HomeLEARNWISE

Privacy

Privacy Policy

Effective August 29, 2026

The short version

  • Booking the free intro call happens on Calendly, which asks a parent for a name and an email. The form on this site asks for six things: your name, your email, your phone if you want to give it, your child's first name, your child's grade, and anything you'd like to add. Nothing else, in either place.
  • We use it to reply to you and run the session. That's all.
  • We never sell it, share it with advertisers, or use it to train AI. No tracking cookies, no advertising, nothing that follows you to other sites.
  • Card payments are not built yet. Where this policy describes them, it says so. The parent portal and student accounts are live, and invite-only.
  • A student can never open their own account. Only a parent can, from inside their own account, after being shown exactly what will be collected — and a parent can delete it all, any time.
  • Ask us any time and we'll show you what we have, correct it, or delete it.

Who this policy covers

This policy explains how LearnWise College Consulting (“we”) handles personal information collected through this website, the intake form on it, the Calendly page where the introductory call is booked, the parent portal, and student sign-in. We are a private college-consulting and mentorship service based in the Bay Area, California, working with students in grades 7 through 12.

It is written to be read by a parent or guardian, and it speaks about your child in the third person, because that is how the form works: you tell us about your child, and your child does not fill anything in.

This policy covers information. What we agree to do for your family, what it costs, and how either side can end it are in the Terms of Service at /terms, along with the plain statement that no consultant can guarantee an admission outcome.

We are not affiliated with, endorsed by, or sponsored by any university named on this site.

What exists today, and what does not

A privacy policy that describes systems nobody has built yet is not a privacy policy, so this one says which is which.

Live today: this website, the Calendly page the free introductory call is booked on, the intake form at /book, the database submissions and accounts live in, the email we reply from, the invite-only parent portal at /login, and the student logins a parent can create at /student/sign-in. That is the whole of it.

Not built yet: card payments. The section headed “Payments” describes how those will work, in the conditional, and it opens by saying it is not switched on. The sections headed “The client portal” and “Students and children's information” describe what is live, in the present tense. Before card payments start, we will post the revised policy with a new effective date.

We would rather tell you the plan early than describe it in the present tense before it is true.

What we collect

Reading the public pages of this site collects nothing you type. There are no advertising scripts and no tracking cookies. Public marketing pages set no cookies at all. Signing in at /login, or as a student at /student/sign-in, sets a small number of strictly necessary session cookies so the site can remember that this browser is signed in. They are described under “The client portal”.

The one thing the public pages record on their own is a count of page views, through cookieless analytics: the page, where you arrived from, a city-level location, and the browser and device type. It is not tied to your name, your email or your IP address, and it is described under “Who else is involved”. Portal and student pages do not carry it.

Booking the introductory call. The buttons on this site that offer a free introductory call do not open a form here — they open Calendly, a scheduling service, in a new tab. What you type there is typed into Calendly, not into this site, and it reaches us afterwards: your name, your email address, the time you picked, and anything you write in the box Calendly offers. We do not ask you for anything about your child in order to book a call, and we would rather hear about your child on the call than in a scheduling form. Calendly is described under “Who else is involved”, and this is the one place where information about you is collected somewhere other than here.

The intake form. The form at /book is still live, and /sessions links to it so you can register interest in a seminar without booking a call. If you use it, it collects six things, and this is the complete list: your name; your email address; your phone number, which is optional; your child's first name; your child's current grade, from 7 to 12; and an optional message telling us anything you want us to know. You choose what to put in the message.

That is genuinely all. We do not ask for your child's surname, date of birth, age, school, home address, photograph, phone number or email address, and we do not ask for transcripts, test scores or school records. If you volunteer something in the message box, we hold what you wrote and nothing more.

The form is for parents and guardians. It asks you about your child; it does not ask your child anything. You do not need an account to use it, and submitting it does not create one.

What the form writes goes into a Postgres database we run on Supabase. It also reaches us as an email: an automated notice is sent through Resend to the one address we reply from, and it carries the whole enquiry — your name, your email, your phone if you gave one, your child's first name and grade, and your message. That is so a mentor reads what you actually wrote and can reply to you directly, rather than working from a notification that says only that you wrote in. Nobody outside LearnWise receives it. That mailbox is covered by the same deletion schedule as everything else, described under “How long we keep it, and how it is kept safe”.

