At a glance
- We do not sell your data
- not to anyone, not ever.
- We do not share it for advertising
- no cross-context behavioural advertising, no targeted advertising to students, and no advertising or social media tracking tags on any page where a student is identifiable.
- We do not train AI on student essays or chats
- student essays, Quaia conversations, academic scores and other student personal information are excluded from all AI model training, ours and anyone else’s. See Section 6.
- Parents see summaries by default, not the full chat
- activity, summaries, drafts and safety flags are visible by default. Parents can request the complete conversation record at any time, and we will provide it. See Section 5.
- We do not keep data forever
- every category has a stated retention period and is purged automatically. See Section 9.
- Children under 13 cannot use mynugen
- enrolment is blocked at the age gate for anyone under 13. See Section 12.
1. Who this policy covers, and the two roles
This Privacy Policy explains how mynugen ("we," "us") handles personal information. mynugen is a subscription service that helps students in grades 9 to 12 navigate the United States undergraduate admissions process. Every account is held by an adult parent or guardian. Every student user is aged 13 to 17.
Because our users are minors, we have written this policy to be read, not skimmed. The Teen & Parent Privacy Notice says the same things in fewer words.
"Parent" means the adult account holder. The parent creates the account, is the contracting party under the Terms of Service, pays for the subscription, grants consent for each student, and can end the account at any time.
"Student" means a person aged 13 to 17 enrolled by their parent. A student has their own login and their own profile, but does not hold the account and cannot purchase, consent or enrol.
This policy also covers people who join our waitlist or contact us without an account.
1A Students who turn 18: data transition
When a Student on a Parent Account turns 18, their personal information transitions from minor processing to adult processing. From their 18th birthday: their data rights under Section 11 become exercisable by them directly, without requiring parental action; the Parent’s right to request the full Quaia conversation record under Section 5.3 ends, unless the now-adult Student provides written consent for it to continue (submit that consent to privacy@mynugen.ai); we will serve an updated privacy notice to the Student at their email address no later than 14 days before their 18th birthday, describing these changes; and processing continues on the existing legal bases until the Student makes an election under Terms of Service Section 3.4, after which this policy applies to them in the capacity of an independent adult account holder.
Where the Admissions Season Protection in Terms of Service Section 3.8.4 applies (student turns 18 between 1 October and 31 March), the transition of data rights follows the same extended timeline: the Parent’s full-record request right continues until 30 April, after which it terminates unless the adult Student has consented to its continuation.
2. Information we collect
2.1 Before there is an account: the waitlist. The waitlist is for parents and guardians. When you join it we collect three things and no more: your full name (so confirmation and launch emails can address you personally), your email address (to confirm your place and tell you when the Service opens), and your country (to tell you when we open in your market).
AT THE WAITLIST STAGE WE DO NOT COLLECT ANY INFORMATION ABOUT A STUDENT, AND WE DO NOT COLLECT A DATE OF BIRTH, A SCHOOL NAME, A GRADE, A GPA OR ANY TEST SCORE FROM ANYONE. JOINING THE WAITLIST DOES NOT CREATE AN ACCOUNT, DOES NOT ENROL A STUDENT, AND DOES NOT BEGIN ANY SUBSCRIPTION.
2.2 Information the parent gives us
Parent identity and contact: name, email address, telephone number, country and state, to create and secure the account, to contact you, and to verify a parental request.
Relationship confirmation: your confirmation that you are the parent, guardian or legal custodian of each student, to make the consent valid.
Student enrolment details: the student’s first name or preferred name, date of birth, and student email address, to create the student profile, apply the age gate, and send the student their account invitation. The student’s email address is required where the invitation flow is the method of delivering the student’s first-login credentials and the disclosures required by Terms of Service Section 4.2A.
Billing: billing name, billing address, last four digits and card type, and a payment token, to take payment and to meet tax and accounting obligations. We never receive or store a full card number.
Consent record: the date and time of each consent, the policy versions shown, the IP address of the device used, and the student profile it relates to, to evidence that consent was properly obtained.
Student invitation details: the student’s email address (provided by the parent at enrolment), the timestamp of the invitation send, and the timestamp of first credential use, to deliver account access to the student and to record that the first-login disclosures were delivered. We do not track open or click events on invitation emails and do not use the student’s email address for marketing.
2.3 Information the student gives us
Academic profile: grade level, school name, coursework, GPA and standardised test scores, all self-reported, to build a college list and readiness view.
