Data Usage Policy
1. Purpose and Scope
In short: This page walks through what happens to your data feature by feature. Three promises up front: we do not sell your personal information, we do not use your grades to target ads, and we never publish your email or account ID.
This Data Usage Policy explains how information moves through specific features of the Service operated by CAA Readiness Index LLC, a Mississippi limited liability company (“CRI”). It supplements our Privacy Policy, which describes our overall privacy practices, and our Terms of Service, which governs use of the Service.
Our commitments: We do not sell your personal information, use your academic profile for third-party advertising, or publish your email address or account ID in community analytics.
2. Account and Profile Data
In short: Supabase stores your login and profile: your email, display name, avatar, preferences, and which plan you are on. We use it to sign you in and run your account.
Supabase provides account authentication and stores your CRI profile. Account data may include your Supabase user ID, email address, display name, optional avatar, preferences, signup and onboarding responses, marketing-email choice, account dates, plan entitlement, and terms-acceptance records.
We use this information to authenticate you, secure sessions, personalize the interface, associate saved data with the correct account, provide plan access, communicate with you, and administer the Service. Your email address is not displayed to other CRI users.
3. Calculator and Saved Results
In short: When you calculate a score, your GPAs and test score go to our backend to be worked out. Saved results stay tied to your account. Community range views show score bands with no name attached.
3.1 Calculator Inputs and Outputs
The calculator processes cumulative GPA, science GPA, test type, and MCAT or GRE score. CRI uses those inputs to generate a score, percentiles, charts, and related comparisons. Inputs are sent to the CRI analysis backend for calculation.
3.2 Calculation Logs and Community Ranges
A calculation record may include the exact inputs, output score and percentile, timestamp and, when signed in, your user ID and current profile display name. These records support calculation history, reliability checks, longitudinal analysis, community activity, and score distributions.
Community surfaces show only selected fields, such as CRI score, GPA range, test type, and test-score range. They do not show the calculation owner's email, user ID, or display name.
3.3 Saved Results and Comparisons
When you save a result, CRI stores its inputs, outputs, percentile data, timestamp, and any supported comparison fields in your account. Free accounts may keep one saved result at a time; CRI Plus accounts may keep additional scenarios as described on the Pricing page.
4. Planning and Tracker Data
In short: The planning tools save whatever you enter: matcher inputs, saved programs and prereqs, tracker schools and dates, and your notes. This is your private data.
CRI planning tools may store information you enter or select, including:
- Program Matcher inputs and preferences
- Saved programs and saved prerequisite snapshots
- Prerequisite course-profile information and notes
- Application Tracker schools, cycles, milestones, dates, fees, response methods, and notes
- Cycle planning entries and application-status history
- Experience-hour categories, entries, dates, descriptions, and goals
We use this data to provide the requested tracker, matching, comparison, and planning functionality; sync it across your sessions; enforce plan limits; and produce de-identified aggregate insights.
5. Application Tracker: Private and Community Fields
In short: Your tracker has two layers. Your notes and your user ID stay private to you. A stripped-down version of the rest, like school, cycle, month, and status, feeds the community timing charts.
Your account-linked application rows and milestone history are available to you through the tracker. Notes and user IDs remain in the private, account-controlled records.
To power community response analytics, a sanitized view may make the following fields visible to CRI users: school, application cycle, submission month, current status, status-received month, response method, reported fee, creation timestamp, and the row's non-identifying ID. The community view excludes your user ID and notes.
Community entries can be sparse, self-reported, delayed, or inaccurate. They should not be treated as an official record from a program.
6. Feedback and Communications
In short: Feedback you send us is tied to your account so we can follow up on it, and it stays private unless you say otherwise.
Feedback submissions may include an issue, idea, written review, rating, account ID, source, and timestamp. We use this information to respond, prioritize fixes, improve CRI, and calculate aggregate review ratings. Written feedback is not made public unless we obtain permission or present it without identifying you.
We use your email for authentication, account security, billing, support, and important service messages. Marketing messages are controlled separately; you can unsubscribe from a message or change Marketing emails in Account Settings.
7. CRI Plus and Payment Data
In short: Stripe runs checkout and holds your card number. We only keep what we need to manage your subscription: your Stripe IDs, plan, status, and refund or dispute records.
Stripe hosts checkout and processes payment-card information. CRI receives and stores limited billing data needed to provide and administer CRI Plus, including Stripe customer and subscription IDs, plan term, subscription status, access period, cancellation feedback, invoice or refund state, and payment-dispute records.
CRI does not receive or store your full card number, card verification code, or full bank-account credentials. Stripe may provide limited details such as payment method type, last four digits, billing country, or payment fingerprint for fraud, support, or dispute handling.
Billing and dispute records may be kept after account deletion when reasonably needed for accounting, fraud prevention, chargeback response, contract enforcement, or legal compliance. See our Refund Policy.
8. Product Analytics and Cookies
In short: Vercel gives us basic traffic counts with no third-party cookies. Google Analytics only runs if you switch it on in Cookie Preferences, and you can switch it back off.
