Privacy Policy

Last updated: September 2026

The short version: your work is yours, we do not sell it, we do not train AI models on it, and your counselor can see that you are progressing without reading what you wrote.

1. Who we are, and which hat we are wearing

GradLaunch AI (“GradLaunch”, “we”, “us”) provides career and college planning software for high school students, college students, the families who support them, and the counselors who run their caseloads. It is used through our website at gradlaunchai.com and our Chrome extension.

There are two ways an account exists, and they are governed differently.

  • Through a school or district. The school decides what we hold and what we may do with it. We act as its service provider, and under FERPA we operate as a school official with a legitimate educational interest, performing a function the school would otherwise perform itself. We use school data only to provide the service to that school. Where a district signs a data privacy agreement with us, that agreement governs and prevails over this policy.
  • Directly, as an individual or family. We are the controller of that account, and this policy is the agreement.

2. What we collect

  • Account data. Name, email address and authentication identifiers, handled by our sign-in provider. We never receive or store your password.
  • What you tell us about yourself. School, graduation year, target role and industries, the plan you have after high school, and anything you write into onboarding or the career conversation.
  • Your work. Resumes, cover letters, college lists, application checklists, activities, scholarships, recommender requests, and essay drafts, including versions as they change.
  • Pages you ask the extension to read. When you press Sync on a job posting or Read this page on a college site, the visible text of that page is sent to us to answer that request. The extension does not read pages in the background, and it does not track your browsing.
  • Connected accounts, if you connect them. Google Drive or Sheets, Microsoft, and Google Classroom. We store an encrypted access token and only the data needed for the feature you switched on.
  • School records, from the school. If your district provides GradLaunch, it may supply roster information such as name, school email, grade level, campus and classroom.
  • Operational data. Subscription and billing status, feature usage needed to run and secure the service, and error logs.

We do not collect precise location, we do not buy data about you from brokers, and we do not use tracking pixels to follow you around other websites.

3. What we do with it

  • Run the product you signed up for, and keep your work where you left it.
  • Produce the coaching, scoring and drafting features you ask for, one request at a time.
  • Show your counselor progress, within the limits in section 5.
  • Bill you, if you pay us directly, and keep the service secure and working.
  • Answer you when you contact us.

We do not sell student data, and we do not advertise to students. We do not use student work to train AI models, and we do not permit our AI providers to train their models on it.

4. How AI processing works

Some features send text you have chosen to work on, such as a resume, a cover letter draft or an essay, to an AI provider so it can produce that specific response. It is sent to answer your request and for no other purpose.

Essay tools coach rather than write. They ask questions, point at sentences you wrote, and count words. They do not return prose for you to submit as your own. This is a design boundary, not a setting.

Our AI provider is OpenAI, and voice replies are generated by ElevenLabs. Data sent through their APIs is not used to train their models. OpenAI may retain API inputs and outputs for up to thirty days for abuse monitoring before deleting them, and neither provider may use the content for any other purpose.

Coursework read from a connected Google Classroom account is not sent to an AI provider.

5. Scores the AI produces about you

The onboarding call ends by scoring five things out of 100 - direction, self-knowledge, plan, experience and confidence - along with a short written snapshot. The scores are produced by the AI from what you said in that conversation. If your school provides GradLaunch, your counselor can see them.

What they are for. They tell a counselor which conversation to have with you next. They are a starting point for that conversation, not a judgment about you.

What they are not. They are not a grade, they do not go on any record outside GradLaunch, they are not shared with colleges or employers, and nothing in the product is decided automatically because of them. No one is admitted, rejected, placed or denied anything on the basis of a score.

They can be wrong. They come from one conversation on one day, and the AI that produced them can misread you. You can ask a human at your school to look at them with you, tell us they are wrong, ask us to correct them, ask us to delete them, or retake the call. Write to us or ask your counselor.

