← Back to ScholarBot

Privacy Policy

Effective date: [ NOT YET IN EFFECT — set this date when you publish ]

Read this first. This policy was drafted with the help of AI and has not been reviewed by a lawyer. It is an honest description of what the code actually does, written by reading it. The effective date above is a placeholder until the operator sets it.
The short version. Your profile, essays and documents are yours. No other user can read them, and neither can an administrator — the database enforces that, not a promise. We do not sell your data and there is no advertising here. The one place your information genuinely leaves our control is when you send it to a scholarship sponsor.

1. Who we are

ScholarBot is operated by [OPERATOR LEGAL NAME] in the United States. This policy covers the ScholarBot website, the browser extension, and the emails we send. Questions, requests and complaints all go to the address at the bottom of this page.

2. What we collect

Your account

  • Email address and a password, held by our authentication provider. We never see your password.

Profile — the basics

  • Name, email, phone number.
  • Street address, city, home state, ZIP code, US region.
  • Citizenship or residency status.
  • School, degree, field of study, GPA, expected graduation date, undergraduate school and major, relevant coursework.
  • Languages you speak, whether you are willing to relocate.
  • Career goals, intended career sector, work experience, employment status, hours worked weekly, whether you run a business and its name.
  • Awards, fellowships, certifications, publications, research interests, professional memberships, volunteer categories, community service hours, Greek life.
  • Your LinkedIn URL and bio, if you import them.
  • Whether you want the weekly digest email.
  • Answers you type while applying. When a scholarship form asks for something we recognise but your profile does not have yet — a phone number, a ZIP code — the answer you type is saved to your profile so the next application fills it in for you. Only fields already listed on this page are saved this way. Nothing in the “never asked for” list below is ever stored, and you can edit or clear any of it in your profile.

Profile — sensitive categories

These are the ones worth knowing about specifically. Every one of them is optional. You can leave all of them blank and ScholarBot still works — you will simply not be matched to awards that exist only for people in those groups.

  • Race or ethnic background, and ethnicity detail.
  • Gender.
  • LGBTQ+ status — the default answer is “prefer not to say”.
  • Religious affiliation.
  • Disability, disability types, and health conditions.
  • Veteran or military status, and military branch.
  • Household income (a band or a figure), household size, dependants, financial need.
  • First-generation student status.
  • Marital status, whether you are a parent or caregiver, Appalachian background.

In plain English: We ask these because thousands of scholarships exist only for particular groups, and there is no way to tell you about one without knowing you qualify. Leave any of them blank and nothing breaks.

Some of these fields are used today only to pre-fill application forms for you, and are not yet read by the matching engine. We are telling you that rather than implying every answer improves your results.

Documents you upload

  • Essays and personal statements, and other writing samples.
  • Résumés and CVs.
  • Transcripts and enrolment verification.
  • Recommendation letters — see the note about these below.
  • Award and acceptance letters, portfolios and work samples.

Documents we refuse

ScholarBot deliberately will not store copies of Social Security cards, tax returns, bank statements, passports, driving licences, birth certificates or payment card details. Uploads whose filenames look like those are refused with an explanation. No legitimate scholarship needs them, and holding a bucket of minors’ identity documents would be a target and a liability with no upside.

What you do in the app

  • Applications you have started, their status, and essays adapted for them.
  • Checklists and to-do items generated for an application.
  • Scholarships matched to you, and the matching scores behind them.
  • Your daily eligibility check-in answers and your streak.
  • Recommenders’ names and contact details, that you enter so letters can be requested and chased.
  • People you have written to through outreach, and what was sent.
  • Addresses that have asked not to be contacted, kept permanently so that request is honoured.
  • A count of AI writing assists used. This log holds the number and the kind only — no prompt, no essay, no output.
  • If you use the browser extension to attach a document: the site it went to, the form field label, and the filename. The file itself stays where it was; only the record is kept, so you can find out later what was sent where.

