Aplyr Legal

Privacy Policy

Effective date
August 18, 2026
Controller
Aplyr Technologies
Privacy contact
support@useaplyr.com

1Who We Are (Controller)

  • Service: Aplyr — a web application, browser extension, and related services for graduate-school application planning ("the Service").
  • Controller / Company: Aplyr Technologies, 8 Ariyo Street , Ojodu , Lagos.
  • Contact / Data Protection Officer: support@useaplyr.com. All privacy and data-subject requests should be sent to this address.

This policy explains what personal data we collect, why we collect it, how it is used, who we share it with, how long we keep it, and the rights you have — including under the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and the Nigeria Data Protection Act 2023 (NDPA).

2Summary (Plain-Language Overview)

  • What you give us: your account details (name, email, phone), your academic profile (GPA, major, test scores, residency, goals), your application tracker data (schools, deadlines, notes, statuses), documents you upload (CVs, essays, transcripts), AI chat content, and — if you use the browser extension — a detailed application profile that may include date of birth, addresses, race/ethnicity, citizenship/immigration status, family member details, counselor contacts, test scores, and application-portal account IDs (Common App, Coalition, UCAS, OUAC, ApplyBoard).
  • What we collect automatically: IP address, user-agent, session data, device push tokens, time you spend on pages, and a log of actions you take in the Service.
  • What we do with it: provide the Service, personalize AI assistance, send notifications/emails, process payments, moderate the community, prevent abuse, and improve the Service.
  • AI: we send content you provide (chat messages, documents, CVs, page extracts, and your profile) to Google Gemini, our AI provider, and use Google Search to research live information. AI output is not guaranteed accurate (see our Terms of Use).
  • Who we share with: limited, vetted service providers (listed in Section 8). We do not sell personal data and do not use third-party advertising trackers.
  • Your rights: access, correct, delete, port, restrict, object, withdraw consent, and complain to a supervisory authority (details in Section 11).

3Personal Data We Collect

3.1 Data you provide

Account & identity: full name; email address; password (hashed — never stored in plain text); Google account data if you sign in with Google (name, email; the Google profile photo is not used — we generate an avatar); phone number (optional); community handle (a public pseudonym); avatar seed.

Academic & application profile: GPA, major, graduation year, application cycle, degree sought, preferred countries, priorities, country/state of residence, standardized test scores (e.g., GRE, GMAT, TOEFL, IELTS, SAT, ACT — name and score).

Application tracker data: schools and programs you track — university, program, degree, department, country, location type, term, format, program length, application deadlines, application/decision/funding statuses, offer types, application fee amounts, fee-waiver status, professor-of-interest name/email and contact status, program and portal URLs, free-text notes, requirements checklists, custom flow diagrams, shortlisted institutions/professors, and time spent per school entry.

Uploaded documents ("Vault"): files you upload — CVs/resumes, statements of purpose, letters of recommendation, personal statements, transcripts, writing samples, and any other file types. Files are stored with our file-storage provider (Cloudinary) under a per-user folder; we retain file names, types, sizes, and URLs.

AI features content: chat messages and AI responses (full transcripts are stored), gap-analysis text/document contents, CV text and research parameters used for school pairing and professor matching, and AI-generated results (match scores, analyses, requirements, recommendations).

Browser-extension autofill profile ("Autofill Profile"): the most extensive set of data we store, used to autofill application portals. If you use the extension you may provide:

  • Basic info: first/middle/last/preferred names, date of birth, phone, home address (street, unit, city, state, postal code, country), separate mailing address (if different).
  • Demographics (special categories): gender, pronouns, citizenship country, citizenship/immigration status, dual citizenship, birth country/city, languages, race, Hispanic origin, and ethnicity.
  • Family: parent/guardian details (names, emails, phone numbers, occupation, employer, education level, college, degree), marital status, household size, living situation, siblings' names/ages/school levels.
  • Education: high school name/city/state/country, start date, graduation date, CEEB code, boarding status, GPA scale, grading system, cumulative/weighted GPA, class rank/size, entry term, career interest, highest intended degree, counselor name/email/phone, intended major.
  • Exams & courses: school-leaving exam results, current courses, schedule system.
  • Test scores: SAT, ACT, TOEFL, IELTS, Duolingo, PTE (with sub-scores and test dates), AP exams, IB exams (level, score, date), and other general scores.
  • Portal IDs & activities: Common App ID, Coalition (Scoir) ID, UCAS Personal ID, OUAC number, ApplyBoard/BC reference, extracurricular activities, and honors/awards.

