MyCollegeStudio Privacy Policy
Last updated: September 5, 2026.
Who we are
MyCollegeStudio is a web app that guides US high-school seniors through the college application process: a step-by-step curriculum, plus tools for school lists, essays, deadlines, activities, recommenders, financial-aid preparation, and scholarships, with an AI coach that helps students think — never one that does the work for them.
Many of our users are minors. We wrote this policy in plain language on purpose, because the people it protects should be able to read it.
MyCollegeStudio is operated by Fawzy Consulting, doing business as "Fawzy Educational" for the MyCollegeStudio product, a California sole proprietorship, with a mailing address at 2540 3rd Street #1087, Sacramento, CA 95818. Payments are processed for Fawzy Consulting by Stripe.
Contact: support@mail.mycollegestudio.com.
The short version
This is a plain-language overview; the detailed sections below are the full policy and govern if anything here reads differently.
- We collect what the product needs to work, and nothing more.
- We do not intentionally request the financial identifiers described below — Social Security numbers, FSA IDs, bank or account numbers, tax data, or your family's actual financial figures. There is nowhere in MyCollegeStudio to enter them.
- We do not sell or share personal information for cross-context behavioral advertising, and we do not display third-party ads.
- MyCollegeStudio never asks for, infers, or derives race or ethnicity, and never uses it — not in ranking, not in coaching, and not as an analytics dimension.
- You can export your data (JSON) or delete your account yourself, anytime, from your profile page.
What we collect
When you use MyCollegeStudio, we store the categories below. Except where noted, we collect this directly from you, use it to provide and secure the product, keep it while your account is active, and do not share it outside the service providers who help us run MyCollegeStudio (see "How we use your data" and "No ads, no selling data").
- Account: your email address, your date of birth (used for the age requirement described under "Minors, parents, and guardians"), and a hashed (scrambled, one-way) version of your password. We cannot see the password itself. If you sign in with Google, or a counselor signs in through their organization, we store the identifier that provider gives us for your account instead of, or alongside, a password — see "How you sign in".
- Sign-in security: if you turn on two-step sign-in, the secret your authenticator app shares with us (encrypted), the public half of any passkey you register (never the private half, and never a fingerprint or face — those stay on your device), hashed one-time recovery codes, and the dates each was added and last used. See "How you sign in".
- Parent or guardian accounts: if a student invites you to follow their progress, we store your email address, a hashed version of your password, the record of your affirmative statement that you are at least 18 and the student's parent or guardian (with the versions of the Terms and this policy in force when you made it, and the date), and which students you are linked to — including when each link started and when you last viewed it. A parent account holds no student content of its own.
- Student profile: name, high school, GPA, test scores and testing plans, interests, intended majors, preferences (like location and school size), and a broad budget band you choose.
- Your college process: your school list; applications with their requirements, platforms, and deadlines; calendar entries; essays with drafts, versions, and the AI feedback you save; activities and honors; recommenders (name, relationship, and an optional email address — only provide this with the recommender's permission, and only what's needed to identify them); financial-aid form checklists and statuses — stored only as yes/no "ready" flags, never the underlying information; scholarships you track; and your progress through the curriculum.
- Billing records: for a purchaser, the transaction and receipt records Stripe provides us — not your full card number, which Stripe holds directly.
- Support communications and feedback: anything you send to support@mail.mycollegestudio.com, and any feedback you type into the in-app feedback form.
- Technical and security data: IP address; device, browser, and cookie/session identifiers; and authentication, security, and fraud-prevention logs.
- AI interaction metadata: for each AI coaching request we log the use case, model, token counts, response time, and outcome (for example: succeeded, refused by a guardrail, or rate-limited). The conversation content itself is not stored by MyCollegeStudio — only essays and notes you deliberately save are kept. See "How the AI processing works" for what happens on our AI provider's systems.
- Analytics events: which features get used, recorded as metadata only. Analytics events never contain essay text or chat content.
- Service diagnostics: technical logs that help us find and fix problems.
