Privacy
Your data, accountable.
A plain-English account of who we are, what we collect, why, who we share it with, how long we keep it, and the rights you have to control or remove it.
Last updated · August 2026
Who we are
The controller of your data.
Counsolero is operated by Counsolero LLC, a California limited liability company with its registered business address at 2018 N St STE N, Sacramento, CA 95816. For purposes of the EU/UK GDPR, the California Consumer Privacy Act ("CCPA"), and other applicable privacy laws, Counsolero LLC is the controller (or "business") responsible for the personal information described in this policy.
For any privacy question, data subject request, or formal complaint, email [email protected]. The Contact page lists our other channels and the path to escalate to a supervisory authority if you are not satisfied with our response.
U.S.-only service. Counsolero is operated from California for U.S.-based students. We do not target, market to, or knowingly accept users from outside the United States. If you are accessing the service from outside the U.S., you do so on your own initiative; see §7 for what that means for your data.
What we collect
What data Counsolero collects.
We collect data tied to your account in five thematic categories. Identifying fields and content payloads are encrypted at rest where noted.
- Account & identity — your email address (via Clerk), your name if you provide it, your role and account-state flags (school-admin status, sponsored-school link, deletion timestamps, legal-hold flag if applicable). Email and name are encrypted at rest.
- Academic data — your courses, enrollments, grades, assignments, and uploaded files synced from Canvas with your OAuth consent (detailed in §8), plus any classes, assignments, or grades you enter manually. File content is encrypted at rest.
- AI features — your conversations with the AI counselor, the AI memory built from your course content, any study resources (quizzes, flashcards, study guides) you keep, and per-call usage metadata (timestamp, provider, model, tokens, cost, latency, success/error). Conversation text and AI-memory passages are encrypted at rest.
- Sessions & security — session metadata (IP address, user-agent, pages visited, duration), per-event interaction logs, security audit events (logins, deletion requests, token changes), and consent records.
- Payments — for school-sponsored or paid plans only: subscription status, consent record, and Stripe identifiers (subscription, item, invoice). Card numbers never reach our database — Stripe handles them.
What we have access to but do not store
The Canvas OAuth scopes you authorize technically permit broader access than we use. We deliberately do not persist other students' content, discussion replies, individual quiz questions or your quiz answers, Canvas Inbox messages, calendar events outside our announcements/discussions/cancellations surface, or your Canvas profile photo. If a future feature would require persisting any additional Canvas surface, we will update this policy in advance (see §15).
Optional personal calendars
If you connect Google Calendar or iCloud Calendar, we read events from the calendars you select, including titles, dates, notes, and locations, to display your schedule. These details can include sensitive information you or an event organizer entered. Google uses its authorization screen; iCloud uses an Apple app-specific password, which we store encrypted with a separate credential key. You can disconnect at any time, which removes the stored credentials. Your events remain with their original provider.
Editing is optional. When enabled, you can create, edit, or delete events in selected calendars from Counsolero. Changes are sent to Google or Apple, and existing guests may receive update or cancellation notifications. A separate AI opt-in allows selected personal calendar details to be sent to our AI provider when you ask about your schedule. AI changes are proposals that require your approval before they are applied. Proposals expire after 15 minutes; their text is encrypted, cleared after a successful change, and expired rows are removed by the daily cleanup. Calendar content is not added to the academic search index. Google event snapshots may be cached for up to 60 seconds; the production cache encrypts these values. Counsolero entries and connection preferences are included in your data export, and account deletion removes the associated records.
Sensitive personal information
Under California's CCPA/CPRA, "sensitive personal information" covers a specific list of categories. The ones we collect are: account credentials (handled by Clerk), contents of communications (your AI chat history and any course content you upload or that we sync from Canvas), and education information (your academic records, which also constitute "education records" under FERPA). We do not collect precise geolocation, biometric or genetic data, racial or ethnic origin, religious beliefs, union membership, health information, sexual-orientation data, government-issued identifiers (SSN, driver's license, passport), or payment-card numbers. We use sensitive personal information only as necessary to provide the service — you have the right to limit our use of it (see §12).
Sources
We collect personal information directly from you, from third parties at your direction (Canvas via OAuth, Clerk for authentication, Stripe if you subscribe), and automatically from your device (IP address, user-agent, and similar request metadata).
