Privacy Policy
Last updated: July 19, 2026
This Privacy Policy explains how UnisPath ("we", "us", "our") collects, uses, stores, and shares information when you and your organization use our student counseling and application management platform (the "Service").
1. Who uses UnisPath
The Service has three account types:
- Students — invited by a counseling organization that has onboarded them. Students cannot self-register.
- Organization members— belong to a counseling organization with full management access to their organization's students, applications, documents, and messages. The founding member registers the organization; after our review and approval, they manage students and invite additional members.
- UnisPath superadministrators — UnisPath employees who approve new organizations, manage webinars, and provide support.
2. Information we collect
Account information. Email address, full name (optional), phone number (optional), WhatsApp number (optional), role, organization affiliation, and a flag indicating whether you must change your password on next sign-in. You may sign in with a password (hash stored by Firebase Authentication / Google Identity Platform) or, where enabled, by connecting a Google or Microsoft account — in that case Firebase, Google, and (for Microsoft sign-in) Microsoft each confirm your identity, and we receive only your verified email address and name. UnisPath does not have access to your Google or Microsoft password.
Student profile and application data.Through the profile setup flow, we collect: country of residence, preferred destination countries and cities, intended majors, grade level, course system and score (e.g. IB, A-Levels), individual subject grades, standardized test scores (SAT/ACT), English proficiency scores (IELTS/TOEFL), extracurricular activities, awards and honors, a personal statement summary, tuition budget, and campus-vibe preferences. We store the universities you shortlist and every application you create, along with each application's status as it moves through our application pipeline (from shortlisting through document preparation and submission to the final outcome).
Uploaded documents. Students upload documents required by their target universities in PDF format, including academic transcripts, English-test scores (e.g. IELTS or TOEFL), personal statements, CVs, and reference letters. An organization may also define additional custom document types for its own students.
Messages. Messages exchanged between students and their counseling team within the platform are stored indefinitely while the account is active.
Status history.Each application's status transitions are logged with a timestamp and the user who made the change, for audit and notification purposes.
Contact information. If you submit our public contact form, we collect your name, email, organization name, and message.
AI assistant conversations. Messages you send to the in-app AI assistant or the public homepage chatbot are sent to our AI provider to generate a response (see Section 4). We do not store chat transcripts on our servers; we log only usage metadata (feature used, timing, and token counts).
Usage and device information. Server logs, IP address, browser user-agent, and request paths, used for security, debugging, and abuse prevention.
AI usage data. We log the type, timing, and token count of AI processing requests for internal monitoring, cost management, and abuse prevention.
3. How we use information
- To authenticate users and enforce role-based access.
- To allow counseling organizations to manage their students, members, and applications.
- To power university search and comparison features using curated data from Hipolabs and QS World University Rankings.
- To run automated AI validation of uploaded documents (checking document type, legibility, and completeness) and surface a status of valid, needs review, or invalid to the organization team.
- To provide AI-powered document coaching that gives students actionable feedback on their uploaded documents before organization review.
- To power the in-app AI assistant for students and counselors and the public AI chatbot on our homepage, which answer questions about your applications and about the Service.
- To develop and evaluate UnisPath's own AI models: UnisPath staff may generate internal exports of counselor-approved documents and related profile data, across organizations, for this purpose (see Section 4).
- To send transactional and operational email notifications (account invitations, application status updates, document review alerts, webinar invitations, direct-message notifications, and platform announcements).
- To provide and improve the Service and prevent abuse.
- To comply with legal obligations.
4. AI processing
The Service uses Google Vertex AI (Gemini) for the following features:
- Automated document validation — when a student uploads a document, its content is sent to Vertex AI to check document type, legibility, completeness, and potential fraud indicators. The result is a status of valid, needs review, or invalid, plus detailed notes for the organization team.
- Document coaching — students may optionally request AI-powered feedback on an uploaded document. The document content is sent to Vertex AI, which returns quality ratings, strengths, suggested improvements, and a readiness assessment.
- Student and counselor AI assistant— signed-in students and organization members can chat with an in-app AI assistant. To answer your questions, relevant context from your account — such as your profile, shortlists, applications, and document statuses (or, for counselors, information about their organization's students) — is included in prompts sent to Vertex AI along with your messages.
- Homepage chatbot — visitors to our public website can ask a chatbot questions about UnisPath. Messages you type are sent to Vertex AI to generate a response. Please do not share sensitive personal information in this chat.
- Superadmin AI assistant — UnisPath superadministrators have access to an AI assistant that helps with platform management decisions. Organization and aggregate data may be included in prompts sent to Vertex AI for this purpose.
- Internal AI model development— UnisPath staff can generate an internal, platform-wide export used to evaluate and, in the future, fine-tune UnisPath's own AI models. This export includes only documents an organization has already approved (not drafts, pending, or rejected documents) and related student profile data, and is produced in two forms: a de-identified version (names, emails, and phone numbers replaced with placeholders on a best-effort basis) and, for internal evaluation purposes, a raw version. Access is restricted to UnisPath superadministrators. This process does not currently distinguish based on individual consent; we are building a consent mechanism so this will become opt-in. If you want your data excluded from this process in the meantime, contact us (Section 15) and we will honor that request for future exports.
