Privacy and student data
Privacy Policy
Effective and last updated: July 23, 2026
The short version
- Summis is only for students age 13 or older.
- We do not sell personal information or use it for targeted advertising.
- We send the profile details needed to provide AI features to our AI service providers. Uploaded transcripts and resumes are also processed by an AI provider.
- You can correct your profile or delete your account from Settings. You can also email us for access, correction, deletion, or another privacy request.
1. Scope and who operates Summis
This policy describes how Summis, referred to as “Summis,” “we,” “us,” or “our,” handles personal information through trysummis.com and related services. Summis is a college application strategy service for students and families.
This policy covers account holders, students whose information a parent or guardian enters, waitlist members, and support contacts.
2. Age requirements and parents
Summis is not directed to children under 13, and no account may be created for or used to submit information about a child under 13. If you are under 13, do not create an account or provide information to Summis.
A student under 18 must have a parent or legal guardian review and agree to our Terms of Service and this policy. A parent or guardian who creates an account must have authority to provide the student's information and consent to its processing. If we learn that information about a child under 13 was submitted, we will disable the account and delete the information unless the law requires otherwise.
A parent or guardian may ask to review, correct, or delete a minor's information by contacting us. We will verify the requester's identity and authority before disclosing information.
3. Information we collect
Account and consent information
Email address, account role, authentication identifiers, account creation date, and records of acceptance of our terms, privacy notice, age requirement, and guardian consent requirement. Supabase manages authentication credentials. We do not receive passwords used with Google sign-in.
Google sign-in information
Google sign-in is optional. If you choose it, Summis requests only the basic openid, email, and profile permissions. Google provides Supabase Auth with an account identifier, email address, and basic profile information that may include a display name and profile image. We use this information only to create or authenticate the Summis account, maintain the session, prevent duplicate accounts, and protect account security.
Summis does not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or other Google service content. We do not send Google sign-in information to our AI providers, use it for advertising, sell it, or use it to train models. The account identifier, email, and available basic profile metadata are stored by Supabase Auth; the Summis application database stores the account identifier and email needed to link the account to its student profile.
Student profile and application information
Information you choose to provide, such as name, graduation year, high school, general location, GPA, test scores, coursework, activities, awards, projects, intended major, interests, motivations, optional self-described race and ethnicity, college preferences, target schools, application plans, deadlines, tasks, waiver status, essay prompts, essay notes, and generated strategy content.
Files submitted for import
If you upload a transcript, resume, document, or image for import, we process the file to draft profile fields for your review. Summis does not intentionally keep the original upload in its application database after the import request finishes. The extracted fields you choose to save become part of the student profile.
Payments and communications
Stripe processes payment details. We receive transaction identifiers, plan and subscription status, and limited billing metadata, but not a full payment-card number. We also collect information sent through support requests, waitlist forms, and email preference controls.
Technical information
Our hosting, authentication, and security providers automatically receive standard request information such as IP address, device and browser details, timestamps, requested pages, cookie identifiers, and error or security events. We do not currently use advertising trackers or third-party behavioral analytics in the Summis application.
4. How we use information
- Create and secure accounts.
- Save a student profile and application workspace.
- Generate strategy reports, essay angles, and personalized recommendations.
- Find relevant schools, programs, and local opportunities.
- When a student chooses to provide race or ethnicity information, use it only when materially relevant to their narrative or to surface programs whose verified source explicitly names a matching community. We do not use it to change profile scores, chance estimates, or school verdicts.
- Process payments and maintain subscription access.
- Send requested service, onboarding, report, and support communications.
- Detect abuse, debug errors, protect the service, and comply with law.
- Evaluate and improve reliability using deidentified or aggregated information when practical.
We do not use a student profile to make an admissions decision, determine eligibility for education, employment, credit, housing, insurance, or another legally significant decision.
5. AI processing
Summis uses Anthropic and OpenAI API services. Depending on feature availability, profile content, activities, projects, academic information, interests, target schools, and application context may be sent to one or both providers to generate a report, recommendation, embedding, or essay strategy. Optional self-described race and ethnicity may be sent only in report-generation prompts when provided; it is not included in profile embeddings or local opportunity-search queries. We minimize direct identifiers in report prompts and do not send account passwords or full payment-card details to AI providers.
