Privacy Policy

Last updated: May 31, 2026

This Privacy Policy describes how AnyOrg ("we," "us," or "AnyOrg") collects, uses, and protects information when you use anyorg.app and related services (the "Platform"). We've tried to write it in plain language. If anything is unclear, contact us at admin@anyorg.app.

Quick summary

  • We collect information you provide (profile, resume, application responses) and basic usage data.
  • We use it to operate and improve the Platform: connecting you with student organizations, processing applications, and sending transactional emails.
  • We do not sell your personal information. We do not share it with advertisers. We do not provide your data to admissions consultants, recruiting firms, or data brokers.
  • The contents of your application go only to the organization(s) you apply to. To run the Platform, we also rely on a small set of service providers and may disclose data for legal reasons or in a business transfer — see Section 4 for the specifics.
  • You can access, correct, export, or delete your data at any time by emailing admin@anyorg.app.
  • If we ever materially expand how we use your data, we will notify you 30 days in advance and give you the option to delete your account before the change takes effect.

The full policy follows. This summary is intended to be a faithful, plain-language overview; the full text in the sections below governs the specifics where more detail is needed.

1. What we collect

Information you provide to us:

  • Account information: name, email address, password (stored hashed), university affiliation.
  • Profile information: major, graduation year, GPA (optional), skills, headline, social and portfolio URLs (optional), avatar (optional), notification preferences.
  • Resume files you upload.
  • Application responses you submit to organizations.
  • Communications you send through the Platform (interview requests, RSVPs, messages).

Information collected automatically:

  • Login and session data: timestamps, IP address, browser and device type.
  • Pages visited and features used within the Platform.
  • Email engagement: whether transactional emails were delivered, opened, or clicked.
  • Cookies and similar technologies: we use strictly necessary cookies to keep you logged in and to maintain your session. See Section 8b.

Information from organizations you apply to:

  • If you apply to an organization, that organization may add internal notes, status updates, interview information, or decisions to your application record. You can request a copy of all such information at any time.

Notice at collection: Before you upload a resume, submit an application, or share GPA or other sensitive profile information, we display a brief notice at that step describing what is collected and how it will be used. This Policy provides the full description.

2. How we use your information

We use your information for the following purposes:

  • To operate the Platform. Create your account, authenticate you, display your profile to organizations you apply to, route your applications, schedule interviews, and send notifications.
  • To send transactional emails. Application confirmations, status updates, decision notifications, interview reminders, and other communications related to actions you have taken on the Platform.
  • To improve the Platform. Analyze usage to develop new features, improve existing ones, and make the product more useful. The detailed limits on this are described in Section 8a.
  • To detect and prevent abuse. Identify spam, fraud, harassment, and unauthorized access.
  • To comply with legal obligations. Respond to lawful requests, enforce our Terms of Service, and protect our rights and the rights of users.

3. What we do not do

These commitments are binding on AnyOrg:

  • We do not sell your personal information — information that identifies you or could reasonably be linked to you — in any form.
  • We do not share your information with advertisers or marketing partners. We do not run ads on the Platform.
  • We do not share your application contents with any organization other than the one you applied to. If you apply to Organization A, only Organization A sees that application.
  • We do not provide your data to admissions consultants, recruiting firms, data brokers, or other third-party data buyers.

If we ever propose to materially expand how we use your data — including any new way of using your data that allows third parties to access it in identifiable form, any new commercial product built on your identifiable data, or any change to the commitments above — we will notify you by email at least 30 days before the change takes effect, give you the option to delete your account before the change applies, and not apply the change retroactively to data you provided under the prior policy without your separate, express consent.

4. How we share information

We share information only in the following circumstances:

  • With organizations you apply to. When you submit an application, that application and the linked profile fields the application form requests are shared with the organization you applied to. Each organization is independently bound by our Terms of Service, which restrict their use of student data to the recruiting cycle the student applied to (plus the limited evaluation window defined in the Terms).
  • With service providers. We use Supabase (database, authentication, storage), Vercel (hosting), and Resend (transactional email) to operate the Platform. These providers process data on our behalf under contract and are not permitted to use it for their own purposes.
  • For legal reasons. In response to a valid subpoena, court order, or other legal process, or where we reasonably believe disclosure is necessary to protect the rights, safety, or property of AnyOrg, our users, or others.
  • In a business transfer. If AnyOrg is acquired, merged, or undergoes a substantial asset transfer, your data may transfer to the successor entity, but only under terms at least as protective as this Policy. We will notify you in advance.

