Privacy Policy

Last updated 13 August 2026

Navora is in early access. We are a new product, built by a very small team and still under active development. This policy is a living document: it will get more detailed as we grow, and we will update the date above whenever it changes in a meaningful way. It is a plain-English description of how we handle your data today, not a finished legal contract. If anything here is unclear or looks incomplete, email us at privacy@getnavora.net and we will fix it.

Who we are

Navora AI ("Navora," "we," "us") operates getnavora.net, a college-planning tool for students applying to university in the United States and internationally. You can reach us any time at hello@getnavora.net.

What we collect

  • Account details — your name and email, handled by our authentication provider (Clerk).
  • Your date of birth — asked once when you sign up. We use it to work out whether you are an adult or a minor, and we apply the protections below accordingly. It is the one thing here you cannot change yourself afterwards; email us if it is wrong.
  • Academic profile — grade, intended intake year and major, test scores (SAT/ACT, IELTS/TOEFL), GPA or board marks, curriculum, school, and budget.
  • Contact and personal details — home address, phone number, gender, pronouns, citizenship and residence country, and languages. Optional.
  • We do not collect race or ethnicity. Navora does not ask for either, and there is no field for them anywhere in the product.
  • Family details — your parents' or guardians' names, emails and phone numbers, marital status, and (for India applicants) a parent income band used only to filter need-based scholarships. All optional.
  • Documents you upload — marksheets, transcripts, and similar records. We process these with OCR and AI to read your marks and subjects (see "Documents and OCR" below).
  • Your work in the product — colleges, essays, and application tasks.
  • Your advisor conversations — the questions you ask and the answers you get back are saved to your account, so a chat is still there when you come back to it. They appear in the chat list on the advisor page, where you can delete any conversation outright. They are yours to read and delete, and we will send you a copy on request — we do not use them to profile you, and they are never used to decide what to show or sell you.
  • Usage data — only if you accept analytics cookies, and never if you are under 18. See "Cookies and analytics".
  • Error reports — when something breaks, we send the error to Sentry so we can fix it. These carry no name, email or IP, and no request or response contents.

We never record your screen. Both our analytics and our error monitoring ship a session-replay feature that would record the page as you use it — including the profile form, with your date of birth, address and family details on it. Both are switched off in our code, not merely left unticked in a settings panel.

How we use your data

We use it only to run the product for you: to build your profile, convert board marks to a US GPA, match you to colleges and scholarships, show sourced cohort context, and power the advisor.

We never sell you. Not to colleges, not to lenders, not to advertisers, not as a "lead". Most free college tools make their money exactly that way — the college is their customer, which is why their advice can never be blunt with you. You are our customer, so ours can be.

We also never use your data to invent an admission probability. Navora reports where you stand against a college's own published numbers, with the source and the year attached — never a personal "chance".

Students under 18, and parents

Most of our users are under 18. That shapes the product, not just this page.
  • Under 13 cannot use Navora. We ask for your date of birth when you sign up. If you are under 13 we do not let the account exist: it and everything in it are deleted immediately and automatically, not flagged for review.
  • If you are 13–17, analytics stay off. Not off-by-default — off. You are never added to an analytics profile, your email is never sent to our analytics provider, and the switch in Settings is disabled rather than merely unticked. There is nothing for you to remember to turn off.
  • We never sell or share any student's data for advertising, lead generation, or anything else — minor or not. No college pays us for your details. This is the whole basis of the product.
  • Parents and guardians can email privacy@getnavora.net to review, correct, or delete a child's data, and we will act on it. Your child can also delete their own account at any time, in the product, without asking us.

To be straight with you about the limit: we do not currently ask a parent to approve a 13–17-year-old's account. Some laws — India's DPDP Act, and Texas's SCOPE Act — reach further than the protections above for under-18s, and we are working through what they require of us. If that matters to you, email us and ask.

Documents and OCR

Documents you upload are stored with our file-storage provider (Cloudflare R2) and processed by OCR and AI so the product can read your marks and subjects. You can delete an uploaded document at any time from your profile, which removes it from your account.

Who processes data on our behalf

We rely on a small set of established providers to run Navora. We share only what each needs to do its job, and never with colleges or advertisers:
  • Clerk — sign-in and account management.
  • Cloudflare R2 — document and file storage.
  • Anthropic (Claude) — the AI behind the advisor, document reading, essay feedback, grammar checking, and activity suggestions. It is the only AI provider that ever receives your own data. Anthropic is contractually barred from training any model on what we send, deletes it within 30 days, and holds it in the United States; the processing itself may run on Anthropic infrastructure in other regions.
  • DeepSeek — used only to research public college information: admission statistics, deadlines, scholarship listings, and the essay prompts colleges publish. It never receives your profile, your documents, your essays, or your questions to the advisor.
  • PostHog — product analytics. Only if you accept analytics cookies, and never for users under 18. Not loaded at all otherwise. Its session-recording and survey features are switched off in our code, so they cannot be turned on from a dashboard.
  • Sentry — error monitoring only. We deliberately do not use its session-recording feature, and errors are sent without your identity or the contents of your requests.
  • Resend — transactional email, and only email you caused: deadline reminders you switched on for a milestone, recommender requests you sent, share invites you sent, your deletion confirmation, and our reply when you write to us. We do not send marketing email.
  • Cloudflare / Arcjet — security and abuse prevention.