Preferences: intended major, location and size preferences, priorities and interests, to generate relevant suggestions.
Application materials: essays, personal statements, supplemental responses, activity lists and drafts, to provide feedback and to keep drafts available.
Quaia conversations: the messages a student sends to Quaia and Quaia’s replies, to operate the feature, maintain continuity across sessions, and run our safety systems.
Progress data: tasks completed, deadlines set, colleges saved, readiness indicators, to run the tracking features.
Onboarding responses: the answers to the short onboarding check-in at first login, covering familiarity with the admissions process, areas of most concern, and stated goals, used to calibrate Quaia’s initial responses to the student’s starting level of knowledge. Stored as part of the student profile under the same retention schedule as academic records, and not used for any purpose beyond personalising the student’s experience.
WE DO NOT COLLECT: PRECISE GEOLOCATION OR GPS DATA; BROWSING ACTIVITY OUTSIDE THE MYNUGEN SERVICE; SOCIAL MEDIA PROFILES, HANDLES OR CONTACT LISTS; BIOMETRIC IDENTIFIERS INCLUDING FACE, VOICEPRINT OR FINGERPRINT DATA; HEALTH OR MEDICAL INFORMATION; RACE OR ETHNICITY, RELIGION, SEXUAL ORIENTATION, GENDER IDENTITY, IMMIGRATION STATUS OR POLITICAL AFFILIATION; CONTACTS, PHOTOS, CAMERA OR MICROPHONE ACCESS; OR ANY DATA FROM DATA BROKERS.
A student may choose to write about any subject in an essay or to Quaia. If a student volunteers information of a sensitive kind in free text, we do not extract it, index it as a category, build a profile from it, or use it for any purpose other than providing the Service and operating the safety systems described in Section 8.
2.4 Information collected automatically
When you or a student use the Service we collect device and connection information (IP address, browser and operating system type, device identifiers), authentication events (sign-in times, sign-in method, session duration), and first-party product analytics about which features are used. Section 14 and the Cookie & Tracking Notice explain the technologies involved.
Device and connection information we collect automatically, including IP addresses and device identifiers, is personal information. It is within scope for all data rights requests in Section 11, including deletion, access and portability.
2.6 Why we retain Quaia conversation data for 24 months
The Quaia conversation content in Section 9.1 is retained on a rolling 24-month basis. This is longer than some comparable products retain chat history, and we explain why.
Admissions continuity: a student typically uses mynugen across a two-year period, junior year for exploration and test preparation, senior year for application. Quaia’s ability to recall earlier conversations and build on them is a core feature of the guidance it provides. Deleting conversations after each session would mean Quaia treats every interaction as a first meeting, which defeats the purpose.
Parent access right: under Section 5.3, a parent may request the complete Quaia conversation record at any time. That right is meaningful only if the record exists. Deleting conversations before a parent has had a reasonable opportunity to exercise this right would render the right hollow.
Safety record integrity: safety records created under Section 8 may reference or be traceable to the underlying conversation. Retaining the conversation ensures that a safety record can be understood in context if it is reviewed or challenged.
You may request deletion of Quaia conversation content at any time under Section 11.3. Deletion from the student’s view does not delete a safety record created under Section 8, as explained in Section 5.4. We do not retain Quaia conversations beyond 24 months for any purpose, and we do not use the content for AI training under any retention period.
3. How we use information
Providing the Service: creating and maintaining accounts and profiles, generating college suggestions and readiness views, operating Quaia, storing and returning drafts, tracking deadlines and tasks.
Consent and parental controls: recording consent, applying the settings a parent chooses, operating the Parent Dashboard, handling withdrawal of consent.
Payment and account administration: taking payment, sending receipts and renewal notices, handling cancellations, tax and accounting records.
Support: responding to questions and problems from parents and students.
Safety: detecting and responding to expressions of distress, self-harm risk and abuse, as described in Section 8.
Security and fraud prevention: authenticating users, detecting unauthorised access, preventing abuse of the Service, enforcing the Terms.
Service improvement: understanding which features are used and where the product fails, using aggregated and de-identified data only. See Section 6 for the strict limits that apply.
Legal compliance: meeting our obligations, responding to lawful requests, establishing or defending legal claims.
Communications: service and transactional messages. Marketing messages are sent only to parents, only with consent where required, and can be stopped at any time without affecting the subscription.