Transcript and resume imports may send the uploaded file itself to Anthropic or OpenAI for extraction. Do not upload Social Security numbers, financial account numbers, medical records, disciplinary records, immigration documents, or other information that is not needed for college strategy.
Anthropic and OpenAI state that they do not use business API inputs and outputs to train their models by default unless the customer opts in. Provider security, abuse monitoring, and retention rules still apply. OpenAI states that API abuse-monitoring logs may be kept for up to 30 days by default. See the providers' current business privacy documentation for details.
6. When we disclose information
We disclose information only as needed for these purposes:
- Amazon Web Services for the Aurora application database and related infrastructure.
- Supabase for authentication and session management.
- Anthropic and OpenAI for AI features described above.
- Vercel for application hosting and request processing.
- Stripe for payments, billing, fraud prevention, and subscriptions.
- Resend for service and follow-up email delivery.
- Google and Supabase for the optional Google sign-in flow described above. Google identity information is used only for account authentication and security.
- Firecrawl for public web search and page retrieval used to find opportunities. Search requests may include a city, state, and general interests, but not the student's name or email.
We may also disclose information when reasonably necessary to comply with law, protect people or the service, investigate fraud or security incidents, or complete a merger, financing, acquisition, or sale. A successor must handle personal information subject to this policy or provide notice of materially different practices.
We do not sell personal information or share it for cross-context behavioral advertising.
Summis's access, use, storage, and transfer of information received through Google sign-in follows the Google API Services User Data Policy, including its Limited Use requirements.
7. Cookies and online tracking
Summis uses cookies and similar storage that are necessary for authentication, account security, preferences, and core operation. We do not currently use third-party advertising cookies or track users across unrelated sites for targeted advertising.
Because we do not sell or share personal information for targeted advertising, browser Do Not Track and Global Privacy Control signals do not change our current practices. Third-party services such as Google sign-in may collect information under their own policies when you choose to use them.
8. Storage and security
Application data is stored in Amazon Aurora. Supabase stores authentication and session information. Access to student records is checked in the application data-access layer and scoped to the authenticated account. We use encrypted HTTPS connections and limit administrative access to people who need it to operate, secure, or support the service.
No online service can guarantee absolute security. Please use a unique password, protect account access, and email us promptly if you believe an account or student record has been accessed without permission.
9. Retention and deletion
- Account profiles, application workspaces, and reports are kept while the account is active and until the account holder deletes them or asks us to do so.
- Original transcript and resume uploads are processed in memory and are not intentionally stored in the Summis application database after the import request finishes. AI-provider retention still applies.
- Waitlist and email-preference records are kept until you unsubscribe or ask us to delete them.
- Raw Stripe webhook payloads are minimized after 90 days. Payment identifiers and fraud-prevention, tax, accounting, dispute, and security records may be kept for the period reasonably required by law or for those purposes.
Self-service account deletion removes active profile data from Summis's application database and requests deletion of the authentication account. Deletion from provider backups and logs follows each provider's deletion cycle. We ordinarily complete a verified emailed deletion request within 30 days, subject to narrow legal exceptions.
10. Your choices and privacy rights
- Review and correct profile information from the Profile area.
- Delete the account and associated student profile from Settings.
- Unsubscribe from optional email using the link in the message.
- Ask for access, correction, deletion, or a copy of information by email.
- Stop using Google sign-in by deleting the Summis account and revoking Summis from your Google Account connections.
Depending on where you live and whether a privacy law applies to Summis, you may have additional rights to know, access, correct, delete, or receive personal information, and to appeal a denied request. We will not discriminate against you for making a privacy request. We may need to verify identity, guardianship, or authority before acting.
California residents under 18 may request removal of content or information they posted to the service. Account deletion is available in Settings, and a removal request can also be sent by email. Removal does not guarantee deletion of copies lawfully retained by others or records that an exception requires us to keep.
11. Policy changes
We may update this policy as the service or law changes. We will post the new effective date here and provide additional notice, such as an account or email notice, when a change materially affects how we use previously collected student information.
12. Contact
For a privacy request, parent or guardian request, or security concern, email caden@trysummis.com. Put “Privacy request” in the subject line. We may ask for information needed to locate the record and verify the request, but do not email a password, government ID, transcript, or other sensitive document unless we specifically provide a secure method.
© 2026 Summis