AI and your data

To generate your results, we send the minimum content necessary to our AI providers. We do not sell your data, and neither we nor any provider we use will train a model on it — not a public model, not an internal one, and not on a de-identified copy. Anything of yours — your profile, uploaded documents, essays, and the questions you ask the advisor — goes to Anthropic and only Anthropic, which deletes it within 30 days. You are talking to an AI, not a human counselor, and AI output can be wrong or incomplete, so treat it as guidance to check rather than a final answer — especially for costs, visas, and scholarships.

Saving a conversation is separate from sending it. The saved copy lives in our own database so you can reopen it; it is not sent back to Anthropic to be reprocessed, and no provider gets a copy of your chat history.

Sharing your profile with a parent or counselor

This is switched off. You cannot share your profile with anyone right now — not a parent, not a counselor, not another student — and nobody has access to it but you. The invite screens are visible but the feature behind them is disabled.

It is off on purpose rather than unfinished. Letting someone else see a student's file is the highest-consequence thing this product could do, and we are not willing to turn it on until we can tell you in advance exactly which fields a recipient would see, what the difference between view and edit access actually is, and what happens to their access when you revoke it or delete your account. Until we can publish those answers, the honest setting is off.

How long we keep it

We keep your data while your account is active. You can delete your account and everything in it yourself, at any time, from Settings — see "Your rights". Some limited records may be retained where the law requires it.

Saved advisor conversations are kept for as long as your account is active, and you do not have to wait for us to remove one: deleting a chat from the list on the advisor page removes it and its messages immediately. Deleting your account removes all of them.

To be straight about what is still unsettled: we have not yet set a fixed number of days after which inactive data is deleted automatically. Indian law requires us to hold some personal data and logs for a minimum period, and other rules push toward deleting promptly — we are working out where those meet rather than publishing a timeframe we would have to walk back. The controls above work today regardless of how that lands.

Your rights

Two of these are buttons, not requests you have to make of us:
  • Download your profile data* — Settings → Privacy & data. It is a JSON file, generated on the spot, containing your account, profile, family details, and what we extracted from your documents. It contains only your own data — if another student has shared their profile with you, theirs is not in it.
  • Delete your account Settings → Delete account. This is not a request queue. It removes your sign-in, every row we hold about you, the documents you uploaded from our file storage, and your analytics profile. We email you to confirm. It cannot be undone.

* What the download does not include: your advisor conversations. The export is your profile record — the information that makes up your account. Your chats live in the chat list on the advisor page, where you can reopen or delete any of them at any time, and deleting your account removes them along with everything else. If you want a copy of your conversations, or of anything else we hold that is not in the file, email privacy@getnavora.net and we will send it to you. We would rather tell you what the button covers than call it "everything" and be wrong.

To correct something, edit it in your profile, or email privacy@getnavora.net and we will help. Depending on where you live you may have additional rights under laws such as the DPDP Act, the GDPR, or the CCPA.

If there is a breach

If personal data we hold is breached, we will tell you without undue delay by email to the address on your account, and notify the regulators we are required to notify — including India's Data Protection Board and CERT-In — within the deadlines the law sets for each of them.

The notice will say what happened, what data was involved, what we are doing about it, and what you can do. We would rather send you a short notice early than a complete one late.

Cookies and analytics

We use cookies to keep you signed in. Those are essential — without them the product cannot work.

One more first-party cookie exists: on our public college pages we set navora_attr, which records only the first page you landed on, the site that referred you, and any campaign tags in the URL — no identifier, nothing about you, and nothing shared with anyone. If you later create an account, that one fact ("this account arrived from a college page via Google") is stored with it and the cookie is deleted; otherwise it expires on its own after 30 days.

Analytics are different, and they are off until you say yes. Not "on unless you object": if you decline, or simply never answer the banner, our analytics provider is never loaded at all — no request, no cookie, nothing stored. If you accept and later change your mind, the switch in Settings turns it off and clears the identifier that linked the data to you.

Analytics never run for users under 18, whatever the banner says.

Security

We use established providers and take reasonable steps to protect your data. No online service can promise perfect security, and as an early-stage product we are actively hardening ours. If you spot a security issue, please email security@getnavora.net.

Changes to this policy

As Navora grows, this policy will change. We will update the date at the top and, for material changes, do our best to notify you in the product.

Writing to us

There is a message box on every page and at /contact. What you type goes straight to a person at Navora by email, along with the address you give us so we can reply. We do not store it in your account — it is not added to your profile, and it is not used for anything but answering you.

You do not need an account to write to us. If something went wrong before you ever signed up, that is exactly the message we most want.

Contact

Questions about privacy? Email privacy@getnavora.net.

Navora AI is a trading name of Pranesh Vats (Indian citizen), a sole proprietorship. Pre-incorporation, operating as a sole proprietor in India.

Duplex-51, Vijaya Heritage, 5th Phase, Uliyan, Kadma, Jamshedpur, Jharkhand 831005, India

Privacy: privacy@getnavora.net · Grievance officer: Pranesh Vats — grievance@getnavora.net

We acknowledge every complaint within 48 hours and resolve it within 30 days.