How we use it

The booking and the form: only to hold the call you asked for, reply to you, and continue the conversation if you want us to. The portal: to sign you in and to let a parent create a login for their child. That is the whole purpose, and we do not repurpose it later for something you did not ask for.

We do not sell personal information and we have never had a reason to. We do not share it with advertisers, we do not use it to build a profile of you or your child, we do not use it to train machine-learning models, and we do not use it to make automated decisions about your child. Judgements about a student are made by a person who has met them.

Who else is involved

Supabase, which hosts the Postgres database the intake form writes to, and which provides sign-in for the portal described below. Submissions and account records are stored in their infrastructure. They process them on our instructions and for no purpose of their own.

Vercel, which hosts this site and provides page-view analytics on its public pages only. The portal and student pages do not carry it. Vercel Web Analytics is cookieless: it identifies a visit by a hash derived from the incoming request rather than by storing anything on your device, records only coarse information such as page URL, referrer, city-level location, operating system, browser and device type, and does not retain a session identifier beyond 24 hours. It is not tied to your IP address or to you as an individual.

Resend, which sends the automated enquiry notice whenever someone writes in. The notice is sent from LearnWise <enquiries@learnwiseconsulting.com> to the one address we reply from, and it carries the whole enquiry, including your child's first name and grade. That sending address does not receive mail; the address at the end of this policy is the one that reaches us. Resend transmits the notice on our instructions and for no purpose of its own, and it is the only party other than us that handles it in transit.

Google, as the provider of the email account we reply from, and as the identity provider for parent sign-in. Because the enquiry notice is delivered to that account, a copy of your enquiry — your child's first name and grade included — sits in a Google mailbox, in the same way any email you sent us directly would. Google does not host our intake form; that form is on this site. Google does not send the automated enquiry notice. Signing in to the parent portal is done with a Google account, so Google knows when a parent signs in.

Calendly, which runs the booking page for the free introductory call. When you follow one of the “Book a free intro call” buttons you leave this site for calendly.com, and the name, email address and chosen time you enter there are collected by Calendly and passed to us, along with anything you write in their optional notes box. Calendly is their site, not ours: it sets its own cookies on its own domain and is governed by its own privacy policy while you are on it. It holds your booking on our instructions and for no purpose of its own. We do not ask for, and their page is not configured to ask for, anything about your child.

Stripe would handle card payments if and when your family enrols. See “Payments”. It is not in use today.

That is the entire list. There is no advertising network, no data broker, no customer-analytics platform, no chatbot and no AI vendor behind this site.

We may also disclose information where the law requires it, and — this is the only other case — where we believe in good faith that someone is at immediate risk of serious harm. Nothing else. If we are ever compelled to hand over information about your family, we will tell you unless we are prohibited from doing so.

We will hold a written data-protection agreement with every processor that holds information about a student, covering confidentiality, purpose limitation, security and deletion. Those agreements are not all countersigned yet, which is why this says “will”.

Payments

Nothing on this site takes a payment today, and we hold no card details of anyone.

If and when your family signs on, our fee is a recurring retainer, billed monthly or by term, and it is handled by Stripe. You would enter your card details with Stripe, not with us. Card numbers never reach this site: we do not see them, do not receive them and have nowhere to store them.

What we would see from Stripe is the name and email on the account, the amount, the date, whether the payment succeeded, and a token that stands in for the card without revealing its number. We use that to know whether an engagement is paid up, and for tax and accounting.

The card transaction has a second function, described under “Students and children's information”: it is one of the methods COPPA approves for verifying that a person consenting on a child's behalf is really the parent.

What the retainer buys, how to cancel it and what happens to money already paid are contract terms, not data terms. They are at /terms.

The client portal

This is switched on. The portal is a private area for families who have already signed on, at /login. It is invite-only, and we should be exact about what that means rather than describing a locked door: anyone can put a Google account in front of the sign-in page, but signing in on its own gets you nothing at all. Access requires a record that only we create, after a conversation — a parent row is created only by claiming an invite — and a session without one can read nothing and change nothing. There is no password for us to store and none for us to lose.

