Privacy Policy
Last updated 13 August 2026
Who we are
What we collect
- Account details — your name and email, handled by our authentication provider (Clerk).
- Your date of birth — asked once when you sign up. We use it to work out whether you are an adult or a minor, and we apply the protections below accordingly. It is the one thing here you cannot change yourself afterwards; email us if it is wrong.
- Academic profile — grade, intended intake year and major, test scores (SAT/ACT, IELTS/TOEFL), GPA or board marks, curriculum, school, and budget.
- Contact and personal details — home address, phone number, gender, pronouns, citizenship and residence country, and languages. Optional.
- We do not collect race or ethnicity. Navora does not ask for either, and there is no field for them anywhere in the product.
- Family details — your parents' or guardians' names, emails and phone numbers, marital status, and (for India applicants) a parent income band used only to filter need-based scholarships. All optional.
- Documents you upload — marksheets, transcripts, and similar records. We process these with OCR and AI to read your marks and subjects (see "Documents and OCR" below).
- Your work in the product — colleges, essays, and application tasks.
- Your advisor conversations — the questions you ask and the answers you get back are saved to your account, so a chat is still there when you come back to it. They appear in the chat list on the advisor page, where you can delete any conversation outright. They are yours to read and delete, and we will send you a copy on request — we do not use them to profile you, and they are never used to decide what to show or sell you.
- Usage data — only if you accept analytics cookies, and never if you are under 18. See "Cookies and analytics".
- Error reports — when something breaks, we send the error to Sentry so we can fix it. These carry no name, email or IP, and no request or response contents.
We never record your screen. Both our analytics and our error monitoring ship a session-replay feature that would record the page as you use it — including the profile form, with your date of birth, address and family details on it. Both are switched off in our code, not merely left unticked in a settings panel.
How we use your data
We never sell you. Not to colleges, not to lenders, not to advertisers, not as a "lead". Most free college tools make their money exactly that way — the college is their customer, which is why their advice can never be blunt with you. You are our customer, so ours can be.
We also never use your data to invent an admission probability. Navora reports where you stand against a college's own published numbers, with the source and the year attached — never a personal "chance".
Students under 18, and parents
- Under 13 cannot use Navora. We ask for your date of birth when you sign up. If you are under 13 we do not let the account exist: it and everything in it are deleted immediately and automatically, not flagged for review.
- If you are 13–17, analytics stay off. Not off-by-default — off. You are never added to an analytics profile, your email is never sent to our analytics provider, and the switch in Settings is disabled rather than merely unticked. There is nothing for you to remember to turn off.
- We never sell or share any student's data for advertising, lead generation, or anything else — minor or not. No college pays us for your details. This is the whole basis of the product.
- Parents and guardians can email privacy@getnavora.net to review, correct, or delete a child's data, and we will act on it. Your child can also delete their own account at any time, in the product, without asking us.
To be straight with you about the limit: we do not currently ask a parent to approve a 13–17-year-old's account. Some laws — India's DPDP Act, and Texas's SCOPE Act — reach further than the protections above for under-18s, and we are working through what they require of us. If that matters to you, email us and ask.
Documents and OCR
Who processes data on our behalf
- Clerk — sign-in and account management.
- Cloudflare R2 — document and file storage.
- Anthropic (Claude) — the AI behind the advisor, document reading, essay feedback, grammar checking, and activity suggestions. It is the only AI provider that ever receives your own data. Anthropic is contractually barred from training any model on what we send, deletes it within 30 days, and holds it in the United States; the processing itself may run on Anthropic infrastructure in other regions.
- DeepSeek — used only to research public college information: admission statistics, deadlines, scholarship listings, and the essay prompts colleges publish. It never receives your profile, your documents, your essays, or your questions to the advisor.
- PostHog — product analytics. Only if you accept analytics cookies, and never for users under 18. Not loaded at all otherwise. Its session-recording and survey features are switched off in our code, so they cannot be turned on from a dashboard.
