Privacy Policy
Last updated September 30, 2026
This Privacy Policy explains how Prof Insider (“Prof Insider,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use profinsider.app and our related services (the “Service”). It covers the people who visit or use the Service. It also covers the professors, researchers, and other staff whose professional information appears in our database; see Information about researchers. We’re based in Ontario, Canada, and we’re responsible for the personal information we control.
At a glance
- We use your profile and resume to match you with researchers and write your emails.
- When you connect Gmail, we send only the emails you approve or schedule. We don’t read the rest of your inbox.
- We don’t sell your personal information or use it for advertising.
- Your resume, emails, and Google data aren’t used to train non-personalized AI models, by us or by our AI providers.
- You can disconnect your email, get a copy of your data, correct it, or delete it at any time.
1. Information you give us
- Account information: your name and email address. If you sign in with Google, we also receive your basic Google profile (name, email address, and profile picture).
- Profile: your level of study, research fields and topics, interests, goals, and anything else you add to your profile.
- Resume: we read the resume you upload and keep the details we extract from it, such as education, experience, skills, and research interests, along with its file name. Resumes often contain contact details and other personal information. Please leave out anything you don’t want us to process, such as government ID numbers.
- Outreach content: the professors you save or add to lists, your instructions to the drafting agent, your drafts, and the emails you send or schedule (recipient, subject, body, and timing).
- Payment information: when you buy a plan, Stripe collects your card details. We receive only limited information, such as your plan, billing history, card brand, last four digits, expiry date, and the billing location needed for taxes.
- Communications: messages you send us, such as support requests, feedback, Reply Guarantee claims, and survey answers.
2. Information from your connected email account
If you connect an email account, we collect:
- Connection details: the email address, the provider, the permissions you granted, and whether the connection is still active. The credentials that give access to your account are held by our email infrastructure provider, Nylas, and are never sent to your browser.
- Emails sent through the Service: a record of each email we send or schedule for you, including the recipient, subject, body, send time, whether it was sent, scheduled, cancelled, or failed, and message identifiers.
- Replies (only if you turn on reply tracking): the messages in threads started through the Service, including the sender, date, subject, and content of replies. We use them to show you responses and track your outreach.
We don’t access your other emails, contacts, calendar, or files. The Google user data section adds further commitments for Gmail.
3. Information collected automatically
- Device and log information: IP address, browser and operating system, referring page, the pages and features you use, timestamps, and error logs.
- Cookies and local storage: see Cookies and local storage.
- We don’t currently use third-party analytics or advertising tools. If we add analytics, we’ll update this policy before we do.
4. How we use information
- To provide the Service: to create and secure your account, match you with researchers, draft and edit emails, send and schedule the emails and follow-ups you approve, show replies and your outreach history, and handle payments and Reply Guarantee claims.
- To communicate with you: to send service messages, answer your requests, and, with your consent, send marketing emails.
- To keep the Service safe: to prevent fraud, spam, and abuse, to enforce sending limits and our Terms, and to honour researchers’ requests not to be contacted.
- To improve the Service: to understand how features are used and fix problems, using aggregated or de-identified information wherever we can.
- To produce aggregated insights: to calculate statistics from activity across the Service, such as how often professors in a field reply or how quickly they typically respond, which we use to improve matching and show general signals. These statistics never include the content of anyone’s emails, don’t identify you, and never use information we receive through your Gmail permissions, such as replies found by reply tracking.
- To meet legal obligations: to comply with the law and protect our rights and the rights of others.
We’ll ask for your consent before using your personal information for a new purpose this policy doesn’t describe.
5. Sensitive information
We don’t ask for sensitive information such as your race or ethnicity, health or disability, religion, sexual orientation, immigration status, or financial situation. Your resume or emails may include some of it anyway. If they do, we use it only to provide the Service to you. We never use it for advertising or to make assumptions about you, and we never sell it.
6. Google user data
This section explains how we handle information we receive from Google when you sign in with Google or connect Gmail.
What we access and why
- Google sign-in (your name, email address, and profile picture): used to create your account and sign you in.