We do not use personal information for automated decision-making that produces legal or similarly significant effects. Readiness indicators and college suggestions are organisational aids and are not decisions about a person.
4. Legal bases and permitted purposes
Where privacy law requires us to identify a legal basis or a permitted purpose, we rely on: performance of the contract with the parent, for account creation, delivery of the Service, payment and support; consent, for the processing of a student’s personal information, for any processing that is not strictly necessary to deliver the Service, for non-essential cookies, and for marketing where consent is required (consent may be withdrawn at any time); legal obligation, for tax, accounting, records and responses to lawful requests; vital interests, for the safety escalation described in Section 8, where there is an apparent risk to life; and legitimate interests, limited to securing the Service, preventing fraud and abuse, and de-identified product improvement. Given our user base, we have set this basis deliberately narrow and it does not override the rights of a minor.
Where the law of a state in which a student resides gives that student their own consent right over processing that is not strictly necessary, we seek the student’s informed consent in addition to the parent’s, we present the choice without dark patterns, we make declining as easy as accepting, and we do not degrade the Service or change its price if a student declines.
5. What a parent can see, and what stays with the student
5.1 The Parent Dashboard shows, by default: the student’s college list, saved programmes and stated preferences; readiness indicators, tasks, deadlines and application progress; application materials the student has saved or uploaded, including drafts; when the student used the Service and for how long, and topic-level summaries of Quaia sessions; any safety flag raised under Section 8; and all billing, consent and account history.
5.2 The Parent Dashboard does not show, by default, the verbatim text of a student’s conversations with Quaia. This is a deliberate choice. A student who believes every sentence will be read will not raise the subjects on which guidance is most valuable, including the ones that matter for their safety. Summaries and safety flags give a parent real oversight without producing that effect.
5.4 What the student can see and control. A student can see everything in their own profile, can edit or delete their own drafts and college list, can delete individual Quaia conversations from their own view, and can ask us at any time what we hold about them. Deleting a conversation from the student view does not delete a safety record created under Section 8, and does not remove it from a parent’s request under Section 5.3 while it is still within the retention period.
5.3 A parent can always obtain the full record
Your legal right as a parent to access the personal information we hold about your child is not limited by Section 5.2. At any time you may request the complete Quaia conversation record for a student on your account, from the Parent Dashboard or by writing to privacy@mynugen.ai. We will verify your identity and your relationship to that student profile, provide the full record within 30 days and usually far sooner, and tell the student that the request was made and fulfilled, unless a trained mynugen safety reviewer determines, following our published safety protocol, that notification would create a credible and specific risk of harm to the student.
Any determination to withhold student notification is: logged with the reviewer’s name, the applicable reason code, and the date of the determination; reviewed for continued applicability at intervals of no more than 30 days; and reversed as soon as the safety concern is resolved, at which point the student is notified retroactively. We do not charge for this request, we do not require a reason, and we do not attempt to talk you out of it.
5A Educational advisor access: what advisors can and cannot see
Where a parent grants an educational advisor access to the Account under Terms of Service Section 4.8, the following governs what that advisor can see from a data-privacy perspective.
What an advisor can access by default (Progress View): readiness indicators, application deadlines, college list, and task completion status. No essays, no test scores, no Quaia activity of any kind.
What an advisor can access if the parent grants Essay Access: all of the above, plus Application Material drafts the student has saved. Still no Quaia conversations.
What an advisor can access if the parent grants Full Profile View: all of the above, plus academic profile data including grades, test scores, and activities. Still no Quaia conversations.
What an advisor can never access, regardless of access level granted: Quaia conversation transcripts, which are never accessible to any third party, including advisors, school counselors, or independent college consultants; safety records created under Section 8; billing information or payment history; or the parent’s own login credentials or consent settings.
How we handle advisor access data. Every advisor access event is logged: the time, the profile accessed, and the access level at the time of access. Advisor access is revoked automatically on Account termination or Student Profile deletion. The parent may revoke advisor access at any time with immediate effect from the Parent Dashboard. We do not share advisor access logs with the advisor themselves.
Advisors are not sub-processors. Educational advisors granted access under Terms of Service Section 4.8 are not our vendors or subprocessors. They access the Service as users, under the parent’s authorisation, and their use of the information they see is governed by the parent’s instructions and by their own professional obligations, not by our agreements. We are not responsible for what an advisor does with information they see through their access.