5. Data retention

  • Active accounts. We retain your data while your account is active.
  • Inactive accounts. If you do not log in for 24 months, we will email you and delete your account 90 days later unless you log in or request retention.
  • After account deletion. We delete personal data within 30 days, except for:
    • Limited records we are legally required to retain (e.g., transactional logs for fraud prevention or tax compliance), held no longer than required.
    • Aggregated statistics that contain no information identifying or relating to you individually.
  • Your applications held by organizations. When you delete your account, we delete your application records from our systems. Organizations may have downloaded copies of applications you submitted to them; per our Terms, they are required to delete those upon request from us or from you. We enforce this obligation through our Terms but cannot independently verify each organization's systems.

6. Your rights

You have the right to:

  • Access. Request a copy of all personal data we hold about you.
  • Correct. Update inaccurate information directly through your profile settings, or request correction of other data by emailing us.
  • Export. Receive your data in a portable format (JSON or CSV).
  • Delete. Request deletion of your account and personal data.
  • Object or restrict. Object to specific processing activities. Note that some objections may limit the functionality of the Platform for you.
  • Withdraw consent for any processing based on your consent at any time. Withdrawal is as easy as giving consent — use your account settings or email us — and takes effect going forward.

To exercise any of these rights: email admin@anyorg.app from the address on your account, or use the in-product settings where available. We will respond within 30 days.

California residents. We honor the rights above — including the right to know, delete, and correct — regardless of whether the CCPA applies to us. Because we do not sell or share personal information as those terms are defined under the CCPA, no opt-out of sale or sharing is required, but you may confirm this status by emailing us.

EU/UK residents. If you are in the European Economic Area or the United Kingdom, you have rights under the GDPR/UK GDPR including those above, plus the right to lodge a complaint with your local data protection authority. Our lawful bases for processing are: performance of a contract (operating the Platform for you), legitimate interests (Platform improvement, abuse prevention), and consent (for any sensitive data fields you choose to provide). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

7. Security

We use industry-standard security measures including encryption in transit (TLS) and at rest, role-based access controls, and row-level security at the database layer. Access to personal data by AnyOrg personnel is limited to authorized individuals on a need-to-know basis, primarily for support, abuse prevention, and debugging.

No security system is perfect. If we become aware of a data breach affecting your personal information, we will notify the relevant supervisory authorities within 72 hours where required (e.g., under GDPR), and we will notify affected users without undue delay where the breach is likely to present a high risk to them.

8. Resumes and application contents — specific notice

Because resumes and application essays contain particularly sensitive personal information, we want to be specific about how we handle them:

  • Resumes you upload are stored in secure cloud storage and are accessible only to (a) you, (b) AnyOrg personnel for support and abuse-prevention purposes, and (c) organizations to which you submit an application that includes your resume.
  • Application essay responses are visible to the reviewing organization and to AnyOrg personnel for support purposes only.
  • GPA, demographic, and other sensitive profile fields are visible only to organizations you apply to. These fields are optional; you can leave them blank.

8a. Deidentified data for internal development

To develop and improve the Platform, we may create deidentified records — records stripped of direct identifiers — for internal use only. We do not attempt to re-identify these records, we do not share them outside AnyOrg, and we require any service provider that processes them to do the same. They are never sold, licensed, used for advertising, or used to train any AI or machine-learning model that we distribute or sell.

8b. Cookies and similar technologies

We use strictly necessary cookies to keep you logged in and maintain your session. We use limited email-engagement tracking (delivery, open, and click signals) in our transactional emails to operate and troubleshoot those emails. We do not use advertising or third-party tracking cookies.

9. Children and minors

The Platform is intended for university students aged 18 and over. We do not knowingly collect information from anyone under 18. If you believe someone under 18 has created an account, contact us and we will investigate and, where appropriate, delete the account.

10. FERPA notice

AnyOrg is not a school official under the Family Educational Rights and Privacy Act (FERPA). We are a third-party platform that students choose to use. Information you upload to AnyOrg is not part of your education record unless and until your university chooses to incorporate it. If your university partners with AnyOrg in the future as an institutional service provider, we will update this Policy to describe the FERPA-relevant data flows and the consent model that applies.

11. International data transfers

Our service providers operate primarily in the United States. If you access the Platform from outside the US, your data will be transferred to and processed in the US. Where required by law (for example, transfers from the EU), we use Standard Contractual Clauses or equivalent safeguards.

12. Changes to this policy

We may update this Policy from time to time. For any material change — including changes to the categories of data we collect, the purposes of use, the parties we share with, or the commitments in Sections 3 or 4 — we will:

  • Email you at the address on your account at least 30 days before the change takes effect.
  • Display a prominent in-product notice on your next login.
  • Allow you to delete your account before the change takes effect.
  • Not apply the change retroactively to data you provided under the prior policy without your separate, express consent.

Non-material updates (typo fixes, clarifications, contact info changes) take effect immediately and will be reflected in the "Last updated" date above.

13. Contact

For privacy-related questions, requests, or complaints:

Email: admin@anyorg.app

We aim to respond within 5 business days and to fulfill data subject requests within 30 days as required by applicable law.