; deleted or anonymized after a verified deletion request unless another period below applies |
| Payment and accounting records | Up to 7 years, or longer when required by applicable law or an unresolved dispute |
| Signup-attempt security records | Normally 14 days |
| Unsuccessful trial-attempt records | Normally 90 days |
| Successful trial anti-abuse record | Up to 3 years after account deletion, stored as keyed identifiers |
| Support communications | Up to 2 years after resolution, unless needed for a dispute or legal duty |
| Infrastructure logs | According to provider settings and operational need, normally no longer than 12 months |
Retention periods may be shortened where the information is no longer needed or extended for fraud prevention, payment disputes, tax, litigation holds, or other legal requirements.
10. Your rights and choices
Depending on your location, you may request access, correction, deletion, restriction, objection, withdrawal of consent, or a portable copy of eligible personal information. You may also complain to your local privacy regulator. Send a request from your registered email to support@academicpilot.com. We aim to respond within 30 calendar days, subject to identity verification and applicable law.
You can export locally stored work using available product controls and remove it by deleting saved versions or clearing AcademicPilot site data in your browser. Essential account, security, payment, and policy notices cannot be opted out of while the account remains active.
11. International transfers
We operate from China and use service providers whose systems may be located in the United States and other regions. Information may therefore be processed outside your country. Where applicable law requires it, we use contractual, organizational, and technical safeguards and limit transfers to what is necessary to provide the Service.
12. Children's privacy
The Service is intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.
13. Third-party websites
The Service links to universities, faculty pages, publications, and other third-party sites. Their privacy practices are outside our control. Review their policies before providing information or relying on their services.
14. Changes and contact
We may update this Policy as our practices, vendors, or legal obligations change. For material changes, we will provide at least 14 days' advance notice by registered email or a prominent in-product notice where reasonably practicable and update the date at the top.
Privacy and support: support@academicpilot.com海口龙华区沃展铭信息咨询工作室(个体工商户)
Registered business location: 海南省海口市龙华区龙桥镇昌荣村60号215室 (Room 215, No. 60, Changrong Village, Longqiao Town, Longhua District, Haikou, Hainan, China)
Website: https://academicpilot.com
AcademicPilot