6. Artificial intelligence and your information
6.1 What is excluded from AI training. STUDENT ESSAYS AND OTHER APPLICATION MATERIALS, QUAIA CONVERSATION CONTENT, ACADEMIC RECORDS AND SCORES, AND ANY OTHER PERSONAL INFORMATION OF A STUDENT ARE EXPRESSLY EXCLUDED FROM: (a) TRAINING, FINE-TUNING OR EVALUATION OF ANY FOUNDATION MODEL OR GENERAL-PURPOSE LARGE LANGUAGE MODEL, WHETHER OURS OR A THIRD PARTY’S; (b) ANY COMMERCIAL ARTIFICIAL INTELLIGENCE DATASET OR DATA PRODUCT; (c) ANY TRAINING DATASET OF ANY VENDOR, MODEL PROVIDER OR SUBPROCESSOR; (d) ANY EXTERNAL ARTIFICIAL INTELLIGENCE MODEL OR SYSTEM; AND (e) SALE, LICENSING OR DISCLOSURE TO ANY THIRD PARTY FOR THAT PARTY’S OWN ARTIFICIAL INTELLIGENCE DEVELOPMENT.
6.5 No emotion inference. We do not use artificial intelligence to infer emotions from a person’s voice, face, body or physiological signals, and we do not build or purchase any capability to do so. Quaia is a text feature. This is a permanent product commitment, not a current limitation, and it is repeated in the AI Disclosure Notice.
6.2 What we do instead
We improve Quaia and the rest of the Service using aggregated and de-identified statistics, de-identified in accordance with the standard in California Civil Code § 1798.140(m), including technical safeguards against re-identification, a public commitment not to re-identify, and contractual obligations on any recipient of such data prohibiting re-identification. We do not attempt to re-identify de-identified data and we do not permit anyone else to do so.
Examples of what this means in practice: how often a feature is used, how often Quaia is asked to do something it cannot do, the rate at which drafts are abandoned. Never: an individual essay, an individual conversation, an individual score.
6.3 What our model providers may do
Quaia runs on large language models supplied by third-party providers listed in Section 7. Under our agreements with them, those providers may process the text we send them only to generate a response back to us. They may not train on it, may not use it for their own purposes, and may not retain it beyond [CONTRACTED RETENTION WINDOW] following each request, which is the maximum period we permit for abuse monitoring.
We confirm the contracted retention windows for each provider at each annual contract renewal and update Section 7.1 accordingly. We review this position whenever a provider changes its terms.
6.4 Human review
A small number of Quaia conversations are reviewed by trained mynugen personnel, for two purposes only: (a) to investigate a safety flag raised under Section 8, following the published safety protocol; and (b) to investigate a specific, documented technical or safety defect in Quaia’s behaviour that has been reported by a user or identified by automated monitoring, where the specific conversation has been identified as the subject of investigation before access is sought.
We do not review conversations for general quality improvement, training, product development, or A/B testing. Access is restricted to named personnel, is logged with the defect ticket number for category (b) reviews, and is subject to confidentiality obligations. We do not conduct routine or random reading of student conversations.
7.4 Business transfers: your rights on acquisition or merger
If mynugen is acquired by, merged with, or transfers substantially all its assets to another entity, personal information held by us will be among the assets involved. Before any such transfer takes effect with respect to personal information of our users, we will: (a) give you at least 30 days’ advance written notice by email to the address on your Account, describing the nature of the transaction and the identity of the acquiring entity; (b) contractually bind the acquiring entity to commitments no less protective than those in this Privacy Policy, including the AI training exclusions in Section 6.1 and the data rights in Section 11; (c) give you the right to request deletion of your Account and all associated data before the transfer takes effect, exercisable under Section 11.3 during the notice period; and (d) confirm in writing, within 30 days of the transfer completing, that the acquiring entity has accepted and is bound by those commitments.
If the acquiring entity’s privacy practices would be materially less protective of student data than those in this Privacy Policy, for example if the acquirer intends to use student data for AI training, we will treat that as a material change under Section 16 and will seek fresh consent from affected parents before any such use begins.
In a bankruptcy or insolvency proceeding, personal information may be transferred as part of the assets. We will notify affected users as promptly as legally permitted in such a proceeding and will use reasonable efforts to ensure the acquiring party maintains commitments consistent with this policy.
8. Safety information
Quaia is configured to recognise expressions of distress, suicidal ideation, self-harm, abuse and similar risk. When it does, the system creates a safety record and, depending on severity, refers the conversation for review by trained personnel under our published safety protocol.