Signing in uses your Google account rather than a password we store. We learn your name and email address from Google and nothing else — no access to your mail, your contacts or your files — and Google knows that you signed in to LearnWise, which is the trade you are making by using it. It sets a small number of strictly necessary session cookies: enough to remember that this browser is signed in, and to complete the sign-in handshake safely. They are not tracking cookies, they are not shared, and they do nothing else. Signing out clears them.

No analytics, no advertising and no third-party script runs inside the portal or on any student page. The site's page-view analytics belong to its public pages, and the portal sits outside them.

Students and children's information

This is the part of the policy to read slowly. We work with students in grades 7 through 12, so some of them are 12 years old, and a parent we have invited can give their child a login at any grade. That brings us squarely under the federal children's privacy rule, COPPA (16 C.F.R. Part 312), and the design below is built around it rather than retrofitted to it. This is switched on. A parent we have invited can create a sign-in for their child from inside their own account, and only that way.

Only a parent can create a student account. A student account is created in exactly one way: by a parent who is already signed in to their own portal account, from inside it. There is no page, link, invitation or route of any kind by which a child can create an account, and none by which a child can be signed up by anybody other than their own parent or guardian.

You are told what will happen before it happens. On that screen, before anything is created, we show you directly what will be collected about your child, what it will be used for, who it will be disclosed to, how long it will be kept, and that you can review or delete it at any time. You then have to consent explicitly. Nothing is created by default, nothing is pre-ticked, and closing the screen creates nothing. We record which parent consented, for which student, on what date, and which version of that notice you were shown, so that both of us can tell later exactly what you agreed to.

How we verify that you are the parent. A student’s access can only be created from inside your own signed-in account, so the person doing it is someone who has already proved they hold your account. We record that you were signed in when you agreed. That is the only method in use today. A payment-card transaction, and consent by email followed by a confirming message to the same address, are methods the rule also approves (16 C.F.R. § 312.5(b)(2)). Neither is built, and neither is used, until billing exists.

Nothing is collected from your child. Not one field. You supply your child's first name; we generate a username and passcode and give them to you. Your child signs in at /student/sign-in; there is no student email. There is no date of birth, no age, no surname, no school, no home address, no photograph, no phone number and no email address belonging to your child, and your child is never asked to fill in a profile or asked a question that invites personal information. We do not condition your child's participation on giving us more than the mentorship needs (§ 312.7).

Nothing your child does here is public. There is no messaging between students, no comments, no display name visible to anyone else, and no way for one family to see another. Whatever your child does in the portal is visible to your child, to you, and to the mentor working with your child.

Who sees it. Your child's first name and login live in our Supabase database and are seen by the mentor working with your child. They are disclosed to no one else, for no purpose. A child's information is never sold, never disclosed for advertising or marketing, and never used to train any machine-learning model, ours or anybody else's.

No tracking, ever, on a student page. No analytics, no advertising and no third-party script runs on any page a student sees. This is a property of how the site is built rather than a setting we could quietly change: the page-view analytics are scoped to the public pages, and student pages sit outside that scope.

You stay in control. You can review everything we hold about your child and delete it at any time, and you can withdraw your consent and refuse any further collection, which ends the account. How to do each of those is in the next section. If you believe a child has given us information through any route we have not described here, write to us and we will delete it.

Reviewing, correcting and deleting

Your own information. Ask us what we hold about you, ask us to correct it, or ask us to delete it. Write to the address at the end of this policy and we will do it. There is no charge, you do not need to give a reason, and we will not ask you to justify it.

Your child's information. Once you have a portal account, the parent's view of a student account shows you everything held about your child, on one screen, in plain form, and carries a control that removes your child's sign-in. You do not need to ask us and you do not need our agreement: the sign-in stops working immediately and the account behind it is deleted at once. To erase the record itself — your child's first name and grade — write to us and we will do it, without charge and without asking why; that step is not yet a button, and we would rather say so than imply one, and it drops out of our backups as those rotate within 30 days.

