Privacy Policy

Last updated May 4, 2026

Welcome to Edura (https://www.getedura.com). This Privacy Policy explains how Hamilton Consulting LLC("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our platform and services. By using Edura, you agree to the practices described in this policy.

This Privacy Policy governs all language versions of our platform (English and Chinese). In the event of any conflict between translated versions, the English version prevails.

Short version

  • We collect account, education profile, usage, payment status, and user-generated content needed to operate Edura.
  • AI messages may be processed by third-party AI providers to deliver assistant features.
  • Analytics and replay tools are controlled by cookie consent in regions that require opt-in.
  • We do not sell personal information.
  • You can request access, correction, deletion, or export of your personal data.

1. Information We Collect

1.1 Account Information

When you create an account, we collect your email address, display name, and password. Authentication is managed through Supabase. If you sign in via Google OAuth, we receive your name, email address, and profile picture from Google.

1.2 Onboarding and Education Profile

During onboarding, you may provide information about your user type (student, educator, parent, professional), school or institution, education system, grade level, graduation year, and educational interests. This data is used to personalize your experience.

1.3 Student Profile and Questionnaire Data

You may optionally complete profile questionnaires that collect information about your academic interests, career goals, skills, and preferences. This information powers personalized recommendations and the AI assistant.

1.4 User-Generated Content

We collect content you create on the platform, including comments, reviews, blog posts, listing submissions, and chat messages with the AI assistant.

1.5 AI Conversation Data

When you use our AI assistant, your messages and the assistant's responses are processed by third-party AI providers (OpenAI and Anthropic). We store conversation history to provide continuity in your interactions. Embeddings (numerical representations) of knowledge documents may also be generated and stored.

1.6 Location Data

If you use location-based features (e.g., finding nearby schools or listings), we process location data through Google Places API and Mapbox. We do not persistently track your real-time location.

1.7 Payment Information

If you subscribe to a Pro plan or purchase listing promotions, payment processing is handled entirely by Stripe. We do not store your credit card number or full payment details on our servers. We receive transaction confirmations and subscription status from Stripe.

1.8 Automatically Collected Data

We automatically collect certain technical information including IP address, browser type, device information, pages visited, and referring URLs. We use PostHog for product analytics and session replay, and Sentry for error monitoring (see Section 5). For visitors in the European Union, United Kingdom, EEA, Switzerland, China, and California, both products are gated behind explicit opt-in consent via our Cookie Consent page.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Personalize your experience, including AI-powered recommendations
  • Process transactions and send related communications
  • Send transactional emails (account verification, password resets, notifications) via Resend
  • Monitor and prevent fraud, abuse, and security threats
  • Analyze usage patterns to improve the platform (aggregated and anonymized where possible)
  • Comply with legal obligations
  • Enforce our Terms of Service and Acceptable Use Policy

3. Third-Party Service Providers

We share your information with the following third-party service providers who process data on our behalf:

Provider
Purpose
Data Shared
Supabase
Stores application data, manages authentication, and enforces row-level security
Account data, education profile data, user-generated content, authentication metadata
Vercel
Hosts the Edura web application and serves pages, assets, and server-rendered routes
Request metadata, IP addresses, logs, deployment diagnostics
Stripe
Processes subscriptions, AI credit purchases, listing promotions, invoices, and fraud checks
Billing contact details, payment metadata, transaction records
OpenAI
Processes prompts and context for AI assistant and generation features
AI messages, conversation context, user-provided educational context
Anthropic
Processes prompts and context for AI assistant and generation features
AI messages, conversation context, user-provided educational context
Sentry
Captures errors, stack traces, performance data, and error-triggered replay buffers
Error logs, IP address, account email when signed in, masked replay diagnostics
PostHog
Measures product usage, funnels, feature adoption, surveys, and accepted session replays
Pageviews, click events, distinct ID, account email when signed in, masked replay data
Google
Provides sign-in, location search, and optional file import integrations
OAuth profile data, location queries, imported file metadata and contents when connected
Mapbox
Displays maps and geocodes listing or user-provided locations
Location queries, map interaction metadata
Resend
Sends account, notification, invite, and service emails
Email addresses, message content, delivery events
Convex
Supports real-time interactions where enabled
Real-time interaction data and related account identifiers
Firecrawl
Extracts content from URLs submitted for AI or listing workflows
Submitted URLs and extracted page content
Microlink
Fetches public website metadata for listing display
Submitted public URLs and extracted website metadata

Each provider processes data in accordance with their own privacy policies and contractual commitments. See our Subprocessors page for regions, trust links, and review status.