Purposes
Why we use it.
We use your information to:
- Provide the service — display your academic data, power AI study tools, run degree planning, authenticate you
- Process payments and manage subscriptions where you have one
- Protect the service and other users — investigate abuse, detect fraud, maintain the security audit log
- Meet legal and regulatory obligations — respond to lawful requests, retain consent and AI-disclosure records as required by FERPA
- Improve and operate the platform — fix bugs, debug issues, plan capacity
- Communicate with you — service notices, security alerts, account-deletion undo links, material policy changes
Where GDPR applies, our legal bases are performance of contract for service-delivery purposes, legitimate interest for security and operations, and legal obligation for compliance retention. We do not process your information for advertising or for any commercial purpose outside the list above.
Retention
How long we keep it.
- Active account data — academic data, chat history, AI memory, study resources, uploaded files, preferences, session activity, Canvas connection: cascade-deleted when your account is hard-deleted after a 14-day grace period
- Consent records — retained permanently as a FERPA record-of-disclosure; personal identifiers are removed when your account is hard-deleted
- Security audit log — retained under a declared policy of up to 3 years for FERPA-relevant actions (e.g. Canvas connect/disconnect, deletion requests, consent, file downloads, chat access) and up to 1 year for other actions, then purged; personal identifiers are removed when your account is hard-deleted
- AI interaction metadata — retained under a declared policy of up to 395 days (about 13 months) as a FERPA record-of-disclosure (timestamp, provider, model, tokens, cost, latency, success), then purged. Prompt and response text are scrubbed immediately; personal identifiers are removed if your account is hard-deleted before the window elapses
- Payment records — retained as required by tax and accounting law (typically 7 years in the United States); Stripe retains its own copy under its own retention policy
- AI retrieval traces — query text is hashed (not stored in plaintext) and traces are auto-purged after 30 days
After hard-deletion, the retained rows above have no path back to a named individual. They exist only to prove to auditors that we behaved correctly while your account was active.
Security
How we protect it.
We use industry-standard technical and organizational measures: TLS encryption in transit, symmetric encryption at rest for sensitive fields (account identifiers, Canvas OAuth tokens, file content, AI conversations, AI memory, study resources, user feedback), HttpOnly and Secure session cookies, CSRF protection, application-level audit logging of security-relevant events, and Content Security Policy plus HSTS in production. Identifying fields use blind-index lookups so that a database compromise alone, without the encryption keys, would not yield plaintext.
No security control is perfect. If you believe you have observed a security incident, report it to [email protected]. Our breach-notification commitments are in §14.
Sub-processors
Who we share it with.
We use the following sub-processors. Counsolero LLC has not negotiated bespoke contracts with any of them; instead, each vendor's own published terms of service and data-protection commitments apply to our use of their service, the same as they apply to every customer who signs up. We do not share your information with any other third party except as required by law.
- Clerk — authentication; receives your email address and manages your session
- Canvas LMS (operated by Instructure, Inc.) — source of academic data, accessed read-only via your OAuth consent
- Azure OpenAI — the AI provider serving all of Counsolero's production traffic today. Google Vertex AI is integrated in our code but is not active in production and receives no data. Both publish terms committing not to use customer inputs to train their models (see §9)
- Stripe — payment processing (paid plans only); receives the payment information you enter when subscribing
- Resend — transactional email; receives your email address and the content of service emails we send you
- Sentry — error telemetry; receives application error events — the error type and message, the URL where the error occurred, and a stack trace. It does not receive your account ID, email address, IP address, cookies, authentication headers, or request bodies. Variables captured in the stack trace are collapsed before sending: short values such as record IDs and counts are kept, and anything longer is replaced with a placeholder describing its shape rather than its contents. We do not enable session replay or front-end performance tracing
- Fly.io — hosting infrastructure; runs the Counsolero application and database in the United States
- Cloudflare — reverse proxy and DNS in front of our servers; it terminates the TLS connection from your browser, so it is able to see request and response content (such as chat messages and file downloads) in transit before re-encrypting and forwarding to our origin
- Upstash — Redis cache and rate-limit store, provisioned through Fly's infrastructure marketplace; temporarily caches some Canvas academic data (such as grades) to improve performance. This cached data is encrypted by us before it is sent, under a key Upstash does not hold, so it is not readable by Upstash. The exceptions are counters used for rate limiting, which hold no personal data
Optional calendar integrations send authorized calendar requests directly to Google or Apple. They receive the event changes you approve. FullCalendar is bundled in our app and receives no calendar data as a hosted service.
