Privacy

What we collect, who can see it, and what we delete. Written to be read rather than to be defensible.

What we collect

Only what the product needs to work.

Things we delete on purpose

Verification codes expire in 15 minutes and are consumed on use.

We no longer collect evidence for scholarship or accepted-school claims. Where any was uploaded previously it was deleted the moment a reviewer decided, either way.

Who can see what

Your masked profile is public. Your full profile is visible to people who have unlocked you.

Files attached to an order are visible to exactly two people: the client and the mentor on that order, plus us if a dispute is raised. They are not public, not indexed, and not shared with anyone else. Download links expire after a minute.

We keep the unmasked original of messages so we can act on reports and abuse. A mentor never learns who reported them.

A message refused for containing a slur is still stored, with what was typed, and shown to us rather than to the person it was aimed at. Refusing it and keeping no record would mean repeated attempts left no trace.

Digital products render in the browser, watermarked with the buyer's name and purchase time. There is no download.

What a mentor writes about themselves is public and searchable. That is what a profile is for.

Administrators can review the contents of an account, including messages and the files and essays attached to it, for safety, disputes and support. That access is logged: every time an administrator opens someone's messages, files or profile, we record who looked, whose account it was, and when. The log cannot be edited or deleted by the person who was looking.

Background tags, where a mentor has chosen them, work the same way: race and ethnicity from a fixed list, plus circumstances such as first-generation or transfer, shown on their profile and usable as a search filter. Faith and language are not collected at all. We never infer any of them, we never require them, and clients are never asked for theirs. A mentor can remove them at any time, and doing so removes them from search.

Who we share it with

Stripe processes payments and payouts. Supabase hosts the database and files. Resend sends email. PostHog records product analytics. Video calls happen on a third-party meeting service.

A waitlist address is used for exactly two emails: one confirming you joined, and one when we launch. It is not used for anything else and is not passed to mentors.

We do not sell personal data, and we do not share it with schools, admissions offices or advertisers.

Cookies and sign-in

Signing in sets a cookie that keeps you signed in. Without it you would log in on every page.

If you arrive from a student's own link we set a cookie for 60 days that credits them if you later unlock somebody. It records which link brought you and nothing else.

PostHog records how the product is used, so we can see which pages people get stuck on. It is product analytics, not advertising: we do not sell it, and we do not use it to target you anywhere else.

Signing in with Google is optional. If you use it, Google tells us your name and email address and nothing more, and we use them for exactly what an email signup would.

Minors

There is no account for an under-18 applicant. Where an applicant is under 18 the account belongs to a parent or guardian, who is the payer and the only messaging identity. This is deliberate: it means there is no private channel between an adult and a minor on Admory.

Your choices

You can edit or delete your profile at any time from your dashboard. Deleting asks for your password first, because a signed-in browser is not proof of who is using it.

Deleting your account removes your profile and any files nobody has bought.

Five things stay, and they are the same five the terms name. Anything somebody already paid for remains readable by the person who bought it, because they bought it. Transaction records are kept for tax and dispute purposes. Messages are kept for safety review and remain visible to the people you exchanged them with, since a conversation belongs to both sides. Your stated reason for leaving is stored separately. And we keep a short record that the account existed, including your name and email address, to prevent fraud and abuse, described in full below. We do NOT keep your essays or your profile to improve our own service, and we never resell or republish them.

An account that has taken or made a payment cannot be deleted outright. We deactivate it instead: the profile comes down at once and nothing new can be bought or booked.

The deletion form asks why you are leaving. Your answer is stored separately so it outlives the account it is about, alongside a short record that the account existed: your name, your email address, the reason you gave, whether the account was suspended at the time, and a one-line summary of what it held: how many listings and conversations, and whether anyone had reported it.

We keep that record to prevent fraud and abuse, and it is the only purpose it serves. An email address is the one thing that can connect a deleted account to a new signup; without it, an account removed for abusing someone could be recreated the same day and we would have no way to tell. It is never used to market to you, never shared, and never sold. It does not contain your profile, your essays, your messages or your files, all of which are deleted.

If you want that record removed as well, write to privacy@admory.io and say so. We will remove it unless it relates to an open safety or fraud matter, and we will tell you which.

We keep transaction records we are required to keep for tax and dispute purposes, even after an account is deleted.

Questions, or a request to see or delete your data: privacy@admory.io.

Questions about any of this: hello@admory.io. Safety concerns: safety@admory.io.