Community content: posts (title, body, images, optional document attachments), comments/replies, votes, saved posts, reports (reason and optional details), best-answer marks, and moderation outcomes. Your community handle and generated avatar identify you publicly.

Payments: we do not collect card details. Payment data (plan, interval, currency, amounts, provider customer/subscription references, card-expiry notifications) is processed and relayed by our payment processor, Paystack.

Communications: notification preferences (push/email/digest on/off, reminder lead days), email delivery logs, and the content of emails we send you (deadlines, digest statistics, plan notices).

3.2 Data we collect automatically

  • IP address and user-agent string — captured on session creation and on essentially every logged-in action, and stored in our activity logs and session records.
  • Device and push-notification data — Firebase Cloud Messaging device tokens and platform type (web/android/ios) when you enable browser push notifications.
  • Usage and behavioral data — pages/contexts you visit and time spent (including per-school time), computed "readiness" scores, feature usage, and AI token usage (counts and credits per feature).
  • Cookies and local storage — see our Cookie Policy for the full list.
  • Geolocation (derived, not stored) — we may read IP-country headers to offer the correct currency (NGN/USD) at checkout. This is not stored as a precise location.
  • Scraped page content (via the extension) — when you use the extension's "Extract from this page" feature, the text of the web page you are viewing (e.g., a university program page) is transmitted to our servers for analysis. We extract only program/admissions information (deadlines, fees, requirements) and do not store the full page text beyond a URL-keyed cache of the extracted facts.

3.3 Data from other sources

  • Google (OAuth sign-in): your Google identity (name, email).
  • Public and research sources: institution and professor data is compiled from public sources (US News, IAU, university websites) and research APIs (US College Scorecard, OpenAlex, Semantic Scholar, ROR, Wikidata, Google Search). Professor emails may be inferred by AI from public sources and are marked as such.
  • AI-generated data: AI tools may generate structured data (deadlines, fees, requirements, professor profiles, match analyses) from the inputs above; such data becomes part of the Service (see Section 9 — Shared Data).

4Purposes of Processing and Legal Bases

We process personal data for the following purposes. The legal bases rely on (where applicable): contract (performance of the service agreement / Terms of Use), legitimate interests (operating, securing, and improving the Service), consent (marketing communications, special-category data, optional features), and legal obligation.

PurposeData categoriesProposed legal basis
Account creation, authentication, and securityAccount, session, IP/UAContract; legitimate interest (security)
Providing the core tracker (schools, requirements, deadlines, documents, exports)Tracker data, documentsContract
Personalizing and providing AI features (chat, pairing, professor matching, gap analysis, requirements generation, extraction)AI content, profile, documents, CVs, page extractsContract; legitimate interest
Autofill via browser extensionAutofill Profile (incl. special categories)Contract; explicit consent for special categories
Notifications and reminders (deadline, trial, inactivity, weekly digest)Notification prefs, tracker data, contactConsent (preferences); legitimate interest (transactional)
Transactional email (OTP, password reset, receipts, payment notices, admin broadcasts)Contact, account, paymentContract; legal obligation
Payments and billingPayment records, subscriptionContract; legal obligation (tax/financial records)
Community and moderation (posts, comments, flags, AI moderation, bans)Community content, flags, moderation metadataContract; legitimate interest (safe community); legal obligation
Abuse prevention and security (rate limiting, IP bans, fraud detection)IP, device tokens, activity logsLegitimate interest
Analytics and product improvement (time tracking, usage, AI token metering)Usage data, activity logsLegitimate interest
Legal compliance and auditsActivity logs, financial recordsLegal obligation
Data-subject rights requests and account deletionAll dataLegal obligation

