Skip to main content

Legal

Privacy Policy

Last updated September 15, 2026

The short version: we collect what we need to run the course and Path 360, keep your work so you do not lose it, and process your payment. Your records are only shared with someone else when you choose to share them. We do not sell your information to anyone.

What we collect

Account information: your name and email address, provided when you sign in. Authentication is handled by our platform provider; we do not create or store passwords ourselves.

Policy acceptance: the Terms and Privacy Policy versions you accepted, the acceptance time and method, and your confirmation that you meet the minimum age requirement and reviewed the guardian notice.

Purchase records: which plan you bought, payment status, amount, promotional code when applicable, and access status. Card details are handled by Stripe and do not reach our servers.

Course progress: modules and lessons opened, quiz attempts, scores, and completion status. The free Career Path Finder keeps your individual quiz answers only while the quiz page is open. If you choose Save my shortlist, the resulting profile, matches, reasons, and tradeoffs are saved in your browser so you can reopen them; your raw answers are not saved there. If you deliberately continue from the quiz while signed in, a summary of the resulting career matches may be saved to your account, but not your raw quiz answers.

Profile details you choose to enter in Path 360: preferred name, phone number, city and state, profile photo, school name and type, graduation year, academic year, intended or current major, GPA, career interests, and a career goal statement.

Records you build in Path 360: experiences and logged hours, goals and tasks, milestones, opportunities and applications, resume entries, achievements, education, skills and languages, saved resources, and written reflections — including any you mark private.

Files you upload: documents such as certifications and transcripts, along with their file name, type, and size.

Information about other people that you enter yourself: supervisor names, titles, emails and phone numbers on an experience, and contacts you save for outreach. Please share only what you need to, and only what you have a reason to hold.

Ask Path360 data: your questions, saved conversations, generated recommendations, and the relevant profile context sent with a request.

Optional first-party usage analytics: page paths, broad page groups, calls to action, selected plan, quiz start and completion, and the quiz's broad top-match group when you allow analytics. We do not send your individual quiz answers, documents, reflections, or contact information in these events. Signed-out consent is stored in your browser; if you later sign in, that choice may be saved to your account.

Checkout attribution: the campaign source, medium, campaign name, content label, search term, first landing path, and external referrer host when those values are available. These fields are sanitized, held in the same browser tab, and attached to the checkout and purchase record if you choose to buy. Full page query strings are not recorded as analytics events.

Where it is stored

Most of what you enter is stored on our servers so it is still there when you sign in from another device — this includes your profile, experiences, hours, goals, documents, and reflections.

A few standalone tools keep progress only in your browser. If you choose Save my shortlist, the free Career Path Finder stores that result in local browser storage; it does not persist your raw quiz answers. Your analytics choice uses local storage and checkout attribution uses same-tab session storage. Clearing browser data resets these browser-only values and does not delete account records.

What we do with it

Give you access to what you paid for, and keep your progress where you left it.

Answer support questions and process refunds or billing corrections.

Improve the material and product when you allow optional usage analytics or product-improvement data in the analytics banner or Privacy Settings.

Measure which campaigns and referral sources lead to completed purchases, reconcile the amount actually paid, and diagnose failed checkout steps.

We do not sell your personal information. We do not share it with advertisers. We do not use your reflections or uploaded documents for advertising, and we do not publish them.

When your information leaves the platform

Sharing a report happens only when you choose it. Reports are downloaded as PDFs or opened in your email app; you are responsible for attaching the PDF and confirming the recipient before sending.

Privacy settings let you control what any report includes — contact information, profile photo, supervisor names and contact details, unverified hours, and private reflections can each be excluded. Review these before sharing anything with a recommender or admissions office.

Transactional communication: Stripe may send payment receipts, and we may send account, security, support, or notification messages needed for features you enable.

Ask Path360 sends your question and relevant profile context through Base44's AI integration to generate a response. Conversations and recommendations are then stored with your account until you delete them or close the account.

Who else touches your data

Base44 — hosting, authentication, file storage, database, app-level analytics events you allow, and platform-level operational logs and activity signals used to run and secure the service.

Stripe — payment processing. Their privacy policy governs your card details.

Email delivery providers — used for transactional messages, deletion-request notifications, support, and partnership inquiries.

AI service providers available through Base44 — used when you deliberately submit a request to Ask Path360.

Each provider handles information under its own contractual terms and privacy policy. We limit the information sent to what is needed for the requested service.

Our own staff: administrators can view student accounts, progress, and support history in order to run the platform and answer support requests, and can attach internal notes to an account. Administrative actions are logged.

Do not enter patient information

Path 360 is not designed to store protected health information. Do not enter patient names, medical record numbers, dates of birth, addresses, phone numbers, patient images, or case details that could identify a patient.

When documenting clinical, shadowing, volunteering, scribing, or research experience, describe your role and what you learned without including patient-identifying information.

Students under 18

You must be at least 13 years old to create an account. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has given us information, contact us and we will delete it.

Account creation requires confirming that you are at least 13. If you are under 18, review this policy and the Terms with a parent or guardian before creating an account, purchasing, uploading documents, or sharing a report.

If your school or program provided your access, records we hold may also be governed by an agreement with that institution, and that agreement may give your school rights over those records.

Your choices

Download your data: Path 360 → Settings → Data and Account generates a JSON file containing the selected profile, records, and settings and downloads it immediately.

Delete your account: request it from Path 360 → Settings → Data and Account. The request is held for 14 days so you can cancel it. Our team is notified and reviews the request for processing after the cancellation period. You can also use the Contact page. Some purchase records may be retained where tax, accounting, fraud-prevention, or dispute-resolution rules require it.

Choose analytics: signed-out visitors can allow or decline optional app-level analytics in the on-site banner. Signed-in users can change Basic Usage Analytics in Privacy Settings. Purchase, checkout, campaign-attribution, security, and fraud-prevention records are kept separately because they are needed to operate access, reconcile payments, measure campaigns, prevent fraud, and address billing disputes.

You can review your report sharing history and delete individual experiences, documents, reflections, and contacts at any time.

Progress stored in your browser can be cleared through your browser settings.

Deleting your account does not automatically refund unused access; see the Terms for that.

How long we keep things

Account and purchase records are kept while your account exists and afterwards only as long as needed for tax, accounting, and dispute-resolution purposes.

Content you create stays until you delete it or close your account.

Report-sharing history is kept with your account so you can review when and where you chose to send a report.

Optional app-level analytics is controlled by your browser choice and Privacy Settings. De-identified or aggregated reporting already produced from earlier activity may remain after you turn analytics off. Same-tab checkout attribution ends with the browser session, while attribution attached to a purchase follows the purchase-record retention period.

Security

Access to account records requires signing in. Base44 provides the hosting, authentication, database, and file-storage infrastructure used by the app.

We use account-level and role-based access rules for application records. Administrative access may be used for support, safety, billing, and platform operations.

No service can promise perfect security. Use a strong, unique password and do not upload patient information or documents you do not need to store online.

If you believe you found a security vulnerability, suspicious account activity, or unauthorized access, use the Contact page and choose Security Concern so the report can be routed appropriately.

Changes

If we change this policy materially we will update the date at the top and, where the change is significant, notify account holders by email.

Questions about your data

Use the Kraena Pre-Health contact form for privacy, export, correction, or deletion questions.