Privacy Policy
The short version
- Student work is never used to train AI models, never sold, and never shared with third parties.
- We ask Google for the smallest access that works: one research folder, never the rest of the Drive.
- Only four roles can see a student's data: the student, the linked parent, the assigned professor, and platform admins. Every access is written to an audit log.
- Card details live with Stripe, our payment provider, not with us.
- Every family can export or delete their data through the support center.
1. What we collect
- Account details: names, email addresses, the student's age, and the parent-student link.
- Research work: the files in the student's one authorized Google Drive folder, and the text we extract from those files to produce feedback. The files themselves stay in the student's Drive.
- Feedback and progress records: AI feedback entries, professor reviews and briefings, the evidence log, achievements, certificates, and the Research Genome (a skill profile built from evidence, not a grade).
- Billing records: subscription status, invoices, and payment history. Card numbers are entered on Stripe's pages and stored by Stripe, never by us.
- Technical records: login events, and an audit log of every file access, AI evaluation, professor review, and feedback insertion.
We collect nothing beyond what the coaching needs. There is no advertising profile and no data broker involved, on either side.
2. What we never do
- We never use student work to train AI models. Work is read only to produce feedback for that student.
- We never sell personal data, and we never share student work or conversations with third parties.
- We never record audio or video. There are no live sessions on this plan, and nothing is recorded.
- We never ask Google for more access than the one research folder.
3. Google access: one folder only
When you connect Google, we request the minimum access that works: the one private research folder the platform creates or connects for the student, never the rest of the Drive. Access tokens are encrypted at rest. You can disconnect Google at any time. The platform then keeps working in degraded mode: existing feedback, portfolio, and progress stay visible, and we simply stop reading new files until you reconnect.
4. Who sees what
Access is scoped by role, and no role sees more than its job requires:
- The student sees their own work, feedback, roadmap, and progress.
- The linked parent sees the student's progress, billing, and consent settings.
- The assigned professor sees the student's work, briefings, and the evidence needed for reviews, certificates, and letters.
- Platform admins see what operating and supporting the platform requires.
Every file access, AI evaluation, professor review, and feedback insertion is written to an append-only audit log, so there is always a record of who touched what and when.
5. How long we keep your data
We keep records while the account exists. After a cancellation, the portfolio, evidence log, and Research Genome are kept so a returning student can pick up where they stopped. If you would rather we keep nothing, ask for deletion at any time (section 6).
6. Your rights: export and delete
Every family can export their data or ask us to delete it, through the support center, at any time. Export gives you the student's portfolio, feedback, and evidence log in a usable form. Deletion removes the family's personal data from the platform; the only exceptions are records the law requires us to keep, such as certain billing records, and we will tell you plainly if any apply.
7. Students and schools: FERPA-minded handling
We handle student records with FERPA in mind: progress records are treated as confidential education-style records, shared only with the roles listed in section 4, and available to the family on request. A parent consents at signup for any student under 18 and keeps visibility through the Parent Portal. Students must be 14 or older to join.
8. Cookies and sessions
We use a session cookie to keep you signed in. That is what it does and all it does. There are no advertising cookies, no cross-site trackers, and no analytics that follow you to other websites.
9. Changes to this policy
If we change this policy in a way that matters, we will email the account owner before the change takes effect, in plain words, with what changed and why.
10. Contact
Privacy questions: hello@resforme.com, or write to us through the support center. The governing law and the formal entity details will be completed before launch.
Draft, awaiting review. Effective date will be set at launch.