Last updated July 31, 2026
This Privacy Policy explains what information ScholarDuck (scholarduck.org) collects, how we use it, and the choices you have. ScholarDuck is operated by Northslate LLC, a Utah limited liability company ("we," "us"). It applies to the ScholarDuck product; GrantDuck, our sibling product, has its own policy, and both share one account system.
The short version: we collect what you give us so we can match you to scholarships and draft materials in your voice; AI processing is core to the service and we tell you exactly who processes what; product analytics only runs with your consent; we don't sell your data; you can delete your account and its data at any time. If you joined through an invite code during our earlier invite-only period, the Beta Agreement covers confidentiality and how that beta works.
Account information: email address, password (stored as a secure hash by our authentication provider — we never see it), and display name.
Academic profile: GPA, test scores (ACT, SAT, AP, IB, PSAT, CLT, and similar), year in school (including gap-year status), residency state, intended schools, majors and programs, activities, honors, work, service, leadership, skills, and scholarships you already hold.
Documents you upload: resumes, unofficial transcripts, writing samples, and essays you ask us to review (Word, PDF, or pasted text). We extract structured information or text from them (for example, courses and grades from a transcript) and store the extraction; for essays submitted to the review tool we store the extracted text and the resulting feedback, not the original file.
Voice profile: an analysis of HOW you write — tone, rhythm, vocabulary, storytelling habits — built from writing samples you provide, together with short verbatim excerpts from those samples. It exists so AI drafts sound like you instead of like a machine. You can view, refresh, or delete it at any time; deleting it removes prior versions as well, not just the active one.
Application work product: essay drafts, revisions, reviews, generated resumes, and export files you create in the product.
Financial aid information (optional): Students may enter family financial information themselves — such as household size, income ranges, FAFSA filing status, and Student Aid Index (SAI) estimates. If a parent or guardian links to the student's account, the parent controls this information and can limit what the student can view or edit. Exact financial figures are never shown to a student whose parent has restricted visibility, are never included in AI essay-drafting prompts, and are used only to match scholarships and estimate aid eligibility. Students aged 13 to 15 need a linked parent or guardian before entering detailed financial information; basic yes-or-no aid questions are allowed. Financial details are self-reported estimates — always verify actual aid eligibility with official sources. Providing any of this is always optional — leaving it blank never disqualifies you from matching; it only means need-based awards show as "check the requirements yourself." If enough information is on file, we also generate a coarse aid estimate for the student — a rounded tier such as "likely full Pell," "likely partial Pell," or "Pell unlikely," never the underlying dollar figures — and when a parent manages the profile, the parent controls whether the student can see even that coarse estimate, with a "share aid estimate" toggle that is on by default.
Family connections: a parent, guardian, spouse, or other family contributor can maintain a connected profile linked to a student. That profile controls the family's financial information and decides whether the student can see those financial details inside the product. Independent students — for example students who are married, 24 or older, veterans, graduate students, have dependents of their own, or are in an unsupportive or unsafe family situation — can manage their own financial information directly, without any linked contributor.
Award letters: if you choose to record financial aid offers you've received from specific schools (grant, scholarship, work-study, and loan amounts), we store them so you can compare cost and estimated debt across schools. This information is school-specific, not derived from family income or household data, so it is visible to the student regardless of the parent's financial-visibility setting above — both the student and a linked parent can view and enter it.
Usage and billing records: which features you use, credits consumed, referral activity (who referred whom, in order to grant credit rewards), and subscription and payment records. Payment card details are handled by Stripe and never touch our servers.
Product analytics (with your consent): at signup, you can optionally check a box to help us with analytics — declining it never affects your access to ScholarDuck. If you consent, we use PostHog to record product analytics for the app: which screens and features you use, funnel events (like completing signup or finishing a draft), and session recordings of your in-app activity (what you clicked, scrolled, and typed into ScholarDuck's own screens — never the contents of third-party pages). This exists so we can find bugs and confusing screens during the beta and improve the product; it is never used to advertise to you. You can withdraw this consent at any time by writing to [email protected], and analytics is off by default for anyone who has not consented. (ScholarDuck's public marketing homepage, before you have an account, runs a separate and much more limited beacon — see "Cookies & local storage" below.)
To run the service: matching you against scholarship eligibility rules, generating and revising drafts, parsing documents, building your voice profile, tracking credits, and showing you your own data.
To operate responsibly: debugging, measuring costs, preventing abuse of usage limits, and (when enabled) sending you service email such as deadline reminders — which you will be able to control in notification preferences.
We do not sell your personal information. We do not use your essays, documents, or profile to advertise to you or to train AI models.
ScholarDuck's core features are powered by artificial intelligence. When you use them, relevant parts of your information are sent to our AI provider, Anthropic, to be processed: transcripts and resumes for extraction, writing samples for voice analysis, and your profile facts, answers, and voice profile for essay and resume drafting.
