Privacy Policy
Last updated: May 11, 2026 ย ยทย Effective: May 11, 2026
Pick My U ("we", "us", "our") is committed to protecting your privacy in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law. This policy explains what personal information we collect, why we collect it, and how you can exercise your rights.
Overview
Pick My U is a Canadian university discovery platform. We help students identify universities that match their passions, strengths, and goals through an interactive quiz and AI-powered guidance. This service is operated as a commercial activity and is therefore subject to PIPEDA.
We collect only the minimum personal information necessary to provide our service. We do not sell your personal information to third parties.
What We Collect
Account Information (optional)
If you create an account: your full name, email address, and a bcrypt-hashed password. Creating an account is entirely optional โ all core features are accessible without one.
Quiz Answers
Responses to our recommendation quiz (interests, strengths, preferences, grade average). These are stored only in your browser's localStorage and are never saved to our servers, except temporarily when you request AI-generated advice (see below).
Session Data
A signed JWT session cookie used to keep you authenticated. It contains your name, email, and user ID. It expires automatically and is never shared with third parties.
What We Do Not Collect
We do not collect payment information, government IDs, precise location data, or any information from minors knowingly. We do not use advertising trackers or analytics cookies.
The 10 PIPEDA Fair Information Principles
PIPEDA requires organizations to follow ten fair information principles. Here is how Pick My U applies each one:
- 1
Accountability
Pick My U is responsible for all personal information under its control. We have designated a privacy contact (see below) who is accountable for compliance with this policy.
- 2
Identifying Purposes
We collect personal information only for the following purposes: (a) to create and authenticate user accounts; (b) to personalize and save quiz results; (c) to generate AI-powered university recommendations. Purposes are identified before or at the time of collection.
- 3
Consent
By creating an account or requesting AI advice, you consent to the collection, use, and disclosure of your personal information as described in this policy. You may withdraw consent at any time by deleting your account. Browsing the site requires no consent as no personal information is collected.
- 4
Limiting Collection
We collect only the information necessary for the identified purposes. We do not collect sensitive personal information (health data, SIN, financial data) and will not do so without explicit, separate consent.
- 5
Limiting Use, Disclosure & Retention
Your personal information is used only for the purposes for which it was collected. We do not sell, rent, or trade your data. Account data is retained until you delete your account. Quiz answers held in localStorage are under your own control and are cleared when you clear your browser data.
- 6
Accuracy
We keep personal information as accurate, complete, and up-to-date as necessary. You can update your account information at any time by contacting us. If you believe information we hold about you is inaccurate, you may request a correction.
- 7
Safeguards
Personal information is protected by security safeguards appropriate to the sensitivity of the information. Passwords are hashed using bcrypt (12 rounds). Session tokens are signed with a secret key. Data is stored on secured servers. We do not transmit personal information over unencrypted connections.
- 8
Openness
Our privacy practices are documented in this publicly available policy. We will inform you of any material changes to this policy by updating the effective date and, where appropriate, by notice on the site.
- 9
Individual Access
You have the right to access the personal information we hold about you and to challenge its accuracy and completeness. To request access, contact us at the address below. We will respond within 30 days.
- 10
Challenging Compliance
If you believe we have not complied with PIPEDA, you may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca or contact us directly first so we can attempt to resolve the concern.
AI-Generated Advice
When you request personalized university advice, your quiz answers and matched universities are transmitted to Anthropic PBC (Claude API) to generate the response. This is a one-time, stateless request โ Anthropic does not store your data for model training under their API terms. Your quiz answers are not stored on Pick My U servers at any point during this process.
You can review Anthropic's privacy practices at anthropic.com/privacy.
Data Retention
| Data | Retention Period |
|---|---|
| Account (name, email, password hash) | Until you delete your account |
| Session cookie | 30 days from last activity, or until sign-out |
| Quiz answers | Stored only in your browser localStorage โ you control deletion |
| AI advice request payload | Not stored โ transmitted and discarded in real time |
| Server access logs | Up to 90 days for security purposes |
Your Rights Under PIPEDA
As an individual, you have the right to:
- โAccess the personal information we hold about you (respond within 30 days)
- โCorrect inaccurate or incomplete information
- โWithdraw consent and request deletion of your account and all associated data
- โKnow whether we hold personal information about you
- โFile a complaint with the Office of the Privacy Commissioner of Canada
To exercise any of these rights, sign in to your account page (where you can delete your account instantly) or contact us at the address below.
Security Breach Reporting
In the event of a breach of security safeguards that poses a real risk of significant harm to individuals, we will:
- Report the breach to the Office of the Privacy Commissioner of Canada as soon as feasible
- Notify affected individuals directly
- Maintain a record of all breaches for a minimum of 24 months
If you suspect your account has been compromised, please contact us immediately at the address below and change your password.
Provincial Privacy Laws
Alberta, British Columbia, and Quebec have provincial privacy laws deemed "substantially similar" to PIPEDA. For intra-provincial commercial activity in those provinces, the provincial law may apply. However, PIPEDA continues to apply to all inter-provincial and international transfers of personal information, as well as to federally regulated activities. Pick My U operates nationally and complies with both PIPEDA and applicable provincial requirements.
Contact & Complaints
For privacy-related questions, access requests, corrections, or complaints, contact our Privacy Officer:
Pick My U โ Privacy Officer
If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada:
Note: The OPC can make recommendations but enforcement may escalate to the Federal Court of Canada under PIPEDA s.14.