Your information belongs to you.
This Policy explains Shineward’s privacy practices across shineward.com, student portfolios, student work pages, path planning, counselor and advisor support, and related services (the “Service”).
1. Scope and operator
Shineward (“Shineward,” “we,” “us,” or “our”) operates the Service from the United States. This Policy applies when you create an account, use the Service, share a portfolio or student work page, connect with a parent, guardian, counselor, or advisor, or contact us. It does not govern third-party sites linked from the Service.
If a school or district uses Shineward under a separate written agreement, that agreement may provide additional privacy commitments. Where we process education records for a school, we act only for the authorized educational purpose and subject to the school’s direction and applicable law.
2. Information we collect
Account and eligibility data: email, name, authentication identifiers, account role, date of birth or age-status result, school, graduation year, and guardian contact and consent details when applicable.
Student content: academic history, courses, grades or GPA, plans, target schools, activities, skills, awards, work and volunteer hours, portfolio text, uploaded photos and documents, links and sources, résumés, and AI prompts or outputs you choose to create.
Advisor, support, and verification data: invitations, connection requests, per-person authorization records, the advisor-workspace categories disclosed at approval, counselor or advisor identity and contact information, organization and school affiliations, credential evidence, verification decisions, connection changes, advisor-specific private notes, shared Action Plan tasks and submissions, and limited audit records.
Technical and usage data: device/browser class, cookies and authentication tokens, approximate network information such as a one-way IP hash for security and rate limiting, interactions, error and security logs, aggregated Vercel Analytics measurements, and, when bot protection is enabled, Cloudflare Turnstile challenge responses and related browser, device, network, and security signals. Public portfolio visitors may provide a share token and create limited access events.
Communications and feedback: contact-form messages, structured product-feedback selections, optional explanations or comments, and any account identifier or email associated with the submission. Signed-out feedback may be submitted without an account identifier.
3. How we use information
We use information to provide accounts, portfolios, documents, path planning, recommendations, counselor/advisor workspaces, guardian authorization, Action Plans, account deletion and data-rights tools; authenticate users and enforce permissions; verify schools, organizations, and support professionals; send requested transactional messages; answer inquiries; prevent abuse and investigate safety or security incidents; debug and improve the Service; comply with law and enforce agreements; and protect users, Shineward, and the public.
We do not use sensitive student content to build advertising profiles. We do not make final decisions about admission, course enrollment, graduation, credit, employment, housing, insurance, or other legally significant eligibility. Students, families, schools, and authorized professionals remain responsible for those decisions.
5. AI-assisted features and public sources
When you choose an AI-assisted feature, the text, images, or document excerpts needed to fulfill that request may be sent to a configured AI provider, which may include Groq, Cloudflare Workers AI, Anthropic, Google Gemini, or OpenRouter. The provider may process this information in the United States or other locations where it operates. Sensitive student requests are routed only to a production configuration approved for that data class; if none is available, the feature fails instead of silently sending the request to an unapproved provider. Shineward does not intentionally enable a provider tier that permits student prompts or responses to be used for general model improvement. OpenRouter requests are restricted to providers configured to deny data collection and use zero data retention. Free evaluation tiers may be used during development only with synthetic or non-student test information.
AI may help organize, explain, summarize, or compare information, but it does not make a final academic or admissions decision. Path Planner combines available transcript information, confirmed catalog or requirement sources, calculations, and optional AI-assisted review. Sources can change and output can be incomplete or inaccurate, so students and advisors must verify recommendations with current official school information before acting.
School document and counselor-finder tools may retrieve public pages from official schools, districts, government datasets, and search providers. Source URLs and excerpts may be cached to show provenance and reduce repeated requests.
6. Students, minors, parents, and schools
Under 13: the Service is not available to children under 13, and the age gate is designed to stop their registration. We do not knowingly collect personal information directly from a child under 13. If you believe this occurred, contact us so we can investigate, restrict the account, and delete information as required. Shineward’s guardian-authorization workflow for teenagers is not a substitute for verifiable parental consent where the Children's Online Privacy Protection Act applies.
Ages 13–17: accounts are private by default. A current guardian standing authorization is required before a qualifying new advisor connection for a minor can activate. A separate, purpose-specific guardian signature is required before a minor publishes an unlisted student work page. The student still recognizes and approves each counselor or advisor individually. Advisor approval grants the categories disclosed in the approval flow as one workspace; the guardian receives a notice for each qualifying activation, and the student can end the connection. A guardian may use the authorization-management process to withdraw qualifying standing authorization and can separately revoke work-page approval, which immediately stops that public link.
Independent and school-directed use: when a student or family independently creates an account and shares information with an advisor, Shineward generally receives that information from the user rather than from a school. A school or district must authorize its own personnel and technology use. Creating an advisor account does not by itself make Shineward an agent or school official of a school or district.
