Loading workspace…
Last updated: August 24, 2026
About this page. This is a plain-language product privacy overview. It does not replace any notice or agreement required by a university.
MyFutureSelf builds Ace, an AI mentor for students at Chaminade High School. This page explains, in plain language, what we collect, why we collect it, who processes it, how long we keep it, and the choices you have. The short version: the implemented institutional analytics surface exposes only authorized, privacy-stabilized aggregates, not student-level rows, we never sell your information, and you can delete your MyFutureSelf account at any time.
When you use Ace, we store:
A resume or degree audit lets Ace give advice that matches your real coursework and experience. When you connect a resume or degree audit (DAR), MyFutureSelf stores the original file in private Supabase storage and keeps extracted text privately so the document remains available between sessions. Each successful newer DAR becomes the current DAR while prior successful DAR uploads remain in private history.
Ace can read only the current DAR. It cannot list or read earlier DAR versions, switch versions, edit a DAR, or delete DAR data. It supplies the current document's extracted text to OpenAI only when it needs to answer you or personalize your plan. The original resume or degree-audit file is not sent to OpenAI through this document-reading flow. Under OpenAI's published API terms, content sent through the API is not used by default to train OpenAI's models.
Uploading a newer DAR does not delete prior DAR history. You can permanently delete every saved DAR file and its extracted text from Profile, or delete your account.
Other files you attach directly to a chat may be sent to OpenAI's API so Ace can answer about them. Those attachments stay in our OpenAI account until they are removed, and deleting your account removes them.
Ace's replies are generated through OpenAI's API. Your messages, the profile context we assemble into the prompt, and document text you invoke are sent to OpenAI so it can generate a reply. Each turn is also stored at OpenAI as a response object under our account until we delete it or OpenAI's own window closes. Zero Data Retention is not enabled on our OpenAI project, and a check on August 21, 2026 confirmed that stored objects persist there. OpenAI's published documentation states at least 30 days of retention for a stored object, and that period is set by provider terms we do not control. Deleting your account deletes those stored objects, as described below.
Voice features run on OpenAI too. Speech playback and transcription go through our server to OpenAI. Realtime voice does not: your browser connects to OpenAI directly using a short-lived key our server mints, so on that connection OpenAI receives the audio and your browser's IP address.
To debug reliability problems we keep a technical log of AI requests and responses. That log has a 30-day retention target. The database includes a purge function, but the scheduled retention job is installed separately and must be verified in each environment. A check of the production schedule on August 21, 2026 found that job active.
MyFutureSelf is a small company that runs on other companies' infrastructure. These are all of them, what each one does, and where it processes what we send it. Every relationship rests on the provider's standard published terms; we have no separately negotiated data processing agreement with any of them.
Our own application, database, storage, backups, and analytics regions are in the United States. That fixes where the service itself runs. It does not establish where OpenAI, Google, Resend, or the search and enrichment providers process what reaches them, and we have not obtained per-provider residency evidence, so we make no claim beyond their published terms.
We have designed an optional feature that can look for a student's own public professional and educational presence. Live production searching remains disabled while provider, university, privacy, and legal review is pending. It will not run merely because you created an account or finished onboarding.
If this feature is approved and enabled, it will first show a separate disclosure and ask you to confirm both your eligibility and your authorization. Only approved public professional, portfolio, project, publication, GitHub, and university-profile sources may be searched. LinkedIn content is not fetched or scraped. The search may use your name, Chaminade High School affiliation, interest area, graduation year, and any canonical URLs you choose to provide. Optional profile links you enter are used only to resolve your identity for that authorized search.
Suggestions are limited to professional or portfolio links, projects, publications, awards, organizations, education, work experience, skills, and interests explicitly stated by you or a source. Suggestions include a source link, access date, and confidence information. Nothing changes automatically. You accept, edit, or reject every suggestion independently. The feature is not used for employment, admissions, credit, insurance, housing, disciplinary, or other eligibility decisions, and it blocks sensitive or high-risk inferred fields.
Raw fetched pages are not retained. Unaccepted suggestions and their provenance have a 30-day deletion target, and a production check found that the scheduled deletion job is not installed, so that target is not enforced by a running job today. Accepted facts and their provenance stay on your private profile until you remove them or delete your account. You can cancel a running search, withdraw future-search authorization, reject any field, remove an accepted field, delete pending results, or delete your account.
