Privacy Policy
This policy explains what Academic Exchange collects, why, and the control you have over it. We do not sell your personal data.
What we collect
- Account data — username, email, and your role (applicant or employer).
- Applicant materials — the profile, education and research history, uploaded documents (CV, statements, transcripts), and profile links you choose to add.
- Avatar data — where you enable it, an extracted profile built from your materials and links, plus transcripts of interviews employers conduct with your avatar.
- Application data — private reusable and position-specific answers you enter for external application forms, plus application-run status.
- Employer data — postings you create and notes or shortlists you keep on candidates.
- Usage data — basic logs needed to run and secure the Service.
How we use it
To operate the Service: to match applicants with postings, to show employers a ranked fit, to power AI features you opt into, to moderate public content, and to communicate with you about your account. We process your data on the basis of the contract between us and, for optional features, your consent.
What is public, and what is not
Postings and discussion posts are public. An applicant's profile is never shown to employers until the applicant chooses to go live, and fields marked private are never shared. Uploaded documents are stored privately and served only through an owner-checked download — they are never given a public URL. Your avatar is built and exposed only after you grant consent, and you can revoke it.
AI processing and third parties
Some features send your content to third-party AI providers to generate summaries, extract your profile, or run avatar interviews. We share only what the feature needs, and only when you have enabled it. We use standard infrastructure providers (hosting, email) bound to process data on our instructions.
Consent controls
Optional processing is off by default. You separately control the personalised market briefing and the candidate avatar, and can turn either off at any time from your workspace.
External application tools
If you use Auto Apply, we combine facts in your private workspace, the position-specific answers you provide, and files you select to prepare an external employer form in a visible local browser. These answers are not added to your public candidate profile. Employer-portal credentials are not stored in your application profile, and CAPTCHA applications are manual-only.
If you connect a dedicated Gmail account, OAuth credentials are encrypted with a deployment-owned key. The mailbox broker searches only recent messages expected by an active playbook, returns the required code or link in memory, and does not retain ordinary message content.
Retention
We keep your data while your account is active. When you delete content or your account, we delete or anonymise the associated personal data, except where we must retain it to comply with law or resolve disputes.
Your rights
You may access, correct, export, or delete your personal data. Email support@exchange.local from your account address and we will respond.
Contact
Questions about privacy: support@exchange.local.