5Special-Category ("Sensitive") Data

  1. What we process. Certain data we collect is classified as sensitive/special-category data under GDPR Article 9 and similar laws (Nigeria NDPA; "sensitive personal information" under CCPA/CPRA): racial or ethnic origin, ethnicity, Hispanic origin, citizenship/immigration status, gender/pronouns, marital status, and date of birth (in the Autofill Profile), as well as academic records that may reveal similar characteristics.
  2. Basis. We process special-category data only with your explicit consent (GDPR Art. 9(2)(a)), given through the extension profile setup flow, for the specified purpose of autofilling your application forms. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal, and you may delete these fields at any time.
  3. Optionality. You are never required to provide special-category data. All fields in the Autofill Profile are optional and only needed if you wish to use the autofill feature.

6AI Processing, Automated Decisions, and Profiling

  1. AI providers. Our AI features are provided by Google (Google Gemini models and Google Search grounding via the Generative AI API). When you use AI features, your content is transmitted to Google for processing. Please read Google's privacy policy and Generative AI terms alongside this policy.
  2. What is sent to AI:
    • AI chat & gap analysis: your messages, the last messages of the conversation, your profile block (name, GPA, major, residence, application cycle, degree, preferred countries, priorities, graduation year), any file attachments you add (PDF, DOCX, TXT, MD, HTML; images), and retrieved knowledge-base excerpts.
    • Pairing & professor matching: your GPA, study level, budget, destination, funding preferences, and/or your full CV text; your research parameters.
    • Requirements generation & page extraction: program/school data, your country of residence, URLs you provide, and page excerpts (limited to 2,000 characters) you extract.
    • Community moderation: post/comment text and images (for safety classification).
    • Embeddings: text you provide is converted into vector embeddings to power search and matching.
  3. Automated decisions. Certain features make automated assessments: school match scores and rankings, professor fit scores, gap-analysis scores for documents, automated moderation flags (spam/harassment/ misinformation) which may shadow-hide content, and readiness scores. These outputs are provided to you for informational purposes and, except for automated moderation, do not produce legal or similarly significant effects on you. Where you have a right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects (GDPR Art. 22; NDPA), you may request human review by contacting support@useaplyr.com.
  4. Profiling. We profile usage for service operation (time-on-page analytics, AI credit metering, activity logs) and, if you enable the extension, to autofill forms. We do not use your data for advertising or behavioral-advertising profiling.
  5. AI transparency. You are interacting with AI in the AI chat, gap analysis, pairing, professor matching, requirements generation, and moderation features. AI output may be inaccurate and must be independently verified (see Terms of Use, Section 7). Automated moderation decisions can be appealed by contacting support@useaplyr.com.
  6. Training. We do not use your raw content to train any machine-learning models. We may use anonymized and aggregated data to improve the Service. Any use of identifiable content for model training would require separate, explicit consent.

7Retention

We retain personal data only as long as necessary for the purposes in Section 4, applying the periods below. Where no specific period is stated, we retain data for the duration of your account plus a short period unless a longer period is required by law.

DataRetention (as implemented)
Session tokens / JWTs / auth cookies7 days
OTP codes, password-reset links10 minutes / 1 hour
Purchase-intent, OAuth-state, invite cookies10 minutes
Offline edit queues (IndexedDB)discarded when older than 24 hours
Page-extraction cache (URL-keyed facts)refreshed after 7 days
Push device tokensdeleted after 90 days inactive
Stale pairing/professor jobsmarked failed after 24 hours
Email dedup/rate-limit logs5-day window (log rows persist)
Free trial14 days
Account after deletion requestpermanent deletion requested within 30 days
AI chat transcripts, CV text, activity logs, token usage, time heartbeats, autofill profile, documents on CloudinaryRetained for the life of your account; data older than 1 year is automatically purged on a rolling basis. All data is deleted when your account is deleted.

