Draft — not final. This page still contains unfilled placeholders and has not been reviewed by a lawyer. It must not be linked from App Store Connect in this state.
Privacy Policy — Kluge
Effective date: [EFFECTIVE DATE] Last updated: 2026-08-26
⚠️ DRAFT — NOT YET REVIEWED BY A LAWYER. This is an accurate engineering description of what the app does, written in the shape of a privacy policy. It is not legal advice. Because Kluge is aimed at high-school students, COPPA (US, under 13), state student-privacy statutes, and — if you have any users in the EU/UK — GDPR/UK-GDPR rules on children's data may all apply. Have counsel review this before publishing. Placeholders in [BRACKETS] must be filled in.
Who we are
Kluge ("the app") is published by [LEGAL ENTITY NAME] ("we", "us"). Questions about this policy or your data: [CONTACT EMAIL].
The short version
- We ask for your phone number so you can sign in. That's the only thing we require.
- Your GPA, test scores, intended major, and preferences never leave your phone. They are stored on the device and are not uploaded to us.
- We store your saved colleges and your high school so they follow you between sessions.
- You must be 13 or older to use Kluge. We do not ask your age, so we rely on you to tell us the truth about it.
- We collect anonymous usage analytics, and we record your screen while you use the app, with typed text and your scores blurred. See Young people.
- We do not sell your data, show you ads, or track you across other apps or websites.
- You can delete your account and everything attached to it from inside the app, at any time.
What we collect, and what we deliberately don't
Stays on your device — never sent to us
The following are stored only in the app's local database on your iPhone. They are used to score how well a college matches you, and that scoring happens on the device:
- Unweighted, weighted, and UC-capped GPA
- SAT and ACT scores
- Intended major
- Preferred regions, campus sizes, and campus settings
- Maximum net price
If you delete the app, this information is gone with it.
Stored on our servers
| What | Why | Where |
|---|---|---|
| Phone number | Sign-in — it's how we know it's you | Supabase Auth |
| Account identifier (a random UUID) | Ties your saved data to your account | Supabase |
| Your selected high school | Powers school-specific admissions insights and recommendations | Supabase |
| Saved colleges, plus any category and notes you add | So your list persists across sessions and devices | Supabase |
| Recommendation runs and their results | So the list is stable between openings | Supabase |
| Feedback you send us, with app version, iOS version, and device model | To understand and fix what you're reporting | Supabase |
Search "Ask" — deliberately unlinkable
When you type a sentence into search, we send it to a language model to interpret it into filters. We designed this so the sentence cannot be traced back to you:
- The cached interpretation is keyed by a cryptographic hash of the normalised sentence and stores no account identifier.
- The rate-limit record stores your account identifier and a timestamp but no text.
The two are kept in separate tables with no join between them, so we cannot reconstruct who typed what.
Analytics
We use PostHog (EU-hosted) to understand how the app is used: screens viewed, features tapped, app opens, and a set of named events such as saving a college or opening the map.
- Analytics is not connected to your account. The app never tells PostHog who you are; events carry a random device-generated identifier.
- Event properties contain IDs, counts, and category values only — never your name, scores, GPA, or the sentence you typed into search.
- Session replay is enabled. This records a screenshot-based playback of your screens. Text you type is automatically blurred. Images are not blurred; the images in the app are college logos, campus photos, and the map.
- We do not collect Apple's advertising identifier (IDFA) and do not track you across other companies' apps or websites.
Who else processes your data
| Processor | What they handle | Where |
|---|---|---|
| Supabase | Account, saved colleges, high school, feedback, recommendations | [SUPABASE REGION] |
| Supabase's SMS provider | Delivering your sign-in code | [SMS PROVIDER — confirm and name] |
| PostHog | Anonymous usage analytics and session replay | EU |
| Anthropic | Interpreting search sentences (no account identifier attached) | US |
| OpenAI | Generating college recommendations | US |
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Young people
Kluge is built for high-school students, so we expect most of our users to be minors, and we've designed accordingly.
You must be 13 or older
Kluge is for students aged 13 and over. We do not knowingly collect any personal information from children under 13.
We do not ask your age or verify it, so this is a condition of use rather than something the app checks. If you are under 13, please do not sign in.
If you believe a child under 13 has created an account, contact us at [CONTACT EMAIL] and we will delete the account and its data.
The website
Browsing collegeapp's website requires no account and sets no tracking cookies.
The website offers the same optional phone sign-in as the app. If you use it, your saved colleges and your high school are stored against your account — nothing else is. Your GPA, test scores, intended major and preferences stay in your browser's local storage and are never uploaded, exactly as on the phone.
Signing out leaves your saved list in that browser; it does not delete your account.
Screen recordings
Because most of our users are minors, we want to be explicit rather than bury this: we record a video-like playback of your screen while you use the app, using PostHog's session replay. It captures what is on the Kluge screen — which colleges you look at, your saved list, your selected high school, and how you move around the app. It does not access your camera, your microphone, or anything outside Kluge.
Text you type is automatically blurred, and the screens showing your GPA and test scores are blurred as well. Images are not blurred; the images in the app are college logos, campus photos, and the map.
Parents and guardians
If you are a parent or guardian and want to see what we hold about your child, correct it, or have it deleted, write to [CONTACT EMAIL]. We will respond within [RESPONSE WINDOW]. Your child can also delete their own account and all data attached to it at any time from Settings.
Your choices
- Delete your account. Settings → Delete Account removes your account and the data attached to it. This cannot be undone.
- Sign out. Settings → Sign Out leaves your data intact.
- On-device data. Deleting the app removes everything stored locally, including GPA and scores.
- Access, correction, deletion, portability. Depending on where you live you may have further rights. Write to [CONTACT EMAIL] and we will respond within [RESPONSE WINDOW].
Retention
Account data is kept while your account exists and is removed when you delete it. Anonymous analytics are retained per PostHog's retention settings ([SPECIFY PERIOD]). Cached search interpretations expire after 7 days.
Security
Traffic is encrypted with HTTPS. Server data is protected by row-level security so one account cannot read another's. No system is perfectly secure, and we can't guarantee absolute security.
Changes
If we change this policy materially we will update the date above and notify you in the app before the change takes effect.
Contact
[LEGAL ENTITY NAME] [POSTAL ADDRESS] [CONTACT EMAIL]