- Sentry — error monitoring only. We deliberately do not use its session-recording feature, and errors are sent without your identity or the contents of your requests.
- Resend — transactional email, and only email you caused: deadline reminders you switched on for a milestone, recommender requests you sent, share invites you sent, your deletion confirmation, and our reply when you write to us. We do not send marketing email.
- Cloudflare / Arcjet — security and abuse prevention.
AI and your data
Saving a conversation is separate from sending it. The saved copy lives in our own database so you can reopen it; it is not sent back to Anthropic to be reprocessed, and no provider gets a copy of your chat history.
Sharing your profile with a parent or counselor
It is off on purpose rather than unfinished. Letting someone else see a student's file is the highest-consequence thing this product could do, and we are not willing to turn it on until we can tell you in advance exactly which fields a recipient would see, what the difference between view and edit access actually is, and what happens to their access when you revoke it or delete your account. Until we can publish those answers, the honest setting is off.
How long we keep it
Saved advisor conversations are kept for as long as your account is active, and you do not have to wait for us to remove one: deleting a chat from the list on the advisor page removes it and its messages immediately. Deleting your account removes all of them.
To be straight about what is still unsettled: we have not yet set a fixed number of days after which inactive data is deleted automatically. Indian law requires us to hold some personal data and logs for a minimum period, and other rules push toward deleting promptly — we are working out where those meet rather than publishing a timeframe we would have to walk back. The controls above work today regardless of how that lands.
Your rights
- Download your profile data* — Settings → Privacy & data. It is a JSON file, generated on the spot, containing your account, profile, family details, and what we extracted from your documents. It contains only your own data — if another student has shared their profile with you, theirs is not in it.
- Delete your account — Settings → Delete account. This is not a request queue. It removes your sign-in, every row we hold about you, the documents you uploaded from our file storage, and your analytics profile. We email you to confirm. It cannot be undone.
* What the download does not include: your advisor conversations. The export is your profile record — the information that makes up your account. Your chats live in the chat list on the advisor page, where you can reopen or delete any of them at any time, and deleting your account removes them along with everything else. If you want a copy of your conversations, or of anything else we hold that is not in the file, email privacy@getnavora.net and we will send it to you. We would rather tell you what the button covers than call it "everything" and be wrong.
To correct something, edit it in your profile, or email privacy@getnavora.net and we will help. Depending on where you live you may have additional rights under laws such as the DPDP Act, the GDPR, or the CCPA.
If there is a breach
The notice will say what happened, what data was involved, what we are doing about it, and what you can do. We would rather send you a short notice early than a complete one late.
Cookies and analytics
One more first-party cookie exists: on our public college pages we set navora_attr, which records only the first page you landed on, the site that referred you, and any campaign tags in the URL — no identifier, nothing about you, and nothing shared with anyone. If you later create an account, that one fact ("this account arrived from a college page via Google") is stored with it and the cookie is deleted; otherwise it expires on its own after 30 days.
Analytics are different, and they are off until you say yes. Not "on unless you object": if you decline, or simply never answer the banner, our analytics provider is never loaded at all — no request, no cookie, nothing stored. If you accept and later change your mind, the switch in Settings turns it off and clears the identifier that linked the data to you.
Analytics never run for users under 18, whatever the banner says.
Security
Changes to this policy
Writing to us
You do not need an account to write to us. If something went wrong before you ever signed up, that is exactly the message we most want.
Contact
Navora AI is a trading name of Pranesh Vats (Indian citizen), a sole proprietorship. Pre-incorporation, operating as a sole proprietor in India.
Duplex-51, Vijaya Heritage, 5th Phase, Uliyan, Kadma, Jamshedpur, Jharkhand 831005, India
Privacy: privacy@getnavora.net · Grievance officer: Pranesh Vats — grievance@getnavora.net
We acknowledge every complaint within 48 hours and resolve it within 30 days.