When these features are used, the relevant inputs — document content, chat messages, application metadata, or platform data — are sent to Google Vertex AI for processing within UnisPath's Google Cloud project. Per Google's Vertex AI terms, Google does not use this data to train its general-purpose models. We log the type and token count of each AI request for internal monitoring.
AI outputs are not guaranteed to be accurate or complete. Students and organization members should independently verify university requirements, deadlines, and document acceptance directly with each university before relying on AI-generated guidance.
5. Subprocessors
We use the following third-party service providers to operate the Service. Each operates under its own terms and privacy policy:
- Google Cloud Platform — hosting (Cloud Run), database (Cloud SQL for PostgreSQL, private IP), document storage (Cloud Storage, private bucket with signed URLs), AI processing (Vertex AI Gemini), and operational logging.
- Firebase Authentication (Google Identity Platform) — user authentication, password management, and session tokens. Password hashes are stored and managed entirely by Firebase; UnisPath does not have direct access to plaintext passwords. Where you choose to sign in with Google or Microsoft, Firebase brokers that sign-in and Google or Microsoft (Azure Active Directory / Microsoft Entra ID) confirms your identity under their own privacy terms.
- Resend — sending transactional email (account invitations, status updates, webinar notifications, and platform announcements). Password reset emails are sent directly by Firebase Authentication.
- Google Meet (Google Workspace)— hosting the webinar feature, where UnisPath or invited presenters hold paid sessions for students. Registered students receive the meeting link for each session. Webinar sessions may be recorded, and Google Meet's built-in AI features (such as automated meeting summaries or notes) may be used; recordings and AI-generated summaries are processed by Google under its own terms and may be shared with registered attendees.
6. Data sharing
- Within your organization:a student's applications, documents, and messages are visible to all members of the organization that onboarded them. Each student is assigned to a single primary counselor via an automatic least-loaded algorithm, but other members within the same organization may access the records as part of normal team operations.
- Between organizations: we do not share student data with any other counseling organization or third party. Each organization can only access its own students.
- Service providers: the subprocessors listed above, strictly for the purposes described.
- Legal: when required by law, valid legal process, or to protect the rights, property, or safety of UnisPath, our users, or others.
We do not sell personal information. We do not use personal information for advertising and do not run third-party advertising trackers in the application.
7. Children and minors
UnisPath is intended for students aged 13 and older. We do not knowingly collect data from children under 13. Many of our users are between 16 and 18 years old and applying to universities; if you are under the age of majority in your jurisdiction, you must have a parent or legal guardian review this policy and agree to it on your behalf. Organizations that onboard minors are responsible for obtaining any consent required by local law.
8. Education records (FERPA, GDPR, and equivalents)
Where UnisPath processes student records on behalf of an educational institution, we act as a service provider on the institution's instructions. Depending on your jurisdiction, this may engage obligations under FERPA (US), state student privacy laws (e.g. SOPIPA in California), GDPR (EU/UK), the UK Data Protection Act, or equivalent regimes. Organizations subject to these regimes can request a Data Processing Agreement before onboarding students.
9. Data retention
We retain account data, application records, documents, and messages for as long as the student or organization account is active. When a student account or an organization (including all of its students) is deleted — whether by the student, an organization admin, or UnisPath — it is immediately deactivated and hidden from all rosters, then held in a recoverable state for 60 days before being permanently erased. During those 60 days, an organization admin or UnisPath can restore the account with its data intact. Backup snapshots are rotated on a 7-day cycle. Aggregated and de-identified analytics data, and internal AI model development exports (Section 4), may be retained longer for product improvement.
10. Security
- Encryption in transit (TLS 1.2+) for all client traffic.
- Encryption at rest for the database (Cloud SQL) and document storage (Cloud Storage).
- Database accessed only over a private IP from inside our Google Cloud VPC.
- Documents are served via time-limited V4 signed URLs; the storage bucket is not publicly accessible.
- Authentication is delegated to Firebase Authentication (Google Identity Platform) with required password change on first invited sign-in.
- Role-based access control enforced at the application layer.
- Automated daily backups of the database with point-in-time recovery.
No security program is perfect. If a confirmed incident affects your data, we will notify affected organizations without undue delay.
11. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, restrict processing of, or export your personal information, and to object to certain processing.
Students may delete their own account directly from the platform; this immediately disables sign-in and hides the account, and starts the 60-day retention period described in Section 9, after which all associated data is permanently erased. Students may also contact their counseling organization for assistance, including to request immediate/earlier permanent deletion. Organizations and other users can contact us via the contact page or email support@unispath.com. We respond within 30 days where required by law.
12. International transfers
UnisPath data is hosted on Google Cloud Platform. Depending on your account's region, data may be stored and processed in data centers in the United States or Europe. Where applicable, we rely on Standard Contractual Clauses (SCCs) and other lawful transfer mechanisms for cross-border transfers.
13. Cookies and similar technologies
We use a small number of cookies that are strictly necessary for authentication (an HttpOnly session cookie issued after sign-in) and for basic functional behaviour. We do not run third-party advertising or social-tracking cookies in the application.
14. Changes
We may update this policy from time to time. We will notify organizations and users of material changes through the Service or by email.
15. Contact
Questions about this policy, requests to exercise your rights, or requests for a Data Processing Agreement can be sent to support@unispath.com or through our contact page.