Where review indicates a credible risk of serious harm, we may notify the parent, surface crisis resources to the student, contact emergency services where there is an apparent imminent risk to life, contact appropriate authorities where we have a reporting obligation, and restrict access where continued use appears to present a risk.
Safety records are retained for the period in Section 9, held separately from ordinary conversation data with restricted access. They are not used for product analytics, are not used for AI training, and are not disclosed to any vendor other than the host that stores them.
THIS IS NOT A MONITORING SERVICE AND NOT A CRISIS SERVICE. OUR SYSTEMS ARE AUTOMATED AND IMPERFECT. THEY WILL NOT DETECT EVERY SITUATION. IF SOMEONE IS IN IMMEDIATE DANGER, CALL 911. IF YOU OR A STUDENT ARE THINKING ABOUT SUICIDE OR SELF-HARM, CALL OR TEXT 988, OR TEXT HOME TO 741741.
9. How long we keep information, and how it is destroyed
9.1 Retention schedule. Waitlist name, email and country: until the waitlist converts or 12 months, whichever is first, then deleted on request within 30 days. Parent identity and contact: life of the account, then 12 months. Student name and date of birth: life of the profile, then 6 months. Academic records and scores: life of the profile, then 12 months. Onboarding responses: life of the profile, then 12 months, the same as academic records. Application materials and drafts: life of the profile, then 6 months. Quaia conversation content: rolling 24 months, then 6 months after closure. College list and application tracking: life of the profile, then 6 months. Consent records: life of the account, then 7 years, retained to evidence consent was properly obtained. Billing and tax records: life of the account, then as required by tax law, currently 7 years. Safety records: life of the profile, then [24] months, or longer where required by law or an active matter. Security and access logs: 12 months while active, then 12 months. Blocked under-13 age gate records: not applicable while active, then [12] months, minimal fields only. Invitation credential records: invalidated on first use, with the log retained for 12 months as a security record. Every category is purged after its retention period ends.
9.2 Automatic purge. When an account or profile is deleted, or a retention period ends, deletion runs automatically. Data is removed from production systems within 30 days and from backups within 90 days, as backup sets rotate out. The parent receives a confirmation email when the purge for their account is complete.
We may retain information beyond these periods only where legally required, or where necessary to establish, exercise or defend a legal claim, and only for as long as that reason lasts. In those cases the data is placed under restricted access and is not used for any other purpose.
9.3 Self-reported data: distinction from official records
All academic data held in the Service, including grade point averages, class rank, standardised test scores, AP and IB results, coursework, and extracurricular activities, is self-reported by the parent or student at the time of profile creation or update. We do not receive, verify, or validate this data against any official source.
This means: we hold no official academic records, and the information in a student’s profile should never be confused with official transcripts, score reports, or records held by a school, college, or testing organisation. We do not verify accuracy; we accept the data as provided, and the parent’s warranty under Terms of Service Section 6A is the mechanism that maintains data quality. We are not a testing organisation and have no relationship with College Board, ACT, Inc., or any other testing organisation in our capacity as a data holder; score data in a student’s profile does not constitute an official score report. Updates are the parent’s and student’s responsibility: when official scores change, it is up to them to update the profile, since we do not receive automatic updates from any institution or testing body.
The self-reported nature of all profile data is also reflected in the retention schedule in Section 9.1: we retain academic records and scores for 12 months after account closure, not indefinitely, because these are profile records, not official transcripts that require long-term preservation.
10. Security
We state only what we actually do. Personal information is encrypted in transit using current TLS, and encrypted at rest using AES-256 or the equivalent provided by our cloud host. Multi-factor authentication is enforced for every mynugen staff account with access to production systems. Access to production data follows least privilege, is granted by role, is reviewed quarterly, and is revoked on the day a person leaves. Access to student conversation content is restricted to named personnel and every access is logged. We keep centralised logs with alerting on unusual access patterns. We maintain a written incident response runbook and rehearse it. We keep a vendor and subprocessor register with the data categories and agreement status of each. No system is perfectly secure. We do not claim that ours is.
10.1 If there is a breach
If a security incident affects personal information, we will investigate, contain it, and notify: affected parents without undue delay and as soon as reasonably practicable after we establish that their information was affected, taking into account the nature of the incident, the need to determine its full scope, and any instruction from law enforcement or a regulatory authority; affected students, where appropriate, at the same time and in age-appropriate language; regulators and attorneys general within the period required by the applicable statute (for New York residents, within 30 days of establishing that more than 500 New York residents are affected, under the NY SHIELD Act); and institutional customers, if any, without undue delay following our notice to regulators.
