Privacy Policy
Last updated: January 2025
1. Introduction
Welcome to Draft_ ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, share, and protect your data when you use our personal statement builder platform.
By using Draft_, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, full name, and password
- Profile Data: Academic background, test scores, target countries, high school information, GPA
- Experience Data: Clinical experiences, volunteer work, research activities, extracurriculars, languages spoken
- Personal Statements: Draft essays, statement sections, and revisions
- Conversation Data: Messages exchanged with our AI guide, including questions and responses
2.2 Automatically Collected Information
- Usage Data: Pages visited, features used, time spent on platform
- Device Information: Browser type, operating system, IP address
- Analytics: Aggregate usage statistics to improve our service
3. How We Use Your Information
We use your information to:
- Provide personalized AI guidance for your personal statement
- Generate country-specific recommendations based on your target universities
- Track your profile completion and progress
- Improve our AI models and guidance quality
- Send you important updates about your account
- Analyze usage patterns to enhance the platform
- Prevent fraud and ensure platform security
4. AI Processing & Third-Party Services
Draft_ uses Anthropic's Claude AI to provide conversational guidance. When you chat with our AI guide:
- Your messages and profile context are sent to Anthropic's API for processing
- Anthropic processes this data according to their Privacy Policy
- We do not use your data to train Anthropic's models without explicit consent
- All AI processing is used solely to provide you with personalized guidance
5. Data Security
We take data security seriously and implement industry-standard measures to protect your information:
- Encryption: All data is encrypted in transit (TLS/SSL) and at rest
- Authentication: Secure password hashing using industry-standard algorithms
- Access Controls: Strict internal access policies and role-based permissions
- Database Security: Hosted on Supabase with row-level security policies
- Regular Audits: Periodic security reviews and updates
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
6. Data Sharing & Disclosure
We do not sell your personal information to third parties. We may share your data only in these limited circumstances:
- AI Processing: With Anthropic Claude for generating personalized guidance
- Service Providers: With trusted partners who help us operate the platform (Supabase, Vercel, etc.)
- Legal Compliance: When required by law, court order, or government regulation
- Safety: To protect the rights, property, or safety of Draft_, our users, or others
- Business Transfers: In connection with a merger, acquisition, or sale of assets (users will be notified)
7. Your Rights & Choices
You have the following rights regarding your data:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information in your profile settings
- Deletion: Request deletion of your account and all associated data
- Export: Download your conversations and personal statements
- Opt-Out: Unsubscribe from marketing emails (account emails may still be sent)
To exercise any of these rights, please contact us at privacy@draft.app
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our services. If you delete your account:
- Your personal data will be permanently deleted within 30 days
- Some anonymized usage data may be retained for analytics purposes
- Backups may retain data for up to 90 days before permanent deletion
9. Children's Privacy
Our service is intended for students aged 16 and older applying to medical school. We do not knowingly collect data from children under 13. If you are under 16, please ensure you have parental consent before using Draft_.
If we discover we have collected data from a child under 13 without parental consent, we will delete that information immediately.
10. International Users
Draft_ is operated from Germany. If you are accessing our service from outside Germany, please be aware that your information may be transferred to, stored, and processed in Germany and other countries where our service providers operate.
By using Draft_, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection laws.
11. Cookies & Tracking
We use essential cookies to maintain your session and preferences. We do not use third-party tracking cookies or advertising cookies.
- Authentication Cookies: Keep you logged in securely
- Preference Cookies: Remember your settings (dark mode, etc.)
- Analytics: Basic usage statistics (anonymized)
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date at the top
- Sending you an email notification for material changes
Your continued use of Draft_ after changes become effective constitutes acceptance of the updated policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: