ScholarSafe

Privacy Policy

Operational draft — attorney review pending

Effective date: August 5, 2026

This Privacy Policy describes how ScholarSafe (“ScholarSafe,” “we,” “us”) collects, uses, and shares information when you use scholarsafe.com and related services (the “Service”). ScholarSafe is currently operated by its founder as an unincorporated online service. No mailing address is publicly available at this time; see “Contact” below. Formal entity registration and a public mailing address are external launch items tracked outside this codebase.

This is an operational draftwritten to accurately describe ScholarSafe's actual current practices during its limited pilot. It has not yet been reviewed by an attorney and should not be treated as a final, legally complete policy. It does not claim compliance with any specific privacy law.

Who can use ScholarSafe

ScholarSafe's initial market is California; the Service may also be reachable elsewhere in the United States, and landlords and students are not technically restricted by location. Users under 13 are prohibited from using ScholarSafe. ScholarSafe's provisional minimum age is 16. Users aged 16–17 may use ScholarSafe only with a parent or legal guardian's involvement and permission. Users under 18 may not create landlord accounts or publish housing listings unless a later, separately approved policy expressly permits it.

Information we collect

Account registration and authentication

When you create an account, we collect your email address and password (stored securely by our authentication provider, Supabase — we never see your raw password). We use your email to verify your account, authenticate logins, and send account-related messages.

School email verification (“School Email Verified”)

If you verify your student status, we record that you demonstrated control of an eligible school-issued email address. This is a trust signal, not proof of identity, age, current enrollment, graduation status, or safety — see “Verification Standards” below and our verification standards page.

Profile information

Name, school/campus, bio, preferences, and any other information you choose to add to your profile. Some profile information is visible to other ScholarSafe users as part of using the roommate and listing features.

Landlord and property verification information

If you apply for landlord verification, you may submit documentation intended to show ownership, management authority, or authorization to list a property. Staff review this documentation manually — ScholarSafe does not currently perform guaranteed third-party identity verification. We distinguish between:

  • Raw verification documents — the files/images you submit. We aim to delete these within 21 days after a verification decision, subject to exceptions for suspected fraud, appeals, safety matters, or legal holds.
  • Verification result records — the outcome (e.g. approved/denied) and internal notes, which we retain longer for audit and safety purposes (see “Retention” below).

Listings and images

Property listings, including address, description, and photos you upload, are stored on our platform and are generally public to visitors browsing ScholarSafe, since listings exist to be discovered by prospective renters.

Messages

Private messages between students and landlords, or between students, are stored so the conversation can be delivered and displayed to its participants. We do not use message content for advertising. Support/safety staff may access message content when investigating a report, safety issue, or policy violation.

Favorites and saved searches

Listings and roommate profiles you save, and search criteria you save for alerts, are stored to power those features and are private to your account.

Reviews

Reviews you write about a listing or landlord are stored and, once published, are visible to other users as public user content.

Reports and moderation records

If you submit a report, or are the subject of one, we retain the report content and our moderation actions for safety and audit purposes.

Device, browser, and security logs

Our hosting and authentication providers (Vercel and Supabase) log standard request metadata such as IP address and browser user agent as part of operating the Service and detecting abuse. ScholarSafe's own application code does not separately collect or display this data to us.

Error diagnostics (Sentry)

We use Sentry to capture application errors so we can fix bugs. Error reports may include your account's internal user ID, the page you were on, and technical error details — not your email address, message contents, or form field values. We've configured Sentry to strip one-time login/verification tokens that could otherwise appear in a page URL before an error report is sent.

Abuse-prevention data (Cloudflare Turnstile)

Where enabled, our signup form uses Cloudflare Turnstile to help distinguish real users from bots. Turnstile runs in your browser and shares standard browser/network information with Cloudflare to compute a challenge result; the resulting token is verified by our authentication provider.

Map data (OpenStreetMap)

Our listings map loads map tiles directly from OpenStreetMap's tile servers. Visiting a page with the map — including as a logged-out visitor — causes your browser to request those tiles directly from OpenStreetMap, exposing your IP address to OpenStreetMap for that request, independent of ScholarSafe.

Service providers

We use the following providers to operate ScholarSafe. See our internal service-provider inventory for engineering detail; in summary:

  • Supabase — authentication, database, and file storage.
  • Vercel — application hosting.
  • Sentry — error monitoring.
  • Cloudflare Turnstile — bot/abuse prevention on signup, where configured.
  • Resend — transactional email delivery, where configured. Not every environment currently has this configured; some transactional email may instead be sent through Supabase's own built-in mailer.
  • OpenStreetMap — map tiles and address geocoding, used without an API key or account relationship.

Purposes of processing

We use the information above to: operate your account and authenticate you; display and moderate listings, reviews, and roommate profiles; deliver messages between users; send transactional notifications you've enabled; investigate reports and enforce our policies; detect and prevent abuse; diagnose and fix technical problems; and comply with legal obligations.

Sharing and disclosure

We do not currently sell your personal information, and we do not currently use your information for targeted/behavioral advertising — ScholarSafe has no active advertising or behavioral-analytics platform. We share information with the service providers listed above as needed to operate the Service, with other users as described above (e.g. your public profile, listings, reviews, and messages you send), and where required by law, to protect the safety of any person, or to investigate suspected fraud or policy violations.

Retention

We retain different categories of information for different periods, and we distinguish between deleting your public content, anonymizing content that also belongs to another user's record (like a shared message thread), and retaining narrow categories of record for safety, fraud-prevention, or legal reasons. Raw verification documents are targeted for deletion within 21 days after a verification decision; ordinary account deletion requests are targeted for completion within 30 days. All specific retention periods are provisional and subject to attorney review. We do not promise that every record is deleted instantly or irreversibly — some categories are anonymized rather than deleted outright, and safety/legal-hold records may be kept longer where necessary.

Your choices: access, correction, and deletion

You can review and edit most of your profile information directly in your account settings. You can request deletion of your account at Delete My Account. ScholarSafe may voluntarily honor reasonable access, correction, or deletion requests even in cases where a particular privacy law does not legally require us to — email privacy@scholarsafe.com if you have a request our account settings don't cover.

We have not yet established that any specific state or federal privacy statute (such as the California Consumer Privacy Act) legally applies to ScholarSafe at its current size and stage, and this policy does not claim that one does.

Children

ScholarSafe is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, contact safety@scholarsafe.com.

Security

We use reasonable technical and organizational measures to protect your information, including database access controls (row-level security) and encrypted transport. No online service can guarantee perfect security, and we cannot promise that information you submit to ScholarSafe will never be accessed, disclosed, altered, or destroyed in a manner inconsistent with this policy.

Changes to this policy

We may update this policy as ScholarSafe's practices evolve, especially during this pilot phase. We'll update the effective date above when we do. Material changes will be communicated through the Service.

Contact

Questions or requests about this policy: privacy@scholarsafe.com. General support: support@scholarsafe.com. Safety concerns: safety@scholarsafe.com.

These addresses are monitored for ScholarSafe pilot requests. Response times may vary based on the nature and complexity of the request.