Under our agreement with Anthropic, content submitted through their API is not used to train their models. Your information is sent only when you invoke a feature that needs it, only in the scope that feature requires, and results are returned to your account — never published anywhere.
Financial aid information gets stricter treatment than everything else: your SAI, income range, and Pell status live in a separate, access-restricted store that ordinary product code and AI prompts can never read, and are NEVER included in essay or resume drafting prompts or in any AI-generated text. Need-based matching happens in our own deterministic code, not in an AI model. Two lighter-weight financial signals do reach AI prompts: a coarse need flag (yes / no / unsure, never a dollar figure) and your FAFSA status — used so the interview can skip questions a parent has already answered, and so drafting can reflect that you've indicated financial need without ever seeing the dollar figures behind it.
AI output can be wrong. Drafts are first-draft assistance you must review and edit; extraction results are shown to you for correction. Nothing AI-generated is sent to any scholarship provider by us — submitting applications is always your action, outside ScholarDuck.
Parent, guardian, spouse, and other family contributor accounts: a student can invite a parent, guardian, spouse, or other family contributor to create their own account from the student's account page. We send the invite by email through our email provider, Brevo; the email contains a single-use link built from a randomly generated token, and we store only a cryptographic hash of that token — never the token itself — which expires automatically if unused. The invited contributor signs up with that email address or with Google, whichever they prefer, and is linked to the student once they finish. A linked contributor can view the student's application progress (counts, statuses, and upcoming deadlines) and can view and enter the student's financial aid information as described above; a linked contributor cannot see or edit the student's essays, drafts, or applications. Viewing or changing financial information additionally requires a step-up: a recent sign-in (within the last 15 minutes) on the contributor's own account. Contributor accounts are free riders — they carry no subscription or credits of their own, and any AI-assisted action a contributor takes draws on the linked student's own credits. A student who is independent under FAFSA's rules, or who has no parent or guardian able to safely act as a contributor, is never required to invite anyone and can manage their own financial information alone.
Parent-managed financial information is visible to the managing parent profile; the parent chooses whether the student can view it in the product. When a parent turns student visibility off, the raw values are withheld from student views on our servers — not merely hidden on screen.
Share links are read-only snapshot pages you can create for a parent, counselor, or mentor. A share link's snapshot contains only your first name, your scholarship shortlist (names, providers, amounts, deadlines, fit), and your application pipeline — full stop; nothing else about you is included. Anyone with the link's URL can view that snapshot until it expires (90 days by default) or you revoke it, which you can do at any time. We count views to limit abuse.
The official browser extension stores its connection tokens on your own device (in your browser's extension storage), reads your profile facts, shortlist, and drafts through your account in order to fill application forms when you ask it to, and sends nothing anywhere except to our servers. Disconnecting the extension or signing out of ScholarDuck revokes its access. We do not collect browsing history through the extension; it acts only on pages where you invoke it.
FAFSA assist: on studentaid.gov specifically, the extension behaves differently from other sites. It never reads or transmits anything from the page back to our servers, and the page-capture feature available elsewhere is disabled entirely there. It may suggest safe values for you to copy into the form — never your Social Security number, FSA ID, or any dollar amount — for you to review and enter yourself. ScholarDuck is not a FAFSA preparer: we never file a FAFSA or submit anything to studentaid.gov on your behalf.
A small number of scholarships are restricted to specific groups — for example, by gender identity, race or ethnicity, disability status, LGBTQ+ identity, tribal enrollment, or immigration status. If you choose to tell us about any of these, we use it for exactly one purpose: confirming whether you actually qualify for a scholarship that requires it.
Answering is always optional and always self-reported. We ask about these one at a time, only when real scholarship money actually depends on the answer, and every question can be skipped — a skipped question is simply left unanswered, never held against you. You can review, change, or clear any answer at any time, and nothing about your matches depends on answering unless a specific restricted scholarship requires it.
This information is kept apart from the rest of your profile, in its own access-restricted store that ordinary product code cannot read — only the matching process that needs a specific answer, and the account-deletion process described below, can reach it. It is never used in essay or resume drafting, never shown to any scholarship provider, and never shared with a parent-linked profile. Deleting your ScholarDuck account deletes this information on the same 90-day schedule described below.
ScholarDuck is not for children under 13, and we do not knowingly collect their information. At signup, we ask for your birth month and year — that is all we collect about your age. Signups indicating you are under 13 are refused. If you indicate an age of 13 to 15, your account works normally, but AI features stay locked until a parent or guardian is linked to your account, as described above under "Family visibility, share links, and the browser extension." We never enable session recordings, described above under "Product analytics," for anyone under 18. If we learn we hold data of a child under 13, we will delete it; parents or guardians can contact [email protected] about any minor's data at any time.
