
Legal
Privacy Policy
Last updated August 27, 2026
The short version
- We collect what you tell us — your academic background, target countries, funding preference, career goal — to research and match real programmes and scholarships for you.
- Resumes/CVs are deleted automatically within 48 hours of upload. We keep them just long enough to be useful and no longer, to minimise the personal data we hold.
- We never sell your data. We use a small number of named third-party services (below) to actually run the product — we don't share data with anyone beyond that.
- GradsHQ never guarantees admission or funding outcomes, and doesn't fabricate university, programme, or scholarship data — see our approach to AI in the sections below.
Information we collect
Account information: name, email address, and a securely hashed password (or, if you sign in with Google, the profile information Google shares with us for authentication).
Profile information: the details you provide during onboarding — your current qualification, field of study, qualification country, grade, citizenship, residence, target degree and field, target countries, funding preference, budget range, career goal, and research interests (where applicable).
Resume/CV file: if you choose to upload one. See “Resume storage and deletion” below — this is handled differently from the rest of your data.
Saved items and computed results: programmes and scholarships you save, and the fit/readiness/eligibility scores GradsHQ generates for your profile.
How we use your information
We use your profile information to scope programme and scholarship research to your actual target countries, generate fit and readiness signals, and keep your saved items and account accessible across sessions. We do not use your information for advertising, and GradsHQ does not display third-party ads.
AI processing (OpenAI)
To research programmes and scholarships and generate fit/readiness/eligibility assessments, GradsHQ sends the relevant parts of your profile (e.g. target degree, field, target countries, academic background) and programme/scholarship data to OpenAI's API. This is necessary for the product's core functionality — it can't generate a personalised result without it.
OpenAI processes this data under its own API terms and privacy policy, which govern how they handle data sent through the API. We encourage you to review OpenAI's policies directly for the specifics of how they handle API data.
GradsHQ is built to avoid fabricating information: programme and scholarship details we can't verify from an actual source are labelled “Not currently verified” rather than filled in with a guess, and fit or eligibility scores are presented as signals, never as guarantees of admission or funding.
Resume storage and deletion
If you upload a resume or CV, it's stored with Cloudinary, a third-party file storage provider — deliberately not in our own database. The file is uploaded directly from your browser to Cloudinary using a short-lived signed authorization; it never passes through our own servers in full.
We automatically delete uploaded resumes within 48 hours. A scheduled job checks daily for resumes past their retention window and permanently deletes them from Cloudinary and removes the reference from our database. This is a deliberate choice to minimise how long we hold a sensitive personal document — not a storage cost-cutting afterthought. If you want your current programme/scholarship matching to keep reflecting your resume, you may need to re-upload it after the retention window passes.
Where your data is stored
Your account and profile data is stored in a PostgreSQL database hosted by Supabase. Resumes are stored separately with Cloudinary, as described above — never in the Supabase database. The application itself is hosted on Vercel. Data in transit is encrypted (HTTPS/TLS).
Cookies and sessions
We use a session cookie to keep you signed in. We don't use tracking or advertising cookies.
Your rights
You can review and update most of your profile information at any time from your dashboard. For requests we don't yet support with self-service tools — including full account deletion, a copy of your data, or questions about how your information is used — contact us at privacy@gradshq.com and we'll act on it directly.
If you're in the European Economic Area or UK, this includes the rights to access, correct, delete, restrict, or port your data, and to object to certain processing, under the GDPR/UK GDPR.
Children's privacy
GradsHQ is intended for graduate-school applicants and is not directed at children. We don't knowingly collect information from anyone under 16.
Changes to this policy
If we materially change how we handle your data, we'll update this page and note the date at the top. Continued use of GradsHQ after a change means you accept the updated policy.
Contact
Questions about this policy or your data: privacy@gradshq.com
This policy describes GradsHQ's current data practices in plain language. It is not legal advice, and it doesn't replace a formal compliance review for your specific jurisdiction. See also our About page.