Our notice will describe what happened, what information was involved, what we have done, and what you can do.
10.2 Invitation credential security
Temporary login credentials issued to a student via invitation email are: generated using a cryptographically secure random function; stored in hashed form, we never store the plaintext credential; transmitted only over encrypted connections (TLS); valid for [CREDENTIAL VALIDITY PERIOD] from the time of issue; and permanently and automatically invalidated on first use.
A student who has not used their invitation within the valid period must request a new one from their parent through the Parent Dashboard. We do not reuse invalidated credentials.
10.3 Annual independent security assessment
We commission an independent security assessment of the controls described in this Section at least once every 12 months. The assessment is conducted by a qualified third party who is not a member of our engineering or operations team. We act on material findings within a reasonable period and update this Section where a control changes as a result. We do not publish the full assessment report, but will confirm to any user on request that the most recent assessment has been completed and the date of completion.
10.4 COPPA: our architectural approach and why it applies
The Children’s Online Privacy Protection Act (COPPA) and its implementing rule (16 C.F.R. Part 312) impose specific requirements, including verifiable parental consent, on operators of websites and online services directed to children under 13, or that have actual knowledge they are collecting personal information from a child under 13.
mynugen’s architectural approach. We have made a deliberate architectural decision to operate outside COPPA’s scope by blocking the enrolment of any user under the age of 13 at the age gate. This is not merely a policy commitment; it is a technical enforcement mechanism. The age gate rejects enrolment where the stated date of birth indicates an age below 13, retains the rejected date of birth as a blocking record, and prevents any Student Profile from being created for a child under 13.
Because we do not knowingly permit any child under 13 to use the Service, and because our age gate is designed to prevent it, we operate on the basis that COPPA does not require verifiable parental consent for our user base. This depends entirely on the age gate working as described. The age gate specification in the Cookie & Tracking Notice is therefore a compliance control, not a user-experience feature.
What this means for you. The parental consent architecture in Terms of Service Section 6, under which the Parent is the contracting party and grants consent for each Student, is built on the assumption that every enrolled Student is aged 13 or over. If we discover that a child under 13 has been enrolled, for example because a false date of birth was provided, we will terminate the Student Profile immediately, delete all personal information collected from or about that child as soon as practicable, and notify the parent that the enrolment was invalid and that data has been deleted.
We do not claim COPPA safe harbor certification through any approved program. Any claim of safe harbor certification in our materials would be a misrepresentation and is not made.
11. Your rights and how to use them
11.1 What you can ask for. Access: a copy of the personal information we hold, including the full Quaia record under Section 5.3. Correction: fixing information that is wrong or out of date. Deletion: deleting an account, a student profile, or specified categories of data, as described in Section 11.3. Portability: a copy in JSON format, including all data you or a student submitted to the Service, all Quaia conversation history, all application materials and drafts, and all progress and tracking data, delivered via a secure, time-limited download link within 45 days (safety records are available under the correction process below, not in the portability export). Withdrawal of consent: at any time, from the Parent Dashboard or by email; withdrawal ends the student’s access and triggers the deletion process in Section 9. Objection and restriction, where applicable law provides them. Non-discrimination: we will not deny service, charge a different price or provide a lesser experience because you used a privacy right.
Review and correction of safety records. A parent may request review of the classification of a safety record created under Section 8, where they believe the record was created in error. Submit the request to privacy@mynugen.ai with the relevant date and profile identifier. A reviewer who was not involved in the original classification will review the record within 30 days and will correct or delete it if the original classification was incorrect. We will notify the parent and, where appropriate, the student of the outcome. Safety records retained for active legal matters are not subject to deletion but must still be correctable.
Limit use of sensitive personal information (California residents). If you are a California resident, you have the right to ask us to limit our use of sensitive personal information as defined by CCPA § 1798.121. For most categories listed in that statute, our answer is that we do not collect them (see Section 2.3). Where a student has voluntarily included sensitive information in an essay or Quaia conversation, we use it only to provide the Service and operate our safety systems, and you may ask us to confirm this at any time by writing to privacy@mynugen.ai.