What we deliberately do NOT collect
This is a design boundary built into the product, not fine print. The Service is not designed to request, and provides no field for:
- Social Security numbers
- FSA IDs (your federal student-aid login)
- Bank, brokerage, or any other account numbers
- Tax data or tax documents
- Your family's actual financial figures
- Your race or ethnicity
MyCollegeStudio never asks for, infers, or derives race or ethnicity, and never uses it — not in ranking, not in coaching, and not as an analytics dimension. There is no field for it anywhere in the product, our AI coach is instructed never to guess it and never to act on a guess, and we never break our usage numbers down by it. That last part matters: when we look at who the product is serving badly, we look at the things the product itself controls — the kind of device you are on, where you are in the process, whether a step completed, whether you hit an error, and whether the page worked with a screen reader or a keyboard.
You are of course free to write about your background, your family, your culture or your language in an essay — that is your story to tell, and helping you tell it well is the point. What we will not do is turn anything you write into a label about you, store it as one, or use one to change what you are shown.
One honest exception to be precise about, because you control it: if you turn on the optional coach memory, the notes it keeps are yours to write and edit, so you could type something about your background into one yourself. We will not put it there and we will not derive it — every note is shown to you before it is kept, and you can edit or delete any of them at any time. What we never do, either way, is infer a demographic attribute or use one to change your ranking, your coaching, or how you are counted.
Please do not submit this information to MyCollegeStudio, including inside the AI coach. If we learn that excluded information was submitted anyway, we will take reasonable steps to delete it and will not use it to provide the Service.
The FAFSA and CSS Profile are completed only on the official sites — StudentAid.gov and cssprofile.collegeboard.org. MyCollegeStudio explains those forms and links you to them; nothing is ever filed or submitted by MyCollegeStudio anywhere. Our aid checklists are checkmarks meaning "I have this ready" — there is no field for the information itself, and the AI coach is designed to detect and refuse this kind of information if it is pasted into a conversation, though no automated system catches every entry every time.
How we use your data
- Running the product: your dashboard, school list, calendar, essay workspace, checklists, and journey progress all read the data you gave us back to you.
- Account administration and support: setting up and maintaining your account, responding to you at support@mail.mycollegestudio.com, and keeping payment and entitlement records for purchasers.
- Reminders: we compute upcoming deadline notifications (30, 14, 7, 3, and 1 days before a due date) from your deadlines.
- AI coaching: when you use the coach, the relevant text — your question, your draft, the minimal profile context the feature needs — is sent to our AI provider to generate the response. See the AI section below.
- Keeping the service healthy and secure: authentication, rate limiting, debugging, fraud and abuse prevention, and understanding feature usage in aggregate — including deidentified, aggregated operational metrics — so we can improve the product.
- Legal and compliance: meeting legal obligations and enforcing our Terms of Service.
We do not use your data for advertising, and we do not sell it. Ever.
How the AI processing works
When you use an AI coaching feature, we send the relevant input — your question, your draft, and small amounts of relevant context, like the essay prompt you are working on — to Anthropic PBC, our AI provider, to generate the coaching response, which streams back to you.
- Under Anthropic's commercial terms, your inputs and the coach's outputs are not used to train Anthropic's models, and are retained by Anthropic only for a limited period for trust-and-safety and reliability purposes. Anthropic's own data-handling commitments are published at anthropic.com/legal/commercial-terms. We require our AI provider to handle this data under contract terms that prohibit selling it, using it for advertising, independently profiling you, or using it to train models beyond what is disclosed here, and that require the provider to maintain security, deletion, subprocessor-disclosure, and incident-notification commitments.
- We log metadata about each interaction: use case, model, token counts, latency, and outcome.
- MyCollegeStudio does not store the conversation content in our own application unless you choose to save it. What you choose to save — essay drafts, versions, notes, saved feedback — is stored as part of your work. This is separate from the transient processing described above: your input is still transmitted to and processed by our AI provider to generate each response, and their systems (and ours, briefly, for safety and reliability — for example, error and abuse-prevention logs) may retain it for a limited time even though MyCollegeStudio's application database does not.
