Legal
Privacy
Pathlumi is a directory for teenagers. The less we know about you, the better this works — so we ask for very little and share less.
Last updated 1 January 2026
Launch-ready draft
The short version
- We collect what is needed to match you to opportunities, and nothing else.
- Student profiles are private. There is no public student page, anywhere.
- Organizations posting opportunities cannot see who you are, what you saved, or that you exist.
- We do not sell personal information, and we do not run advertising.
- No third-party analytics or tracking scripts run on Pathlumi.
- You can delete your account and everything attached to it.
What we collect
Everyone with an account
- An email address and a password, held by our authentication provider
- A display name that you choose
- Your account type: student, provider or administrator
- Timestamps for account creation and updates
Students
- First name, grade level and expected graduation year
- A coarse location: city, state and ZIP code. We store the approximate centre of that ZIP code, not an address
- Preferences: interest areas, preferred categories, in-person or remote, maximum cost, whether you need financial aid, time commitment, travel distance
- An optional free-text note about what you hope to explore
- A record that you confirmed you are at least 13 years old
- Your saved opportunities, their status labels, and any private notes you write
Providers
- Your name and role at the organization
- Organization details: name, type, website, contact email and phone, general location, mission, description and logo — all of which are published on the organization's public page
- Any information you give us to support verification
What we never collect
Pathlumi does not ask for, and has no field to store: Social Security or national identification numbers; bank or payment card details; medical, health or immunisation records; government identification documents; street addresses; or exact dates of birth.
Provider listings are checked for requests of this kind. A listing asking students to submit any of it through Pathlumi is rejected.
How we use it
- Matching. Your preferences drive the relevance score and the reasons shown on each card. That calculation happens on our own servers using published rules — no external service, no machine-learning model, and no profile sold or shared.
- Running your account. Signing you in, keeping your saved list, sending the in-app notifications you would expect.
- Safety and moderation. Reviewing organizations and listings, investigating reports, and keeping an audit trail of moderation decisions.
- Aggregate counts. How many people viewed or saved a listing, so providers know whether anyone is finding it.
Analytics and cookies
Pathlumi records three things: that a listing page was viewed, and that its official application link was clicked. That is the whole list.
For each event we store the listing, the date, and a salted one-way hash of your IP address combined with your browser's user agent. We do not store the IP address itself, the user agent itself, a referrer, or a tracking identifier. The hash cannot be reversed and exists so that refreshing a page twenty times does not count as twenty views.
The only cookies Pathlumi sets are the ones that keep you signed in. There are no advertising cookies, no third-party pixels, and no analytics scripts from anyone else.
How long we keep it
- Account and profile data: until you delete your account
- Saved opportunities and notes: until you remove them or delete your account
- Analytics events: 24 months, after which only aggregate counts remain
- Moderation records: retained after an account is deleted, with the account reference removed, because a safety record has to outlive the account it concerns
Your choices
- See and change your data. Everything a student profile holds is editable at your preferences.
- Turn off email. In-app notifications are part of the product; email notifications are optional and can be switched off in settings.
- Delete your account. Ask from settingsor write to us from the account's email address. Deletion removes the profile, the saved list and the notes.
- Export. Ask and we will send you what we hold in a machine-readable format.
Students under 18
Pathlumi requires students to be at least 13 years old and asks for confirmation at sign-up. We do not knowingly create accounts for children under 13; if we learn that we have, we delete the account and its data.
We deliberately do not collect an exact date of birth. A confirmation that a student meets the minimum age answers the question we actually need answered, without holding another identifier.
A parent or guardian may request access to, correction of, or deletion of a student's data by contacting us from an address we can verify against the account.
Changes
If this policy changes in a way that materially affects what we collect or who can see it, we will say so in the product before the change takes effect. The date at the top always reflects the current version.
Questions about any of this: contact the team.
Something here unclear or wrong? Tell us.