11.2 How to make a request. Use the Parent Dashboard, or write to privacy@mynugen.ai. A parent may exercise these rights for a student on their account. A student aged 13 or over may make a request about their own information directly.
Where a student’s request and a parent’s instruction conflict: for processing that is not strictly necessary to provide the Service, and where applicable state law gives the student their own consent right, we will action the student’s instruction and notify the parent; for requests that would materially change or delete the Account as a whole, we will action the parent’s instruction unless a court order establishes the student’s independent right to act; and in all cases, we will notify both the parent and the student of the action taken and the basis for it.
Where two adults submit competing data rights requests regarding the same student, for example in a custody dispute, we will process the request from the Primary Account Holder and will notify the competing claimant that a certified court order establishing their legal custody or guardianship must be submitted before we can process their request. This process mirrors Terms of Service Section 4.6.
11.3 Deletion, specifically. The Parent Dashboard includes a "Delete data" control that allows you to choose what to delete: Quaia conversations only; application materials and drafts only; college list and application tracking only; an entire student profile; or the entire account and everything in it. We acknowledge the request within 24 hours, complete production deletion within 30 days, complete backup purge within 90 days, and send a written confirmation when it is done. Every deletion request includes all personal information for the relevant scope, including device identifiers and analytics data associated with the deleted profile or account. We do not require you to give a reason and we do not add friction to the flow.
11.4 Verification, timing and appeals. We verify requests before acting, proportionately to the sensitivity of what is asked. We respond within 45 days and may extend once by a further 45 days where the request is complex, telling you why. There is no charge unless a request is manifestly unfounded or excessive. If we refuse a request, we will tell you why and how to appeal; you may appeal by writing to privacy@mynugen.ai with "Appeal" in the subject line, and we will respond within 45 days. If we deny your appeal you may complain to your state attorney general or other competent authority.
12. Children under 13
mynugen is not directed to children under 13 and we do not knowingly collect personal information from them. Our age gate is designed to block enrolment where the stated date of birth indicates an age below 13. If we learn that we hold information about a child under 13, we delete it and terminate the profile.
If you believe a child under 13 has provided us with personal information, write to privacy@mynugen.ai and we will act promptly.
13. State-specific disclosures
13.1 All US residents. Depending on where you live, you may have some or all of the rights in Section 11 under a state privacy statute. We extend the rights in Section 11 to every US user regardless of state, because maintaining different tiers of protection for minors would be both operationally fragile and difficult to justify.
13.2 California
Under the California Consumer Privacy Act as amended, for the preceding 12 months: categories collected include identifiers, customer records, commercial information, internet or network activity, education information, text-limited audio or electronic information, and inferences drawn to generate college suggestions. Sources are directly from the parent and student, automatically from device and usage, and from our service providers. Categories sold: none, we have not sold personal information. Categories shared for cross-context behavioural advertising: none. We do not collect sensitive personal information for the purpose of inferring characteristics; where a student voluntarily discloses sensitive information in free text, we use it only to provide the Service and operate safety systems, permitted purposes under § 1798.121. Right to limit sensitive PI: California residents have the right under CCPA § 1798.121 to limit our use of sensitive personal information; as stated above, we do not collect most categories, and for voluntarily disclosed sensitive information in free text, you may request confirmation of our permitted-use-only position by writing to privacy@mynugen.ai (see Section 11.1 for the exercise process). Minors: we do not sell or share the personal information of any consumer we know to be under 16. Every student user is aged 13 to 17. Authorised agent: California residents may designate an authorised agent to exercise rights on their behalf.
California "Shine the Light" (Cal. Civ. Code § 1798.83). California residents have the right to request, once per calendar year, information about any personal information we disclosed to third parties for their own direct marketing purposes. Our answer is that we make no such disclosures, have made none in the preceding 12 months, and have no plans to do so. There is no list to provide. To request written confirmation of this position, write to privacy@mynugen.ai with the subject line "Shine the Light Request" and your California residential address. We will respond within 30 days.
13.3 New York
For students who are New York residents aged 13 to 17, we process personal data only where it is strictly necessary for a permitted purpose, or where we have obtained the student’s own informed consent presented separately from any other transaction, without dark patterns, with declining as easy as accepting, and with no penalty for declining. Consent may be revoked at any time. We honour Global Privacy Control signals where we are able to detect them.
NY SHIELD Act (breach notification). Where a breach affects the private information of more than 500 New York residents, we will notify the New York Attorney General within 30 days of establishing that New York residents are affected, in addition to the individual notifications described in Section 10.1. We will notify the affected individuals at the same time or before notifying the AG.