- The coach runs behind guardrails: it does not ghostwrite, predict admission chances, decide for you, estimate aid eligibility, recommend financial products, or accept your family's financial figures — though, like any automated system, it does not catch every attempt every time.
- Every AI coaching surface tells you plainly that you are talking with AI, not a human.
No ads, no selling data, no ad tracking
We do not sell personal information or share it for cross-context behavioral advertising, and we do not use it for targeted advertising. We do share data with the service providers who operate MyCollegeStudio for us — for example, hosting, payments, AI coaching, email delivery, error monitoring, and product analytics — strictly to perform the contracted service, under contracts that prohibit them from independently using, combining, selling, sharing, or advertising with it, or using it to train their own models beyond what's disclosed in this policy. Our analytics are metadata-only and exist to make the product better, not to profile students.
Your rights and controls
- Export: download your data as a JSON file from your profile page, anytime.
- Deletion: delete your account from your profile page. This permanently removes your account and all data attached to it. It cannot be undone.
- Correction: almost everything in MyCollegeStudio is directly editable by you. For anything you cannot edit yourself, email us and we will fix it.
- Additional rights: depending on where you live, you may have additional rights — for example, to confirm what we process, receive a portable copy, appeal a denied request, or learn what categories of recipients we share data with. We authenticate requests and may deny or limit a request where permitted by law. If applicable law gives you an appeal right, email support@mail.mycollegestudio.com with "Privacy Appeal" in the subject line.
- Questions: email support@mail.mycollegestudio.com about any of the above, or about anything in this policy.
These are MyCollegeStudio's own privacy controls, not FERPA rights — FERPA does not apply to this direct-to-you service (see "Who we are"). If MyCollegeStudio ever makes user content visible to other users, we will add the notice and instructions California law requires for minors to request removal of content they posted. The one case today where your content becomes visible to another user is a family link you created yourself: you choose what it includes, switching a section off removes it from their view immediately, and ending the link removes all of it.
Minors, parents, and guardians
MyCollegeStudio is built for high-school students aged 13 and older, and many users are under 18. Sign-up asks for your date of birth and includes a short, plain-language consent notice with a checkbox, written so a student can actually understand what they are agreeing to.
MyCollegeStudio is not directed to children under 13, and we do not knowingly collect information from them. If we learn that a user under 13 has supplied personal information, we will suspend further collection from that account and promptly delete the information, unless we are able to obtain verifiable parental consent as the law allows. If you believe a child under 13 has created an account, contact us and we will act on it.
A parent or guardian who purchases the Season Pass does so as the contracting purchaser (see our Terms of Service) — that role is separate from the student's own account, and paying for the Pass does not by itself give the purchaser access to the student's private content. If you are a parent or guardian of a MyCollegeStudio user under 18, you may ask what information we hold about your student, request a copy, or request deletion by emailing support@mail.mycollegestudio.com. We verify your identity and your legal authority before acting on a request, we notify the student where appropriate, and we disclose information only as permitted by law and this policy.
Separately from purchasing, a student can invite a parent or guardian to follow their progress. Only the student can start that — from Profile → Family & sharing — and only to an email address they type themselves; the invitation creates the parent's own account, with the parent's own password. That account sees a read-only planning summary (progress through the guide, deadlines, the school list and application status, upcoming interviews, and whether the aid forms are ready), plus whichever of five sections — essays, brag sheet, academic record, activities, aid offers — the student has switched on. Each of those five starts off. Conversations with the coach, brainstorms, and worksheet reflections are never included, with or without a switch. The student can open the same page the parent sees, can see when the parent last looked, can switch any section off — which removes it from the parent's view immediately — and can end the link entirely at any time. A parent account is read-only: it cannot write, edit, export, or delete anything belonging to the student, and it is not a channel for the requests described in the paragraph above, which still go to support so we can verify identity and authority.