We do not use analytics, advertising, or tracking-pixel services. We do not sell or share your personal information for cross-context behavioral advertising.
Canvas disconnect
When you disconnect Canvas via the Canvas Connections page, we revoke your access token with Canvas and clear our stored credentials. Previously synced course data remains visible to you so you can reconnect and resume — same model as "signing out of Netflix on a TV." If you want the synced Canvas data removed as well, use Delete My Account, which cascade-deletes the mirror data along with the rest of your account.
Transfers
International data transfers.
Counsolero is a U.S.-only service. Our infrastructure is in the United States, and we do not target users outside the U.S. We have not implemented EU-, UK-, or other non-U.S.-specific data-protection safeguards because we do not serve those markets. If you access the service from outside the U.S. on your own initiative — including from the EEA, the UK, Switzerland, Canada, or elsewhere — your information will be transferred to and processed in the U.S., where data-protection laws may differ from your country's, and you accept that risk.
To the extent our U.S. sub-processors offer transfer mechanisms — such as the EU–U.S. Data Privacy Framework, the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Agreement — those mechanisms apply automatically to our use of their services under their published terms. Counsolero LLC has not separately negotiated SCCs or other transfer-specific contracts with any vendor.
Canvas sync
Canvas data we sync.
When you connect Canvas via OAuth and grant sync consent, we mirror these content categories. Every category below — grades, assignments, files, page bodies, module structure, announcements, discussion prompts, rubrics, and quiz metadata — can be turned off individually from the Canvas Settings page; only your basic course list and enrollment status form the always-on connection. Turning off a category stops future syncs; existing data is kept until you disconnect Canvas or delete your account.
- Course files — files attached to your Canvas courses. File content is encrypted at rest; metadata (filename, size, MIME type) is stored unencrypted.
- Announcements — title and body text posted by instructors.
- Rubric criteria — names, descriptions, and point ranges.
- Discussion topic prompts — the instructor's prompt text only, not student responses.
- Quiz metadata — title, due date, and point value. Individual question bodies and your quiz answers are not stored.
- Page bodies — HTML content of Canvas Pages in your courses.
- Module structure — module names and the items inside them.
Deletion: Disconnecting Canvas revokes your OAuth access token and deactivates the connection. Synced Canvas content is cascade-deleted when you delete your account. If you want synced Canvas content removed before account deletion, use Delete My Account.
AI
AI and your data.
We do not train AI models on your data
Counsolero never uses your personal information, your Canvas data, your chat history, your uploaded files, or any other content you provide to train, fine-tune, evaluate, or benchmark AI models — ours or anyone else's. The third-party AI providers we use publish terms committing not to use customer inputs for model training; we have not separately negotiated those terms, and they apply to our use of those services the same as they apply to any other customer.
Automated decision-making
Counsolero uses AI to generate study materials, summarize academic content, and suggest degree-planning options. These outputs are suggestions for you to consider — not automated decisions that produce legal or similarly significant effects on you under GDPR Art. 22. You can ignore, modify, or override any AI suggestion at any time.
Records of disclosure
For each AI call we make on your behalf, we record per-call metadata (described in §2) so that you and any auditing institution can verify what we did with your education records. See the FERPA Transparency Notice for the full disclosure-log pattern.
Cookies
Cookies and similar technologies.
Counsolero uses cookies only as needed to operate the service. We do not use cookies for analytics, advertising, profiling, or third-party retargeting.
- Strictly necessary — session cookies set by Counsolero and by Clerk for authentication. Required to function.
- Functional — UI preferences (theme and similar) stored in your browser's local storage on your device. Not shared with us.
- Security — CSRF and similar tokens used to defend against cross-site request forgery. Required to function.
We do not sell or share your personal information, so the Global Privacy Control (GPC) signal is honored automatically by virtue of our data-handling model. A cookie banner is presented on first visit; you can adjust your choices at any time via the banner.