- Permission to send email (Gmail’s send permission): used only to send emails you approve or schedule, including the follow-ups you turn on. This permission lets us send email; it doesn’t let us read your inbox.
- Reply tracking (if we offer it and you turn it on): we’ll ask separately for the additional permission it needs and explain it at that time. We’ll use it only to find and show replies in threads started through the Service. You can decline it and keep sending.
Limits on how we use it
- We use Google user data only to provide and improve the features described above, which you can see and use in the Service. We don’t use it to calculate the aggregated statistics described in How we use information.
- We don’t sell Google user data, and we don’t use it for advertising, including retargeting or interest-based ads.
- We don’t use it to decide creditworthiness or for lending.
- We don’t use Google user data, including data from Google Workspace APIs such as Gmail, to develop, improve, or train non-personalized AI or machine learning models, and our AI providers can’t either.
- We transfer it only as needed to provide these features (to our email infrastructure and hosting providers, and to our AI provider when you ask the agent to work with a message), for security, to comply with the law, or as part of a merger or acquisition with your prior consent.
- Our staff don’t read it unless you give us permission for specific messages (for example, in a support request), it’s needed for security, such as investigating abuse, it’s required by law, or it has been aggregated and anonymized for internal operations.
Prof Insider’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Removing access
You can disconnect Gmail at any time in Settings, or remove Prof Insider’s access at myaccount.google.com/permissions. When you disconnect in Settings, we delete the access grant held by our email infrastructure provider and cancel any emails that haven’t been sent. If you only remove access in your Google Account, also disconnect in Settings to make sure scheduled emails are cancelled. Records of emails you already sent stay in your outreach history until you delete them or your account.
7. AI processing
We use AI models from third-party providers to match you with researchers, summarize their work, and draft and edit emails. Drafting requests go through OpenRouter, which passes them to the provider hosting the AI model (currently DeepSeek models). For each task, we send only what the task needs. That can include your profile, relevant resume details, the researcher’s public profile, your instructions, the draft, and, if you ask the agent about a reply, that reply.
- We use only AI providers that process this data on our behalf and aren’t allowed to store it for training or to train their models on it.
- We don’t use your resume, drafts, emails, or Google user data to develop, improve, or train non-personalized AI models.
- We don’t use AI to make decisions that have legal or similarly significant effects on you. Matches and drafts are suggestions you choose whether to use.
8. Information about researchers
If you’re a professor, researcher, or other staff member listed by a university, this section explains how we handle information about you.
What we collect
We collect professional information that you or your institution have published, and metrics that scholarly indexes such as OpenAlex calculate from your publications:
- your name, the titles and positions listed for you, and your institution and department;
- your work email address and other business contact details, such as your office phone number and office location;
- your profile page, including a copy of its text, and the research interests and descriptions it lists;
- links listed on your profile, such as Google Scholar, ORCID, ResearchGate, LinkedIn, X, GitHub, Bluesky, Mastodon, and YouTube accounts, your CV, and lab or personal websites;
- employment details from your public ORCID record; and
- your publications (titles, dates, venues, abstract excerpts, and topics) and publication metrics, such as publication and citation counts and h-index.
Where it comes from
University websites, including department faculty pages and the research-profile portals universities publish (some of which are hosted by third-party providers); your own public profile pages; and the open scholarly databases OpenAlex and ORCID. We use automated tools to collect this information, including web search and crawling services such as Exa, which return results from their own indexes and fetch pages for us. We use AI models from TypeSafe, which process the information on our behalf, to check it (for example, whether an email address belongs to you) and to categorize it (for example, tagging your research fields from your recent publications).
What we derive from it
We derive research field tags from your recent publications. As the Service develops, we may also derive short summaries of your research, match scores for students, signals such as whether a lab may be recruiting, and general reply patterns, such as typical response times, from aggregated and de-identified outreach activity. Reply patterns never use information received through students’ Gmail permissions.
Why we use it
To help students find researchers whose work fits their interests and contact them about academic opportunities. That’s the same purpose for which your professional contact details are published.
