Legal

Privacy policy

What we collect, why we collect it, and what you can do about it. Last updated July 25, 2026.

The short version

PhdFit exists to help you find PhD advisors who actually fit your background. We collect the minimum signal we need to do that — your résumé, your stated goals, and the matches and outreach you produce inside the workspace. We do not sell your data. You can request an export or delete your account at any time.

What we collect

  • Account data: email, name, and the identity provider you signed in with (Supabase Auth — Google, email magic link, or password).
  • Profile data: the résumé you upload and the structured profile our Candidate Analyst derives from it — research interests, methods, publications.
  • Workspace data: your conversations with the agents, your shortlists, your outreach drafts, and your meeting-prep notes.
  • Usage data: anonymous request logs and error traces used to keep the service running. Not sold, not cross-referenced with other services.

How we use it

Your résumé and profile are the raw material for the six specialist agents — they read it to rank faculty, write explanations, and draft outreach. We only send the fields a given agent needs for the task at hand, and we do not use your content to train third-party models.

Subprocessors

We use Supabase (database, authentication, file storage), Anthropic, OpenAI, and Zhipu (LLM inference for the agent pipeline). Each subprocessor processes only the data needed for a specific task and is bound by a data-processing agreement.

Your rights

You can request an export of the files, messages, matches, and drafts you have produced by emailing us. Account deletion is self-serve in Settings: it cancels active subscriptions, deletes uploaded files and workspace data, and removes your sign-in account. Deletion does not automatically refund prior charges. A minimal, pseudonymous deletion audit and payment records needed for fraud prevention, tax, accounting, or legal obligations may be retained. Deleted data may also remain temporarily in encrypted disaster-recovery backups until their routine rotation, where it is unavailable for ordinary product use. Contact hello@phdfit.com if a deletion remains incomplete.

Contact

Questions about this policy or how we handle your data? Write to hello@phdfit.com and we will reply within two business days.