Skip to main content

Privacy Policy

Last updated: 28 August 2026

This is a draft, not a finished legal document. It accurately describes what the UniEU platform actually does with your data today — what's collected, why, and for how long — based on the current codebase. It has not been reviewed by a lawyer, and the data processing agreements referenced below have not yet been signed with our processors. Bracketed fields (like [Company Legal Name]) are placeholders. Do not treat this page as a certification of legal compliance until that review is complete.

1. Who we are

UniEU (“we”, “us”) is operated by [Company Legal Name], [registered address]. For any question about this policy or your data, contact [privacy contact email].

2. What we collect

Depending on how you use the platform, we collect:

  • Free eligibility scan (no account): the CV file you upload, the text extracted from it, your email address if you provide one, and the resulting score/feedback. Kept for 30 days if you don't create an account, then deleted.
  • Account & profile: your email address (via Supabase Auth), and whatever academic profile details you enter — degree, institution, GPA, language test scores, work experience, skills, and target programs.
  • Documents: CVs and other files you upload to your document vault, and any AI-generated eligibility report PDFs.
  • Applications: the programs you track, application stage, and document checklist status you record.
  • Support: the content of any helpdesk ticket you submit.

We do not currently run any analytics or advertising tracking on this site — no cookies beyond the session cookie Supabase Auth sets to keep you signed in.

3. Why we process it

To provide the service you asked for: scoring your eligibility against program requirements, letting you track applications, and giving our admissions team what they need to review and respond to you. This is processing necessary to perform a contract with you (or to take steps at your request before you have an account, for the anonymous scan).

4. AI processing and third parties

Your CV text and academic profile are sent to a third-party AI provider to generate your eligibility score and guidance — currently one of Groq, OpenAI, or OpenRouter, depending on configuration. We also use:

  • Supabase — our database, authentication, and file storage provider. Everything above is stored there.
  • Firecrawl / Unstructured — used internally to extract text from official university admissions documents (not your personal data).

Formal data processing agreements with these providers are in progress and not yet finalized — see the note at the top of this page.

5. How long we keep it

  • Anonymous scan results you never convert into an account: 30 days.
  • Account data: retained for as long as your account exists, then deleted — including uploaded files — when you delete your account.

6. Your rights

Subject to applicable law (including, for EU/EEA residents, the GDPR), you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct data that's wrong or out of date.
  • Delete your account and associated data.
  • Export your data in a portable format.

You can delete your own account and data directly from your dashboard, or contact [privacy contact email] for anything else.

7. Security

Your data is protected by row-level security policies scoping every student to their own records, encrypted transport (HTTPS) everywhere, and role-based access for our admissions team. No system is perfectly secure, and we'll notify affected users if that ever changes materially.

8. Children

UniEU is intended for prospective graduate students and is not directed at children under 16. We don't knowingly collect data from anyone under that age.

9. Changes to this policy

If this policy changes materially, we'll update the date at the top of this page and, once account notifications exist, tell you directly.