Your rights
Your privacy rights.
Your jurisdiction determines which of these rights apply to you. Most users have most of them: access, portability, rectification, erasure, restriction, objection, withdrawal of consent, opt-out of sale or share, limit on use of sensitive personal information, non-discrimination, and the right to appeal a denied request.
How to exercise them
- Access / portability — use the Export My Data page to download a structured archive containing JSON files for each data category in §2 (account profile, courses, grades, chat history, uploaded-file metadata, preferences, consent history, AI memory, study resources, AI interaction metadata, and Canvas connection metadata). Raw vector embeddings are internal index data and are not part of the export.
- Deletion — use the Delete My Account page. We deactivate your account immediately, email you an undo link, and hard-delete after 14 days. Legal-hold exception: if a legal hold has been placed on your account (rare — usually a school-level compliance action), the request is rejected; contact support to resolve.
- Disconnect Canvas — use the Canvas Connections page (see §6 for what happens)
- AI provider — the in-chat model picker is visible, but during the current production beta, every request is served by Microsoft Azure OpenAI regardless of the picker selection; there is no alternate provider currently receiving your data to switch to
- Anything else — including rectification, restriction, objection, withdrawal of consent, opt-out of sale/share, limit on use of sensitive personal information, or appeal of a privacy decision: email [email protected]. For appeals of account actions under the User Policy (suspension, termination, etc.), use the appeal procedure in that document instead.
We aim to respond to verifiable requests within the statutory deadline (typically one month for GDPR, 45 days for CCPA, with the legal option to extend with notice). We may need to verify your identity by asking you to confirm details from your account — we do this to protect you against unauthorized requests, not as a barrier.
Our commitments to student data
Consistent with the spirit of U.S. state student-privacy laws — including the California Student Online Personal Information Protection Act (SOPIPA), the Illinois Student Online Personal Protection Act (SOPPA), New York Education Law § 2-d, Colorado's Student Data Transparency and Security Act, and analogous laws in Connecticut, Tennessee, Florida, and other states — Counsolero LLC commits that we will not:
- Sell student personal information
- Use student data for targeted advertising of any kind
- Build a profile of a student for any purpose other than providing the Counsolero service to that student
- Disclose student data to any third party except as described in this Privacy Policy or as required by law
These commitments apply to all students who use Counsolero, regardless of whether any specific state law technically applies to us.
Right to lodge a complaint
If you are not satisfied with our response, you may lodge a complaint with a supervisory authority. Contact information is on the Contact page (Section 4) (EU Data Protection Authorities, UK ICO, the California Privacy Protection Agency, state Attorneys General).
California
California: do not sell or share.
Counsolero does not sell your personal information and does not share it for cross-context behavioral advertising as those terms are defined in California's CCPA/CPRA. We never have, and we will give you 30 days' notice if that ever changes (see §15). California residents have the rights enumerated in §11, including the right to use an authorized agent to submit requests with written authorization. The categories of personal information we collect, the sources, our processing purposes, the recipients, and our retention practices are described in §§2–6.
Children
Children's privacy.
Counsolero is intended for adult students. By accepting our Terms of Service, you confirm you are 18 or older. The service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13.
If you are a parent or guardian and you believe a child under 13 has provided us with personal information, contact [email protected] immediately. We will investigate and, where confirmed, delete the child's account and personal information promptly and without charge, in accordance with the Children's Online Privacy Protection Act (COPPA) (15 U.S.C. § 6501 et seq.) and 16 CFR Part 312.
Breach response
If something goes wrong.
In the unlikely event of a security incident that compromises your personal information, Counsolero LLC will investigate promptly, notify affected users and the relevant supervisory authorities within the timeframes required by applicable law, work in good faith with affected schools where education records are involved, and publish a post-incident summary describing what happened, what was affected, what we did to remediate, and what we changed to prevent recurrence.
Report suspected incidents to [email protected].
Changes
Changes to this policy.
We may update this Privacy Policy from time to time. When we do, we update the "Last updated" date at the top of this page and bump our policy version, which prompts re-acceptance at your next login. For material changes affecting your data rights, sub-processors, or retention, we will also notify you by email.
For questions about this Privacy Policy, email [email protected] or see Contact.