We are mindful that most ScholarDuck users are teenagers. We collect only what the service genuinely needs, we never sell it, and you can delete your account and its data at any time, as described below.
We use a small set of service providers to run ScholarDuck, each only for its stated purpose:
Supabase — database, authentication, and file storage. Google Firebase — website hosting. Anthropic — AI processing as described above. PostHog — product analytics and session recording inside the app (only after you consent), plus a limited cookieless beacon on our public marketing homepage, both as described above. Stripe — payment processing. Brevo — transactional email. This already includes account email such as confirming your address and resetting your password; other notifications, such as deadline reminders, will use it as those features launch.
ScholarDuck's public marketing homepage — before you've made any consent choice — runs a basic, cookieless PostHog beacon: it records that the page was visited and whether the invite-code form was submitted (never the code itself), sets no cookies, and never identifies you. The login, signup, and password-reset screens carry no analytics of any kind. We do not use Google Analytics anywhere. This homepage beacon is unrelated to the consent-gated, in-app PostHog analytics (including session recording) described above.
We may also disclose information if required by law, or to protect the rights, safety, and security of users and the service. If Northslate LLC is ever part of a merger or acquisition, your information may transfer with the business; this policy would continue to apply until replaced with notice.
ScholarDuck uses cookies and browser storage only for the purposes below — never for advertising, and never to track you across other websites.
Supabase sets an authentication cookie (or, on some browsers, local storage) so you stay signed in between visits; this is required for the product to work and isn't optional.
PostHog sets cookies inside the app once you've consented to analytics, as described above; the cookieless public-page beacon (also described above) sets no cookies at all.
ScholarDuck stores a small number of non-sensitive preferences in your browser's local storage — for example, a referral code you arrived with and your light/dark theme choice — so you don't have to re-enter them each visit.
The official browser extension stores its connection token in its own extension storage (chrome.storage), on your device only, as described above under "Family visibility, share links, and the browser extension."
You can delete your account from the account page at any time. Deletion takes effect immediately in the product; data is retained for 90 days (so mistaken deletions can be reversed and legal obligations met) and then permanently purged, including uploaded files, extractions, voice profiles, drafts, exports, and any page captures you've submitted. Because ScholarDuck and GrantDuck share one account, deleting your account removes your data from both products on the same schedule. A small amount of aggregate usage data (which features were used, and when) is retained past the 90 days for product analytics and cost accounting, but it is no longer linked to your account once your account is deleted.
You can also delete individual items — writing samples, voice profiles, uploads, and essay drafts — without deleting your account. Deleting a draft removes its full version history as well, not just the current text.
Your data is protected by per-account access rules enforced in the database itself (row-level security), authenticated and encrypted connections, and server-side authorization checks on every operation. Access credentials and API keys are stored as managed secrets, never in code. No system is perfectly secure, but security has been part of ScholarDuck's design from the first migration, not an afterthought.
The ScholarDuck browser extension reads the contents of the page you are viewing only when you click Capture. Captured page content — including application form questions — is sent to ScholarDuck, processed to extract scholarship details, and stored (including a cached copy of the page text) so we can verify the listing. Captured scholarship information joins the shared catalog under the Terms' Contributions section. Your account is recorded internally as the contributor for verification and abuse-prevention; other users never see your identity.
Before that text ever leaves your browser, and again on our servers, we strip anything that looks like an email address, phone number, or Social Security number; the feature is disabled entirely on studentaid.gov, same as the rest of the extension's page-capture behavior described above.
A captured scholarship's own facts (name, provider, amount, deadline, links) can appear in the catalog right away, held for our own staff review, and any essay question it found is labeled as reported by a student until we confirm it — it is never used to change an existing, already-verified listing automatically. If a capture turns out to confirm or improve a scholarship entry, we may extend the submitting student's monthly usage as a thank-you; the in-app notification for this only says your usage was extended, not by how much, so you'll see the effect in what you're able to do rather than a specific number in the message itself.
You can access, correct, export (copy/download from the product), and delete your information as described above. Depending on where you live, you may have additional legal rights — such as the right to know what we hold about you or to request deletion — and we honor reasonable requests regardless of jurisdiction. Write to [email protected] and we will respond promptly.
California residents may exercise rights to know, delete, and correct their personal information. We do not sell or "share" personal information as those terms are defined in the CCPA, and we do not use or disclose sensitive personal information beyond the purposes described in this policy. Residents of Virginia, Colorado, Connecticut, and other states with similar laws may appeal a refused request simply by replying to our response, and may contact their state attorney general if they remain unsatisfied. Canadian users may raise concerns with us at [email protected] and, if unresolved, with the Office of the Privacy Commissioner of Canada.
If we materially change this policy — new data types, new subprocessors, new uses — we will post the update with a new effective date and ask you to review and accept it before continuing. The current version is always available at this page.
Northslate LLC (d/b/a ScholarDuck) [email protected]
Questions? Email [email protected].