Under the implemented institutional analytics design, individual student data is not available in the university reporting surface. There is no student drill-down: not chats, profiles, contacts, messages, or private progress.
This describes the current product design, not an unconditional legal guarantee. Any different institutional sharing would require its own approved notice, agreement, and authorization.
Institutional reporting is aggregate-only with minimum-cohort and complementary suppression designed to reduce identification risk. Student-reported career outcomes include only students who explicitly opted in. Sharing is off by default, and you can change your choice in account settings; changes apply to later weekly reports. The “What Chaminade sees” section lists exactly what the school can see.
Authorized Chaminade staff can see only the aggregate reporting listed here. Never your name, your chats, your contacts, your notes, or any individual row.
These are counts or rates with a privacy-qualified contributing-student count attached. Every released cell has at least 10 contributing students, with additional suppression when totals or neighboring cells could reveal a smaller group. Chaminade sees "Privacy-suppressed" for a missing cell or "No reportable aggregate cells in this view" when the whole view is withheld, instead of those numbers. That floor is enforced inside the database itself, not in the page that displays the numbers.
Student-reported career outcomes are only counted for students who turned on outcome sharing, and only as counts. Outcome sharing stays off until you turn it on, and you can change your choice anytime in Settings.
Reports are frozen weekly. A sharing change applies to later publications and does not rewrite an already frozen aggregate.
We do not sell your personal information. We do not share it with advertising networks or data brokers, we do not use it for marketing unrelated to the service, and we do not build profiles of you for anyone else. That applies to de-identified and aggregated data too.
The providers listed above receive only what they need to do the job named next to them, under the purposes described on this page. Disclosure to your university happens only under the institutional agreement, and what it covers is the aggregate reporting surface described above.
If law enforcement asks us to disclose personal data, our privacy program requires the request to go to our legal counsel before anything is disclosed. We have not yet adopted a separate published standard for handling those requests, and saying so is more useful to you than implying one exists.
If a breach at one of our providers exposes your data, it is our incident and our obligation to notify. We do not treat a forwarded vendor notice as having notified anyone.
You can delete your account at any time from your account settings (Delete my account). You do not have to ask us, and the request is not routed to your university for approval. Deleting the account removes the profile, chats, memories, tasks, roadmap and plan state, saved contacts, outreach records, telemetry rows, upload records, and consent records controlled by MyFutureSelf. The purge works from an explicit list of every table that carries a student identifier, currently 30 tables, and a test in our build fails if a new such table ever appears without a deletion decision.
Before removing the account, the service must delete its linked private-storage files and your stored records; if either cannot be verified, account deletion stops so it can be retried safely. The order matters: your data goes first, and your sign-in identity is deleted only after that succeeded, so a half-finished deletion never leaves you locked out with your data still here. Retrying is safe.
Deletion reaches OpenAI as well. The purge deletes your stored responses, the items inside each OpenAI conversation object, the conversation objects, your uploaded files, and the search stores built from them. OpenAI cleanup is best-effort and failures are logged for follow-up, and any artifact OpenAI refuses to delete is reported rather than quietly dropped. Anything not deleted that way still falls under OpenAI's own retention window, which its documentation puts at a minimum of 30 days for a stored object.
Some things survive by design, and they are worth naming. Aggregate, de-identified statistics that cannot be traced back to you may be retained. So may shared reference data such as company, industry, and program records, and the alumni corpus, which is not student data. Backups and provider request logs age out on the cycles described above.
One record is not yet removed automatically: the profile our product analytics provider keeps under your account identifier. You can ask us to delete it at any time, we do it by hand, and we are working to make that automatic. What that profile holds is pseudonymous product usage: no conversation text, no query text, no name, and no email address. Account deletion cannot be undone.
We use local storage in your browser to keep you signed in. We do not run third-party advertising trackers.
If this policy changes, we will update this page and the date at the top. Questions, requests, and complaints, including data export requests and analytics-profile erasure, go to kaya@myfutureselfapp.com. A privacy complaint reaches the owner of our privacy program, who is accountable for answering it. Our terms of service are at /terms.