Deletion requests are processed as described in the Terms of Use (Section 5) and Section 11 below.

8Recipients and Processors

We share personal data only with the following categories of recipients, as needed to operate the Service. All are contractually bound as data processors (or independent controllers where noted) and are required to implement appropriate technical and organizational measures.

RecipientRole / what dataPurposeLocation
Google (Gemini AI, Google Search, OAuth, Calendar, College Scorecard)Processor / separate controllerAI generation, web research, sign-in, calendar sync, enrichmentUSA
CloudinaryProcessorFile storage (documents, images, avatars)USA
ResendProcessorTransactional and marketing email deliveryUSA
PaystackProcessor (separate controller for card data)Payment processing, subscriptions, billing portalNigeria
Upstash (Redis)ProcessorCaching, rate limitingUSA/EU
InngestProcessorBackground job orchestrationUSA
Firebase (Google)ProcessorPush notifications (FCM)USA
VercelProcessorHosting and infrastructureUSA
OpenAlex, Semantic Scholar, ROR, Wikidata, US College ScorecardIndependent controllers (queries only)Research-data enrichment (institution/professor facts)Various
Internal personnel (Admins, Moderators)InternalSupport, moderation, enforcement, analytics — access limited by role-based access control and logged

Community visibility. Content you publish in the community is visible to other users (Section 9). AI-generated school matches and your community handle/avatar may be visible to other users on public institution pages.

We do not sell personal data, and we have no knowledge of selling or sharing personal information of minors under 16 (CCPA). We do not engage in cross-context behavioral advertising.

9Data Shared Across the Service (Public and Shared Data)

  • Community: posts, comments, votes, images, and attachments are public to other users; attachments you publish remain accessible publicly even if you later delete the post (our UI warns you of this).
  • Institution database: AI-enriched institution profiles (deadlines, fees, requirements, match analyses) are stored once and served to all users.
  • Professor database: professor profiles generated from any user's matching request (name, university, email — stated or inferred — social handles, publications) are stored in a shared database used by all users.
  • Extraction cache: extracted program facts are cached per-URL and may serve other users.
  • Community pairings: your name, avatar, and match scores may appear on an institution page's community pairings list. Shared pairing links may expose your pairing criteria (field, study level, destination, GPA, funding/budget preferences) to anyone with the link.
  • Referrals: referral codes link you to people you invite; redemption records link the referrer and referee.

10Consent and Preferences

  1. Notification preferences. We provide controls (Settings → Notifications) for push notifications, email notifications, weekly digest, and reminder lead days (1/3/7/14). Transactional notifications (deadline reminders, payment confirmations, security alerts) are enabled by default. Marketing or promotional communications require your opt-in consent. You can manage all notification preferences from Settings → Notifications.
  2. Google Calendar. Connecting your calendar is a separate, explicit OAuth consent you grant to Google and to us; you can disconnect at any time.
  3. Cookies. We use only strictly essential cookies and functional local storage, which do not require consent under applicable law. See our Cookie Policy for the full list.
  4. Withdrawal. You may withdraw consent at any time through the relevant settings, or by contacting support@useaplyr.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

11Your Rights

11.1 GDPR / NDPA rights (and similar laws)

  • Access: obtain a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data (you can edit most data yourself in Settings).
  • Erasure ("right to be forgotten"): request deletion of your data (see the Terms of Use, Section 5; community content you authored may be exempt where it is public content other users rely on).
  • Restriction: restrict processing in certain circumstances.
  • Data portability: receive your data in a structured, machine-readable format — for your tracker, the Excel export is the primary mechanism; additional exports can be provided on request.
  • Object: object to processing based on legitimate interests, including analytics and direct marketing.
  • Not be subject to automated decision-making that produces legal or similarly significant effects (Section 6.3).
  • Withdraw consent at any time (Section 10.4).
  • Complain to your supervisory authority: in Nigeria, the Nigeria Data Protection Commission (NDPC); in the UK, the Information Commissioner's Office (ICO); in the EU, your local data-protection authority; in California, the California Privacy Protection Agency (CPPA) and the California Attorney General.

11.2 CCPA/CPRA rights (California residents)

  • Know: the categories and specific pieces of personal information we collect, use, share, and sell.
  • Delete: request deletion of personal information we collected from you, subject to exceptions.
  • Correct: correct inaccurate personal information.
  • Limit: limit the use and disclosure of sensitive personal information (e.g., race/ethnicity, citizenship status, date of birth) — we will not use sensitive information beyond what is necessary to provide the requested service (autofill) without your opt-in.
  • Opt-out: we do not sell personal information and do not share it for cross-context behavioral advertising; no opt-out is required, but you may contact us to confirm.
  • Equal treatment (non-discrimination): we will not discriminate against you for exercising your rights.
  • Other state laws: California Civil Code §1798.83 requests can be sent to support@useaplyr.com.

11.3 How to exercise your rights

Send a request to support@useaplyr.com with the subject "Privacy Request". We will verify your identity (we may ask for information matching your account, and may use two-factor verification) and respond within the time required by law (typically 30 days under GDPR/NDPA; 45 days under CCPA, extendable). You may authorize an agent to make requests on your behalf. We do not charge a fee except where the law permits (e.g., manifestly unfounded or excessive requests).

12Children's Privacy

  1. The Service is not directed at children under 13 and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us personal data, contact support@useaplyr.com and we will delete it.
  2. Users aged 13–18 may use the Service only with parental/guardian consent as described in our Terms of Use (Section 2).

13Security (GDPR Art. 32)

We implement appropriate technical and organizational measures to protect personal data, including:

  • Passwords stored hashed by a reputable authentication framework; session tokens stored securely.
  • HTTP-only, Secure, SameSite cookies for session credentials; short-lived JWTs (7 days).
  • Server-side rate limiting and abuse detection (including hashed-IP bans and rate-limit counters).
  • Role-based access control for administrators with granular permissions; all admin actions logged.
  • Transport encryption (HTTPS/TLS) for all traffic; API responses configured not to be cached.
  • Activity logging for auditability (including IP and user-agent).
  • AI input size caps and prompt hardening to limit exposure of unintended data.
  • Storage of OAuth tokens (e.g., Google Calendar) with least-privilege scopes.

While we take reasonable measures, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

14Data Breaches

In the event of a personal-data breach, we will: (a) assess risk to data subjects; (b) where required, notify the relevant supervisory authority within 72 hours (GDPR) or as required by applicable law (NDPC 72-hour notification under NDPA); (c) notify affected individuals without undue delay where the breach creates a high risk to their rights and freedoms; and (d) document the breach and remedial measures.

15International Transfers

  1. Your data may be transferred to and processed in countries outside your country of residence, including the United States (Google, Cloudinary, Resend, Upstash, Inngest, Vercel) and Nigeria (Paystack).
  2. For transfers from the EU/UK/EEA, we rely on: (a) adequacy decisions where applicable; (b) Standard Contractual Clauses (SCCs) with our processors, supplemented by additional safeguards where necessary; and (c) the EU-US Data Privacy Framework where our processors participate. You may request a copy of the relevant safeguards by contacting support@useaplyr.com.

16Changes to This Policy

We will post any changes on this page and, where required, notify you by email or in-app notice before they take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

17Contact and Complaints

  • Privacy requests / DPO: support@useaplyr.com
  • Company: Aplyr Technologies, 8 Ariyo Street , Ojodu , Lagos
  • Supervisory authorities:
    • Nigeria: Nigeria Data Protection Commission (NDPC), info@ndpc.gov.ng
    • UK: Information Commissioner's Office (ICO), ico.org.uk
    • EU/EEA: your local data-protection authority
    • California: California Privacy Protection Agency (CPPA), privacy.ca.gov; California Attorney General, oag.ca.gov