Schools and FERPA: Shineward does not claim that every user-provided record is a FERPA education record. Before a school discloses personally identifiable information from education records under FERPA’s school-official exception, the school must determine that Shineward performs an institutional service, is under the school’s direct control regarding use and maintenance of the records, uses them only for the authorized purpose, and is subject to applicable use and redisclosure restrictions. A separate written school agreement should define authorized data, access, security, incident response, retention, deletion, and audit responsibilities before school-directed use.
7. Your controls and choices
You may edit account and student content; manage portfolio visibility; approve or decline each support professional; revoke a counselor or advisor's whole connection; download a machine-readable copy of available records from Account Settings after a recent sign-in; or delete your account through account settings. Advisor-workspace categories are bundled for new connections and cannot be switched on or off separately. A parent or guardian may use the authorization-management link provided to review or withdraw an authorization.
The self-service export includes account and student records, portfolio content, collaboration records, and a manifest containing short-lived private links to available uploaded originals. It excludes credentials, private abuse controls, another person's private records, and an advisor's private notes. A parent or guardian requesting a minor's records should use the privacy-request process so identity and authority can be verified.
Connections already activated under an earlier per-section model retain their historical grants until they are revoked or replaced; Shineward does not silently expand those older connections. New full-workspace connections for a minor require the current guardian authorization.
You may also request access, correction, portability, deletion, restriction, or an explanation of our practices through the contact form. Select “Privacy or data-rights request.” We will verify requests proportionately and may deny or limit a request where law permits, including to protect another person, security, legal claims, or records we must retain. Authorized agents must provide proof of authority. If we deny an applicable request, you may appeal through the same form by identifying the earlier request.
Browser “Do Not Track” signals are not standardized. Because Shineward does not sell data or use cross-context behavioral advertising, we do not provide a sale/sharing opt-out. Where required, we will honor legally recognized universal opt-out signals for covered processing.
8. Retention and deletion
We keep account and student content while the account is active and delete it when requested, subject to limited backup cycles, security needs, unresolved disputes, valid legal obligations, and records that must be preserved. Revoked connection records are minimized and retained for their configured audit period; consent, verification, safety, and authorization audit events are generally retained for up to two years. Expired invitation and queue records are generally removed after 90 days. Contact and product-feedback submissions are scheduled for deletion after 24 months unless an earlier verified deletion request applies or a legal, safety, or dispute need requires longer retention.
We periodically review retention needs and use reasonable deletion or de-identification measures when information is no longer required for its stated purpose.
9. Security and incident response
We use measures appropriate to the information and Service, including encrypted transport, managed authentication, row-level database authorization, private storage paths, least-privilege database functions, per-person consent, audit events, rate limits, bot verification, edge DDoS mitigation, and access revocation. Sensitive student profiles, advisor-note bodies, uploaded-document metadata, and uploaded document bytes are additionally protected with server-side authenticated encryption; the encryption key is kept outside the database. Passwords are handled by the authentication provider as one-way hashes and are never stored in decryptable form. No internet service is completely secure, and we cannot guarantee absolute security. Keep credentials and private share links confidential and tell us promptly if you suspect unauthorized access.
We maintain procedures to investigate suspected incidents, contain and remediate harm, preserve appropriate evidence, assess what information and people were affected, and provide notices to individuals or regulators within the time and in the manner required by applicable law. Encryption may reduce risk, but it does not eliminate every security or notification obligation.
10. United States state privacy rights
Depending on your state and whether its law applies to Shineward, you may have rights to know or access personal data, correct inaccuracies, delete data, obtain a portable copy, opt out of sale, targeted advertising, or certain profiling, limit certain sensitive-data uses, and appeal a denied request. Shineward will not discriminate against you for exercising an applicable privacy right.
California notice: the categories collected during the preceding 12 months are identifiers; customer records; protected-class/age information; internet or electronic activity; education-related information; professional or employment-related information; user-created media and documents; inferences generated to provide requested planning features; and potentially sensitive personal information such as account credentials, precise educational records, or guardian communications when you provide them. The sources, purposes, recipients, and retention criteria are described in Sections 2–8. We do not sell or share personal information as those terms are defined by the CCPA, and we do not knowingly sell or share personal information of people under 16. Applicable California rights may be submitted through our contact form and may be appealed by replying through the same channel.
State-law coverage and exemptions vary, including for nonprofit entities and education records governed by other laws. We will honor rights that apply and may voluntarily honor comparable requests where practical.
11. Changes to this Policy
We may update this Policy to reflect changes in the Service, law, or our practices. We will post the new date and provide additional notice when legally required. We will not use previously collected personal information in a materially different way without the notice or consent required by law.
12. Contact and complaints
Operator: Shineward, United States. Submit privacy questions, rights requests, complaints, legal notices, or school inquiries through the Shineward contact form. Choose the matching topic so the request can be routed correctly. If you are dissatisfied with our response, you may appeal through the form and may contact your state attorney general or applicable privacy regulator.