Payment

If you buy a paid plan, our payment processor handles the card. We never see or store your card number. What we store is your plan, its status, when the current period ends, whether you have cancelled, and the processor’s customer and subscription identifiers.

If you connect Google

Connecting Google is optional. If you do, we ask for exactly two permissions and no more:

  • Send email as you, so a request for a recommendation letter comes from you and the reply reaches your inbox.
  • Create calendar events, so deadlines land in your calendar.

We deliberately do not ask for permission to read your mail. We store one Google refresh token, encrypted before it reaches the database, and nothing reachable from a browser can read it.

Technical data

Our hosting and database providers keep ordinary server logs, which include IP addresses, browser type and the requests made. We do not run any analytics product, any advertising tag, or any third-party tracker. There are no advertising cookies. The only cookies are the ones that keep you signed in.

The browser extension

The ScholarBot Autofill extension reads the page you are on only when you press its button. It is not running on the pages you visit the rest of the time: it has no standing access to any site, and Chrome grants it the current tab for that one action.

When you press it, this is what moves:

  • The application form’s markup goes to ScholarBot, so the answers can be worked out on our side rather than in the browser. We keep the plan long enough to answer the request, not after.
  • The answers come back and are typed into the form. Signatures, Social Security numbers, bank details and anything the rules do not recognise are refused, and the refusal is shown to you as a reason.
  • If it attaches a document, the site it went to, the field label and the filename are recorded so you can find out later what was sent where.

It holds no password. It works because you are signed in to ScholarBot in the same browser, using that session. What it collects is used to fill your application and nothing else — not sold, not transferred to anyone but the sponsor whose form you filled, and not used to work out anything about your creditworthiness or to build an advertising profile.

3. Why we collect it

  • Profile, including the sensitive categories — to match you to scholarships whose eligibility rules you meet, and to pre-fill application forms so you are not typing the same answers thirty times.
  • Documents and essays — so they are to hand when an application needs them, and so an essay can be adapted for a particular prompt when you ask.
  • Applications and check-ins — to show you what you have done, what is due, and what is next.
  • Recommender and outreach details — to send the messages you write, and to honour anyone who asks not to be contacted.
  • Payment data — to take payment and to know which plan you are on.
  • Technical data — to keep the service running, secure and within its limits.

We do not use your data to build advertising profiles, and we do not use your essays or documents to train AI models.

4. Who your information goes to

The scholarship sponsor — the important one

When you apply for a scholarship, the information you put in that application goes to the sponsor. That is the point of applying, and it is also the moment your data leaves our control entirely.

  • What the sponsor does with it is governed by their privacy policy, not ours.
  • We cannot get it back, correct it, or delete it for you once it is sent.
  • Nothing is ever sent to a sponsor without you reviewing it and pressing submit yourself.

In plain English: Once you hit submit on a sponsor’s form, that information is theirs. Read who you are sending it to.

Service providers we use

These companies process data on our behalf so ScholarBot can work. They are not allowed to use it for their own purposes, except where noted for the free AI tier below.

  • Supabase — database, file storage and sign-in. Holds everything.
  • Vercel — hosting. Sees requests and server logs.
  • Stripe — payments. Sees your card and billing details; we do not.
  • Google (Gemini), OpenAI, Anthropic — the AI models. See only the text you ask an AI feature to work on.
  • Google (Gmail API) — sends mail from your own account, if you connected Google.
  • Resend, or an ordinary Gmail account — sends mail when you have not connected Google, and sends the weekly digest.
  • Google Safe Browsing — receives an application link so it can say whether it is a known phishing or malware page. It receives the link, not you.
  • Brave Search — receives a scholarship name when we are trying to find its official page. Nothing about you.
  • ProPublica and US Department of Education data — read-only public lookups about foundations and institutions. Nothing about you is sent.

We may also disclose information if the law requires it, to enforce our Terms of Use, or to protect someone from harm. If ScholarBot were ever sold or transferred, your data could move with it, and we would tell you first.