4. AI Features and Data Processing

Our AI assistant is powered by OpenAI and Anthropic Claude. When you interact with the AI assistant:

  • Your messages are sent to these third-party AI providers for processing
  • Conversation history may be used to provide contextual responses
  • Embeddings (vector representations) of knowledge documents may be generated and stored to improve response relevance
  • AI providers may process your data according to their respective privacy policies and data processing agreements

We do not use your personal conversations to train AI models. For details on how AI providers handle data, please refer to OpenAI's and Anthropic's privacy policies.

5. Analytics and Session Replay

We use two products to understand how the platform is used and to diagnose issues:

  • PostHog — product analytics. Records pageviews, feature usage, funnel progression, and full session replays for accepted sessions. Used to understand how students, educators, and parents interact with the platform.
  • Sentry — error monitoring. Captures stack traces and a short replay buffer that is uploaded only when an error fires (buffer mode). We do not record full sessions in Sentry.

All session replays mask text input by default and block media (images, video) so sensitive content is not captured. For visitors in the European Union, United Kingdom, EEA, Switzerland, China, and California, both products are off until you accept analytics via our Cookie Consent page. For visitors elsewhere, both run by default and you can opt out at any time on the same page.

6. Data Retention

  • Account data: Retained for as long as your account is active. You can delete your account at any time via the /account section.
  • AI conversation history: Retained for the duration of your account unless you manually delete conversations.
  • Payment records: Retained as required by applicable tax and financial regulations (typically 7 years).
  • Error logs and session replays: Retained for up to 90 days.
  • Transactional email logs: Retained for up to 30 days.

Upon account deletion, we will remove or anonymize your personal data within 30 days, except where retention is required by law.

7. Your Rights

7.1 All Users

Regardless of your location, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Delete your account and associated data
  • Export your data in a portable format

7.2 EU/EEA Users (GDPR)

If you are located in the European Union or European Economic Area, you additionally have the right to:

  • Restrict processing of your personal data
  • Object to processing based on legitimate interests
  • Data portability
  • Withdraw consent at any time (where processing is based on consent)
  • Lodge a complaint with your local data protection authority

Our legal bases for processing under GDPR include: performance of a contract (providing our services), legitimate interests (improving our platform, preventing fraud), consent (where explicitly given), and legal obligations.

7.3 California Users (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Request deletion of your personal information
  • Opt out of the sale or sharing of personal information
  • Non-discrimination for exercising your privacy rights

We do not sell your personal information. To exercise any of these rights, contact us at support@getedura.com.

8. International Data Transfers

Edura is operated from the United States. If you access our platform from outside the United States, your data will be transferred to and processed in the United States. Our hosting (Vercel), database (Supabase), email (Resend), product analytics (PostHog, US region), error monitoring (Sentry), and AI providers (OpenAI, Anthropic) primarily process data in the United States.

For EU/EEA users, we rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework, where applicable, as appropriate safeguards for international data transfers. For more details, see our Data Processing Agreement.

9. Children's Privacy

Edura is intended for users aged 16 and older. We do not knowingly collect personal information from children under 16. If we discover that we have collected data from a user under 16, we will promptly delete that information. If you believe a child under 16 has provided us with personal data, please contact us at support@getedura.com.

10. Security

We implement industry-standard security measures to protect your data, including encryption in transit (TLS/SSL), secure authentication via Supabase, and row-level security (RLS) policies on our database. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Cookies and Consent

We use cookies and similar technologies. The full list of cookies, what they do, and the controls to accept or reject non-essential ones are on our Cookie Consent page. Visitors in the European Union, United Kingdom, EEA, Switzerland, China, and California must explicitly opt in before we run analytics; visitors elsewhere can opt out at any time on the same page.

12. Related Documents

This Privacy Policy should be read together with our:

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the platform after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

  • Email: support@getedura.com
  • Mail: Adam Hamilton