How long we keep data (retention)
We keep your data while your account is active so the product can work. When you delete your account, your account and its data are removed immediately from the live database (a full cascade — profile, essays, deadlines, and the rest). Encrypted routine backups are isolated from normal use and expire within 30 days; if a backup is ever restored for disaster recovery, deletion requests already made are reapplied. Deleting a student's account also removes every family link on it, so a parent following them loses access at once; deleting a parent's account removes that parent's links and leaves the student's own data untouched. We may retain limited records beyond that where required for security, fraud prevention, dispute resolution, tax and accounting, or other legal obligations.
How you sign in
Your email address and password remain the ordinary way in. Depending on what you choose — and, for staff, what their role requires — three more things can be part of signing in. None of them adds anything to what the AI coach sees, and none of them changes what a parent, a counselor, or anyone else can see.
- Two-step sign-in (optional for students and parents; required for counselors and MyCollegeStudio staff). A second step after your password: a passkey on a device you own, or a six-digit code from an authenticator app. For a passkey, your device keeps the private key and we keep only the public half, which can verify a sign-in but cannot perform one; your fingerprint or face never leaves your device and is never sent to us. For an authenticator app, we keep the shared secret encrypted with a key that is never stored beside it. We also give you ten one-time recovery codes, kept only as one-way hashes. We record which second step you used and when, so we can ask for it again after a while. Turning two-step sign-in off later removes these records.
- Sign in with Google (students and parents, optional). If you choose it, Google tells us the account identifier and the email address of the Google account you picked, and whether Google has verified that address. We keep the identifier so we can recognise you next time, and the address as a record of the link. We ask Google for nothing else — not your contacts, your files, or your calendar — and Google receives nothing about what you do inside MyCollegeStudio. An account created with Google has no password until you set one.
- Organization sign-in (counselors only). If a counselor's school or organization uses single sign-on, the organization's own identity provider vouches for the counselor and sends us their identifier and email address. That tells us who the counselor is; it does not give the organization any access to a student's account, and it does not change what the counselor can see, which still depends entirely on what each student chose to share. The organization can end a counselor's ability to sign in this way; it cannot read a student's work through it.
Sign-in attempts, successes and failures are logged for security, keyed to your account rather than to your email address, and are kept as described under "How long we keep data". We keep the identifiers above for as long as your account exists, or until you disconnect that way of signing in from Profile → Sign-in & security.
Security, honestly
- Passwords are stored only as one-way hashes; authenticator secrets are encrypted at rest; passkeys leave only their public half with us.
- Two-step sign-in is available to every account and required for accounts that can see other people's data.
- Traffic to MyCollegeStudio runs over HTTPS in production.
- Your data is stored on managed infrastructure that encrypts it at rest.
- Your data is scoped to your account; other students cannot see it. A parent or guardian you invite sees only what you choose to share, and only for as long as you choose to share it.
- Access to production systems is limited to the few people who operate the service.
We maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the data we hold. No system on the internet is perfectly secure, and we won't pretend ours is the exception. If a security incident occurs, we will investigate, take appropriate remedial steps, and notify affected individuals and authorities when and as required by applicable law.
Changes to this policy
Recent changes: September 4, 2026 — parent and guardian accounts; September 5, 2026 — the "How you sign in" section (two-step sign-in, sign in with Google, organization sign-in for counselors).
If we change this policy, we will update it here with a new date. Changes apply prospectively. For a materially adverse change, we will give the purchaser and the student at least 30 days' advance notice when practicable, in plain language, before it takes effect. If a change introduces a materially different use of your data, we will ask for your fresh, affirmative consent rather than relying on continued use alone — unless the law requires the change or it addresses an urgent security or legal issue, in which case it may take effect sooner, with prompt notice.
Contact
Fawzy Consulting 2540 3rd Street #1087, Sacramento, CA 95818 support@mail.mycollegestudio.com
We read everything. If any part of this policy is unclear, that's a bug in the policy — tell us and we will fix the words.