Privacy Policy
Effective date: October 2, 2026
collegedata.fyi is designed to work without accounts, logins, or saved student profiles. You can browse school pages, read source documents, use the public API, and use the current planning tools without submitting personal information to us.
What we collect
We use Vercel Analytics to understand anonymous, aggregate site usage: things like page views, referrers, browser type, device type, general location, and which site features are used, such as school search, source links, downloads, copy buttons, and recipe controls. This helps us see which pages are useful and whether the site is performing reliably.
Vercel Analytics does not give us a list of named visitors, and we do not send locally entered GPA, test scores, intended majors, search terms, or share codes as analytics properties. We do not use analytics to build student profiles or sell audience data.
What we do not collect
- No account information, because there are no accounts.
- No student profile database.
- No application lists, grades, test scores, essays, or financial details.
- No sale of personal data to schools, lenders, advertisers, or data brokers.
Public API and server logs
Requests to the website and public API may create ordinary hosting, database, and security logs. We use those logs to operate the site, debug problems, and protect the service from abuse. We do not use them to identify students or build marketing profiles.
We also count how the archive and API are used, from the logs our database host keeps for 90 days. A scheduled job reads those logs and stores only totals: requests per hour by type of client, and unique downloads per school per day. To count a download once per visitor, the job matches IP address and browser user agent inside the log query. It does not store IP addresses or full user agents.
For automated API clients (scripts and bots, not browsers), we keep a short code made from the IP address and user agent with a random key that changes every day and is deleted two days later, so the code can't be traced back or linked across days. Next to it we keep the client's self-declared name, the network it came from (such as a cloud provider), and its country. We keep these hourly client counts for 400 days to spot abuse and heavy users.
If we publish anything from this data, it will be aggregate counts only, such as total downloads per day and per school per month, with small per-school numbers hidden. We will never publish anything about an individual visitor or client.
Questions
This project is open source. If you have a privacy question or want to report an issue, please open an issue on the GitHub repository.