The same right, exercised by email. If you would rather not use the portal, write to us and we will show you what we hold about your child, correct it, or delete it, on the same terms. We will not use that request as an occasion to ask you for more information than we need to be sure we are talking to the parent.

Refusing further collection. Withdrawing your consent for your child's account is the same act as deleting it, and it is honoured without argument (16 C.F.R. § 312.6). Deleting your child's account is a data decision, not a cancellation notice; if you also want to end the engagement, see /terms.

How long we keep it, and how it is kept safe

An enquiry that does not become an engagement is deleted within 12 months of the last message between us. That covers both copies: the record in our database and the notice sitting in the mailbox we reply from, which carries the same details. We delete the mail too, on the same clock — a promise about a database is not worth much if a second copy of the same enquiry stays in an inbox indefinitely.

A booking for the introductory call is a third copy of the same details, held by Calendly, and it follows the same clock: we delete bookings from Calendly on the schedule in this section, and you can ask us to remove one sooner. A promise about a database and a mailbox is not worth much if the calendar keeps its own record indefinitely.

If your family does become a client, your own contact details and our correspondence are kept while we are working together and for 24 months after the engagement ends, so that we can pick the conversation back up if you return, and are then deleted.

Children's information has a hard limit. A student account and everything in it — the sign-in, and whatever the account holds — are deleted no later than 90 days after your family's engagement ends, or sooner if you ask. We keep a child's information only for as long as running the mentorship you asked for actually requires, and we never keep it indefinitely: indefinite retention of children's data is prohibited (16 C.F.R. § 312.10). We do not keep it for any secondary purpose, and there is no archive of former students.

One honest qualification to that 90 days. Your child's first name and grade are in the enquiry you sent us and in the notice of it that reached our mailbox, and where you have written to us about your child, they are in that correspondence too. Those follow the correspondence schedule in the paragraphs above — 12 months if the enquiry goes nowhere, 24 months after an engagement ends — not the 90-day account limit, because deleting an account cannot reach inside a conversation you and we had. If you would rather we deleted the correspondence sooner, say so and we will, and you can ask us to erase your child's details from it at any time without giving a reason.

Payment records are the exception, and they are not about your child: we keep the record of who paid what and when for as long as tax and accounting law requires us to.

Security. Access to the database is limited to the people who need it to do the work, information is encrypted in transit, and each processor named above is bound by its own published security and confidentiality terms, with the specific written agreements described under “Who else is involved” still to be countersigned. We will hold a written security programme covering children's information, and written assurances from each processor that touches it, as 16 C.F.R. § 312.8 requires. Those are not all in place yet. No system is perfect; if information about your family is ever exposed, we will tell you promptly and directly.

California, and why none of this is for sale

We are not a “business” under the CCPA as amended by the CPRA: none of the three thresholds in Civ. Code § 1798.140(d) is met — we are far below $25 million in annual revenue, we handle nowhere near 100,000 consumers, and we derive no revenue whatsoever from selling or sharing personal information.

The CCPA has particular rules for minors: it requires opt-in consent before the personal information of anyone under 16 is sold or shared, and the parent's consent for anyone under 13 (Civ. Code § 1798.120(c)). Those rules never come into play here, because we do not sell or share personal information at all, at any age, and are not structured to.

We give you the review, correction and deletion rights described above whether or not a statute obliges us to, and we will not treat you differently for using them.

Do Not Track

We do not track you across other websites, so there is nothing for a Do-Not-Track signal to switch off. We honour it by default, in the sense that we never do the thing it asks us not to do. Public marketing pages set no cookies. The session cookies signing in sets, described under “The client portal”, are strictly necessary to keep you signed in, carry no advertising identifier, and follow you nowhere.

No third party collects personally identifiable information about your activity across different sites through this website.

Changes to this policy

If we change this policy materially, we will update the effective date at the top and post the revised policy at this same address before the change takes effect.

The one system this policy still describes before it exists is card payments. We will not switch that on before the policy describing it is posted with a new effective date.

If a change would materially affect information we have already collected about a child, we will not apply it to that information without asking the parent again and obtaining consent afresh.

Contact

Questions about this policy, or about information we hold about you? Write to consultinglearnwise@gmail.com.