6. What your school can see

If your school provides GradLaunch, staff assigned to you can see how you are progressing: the colleges on your list and their deadlines, whether an essay has been started and how long it is, whether recommendation letters have been requested, financial aid status, and what you have completed against your plan.

Staff cannot read the text of your essays or your chats with the coach. They see that a personal statement is at eighty words in November. They do not see the eighty words. The counselor screens are built to withhold the writing itself.

Staff can see this only for students assigned to them at their own campus, and district leadership sees campus level reporting rather than individual writing.

7. Who else touches it

We use a small number of processors to run the product. They act on our instructions and may not use the data for their own purposes.

  • Vercel (United States) - hosting and delivery of the application.
  • Supabase (United States) - the database holding your account and your work.
  • Clerk (United States) - sign-in and account security. Passwords are never seen by us.
  • OpenAI (United States) - the coaching features described in section 4. No training on your content.
  • ElevenLabs (United States) - speech for conversation mode, when you use it. No training on your content.
  • Stripe (United States) - card payments, if you pay us directly. We never see your card number.
  • Resend (United States) - delivery of the emails the product sends.

School and college logos are fetched by our own server rather than by your browser, so no third party learns which schools you are looking at.

    This list is the current one, and it is the same list attached to district agreements. We will give districts notice before adding a subprocessor, so a district can object before any data reaches a new one.

    We may also disclose data if the law requires it, and we will tell the affected school or user unless we are legally prohibited from doing so. If GradLaunch is ever acquired, student data stays subject to commitments at least as protective as these, and districts will be notified.

    8. Students, parents and student privacy law

    Students own their work. It stays theirs if a subscription ends or a district contract ends, and we do not delete it for non-payment.

    Under 13. Children under 13 may use GradLaunch only through a school or district that has provided it, where the school gives consent on the parents’ behalf for educational purposes as COPPA permits. We do not knowingly accept direct sign-ups from children under 13. If we learn we have one, we delete the account.

    Parents. A parent or guardian may ask what we hold about their child, have it corrected, or have it deleted, through the school or by writing to us directly.

    Districts. We will sign your data privacy agreement, including a New York Education Law 2-d rider and the equivalent addenda for states such as California, Illinois and Connecticut, and we will publish a parents’ bill of rights where your state requires one.

    Everyone. You may request access to your data, a copy of it, correction, or deletion, and you may withdraw consent for optional analytics at any time.

    9. Cookies

    Essential cookies keep you signed in and protect the account. They cannot be switched off without breaking sign-in.

    A preference cookie remembers your answer to the cookie banner, so we do not ask again on every visit.

    Optional analytics load only if you accept them, and tell us which pages are used and where the product breaks. You can change your answer at any time through Cookie settings in the footer.

    We do not use advertising cookies, and we do not sell what analytics tell us.

    10. Keeping it, and keeping it safe

    Data is encrypted in transit and at rest with our hosting providers. Tokens for connected accounts are encrypted before storage. Access inside GradLaunch is limited to the people who need it to operate and support the product, and staff access to a school’s data is scoped to that school.

    We keep your work while your account exists. When an account is deleted, we remove the work within 30 days, except where we must keep a record for legal or accounting reasons. When a district contract ends, we return or delete district data on request, and otherwise within the period the agreement states.

    If a breach affects your data, we will notify affected schools and users without undue delay, and within the time your agreement or applicable law requires.

    11. The Chrome extension

    The extension signs in with the same account as the website and shows you the same data. It reads a page only when you press a button on that page, and it asks Chrome for permission to a single website at the moment you ask it to read one that is not a supported job board.

    It does not run in the background, does not collect your browsing history, and does not read pages you have not asked it to read.

    12. Changes, and how to reach us

    If we change this policy we will update the date at the top, and for material changes affecting schools we will give notice under the relevant agreement.

    Write to gradlaunchai@gmail.com or use the contact form. Districts should route data privacy requests through their agreement contact so we can verify them.

    Questions about any of this: contact us.