13.4 Other states
Residents of states with comprehensive privacy statutes, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and others, have the rights described in Section 11, exercisable in the same way. Where a state statute requires opt-in consent before processing the personal data of a person aged 13 to 17 for targeted advertising, sale or profiling, our answer is that we do none of those things for anyone.
Data Protection Impact Assessments. Where required by applicable state law, including the Colorado Privacy Act, the Virginia Consumer Data Protection Act, and the Connecticut Data Privacy Act, we conduct and document data protection impact assessments for processing activities that present a heightened risk of harm to data subjects, including our processing of personal data of users aged 13 to 17 and our use of Quaia to generate profile indicators. These assessments are available to relevant regulatory authorities on request.
13.5 Design code and duty-of-care obligations
Several states impose additional duties on services likely to be accessed by minors, including default settings, prohibitions on dark patterns, restrictions on notifications during night and school hours, and a duty to avoid designs that foreseeably cause compulsive use. mynugen is built without engagement-maximising design: there is no algorithmic feed, no infinite scroll, no streaks, no student-to-student messaging.
We do not send push notifications, in-app alerts, or email reminders to students between 10:00 PM and 7:00 AM in the student’s local time zone. Safety alerts and crisis resource messages are exempt from this restriction and may be sent at any hour where there is an apparent risk to the student’s wellbeing.
Vermont’s Age-Appropriate Design Code (in force 1 January 2027) will apply to mynugen given that our entire user base consists of known minors. Its duty of care reaches designs that foreseeably cause emotional distress or compulsive use. We are monitoring this statute and will confirm compliance before its effective date.
13.6 Privacy by Design commitment
We design mynugen’s features with privacy as a starting condition, not an afterthought. Before any new feature involving the collection or processing of personal data is built, we assess its privacy impact and apply the following principles: data minimisation by default, collecting only what is necessary for the stated purpose, and asking before adding a new data field whether the Service genuinely requires it; protective defaults, with our default settings the most protective available for each feature, so parents and students can choose to share more rather than needing to opt out of sharing they never agreed to; no engagement-maximising design, meaning no algorithmic feed, no infinite scroll, no social comparison features, no streaks, and no overnight notifications (Section 13.5), enforced at the design level rather than as policy commitments a future product team might override; privacy impact assessment for high-risk processing, conducted and documented before building any feature that would involve processing presenting a heightened risk to users, particularly minors, satisfying the Colorado Privacy Act, Virginia CDPA, and Connecticut Data Privacy Act (Section 13.4); and third-party review, with our annual independent security assessment under Section 10.3 including a review of whether the controls described in this Privacy Policy are reflected in the running product, not just in the document.
This commitment is intended to satisfy the Privacy by Design expectations in California’s Age-Appropriate Design Code, New York’s minor-data design duties, and Vermont’s Age-Appropriate Design Code (effective 1 January 2027). It is reviewed at each annual policy update to ensure it reflects the product that actually exists.
15. International transfers
We are based in the United States and our infrastructure is located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection law differs from that of your country.
WE DO NOT CLAIM CERTIFICATION UNDER THE EU-US DATA PRIVACY FRAMEWORK, THE UK EXTENSION, OR THE SWISS-US FRAMEWORK. NO SUCH CLAIM MAY BE MADE ANYWHERE IN OUR MATERIALS UNLESS AND UNTIL CERTIFICATION IS ACTUALLY COMPLETED WITH THE US DEPARTMENT OF COMMERCE.
Where we transfer personal data out of a jurisdiction that restricts transfers, we will use an approved mechanism such as standard contractual clauses, and will publish the details before opening that market.
16. Changes to this policy
We may update this policy. We will change the effective date and, for material changes, give at least 30 days’ notice by email and by prominent notice in the Service, describing what changed. Where a change materially expands the categories of information we collect about a student or the purposes for which we use it, we will seek fresh consent rather than rely on continued use. Prior versions are archived at [ARCHIVE URL].
17. Contact us
Privacy and data rights: privacy@mynugen.ai. Named privacy contact: Kedarnath Karnik, privacy@mynugen.ai. General support: support@mynugen.ai. Safety concerns: safety@mynugen.ai. Legal notices: legal@mynugen.ai. Post: mynugen, 673 W Aster Ct., Chandler, AZ 85248, Attention: Privacy.