What goes to an AI model, and what does not

Nothing is sent to an AI model unless you use a feature that needs one. Matching, eligibility checks, deadline tracking, word counts and the letter tracker are all computed here with no model call at all. When you do use an AI feature, the text you asked us to work on is sent, and the result is shown to you as a difference so you can see exactly what changed.

Worth knowing: which provider handles a request depends on how the deployment is configured and which service is available. The default is Google’s free Gemini tier, and Google’s terms for its free tier allow it to use content sent to it to improve Google’s products, including review by people. That is a real difference from the paid tiers. Do not put anything into an AI feature that you would not want a provider to hold.

5. What we do not do

  • We do not sell your personal information, and we never have.
  • We do not share it for cross-context behavioural advertising. There is no advertising on ScholarBot, no advertising SDK in it, and no analytics product tracking you across sites.
  • We do not sell, publish or show your essays or documents to other users.
  • We do not use your writing to train AI models.
  • We do not send you to lead-generation forms. Scholarship links point at the sponsor’s own page wherever we can establish what it is.

6. Recommendation letters

A confidential recommendation letter can be uploaded to ScholarBot but cannot be read back — not by you, and not through any part of the app. You can see that one exists and you can delete it. You cannot open it.

That is on purpose. When a student waives the right to see a letter, the recommender writes on that understanding, and a locker that quietly handed the letter back would break it.

7. How long we keep things, and what gets deleted

Different things are kept for different lengths of time:

  • Essays, résumés, award letters, portfolios — until you delete them.
  • Transcripts and enrolment verification — 365 days. They are sensitive and they go out of date.
  • Recommendation letters — 90 days after the application they belong to closes.
  • A document whose type we cannot work out — 365 days.
  • Your profile, applications and account data — until you delete them or close your account.
  • Suppression list entries — permanently. That is the only way “do not contact me again” can be honoured.

Nothing is deleted without warning first. A file is only removed if a warning about it has been recorded at least 14 days earlier and is visible to you. If anything is unclear — an unreadable date, an unknown document type — the file is kept. Deleting your work is never what happens when the system is unsure.

Where this actually stands today. The weekly sweep currently runs in report-only mode: it works out what has passed its limit and records the warning, and deletes nothing. Automatic deletion is switched on separately and deliberately. We would rather tell you that than describe a policy we are not yet enforcing.

8. Deleting your account

There is a delete button in Settings. It removes, immediately:

  • every file you uploaded, from storage;
  • your profile and all of your per-user data, including any stored Google token;
  • your login.

Files are deleted first, and if any step fails your login is not removed — you are told what failed so you can try again. A half-deletion that reported success would leave records nobody could reach and nobody could remove.

The honest exception is backups. Our database host keeps automatic backups for a short window. Deleted database rows persist in those until they roll off, and no application can reach into a backup to erase one row — so for database records, “deleted” means “deleted going forward”. Uploaded files are different: they are not in those automatic backups at all, so a deleted transcript is not sitting in a snapshot somewhere.

Anything you already submitted to a sponsor is with the sponsor, and deleting your ScholarBot account does not reach it.

9. Your rights

Everyone

Whoever and wherever you are, you can ask us to:

  • tell you what we hold about you;
  • give you a copy of it;
  • correct anything that is wrong — most of it you can edit yourself in your profile;
  • delete your account and its data.

If you live in California

Under the California Consumer Privacy Act as amended by the CPRA, you have the right to:

  • Know what personal information we have collected, the categories, where it came from, why we collected it, and who we disclosed it to.
  • Delete the personal information we hold about you, subject to the exceptions the law allows.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of your personal information. We do neither, so there is nothing to opt out of and you will not find a “Do Not Sell or Share” link — there is nothing behind it.
  • Limit the use of sensitive personal information. We collect sensitive personal information — race or ethnicity, religion, health and disability, sexual orientation — only because you chose to give it, and we use it only to match you to awards and to fill in forms you asked us to fill in. We do not use or disclose it to infer characteristics about you, and we do not use it for any purpose the law would let you limit.
  • Not be discriminated against for exercising any of these rights. We will not deny you service, charge you differently, or give you a worse experience.