What students see and send
Users of the Service, including paying subscribers, see your professional profile and the information we derive from it. Students who contact you do so from their own email accounts, and they’re responsible for what they send. Our Outreach rules require genuine, individual, academic inquiries and require students to stop when asked. If a student has turned on reply tracking, we process your reply to their email on their behalf so they can see it in the Service.
Your choices
Email privacy@profinsider.app with the subject “Researcher request” to see what we hold about you, correct it, remove your profile, or mark yourself as “do not contact.” We’ll act on your request within 30 days. A “do not contact” flag stops students from emailing you through the Service. To make sure your request keeps working, we keep your name and email address on a suppression list.
We don’t provide researcher information to advertisers or data brokers, and we don’t let users export it in bulk.
11. How long we keep information
- Account, profile, and resume: while your account is open.
- Emails sent through the Service, and replies: while your account is open, including after you disconnect your email account, so you can see who you’ve contacted.
- Email access grant: deleted when you disconnect your email account or delete your Prof Insider account.
- Billing records: as long as tax and accounting laws require, generally six years in Canada.
- Logs: for a limited period, for security and debugging.
- Researcher information: while it’s relevant to the Service, or until the researcher asks us to remove it (apart from the suppression list described above).
- When you delete your account: we disconnect your email account, cancel scheduled emails and your subscription, and delete your personal information within 30 days. We keep only what we need to meet legal, tax, dispute, or fraud-prevention obligations. Copies in backups are deleted as those backups expire.
12. Security
We use administrative, technical, and physical safeguards suited to the sensitivity of the information. They include encryption in transit, access controls, restricted database access, and leaving email access credentials with our email infrastructure provider, so they never reach your browser. No method of storage or transmission is completely secure, so we can’t guarantee absolute security. If a breach creates a real risk of significant harm, we’ll notify you and the authorities as the law requires.
13. Your rights and choices
You can:
- access your personal information and get a copy of it in a structured, commonly used format;
- correct it, by asking us or, where the app lets you, by editing it yourself;
- delete it, by deleting your account in Settings or by asking us;
- withdraw consent, for example by disconnecting your email account, turning off reply tracking, or unsubscribing from marketing emails (some features may stop working); and
- complain to us or to a privacy regulator.
To make a request, email privacy@profinsider.app from the email address on your account. We’ll verify your identity and respond within 30 days. If we need more time where the law allows it, we’ll tell you why. Requests are usually free.
Canada
If you’re not satisfied with our response, you can contact the Office of the Privacy Commissioner of Canada (priv.gc.ca). Quebec residents can contact the Commission d’accès à l’information du Québec, and residents of Alberta and British Columbia can contact their provincial privacy commissioner.
United States
Depending on your state, you may have the right to know what personal information we collect, use, and disclose; to access, correct, delete, or get a portable copy of it; to opt out of its sale, sharing for targeted advertising, or profiling; and to limit how we use sensitive information. We don’t sell or share users’ personal information for targeted advertising, and we use sensitive information only to provide the Service. You can use an authorized agent, and we won’t discriminate against you for exercising your rights. If we deny your request, you can appeal by replying to our decision. If you’re still not satisfied, you can contact your state attorney general.
14. Children and teens
The Service isn’t directed to children under 13, and we don’t knowingly collect their personal information. If you believe a child under 13 has given us personal information, contact us and we’ll delete it. Users who are 13 or older but under the age of majority need a parent or guardian to agree to our Terms.
15. Where information is processed
We’re based in Canada, and we offer the Service to people in Canada (outside Quebec) and the United States. Our service providers store and process information in the United States and other countries where they operate. There, it’s subject to local laws and may be accessible to courts, law enforcement, and national security authorities. We use contracts and other measures to protect personal information that our providers handle for us.
16. Changes to this policy
We may update this policy. For material changes, we’ll notify you by email or in the Service before they take effect. Where the law requires it, we’ll ask for your consent before using information we already hold in a significantly different way. The date at the top shows when the policy last changed.
17. Contact us
Our Privacy Officer is responsible for how we handle personal information. Contact them at privacy@profinsider.app, or write to the Privacy Officer, Prof Insider, [Business mailing address], Ontario, Canada. For everything else, email support@profinsider.app.