8.1 Vercel Web Analytics
Vercel Web Analytics helps us understand aggregated page views and traffic. Its data points may include timestamp, route, referrer, filtered query parameters, approximate geolocation, browser, operating system, and device type. It does not use third-party cookies or give CRI a cross-site profile of you.
8.2 Google Analytics
Google Analytics loads only if you enable Analytics in our consent controls. Its standard implementation may process page views, sessions, approximate location, browser and device information, and a first-party client identifier. CRI does not intentionally send calculator inputs, tracker entries, email addresses, or user IDs to Google Analytics.
8.3 Your Controls
Use Cookie Preferences in the site footer to enable or disable Google Analytics. You may also clear browser cookies and site storage or use the Google Analytics Opt-out Browser Add-on. Necessary authentication and security storage cannot be disabled through the CRI preference panel.
9. Other Service Providers
In short: The outside companies we rely on, and what each one does for us.
- Supabase: authentication, database, and avatar storage
- Vercel: hosting, content delivery, infrastructure logs, and web analytics
- Stripe: checkout, recurring billing, invoices, refunds, and disputes
- Resend: transactional, service, and marketing email delivery
- Mapbox: map styles, tiles, and interactive program-map requests
- Google/YouTube: playlist retrieval and video playback when collaboration content is used
These providers receive the information reasonably needed to perform their services and handle it under their own terms and privacy notices. Provider links are available in our Privacy Policy.
10. Aggregation, De-identification, and Research
In short:We combine everyone's data into anonymous charts and benchmarks. We take steps to make sure nobody can be picked out of them, and we do not try to reverse it.
CRI may aggregate or de-identify calculator, tracker, application, and usage data to build benchmarks, distributions, trend charts, reliability checks, product insights, public reports, or research. We use reasonable measures designed to prevent those outputs from identifying an individual and do not attempt to re-identify de-identified data.
Small groups and unusual combinations can increase re-identification risk. We may suppress, bucket, round, delay, or omit fields when needed to reduce that risk. De-identified and aggregate information may be retained longer than the underlying account data.
11. Automated Analysis
In short: Your score and matches come out of a formula, not a person and not an admissions committee. They cannot see everything a program looks at, and they are not a guarantee.
CRI scores, percentiles, matches, and comparisons are generated by statistical methods using the information you enter and the comparison datasets available to CRI. They are not an admissions decision, do not account for every factor a program considers, and should not be treated as a guarantee. Programs make their own decisions independently of CRI.
12. Retention and Deletion
In short: We keep your data while your account is open. You can delete most things yourself. Deleting your account removes your login and linked records, though some backup, legal, and payment records have to stay.
- Account and private planning data are generally retained while your account remains active
- You may delete individual user-managed entries where the applicable tool provides that control
- Account deletion removes the authentication user and account-linked records subject to provider, backup, legal, security, and transaction-record exceptions
- Community, aggregate, and de-identified data may remain after deletion where it no longer identifies you or is needed to preserve shared context
- Infrastructure and analytics data follow provider settings and retention schedules
Deleting your CRI account is not a substitute for canceling a Stripe subscription. Cancel CRI Plus in Account Settings > Billing before deleting the account.
13. Your Data Controls
In short: What you can change yourself, and where: profile and email settings, tracker and saved entries, analytics consent, billing, and account deletion.
- Update your display name, avatar, and email preferences in Account Settings
- Delete or edit supported tracker, planning, and saved-result entries in the relevant tool
- Change consent-based analytics through Cookie Preferences
- Manage or cancel CRI Plus through Account Settings > Billing
- Delete your CRI account through Account Settings
- Request access, correction, deletion, or a portable copy by emailing team@criscore.org
We may verify your identity and apply exceptions required or allowed by law. For location-specific rights, response periods, and appeal information, see the Privacy Policy.
14. Security and Access
In short: We use HTTPS, database-level permissions, and access controls. Your private records are visible only to you, community views show only the stripped-down fields, and staff access is limited.
CRI uses HTTPS, server-side authorization, database row-level security, access controls, and other safeguards designed to protect account data. User-facing access is limited according to the feature: private records are restricted to their owner, sanitized community views expose only selected fields, and administrative access is limited to operating and protecting the Service.
No system is perfectly secure. Keep your login links and credentials private, use a secure device, and report suspected compromise to us promptly.
15. Permitted Use of CRI Analytics
In short: Our charts and data are for planning your own application. Do not scrape them, republish them, or sell them without asking us first.
CRI analytics, charts, program data, and insights are provided for personal, non-commercial application planning. You may not scrape, systematically extract, republish, sell, or redistribute substantial portions of them without written permission. Limited personal reference and uses that applicable law expressly permits are not restricted beyond what the law allows. See our Terms of Service.
16. Changes and Contact
In short: We update this page when features or rules change, and post a new date when we do. Email us with any questions.
We may update this policy as CRI features, vendors, data practices, or legal requirements change. We will post the revised version with an updated date and provide additional notice for material changes when required.
Questions, permission requests, and privacy requests may be sent to team@criscore.org.
