Privacy Policy
This policy explains how GradShore handles information about applicants, account holders, professors, and visitors.
Effective and last updated: July 19, 2026
1. Scope and controller
This Privacy Policy applies to gradshore.com and the GradShore services. GradShore is a product operated by Cheng Chung, an individual based in Taiwan, who acts as the controller of the personal information described here. In this policy, “GradShore,” “we,” and “us” refer to Cheng Chung operating GradShore. Questions and privacy requests may be sent to privacy@gradshore.com.
2. Information we collect
- Account information: email address, display name, authentication provider, internal user identifier, account status, and sign-in/session information.
- Saved activity: professors on your watchlist, application-target selections, fit ratings, admission bands, application stages, linked programs, deadlines, private notes, decision reasons, verification checklists, saved fit snapshots, and notification history.
- Saved comparisons and public shares: the title and selected program identifiers for a saved program comparison, or the title and structured criteria of an advisor list created while that feature was available. These records use an unlisted, link-accessible URL.
- Legacy Advisor Chat data: if you used Advisor Chat while it was available, saved conversations may remain associated with your account until you delete the account or request deletion. GradShore did not intentionally store uploaded document text in its application database.
- Subscription information: plan, status, price, currency, trial dates, entitlements, and Lemon Squeezy customer, order, and subscription identifiers. GradShore does not receive or store your complete payment-card number.
- Professor verification information: ORCID iD and professor-submitted details such as recruiting status, degree preferences, rank, department, and contact preference.
- Usage and technical information: pages and features used, approximate location, referral and campaign data, experiment assignment, browser/device information, IP-derived security and rate-limit signals, timestamps, and diagnostic logs. When you are signed in, analytics events may be associated with your internal user identifier.
- Public professional information: names, affiliations, publications, citations, grants, research topics, and collaboration relationships obtained from scholarly and government sources.
3. Sources of information
We receive information directly from you, from your authentication provider, from service providers, and from public or licensed sources including OpenAlex, NSF, NIH, IPEDS, GSS, HERD, and ORCID where its verification feature is available. Public-source records may be incomplete, delayed, or incorrectly matched.
When you choose Continue with Google, GradShore receives your Google account identifier, name, email address, and profile image through Google OAuth and Supabase Auth. We use this information only to authenticate you, create and maintain your GradShore account, secure the service, and provide account-related features. Supabase processes and stores the authentication record on our behalf.
GradShore does not use Google account data for advertising, sell it, or access your Gmail, Google Drive, contacts, or calendar. We disclose Google account data only to service providers as described in this policy, or when required by law. Account deletion and retention are handled as described in Sections 9 and 10.
4. How we use information
- Provide professor and program search, profiles, rankings, maps, funding indicators, application workspaces, comparisons, watchlists, and sharing.
- Authenticate users and maintain account and subscription access.
- Process professor corrections, claims, and opt-out requests where available.
- Send account messages and, where enabled, watchlist digests and deadline reminders.
- Measure feature performance, diagnose errors, prevent abuse, and secure the service.
- Comply with law, enforce our terms, and establish or defend legal claims.
Where applicable law requires a legal basis, we rely on performance of our contract, legitimate interests in operating and securing the service, consent where requested, and compliance with legal obligations.
5. Automated analysis
GradShore uses public scholarly and government data to compute search relevance, funding summaries, rankings, research-fit signals, and other derived indicators. These automated outputs may be incomplete or wrong and are not used by GradShore to make admission, employment, or funding decisions about you.
Do not place Social Security numbers, financial credentials, medical information, or other sensitive information in workspace notes or other free-text fields.
6. When we disclose information
We disclose information only as needed to the following categories of recipients:
- Supabase for Google sign-in integration, authentication, and database hosting.
- Vercel and Railway for application hosting, delivery, and operational logs.
- Upstash for short-lived caching and service reliability.
- Google for sign-in and, if enabled, Firebase/Google Analytics.
- Amplitude for product analytics, if enabled.
- Lemon Squeezy as merchant of record and payment/subscription provider, if purchasing is enabled.
- ORCID for professor identity verification, where that feature is enabled.
- SendGrid for service email, if enabled.
- Authorities, advisers, or counterparties when required by law or a transaction.
We do not sell personal information for money, and we do not use personal information for cross-context behavioral advertising.
7. Cookies, browser storage, and analytics
GradShore uses cookies, local storage, session storage, and similar technologies for authentication, OAuth return paths, session continuity, security, referral attribution, and experiment assignment. When analytics integrations are enabled, they may set or read device identifiers and browser storage to measure acquisition and product usage. You can limit these technologies through your browser settings or privacy tools, although blocking essential storage may prevent sign-in and saved features from working.
8. Public content
Using Save comparison creates an unlisted page that is accessible to anyone with its URL. Legacy shared advisor lists work the same way. GradShore currently asks search engines not to index these pages, but that instruction does not prevent a recipient from forwarding, copying, or publishing the content. Professor profiles and program records are public pages based primarily on public professional and government data. Do not put confidential, infringing, or personal information about another person in a share title or criteria.
9. Retention and deletion
- Account and saved-feature records are retained while your account is active.
- An account deletion request deactivates the GradShore account immediately. Signing in during the next 30 days reactivates it; after that grace period, GradShore deletes the application account and associated workspace, entitlement, subscription, digest, reminder, saved-comparison, share, and legacy conversation records through its scheduled cleanup process.
- Security logs, provider records, backups, and transaction records may remain for limited periods where reasonably necessary for security, dispute resolution, or legal compliance.
- The in-app deletion flow does not delete your Google account or records that a payment, authentication, analytics, or infrastructure provider must retain under its own legal obligations. Contact us to request deletion beyond the application records described above.
- Public academic and government records remain while GradShore provides the service, subject to correction and opt-out procedures.
10. Your choices and rights
Depending on your location, you may have rights to access, know, correct, delete, restrict, object to, or receive a portable copy of personal information, and to appeal or complain to a regulator. We will not discriminate against you for exercising a privacy right.
- Account holders can request deletion from Account Settings.
- Professors may use ORCID verification to update or opt out of a profile where that flow is enabled. If it is unavailable, send the request by email.
- Other requests may be sent to privacy@gradshore.com. We may need to verify your identity before acting on a request.
11. International processing
GradShore and its providers may process information in countries other than your own, including the United States. Where required, we use contractual or other legally recognized safeguards for international transfers.
12. Security
We use technical and organizational safeguards designed to protect information, including encrypted transport, managed authentication, access controls, signed webhooks, and rate-limiting. No system is completely secure, and we cannot guarantee absolute security.
13. Children
GradShore is intended for graduate-school applicants, researchers, and other users aged 13 or older. It is not directed to children under 13, and we do not knowingly collect personal information from them. Contact us if you believe a child under 13 has provided information.
14. Changes and contact
We may update this policy as the service or law changes. We will update the date above and, for material changes, provide additional notice where appropriate. Contact privacy@gradshore.com with questions or requests.