Privacy Policy

Last updated: August 13, 2026

Gateway is available to people age 16 or older. This policy covers Free, Plus, and Family accounts, Stripe billing, and AI-assisted planning features.

1. Scope

This policy explains how Gateway collects, uses, stores, and protects information when you use our college-search and planning service. It applies to Gateway's website, accounts, support forms, and related product features.

2. Information we collect

  • Account information: email address, name, password credentials handled by our authentication provider, and date of birth used to enforce the 16+ requirement.
  • Student profile information: optional academic interests, intended majors, location preferences, goals, activities, GPA, and test scores.
  • Planning information: saved colleges, milestones, notes, deadlines, and documents that you choose to upload.
  • Communications: information included in support and feedback submissions.
  • Technical information: basic device, browser, request, security, and service-performance information needed to operate and protect Gateway.

Do not upload Social Security numbers, bank information, medical records, or other information that is not necessary for college planning.

3. How we use information

  • Authenticate users and maintain accounts.
  • Enforce the age requirement and prevent abuse.
  • Provide college search, saves, planning tools, and private document storage.
  • Respond to support requests and communicate service changes.
  • Diagnose errors, secure the service, and improve reliability.
  • Comply with applicable legal obligations and enforce our Terms of Service.

4. College data

Gateway's college catalog uses institution-level data from the U.S. Department of Education College Scorecard. Gateway identifies when it is using the most recent source available. Gateway does not claim endorsement by the Department of Education, individual institutions, or other data providers.

Public college data is not your personal information. You should verify deadlines, prices, admission requirements, and program availability directly with each institution before acting.

5. Service providers and disclosures

Gateway uses service providers to operate the product, including Supabase for authentication, database, and storage services; Vercel for application hosting and operational telemetry; Resend for account emails; Stripe for subscription billing; OpenAI for text-first AI planning; and Google Gemini for multimodal planning, speech, and requested visuals. Providers receive information only as needed to perform those services and are subject to their own security and privacy obligations.

Optional Google Analytics, Vercel Analytics, and Vercel Speed Insights remain off until you opt in through the cookie banner. Gateway limits those events to coarse product actions and counts; it does not send prompts, planning content, account identifiers, school choices, financial details, messages, or document contents to optional analytics. Operational error monitoring is configured without session replay, profiling, default personal information, request payloads, or raw error messages.

We do not sell personal information. We may disclose information when required by law, to protect users or the service, or as part of a legitimate organizational transaction with appropriate safeguards.

Stripe receives the information needed to create and manage a paid subscription. When you use AI-assisted features, Gateway may send your prompt and relevant planning context to OpenAI or Google Gemini to generate the requested response. Gateway chooses a provider based on the request and may switch providers before a response begins if one is unavailable. If you attach an image or PDF to the planning companion, that file is sent to the selected provider for the requested reply, but Gateway does not save the file in your chat history. Do not submit sensitive information that is unnecessary for your planning request.

6. Storage, security, and retention

Gateway uses access controls, row-level database policies, private storage, encrypted network transport, and operational monitoring. No system can guarantee absolute security, so use a unique password and report suspected account misuse.

We retain account and planning information while your account is active and as reasonably necessary to operate the service, resolve disputes, secure the product, and meet legal obligations. Test and temporary operational data is removed when it is no longer needed.

For account-email reliability, Gateway may keep a provider message identifier, delivery event type, and timestamps for up to 90 days. These receipts do not store your email address, message subject or content, account action link, or email open/click activity.

7. Your choices and requests

  • Review and update editable profile information in Gateway.
  • Remove saved items and uploaded documents that you control.
  • Request access, correction, export, or deletion through the support page.
  • Unsubscribe from optional communications where an unsubscribe option exists.

We may need to verify your identity before completing a request. Some information may be retained when required for security, fraud prevention, or legal compliance.

8. Age requirement

Gateway does not permit accounts for people under age 16. We request a date of birth during registration and reject under-16 account creation at the database boundary. If we learn that an under-16 account or inaccurate age information bypassed these controls, we may suspend the account and delete the associated information.

9. Changes to this policy

We may update this policy when Gateway's features, providers, or legal obligations change. Material changes will be posted here with a revised date and, when appropriate, communicated to account holders.

10. Contact

Submit privacy questions and account-data requests through Gateway's support page.