← Compass

Privacy Policy

Last updated July 28, 2026

Who we are

Compass (operating as Compass College Counseling, run by Cem Kocaoglu) helps high-school students plan and manage college applications. Compass is offered to students in the United States and your information is processed and stored in the United States. Compass is intended for students aged 13 and older; you confirm your age when you accept these policies, and we do not knowingly collect data from children under 13. If we learn an account belongs to a child under 13, we will delete the account and its data. Many of our users are minors, and we take that seriously: we minimize what we collect and give you direct control over your data.

What we collect

We do not collect: date of birth, home address, phone number, government IDs, payment card details, or health data. We show no ads, use no ad networks, and never sell personal information or share it for targeted advertising.

Cookies: we use sign-in cookies from our authentication provider (strictly necessary), one small cookie remembering your sidebar preference, and a first-party analytics cookie from PostHog (see Analytics below). We do not use advertising cookies. We do not respond to Do Not Track or Global Privacy Control signals; because we do not sell or share personal information, there is nothing for those signals to opt out of.

How we use it

To provide the planning tools (for example, computing fit scores from your stats), to power the AI features below, to run the parent features you set up, to process the subscription, to secure the service, and to improve the product. We do not use your information for advertising.

AI features

Compass’s AI features are powered by Anthropic’s Claude models. Here is exactly what is sent when you use them: Atlas chat sends your recent chat messages plus your hook statement; entry feedback sends the one activity, honor, or program entry you asked about plus your hook; and the idea generator sends your request plus your hook. Compass never attaches your stored essays or drafts, college list, test scores, or name to an AI request (anything you yourself type into the chat is, of course, part of the conversation that gets sent). Under Anthropic’s API terms, this data is not used to train models and is deleted on Anthropic’s standard retention schedule (currently around 30 days, longer only if flagged for a trust-and-safety review); see Anthropic’s privacy documentation for the current terms. The assistant is designed and instructed to coach, not to write your application for you. AI usage is capped per account each month.

Subscriptions and payment

Compass is a paid subscription with a 30-day free trial, and the paying customer is a parent or guardian, not the student. You give us your parent’s name and email; we email them a private checkout link; they pay on Stripe’s secure pages. Compass never sees card numbers. We keep only what we need to run your account: the plan, its status, and Stripe’s reference IDs. Stripe retains billing records (like invoices) under its own policies as financial records.

Sharing features and secret links

Emails we send

All email is transactional: the parent-confirmation request, the weekly parent progress summary (only after the parent confirms; every one includes the parent’s own unsubscribe link), the subscription checkout link your student asked us to send, a warning before a long-unused cycle-ended account is deleted, and security notices. There is no marketing mailing list.

Analytics

We use PostHog to understand feature usage (page views and product events). Events are tied to a random account ID, not your name or email; session recording is off; secret share, confirmation, and checkout links are scrubbed before events leave your browser. We also use Vercel’s cookieless, aggregate web analytics. As with most internet services, servers see your IP address: our infrastructure providers (Supabase for sign-in events, Vercel for requests, PostHog with events) record it in their operational logs, which age out on their schedules. One more third party: when you open a school’s detail page, your browser fetches the campus photo and summary directly from Wikipedia, which (like any website you visit) sees your IP address and the page requested.

Your control

Both export and deletion stay available even if your subscription has lapsed and the dashboard is locked; a locked account is never a data hostage. We aim to respond to access and deletion requests within 30 days. Parents/guardians can request access or deletion on behalf of their child by emailing cem.kocao01@gmail.com; we verify the requester’s identity and relationship to the student before acting.

How long we keep data

Your account and its content are kept while the account exists. Long-unused accounts become eligible for deletion: once your application cycle has ended and you haven’t signed in for 12 months, or after 24 months without signing in otherwise. A cycle-ended account is never deleted without a warning email sent at least 7 days beforehand, and simply signing in keeps your account alive. Security-log entries are kept 18 months. Backups expire within 7 days.

Who processes your data

Trusted providers that run the service on our behalf, each under a data-processing agreement: Supabase (database & sign-in), Vercel (hosting & aggregate analytics), Anthropic (AI), Stripe (subscription payments; card details go directly to Stripe and never touch our servers), Resend (email), and PostHog (product analytics). Sign-in itself is provided by your Google account. Our content system (Sanity) holds no personal information. We may also disclose information if required by valid legal process; where legally permitted, we will try to notify you first.

Security

Data is encrypted in transit and at rest, and your most sensitive content (essays and drafts, your hook statement, Atlas chats, activity and honor descriptions, task text, and personal notes) gets an extra layer of application-level encryption, so a database leak alone would not expose it. This protects against database-level exposure; like any service, Compass itself can still process your data to run the product for you. Every record is protected by per-account access rules, optional two-factor authentication is available in Settings, and security-relevant actions leave an audit trail. No system is perfectly secure, but we hold your data to a strong standard.

Changes to this policy

Each version of this policy is dated. If we make a material change, the app will ask you to review and accept the updated policy before you continue using your account.

Contact

Privacy questions or requests: cem.kocao01@gmail.com.