AcademicPilot

Last updated September 6, 2026

Privacy Policy

1. Data controller

2. Personal information we process

2.1 Information you provide

2.2 Information processed automatically

3. Browser-local information

CV drafts and versions, saved advisor lists, advisor search state, admissions checks, application tracker records, outreach versions, and outreach chat history are stored in browser local storage rather than our application database. They remain on that browser until you delete them or clear browser storage. Switching devices or browsers, using private browsing, or clearing site data can make them unavailable unless you exported them.

Browser-local content is transmitted to our server only when needed for an action you initiate, such as AI generation, editing, URL checking, or payment/account operations.

4. How and why we use information

We do not sell personal information and do not use your application content for targeted advertising. We do not currently send marketing messages without a separate opt-in.

5. AI processing

When you run an AI feature, the input required for that request passes through our Vercel-hosted server and is sent to OpenAI. Depending on the feature, input may include your current block or draft, CV text, advisor or program information, retrieved public webpage text, research interests, and your instruction. We use this content to return the requested result, secure the request, and diagnose failures. We do not add the full AI prompt or generated document to our application database, and we do not use it to train our own models.

Advisor and admissions research may use OpenAI background processing so a long search can continue while your browser polls for completion. OpenAI temporarily stores the response state needed for polling, currently for approximately ten minutes. AcademicPilot stores only task metadata such as the response identifier, status, model, request hash, and credit event; it does not store the underlying research description or admissions notes in the task record.

OpenAI and infrastructure providers may process limited content and logs under their applicable terms, privacy commitments, and retention controls. Do not submit information you are not authorized to process or information unnecessary for the requested result.

6. Local storage and similar technologies

AcademicPilot uses browser storage for authentication sessions, language preferences, anti-abuse identifiers, and your locally saved application work. These technologies are necessary or functional; we do not currently use advertising cookies. Cloudflare Turnstile may process device and network signals to distinguish people from automated abuse. Google Fonts may receive ordinary request metadata when fonts load from its servers.

7. Service providers and disclosure

We disclose only the information reasonably required for the following providers to perform their services:

We may also disclose information when required by valid law or legal process, to protect users and the Service, during a corporate transaction subject to continued safeguards, or with your consent. Payment-card data is processed by Waffo Pancake and does not pass through AcademicPilot servers.

8. Security

We use HTTPS encryption in transit, Supabase authentication and row-level access controls, server-side API secrets, signed payment webhooks, rate limits, CAPTCHA, and hashed anti-abuse identifiers. Access is restricted according to operational need. No online system is completely secure, so you should protect your credentials and avoid storing unnecessary sensitive information. Where required by law, we will notify affected users and competent authorities of a qualifying breach within the applicable deadline.

9. Retention

Retention periods may be shortened where the information is no longer needed or extended for fraud prevention, payment disputes, tax, litigation holds, or other legal requirements.

10. Your rights and choices

Depending on your location, you may request access, correction, deletion, restriction, objection, withdrawal of consent, or a portable copy of eligible personal information. You may also complain to your local privacy regulator. Send a request from your registered email to support@academicpilot.com. We aim to respond within 30 calendar days, subject to identity verification and applicable law.

You can export locally stored work using available product controls and remove it by deleting saved versions or clearing AcademicPilot site data in your browser. Essential account, security, payment, and policy notices cannot be opted out of while the account remains active.

11. International transfers

We operate from China and use service providers whose systems may be located in the United States and other regions. Information may therefore be processed outside your country. Where applicable law requires it, we use contractual, organizational, and technical safeguards and limit transfers to what is necessary to provide the Service.

12. Children's privacy

The Service is intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.

13. Third-party websites

The Service links to universities, faculty pages, publications, and other third-party sites. Their privacy practices are outside our control. Review their policies before providing information or relying on their services.

14. Changes and contact

We may update this Policy as our practices, vendors, or legal obligations change. For material changes, we will provide at least 14 days' advance notice by registered email or a prominent in-product notice where reasonably practicable and update the date at the top.