Legal
Privacy Policy
Last updated: February 25, 2026
⊕ Your Privacy at a Glance
✓ What we use your data for
- • Compute ScholarlyFit compatibility scores
- • Facilitate connection requests and in-platform messaging
- • Generate AI match analyses (opt-in, costs credits)
- • Process credit purchases securely via Stripe
- • Send connection alerts and receipt emails
✗ What we NEVER do
- • Sell, rent, or trade your personal data
- • Store your credit card number or CVV
- • Share your profile without your consent
- • Use your content to train AI models
- • Use advertising or cross-site tracking scripts
🔒 How we protect your data
- • TLS encryption for all data in transit
- • AES-256 encryption at rest (AWS/Supabase)
- • Row-level security — your data is yours alone
- • API keys server-side only, never in the browser
- • Stripe webhook signature verification on payments
👤 Your rights — always available, no questions asked
Email privacy@scholarly.fit — we respond within 30 days.
1. Information We Collect
Account Information
When you register, we collect your name, email address, password (hashed — never stored in plain text), and your role (student or faculty advisor).
Student Profile Information
To compute your ScholarlyFit Score, we collect: your academic institution, department, doctoral program, dissertation title and abstract, research areas, preferred research methodology, career goals, preferred communication style, and meeting preferences.
Faculty Advisor Profile Information
For faculty advisors we collect: institutional affiliation, academic title and rank, research areas, publications, methodology expertise, mentoring philosophy, current and maximum student capacity, professional bio, terminal degree information, and optionally a curriculum vitae (CV) and academic transcript uploaded to our secure file storage.
Communications
Messages exchanged between students and advisors through the platform are stored to provide the messaging service. Message content is only accessible to the two parties in a connection.
Usage Data
We collect profile view counts, match scores computed between students and faculty, connection requests, and advisor ratings submitted through the platform. We also collect standard server logs (IP address, browser type, pages visited) for security and performance purposes.
Payment Information
Credit purchases are processed by Stripe, Inc. We do not store your credit card number, CVV, or full payment details on our servers. We receive from Stripe a confirmation of payment, the transaction amount, and a session identifier for fulfillment purposes.
2. How We Use Your Information
We use collected information to:
- Compute and display ScholarlyFit compatibility scores between students and faculty
- Facilitate connection requests and secure in-platform messaging
- Generate AI-powered match analyses via Anthropic Claude (see Section 4)
- Process credit purchases and maintain purchase history
- Send transactional email notifications (e.g., new connection requests, accepted matches) via Resend
- Display faculty public profiles to prospective doctoral students
- Aggregate anonymized advisor ratings for quality indicators
- Detect abuse, prevent fraud, and maintain platform security
- Improve our matching algorithm and platform features
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
3. FERPA Notice
ScholarlyFit serves doctoral students at accredited universities. Information you voluntarily provide — including dissertation topics, research interests, and academic program details — is submitted by you directly and used solely to facilitate advisor matching.
ScholarlyFit is not a school official and does not have access to official education records. Students control what profile information they share. We recommend that you do not include sensitive academic record information (grades, disciplinary records, official transcripts) in your profile beyond what is directly relevant to advisor matching.
If you are a student at the University of Bridgeport or another institution with specific FERPA data use agreements, please consult your institution's registrar or compliance office if you have questions about sharing academic information with third-party platforms.
4. Artificial Intelligence & Third-Party Services
Anthropic Claude (AI Match Analysis)
When you request an AI-powered match analysis (which costs 1 credit), anonymized profile data including research areas, dissertation topic, methodology preferences, and career goals is transmitted to Anthropic, Inc. for processing. Anthropic's usage policies apply to this data. We do not send your name, email, or institutional identity to Anthropic. Analyses are ephemeral — we store only the returned text summary, not the underlying prompt.
Supabase
Database hosting and authentication are provided by Supabase, Inc. Data is stored in US-based data centers with encryption at rest and in transit.
Stripe
Payment processing is handled by Stripe, Inc. Stripe's Privacy Policy governs data processed during payment transactions.
Resend
Transactional emails are sent via Resend, Inc. Your email address is shared with Resend only to deliver notifications you have triggered (e.g., new connection request alerts).
Vercel
ScholarlyFit is hosted on Vercel, Inc. infrastructure. Standard web request logs (including IP addresses) pass through Vercel's servers.
5. Data Sharing
We share your information only in the following circumstances:
- With your matched advisor/student — when a connection is accepted, limited contact information (name, email) is shared between the two parties
- With service providers — as described in Section 4, with the minimum data necessary
- Faculty public profiles — when a faculty advisor completes onboarding, their public profile (name, institution, research areas, bio, CV link, ratings summary) is visible to all authenticated users
- Legal compliance — if required by applicable law, court order, or governmental authority
- Business transfer — in connection with a merger, acquisition, or sale of assets, with notice provided to users
6. Data Retention
We retain your account and profile data for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required for legal or financial compliance (e.g., Stripe transaction records are retained for 7 years).
Advisor ratings are retained in aggregate anonymized form after account deletion to preserve the integrity of historical quality indicators.
7. Your Rights & Choices
You have the right to:
- Access — request a copy of the data we hold about you
- Correct — update your profile information at any time via your account settings or profile editor
- Delete — request deletion of your account and associated data
- Export — request a data export in a portable format
- Opt out of AI analysis — AI match analyses are opt-in (triggered manually and cost credits); you may choose not to use this feature
To exercise any of these rights, email us at privacy@scholarly.fit. We will respond within 30 days.
8. Security
We implement industry-standard security measures including: TLS encryption for all data in transit, AES-256 encryption for data at rest, row-level security on all database tables (users can only access their own data), server-side API keys (never exposed to the client), and Stripe-verified webhook signatures for payment processing.
No method of transmission or storage is 100% secure. We encourage you to use a strong, unique password and to notify us immediately at privacy@scholarly.fit if you suspect unauthorized access to your account.
9. Children's Privacy
ScholarlyFit is intended for doctoral students and university faculty. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have inadvertently collected data from a minor, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email and will update the “Last updated” date at the top of this page. Continued use of ScholarlyFit after changes take effect constitutes acceptance of the revised policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact: