Our Commitment

Data Privacy Principles

UniAtlas AI, Inc. operates an AI-powered platform built to help students reach their potential. Protecting your personal data is fundamental to that mission — not a side consideration. These eight principles guide every decision we make about how we collect, use, and safeguard your information.

1
🎓

Students Come First

Every data decision starts with a simple question: does this serve the student?

We collect information to help you find the right university, discover scholarships, and plan your academic future — not to exploit or monetize your personal life.

We will never use your data in ways that work against your educational interests. Your academic profile exists to open doors, not to restrict opportunities.

When we design new features, privacy impact is evaluated before development begins — not as an afterthought.

2
🔍

Radical Transparency

You should never have to guess what we do with your data.

Our Privacy Policy is written in clear, straightforward language. We avoid legal jargon wherever possible and explain technical concepts when we must use them.

When we update our privacy practices, we notify you directly and explain what changed and why — not just update a date at the top of a page.

We publish what categories of data we collect, how long we keep it, and who we share it with. There are no hidden data flows or undisclosed partnerships.

3
📦

Collect Only What Matters

We gather the minimum data needed to provide the service you asked for.

We do not require information that is not directly relevant to the features you use. Your profile fields are optional beyond what is needed for core functionality.

We do not build shadow profiles from external data sources. We do not purchase data about you from data brokers or third-party aggregators.

If a feature can work with anonymized or aggregated data instead of personal data, that is how we build it.

4
🎛️

You Control Your Data

Your data belongs to you. You decide what to share, and you can change your mind.

You can view, download, correct, or delete your personal data at any time from your account dashboard. We do not make these options hard to find or use.

You choose what information appears on your profile, what is shared with AI features, and what communications you receive. Preferences are granular, not all-or-nothing.

If you delete your account, we remove your personal data from our active systems within 30 days and from backups within 90 days, except where legal obligations require retention.

5
🚫

We Do Not Sell Your Data

Your personal information is never sold, rented, or traded to third parties.

We do not sell or rent your personal information to advertisers, data brokers, recruiters, or any other third party. This is not a qualified statement — it is absolute.

When we share data with service providers (such as cloud hosting or payment processing), those providers are contractually prohibited from using your data for their own purposes.

We do not engage in behavioral advertising based on your personal data. If we display promotions, they are based on general context (such as the page you are viewing), not your individual profile.

6
🤖

Responsible AI, Honest Boundaries

AI features are tools to help you — with clear limits and your consent.

When you use AI-powered features (such as the Scholarship Advisor, Essay Coach, or University Matcher), we tell you an AI is involved. We never present AI-generated content as human-authored.

Your AI interactions are not used to train third-party AI models. Conversations with our AI features are processed to provide responses and then handled according to our retention policy — they are not harvested for machine learning datasets.

AI recommendations are supplementary guidance, not definitive decisions. We clearly label AI outputs and encourage you to verify information independently. We are transparent about the models we use and their limitations.

7
🔒

Security Is Not Optional

We protect your data with industry-standard safeguards at every layer.

All data in transit is encrypted using TLS. Data at rest is encrypted using AES-256. We follow OWASP security guidelines and conduct regular security assessments of our codebase and infrastructure.

Access to personal data within our organization is role-based and logged. Only team members who need access to perform their job functions can view personal data, and every access is auditable.

We will never ask you for your password, credit card number, or other sensitive information via email, phone, or chat. If you receive such a request claiming to be from UniAtlas, it is not from us.

8
⚖️

Accountability and Continuous Improvement

We hold ourselves to these principles and welcome scrutiny.

These principles are not aspirational — they are operational. We evaluate our products, partnerships, and internal practices against them. If something does not meet these standards, we change it.

We respect your rights under applicable privacy laws, including GDPR, CCPA/CPRA, FERPA, and other education-specific data protection regulations. We aim to meet the highest standard, regardless of which jurisdiction you are in.

If we make a mistake — a data incident, a misconfigured setting, an unclear disclosure — we tell you promptly, explain what happened, and describe the steps we are taking to prevent it from happening again.

Want the Full Details?

These principles summarize our commitments. For the complete legal documentation of how we handle your data, review our Privacy Policy and Terms of Service.

Questions about our privacy practices?
Reach us at privacy@uniatlas.org — we aim to respond within 30 days.