The categories we collect, in the law’s language, are: identifiers; personal records; characteristics of protected classifications; commercial information (your plan); internet activity (server logs); professional and education information; sensitive personal information as listed above; and inferences (which scholarships we think you qualify for). We collect them from you, from documents you upload, and from public records about institutions. We disclose them for business purposes to the service providers listed in section 4.

You may use an authorised agent. We will need to verify that they are acting for you.

Other US states

Several other states now give similar rights. Rather than argue about which ones apply to you, we extend the rights above to everyone who asks.

If you are outside the United States

ScholarBot is a United States service for United States scholarships, and everything is stored in the United States. We do not target the service at the European Economic Area or the United Kingdom, and we do not claim to comply with the GDPR or the UK GDPR. Saying otherwise without doing the work behind it would be worth less than saying nothing. If you use ScholarBot from outside the US, you are sending your information to the US, where the law protecting it is different from the law where you live. If that is not acceptable to you, please do not use ScholarBot.

How to exercise any of this

Email the address at the bottom of this page, from the address on your account, and say what you want. We will confirm we have it, verify who you are (usually by replying from the account address), and respond within 45 days. If we need longer we will tell you why and take at most another 45. There is no charge. If we refuse a request, we will say why and how to appeal it.

10. Children, and parents

  • ScholarBot is for people aged 13 and over. We do not knowingly collect anything from a child under 13. If we learn that an account belongs to someone under 13, we delete the account and its data.
  • Users aged 13 to 17 need a parent or guardian’s permission, and that parent or guardian agrees to our Terms of Use alongside them.
  • Parents and guardians may email us to see what we hold about their child, correct it, or have the account and all of its data deleted. Say who you are, name the account email, and we will act on it. We may ask a question or two to establish the connection before we act.
  • We do not show advertising to anyone, of any age, and we do not build profiles of students for marketing.

We hold a lot of information that belongs to minors — transcripts, home addresses, essays about family circumstances — and we try to treat it accordingly rather than as ordinary customer data.

11. Security

What is actually in place:

  • Every table holding student data has row-level security keyed to your account, so the database itself refuses to return another user’s rows.
  • Uploaded files live in a private storage bucket, in a folder named after your account, and the storage rules compare that folder name to your account before allowing any access. The bucket is never public, and every migration resets that setting so it cannot be switched on and quietly stay on.
  • Recommendation letters cannot be read back, enforced in the storage rules and not only in the app.
  • Administrators cannot read your documents, essays, profile or applications. The operator role exists to maintain the shared scholarship catalogue and reaches nothing else.
  • Your Google refresh token, if you have one, is encrypted with AES-256-GCM before it is stored.
  • Everything travels over encrypted connections.
  • Files the extension attaches to a form are recorded in a log you can read and nobody can rewrite.

What we will not claim. No system is completely secure and we do not guarantee that yours will never be reached. The encryption on the Google token protects against a leaked database copy, not against someone who has the running server — which is why the permissions we ask Google for are as narrow as they are. If there is ever a breach affecting your data, we will tell you.

12. Changes to this policy

If this policy changes in a way that affects what is collected, who it goes to, or how long it is kept, we will change the effective date at the top and tell you in the app or by email rather than quietly.

13. Contact

For anything in this policy — a question, a request to see or delete your data, a parent getting in touch about their child’s account, or a complaint — email the address just below. A real person reads it.

Drafted with AI assistance and not reviewed by a lawyer. It is written from the code rather than from a template, and if the code stops matching it, this page is the thing that is wrong and has to change.

Questions about any of this? Email morganfizer@gmail.com.