Privacy Policy
This policy explains what personal information EliteApply handles, why it is used, when it may be shared and the controls available to you.
Who is responsible and what this policy covers
EliteApply is the online service available at eliteapply.net, operated by Executive Precision Era, established in the European Union. Executive Precision Era is the controller of the personal data described here and can be reached at support@eliteapply.net.
This policy covers the public website, the authenticated workspace, billing, and messages you send to our support address. We have not appointed a data protection officer because we are not required to; privacy questions go to the address above and are handled by the operating team.
Scholarship providers, universities and third-party sites have their own privacy practices. Their policies apply when you leave EliteApply, submit an application to them or use their services.
Information we handle
The information processed depends on the features you use. You can browse public pages without creating an account; an account is required for the private workspace.
- Account and profile data, such as name, email, authentication state, avatar, timezone, consent choices and academic-profile details.
- Application data, such as opportunities, deadlines, requirements, tasks, reminders, status, notes and submission records.
- Content you provide, including drafts, stories, interview answers, documents, evidence and information about references.
- Collaboration and referee data, including invitation state, contact details you enter and material submitted through authorised workflows.
- Support correspondence and feedback you choose to send.
- Billing data if you buy a paid plan or tokens: plan, subscription and trial status, token purchases, amounts, currency and refund state. Card details are entered with our payment provider and are never received or stored by EliteApply.
- Technical and security data needed to deliver requests, diagnose failures and protect the service, such as correlation identifiers and request metadata processed by the API or hosting systems.
How we use information
We use personal information only for purposes connected to operating EliteApply, meeting our obligations to users, protecting the service and complying with law.
- Create and secure accounts, restore sessions and provide requested workspace features.
- Store, organise, export and delete application content at your direction.
- Send transactional messages such as email confirmation, password-reset and account-deletion codes.
- Provide support, investigate errors, prevent misuse and maintain service integrity.
- Record limited first-party product events to understand whether features work, without intentionally sending essays, references, passwords, tokens or codes as event properties.
- Record your product-update preference so that if we start sending them, we only send them to accounts that opted in; you can change that preference in privacy settings.
Legal bases for processing
Under the GDPR and equivalent laws we must have a legal basis for each purpose. If you are in the EU, EEA or UK, these are the bases we rely on.
- Performance of a contract (Art. 6(1)(b)): creating and running your account, storing and organising your application content, running the features you request including AI-assisted ones, handling collaboration and referee workflows, and providing paid plans and token purchases.
- Legitimate interests (Art. 6(1)(f)): keeping the service secure and available, preventing abuse and fraud, diagnosing failures, and measuring with limited first-party product events whether features work. You can object to processing based on legitimate interests at any time.
- Consent (Art. 6(1)(a)): optional product-update emails, and any feature we describe as optional at the point you switch it on. You can withdraw consent at any time without affecting processing already carried out.
- Legal obligation (Art. 6(1)(c)): keeping billing, tax and accounting records, and responding to lawful requests.
- Vital or public interests are not bases we rely on for this service.
Sensitive information in your documents
EliteApply does not ask for special-category data. Application material can still contain it — a disability statement in a personal essay, a medical circumstance in an extenuating-circumstances note, religious or political activity in a story, or ethnicity in a diversity-scholarship form.
Where you choose to upload or write such material, we process it to store and handle the content you asked us to handle, on the basis of your explicit consent (Art. 9(2)(a)), which you give by adding it and can withdraw by deleting it. We do not use it to profile you, target you or train models on your behalf.
Only include sensitive detail a provider actually requires, and remove it from drafts and uploads when it is no longer needed.
AI-assisted features
When you deliberately request an AI-assisted feature, EliteApply may process the prompt, selected application context and returned output needed to complete that request. Do not include information you are not entitled to use or confidential third-party material that is unnecessary for the task.
Generated suggestions are assistance, not decisions. You remain responsible for reviewing accuracy, protecting third-party privacy and deciding what becomes part of an application.
The AI Transparency Notice lists every AI-assisted feature, how AI-assisted content is labelled and what these features are not allowed to do.
Cookies and browser storage
The authenticated session uses an essential server-issued HttpOnly refresh cookie. Active access and ID tokens are kept in browser memory and are not written to localStorage or sessionStorage by the client.
Everything else the client stores is strictly necessary for a feature you started, or a display preference you set. This is the complete list:
- Refresh cookie (HttpOnly, server-issued) — keeps you signed in and lets a session be restored.
- ea_has_session (localStorage) — a flag telling the app a session may exist, so it knows whether to attempt a restore.
- eliteapply-sidebar-collapsed (localStorage) — your sidebar display preference.
- eliteapply-recent-searches (localStorage) — your recent searches in the workspace search, cleared from the search panel.
- eliteapply-reviewer-name (localStorage) — the display name you typed when commenting on a shared document, so you do not retype it.
- eliteapply.collaborator-invitation (sessionStorage) — an invitation value held only while you accept an invitation, removed when the flow completes or the browser session ends.
No advertising or cross-site tracking
There are no advertising pixels, no third-party analytics scripts and no cross-site behavioural advertising code in the frontend. Product events are first-party: they are sent to EliteApply's own API, are not stored in your browser, and pass a client-side filter that rejects sensitive-looking property names such as password, token, code, essay, reference, story and profile.
Because we set no non-essential tracking storage, there is no consent banner to click through. If that changes, we will ask for consent before setting anything new and update this policy first.
International transfers
EliteApply and its service providers may process information outside your country, including outside the EEA. Where that happens we rely on a European Commission adequacy decision for the destination country, or on the Commission's Standard Contractual Clauses together with an assessment of the transfer and additional technical and organisational measures where they are needed. For UK transfers we use the UK Addendum to those clauses.
You can ask us for information about the safeguards used for a particular transfer by emailing support@eliteapply.net with the subject “Privacy request”.
Retention and deletion
We keep account and application information while your account is active, because that is the service you asked for. When you delete the account, account and application data is removed from active systems.
Some records are kept longer for a specific reason: billing, tax and accounting records for the period required by law — our payment provider Stripe, as the merchant of record for these transactions, retains this record after account deletion under its own retention obligations, while our own local copy of your billing history is deleted with the account; security and abuse-related records for as long as needed to investigate and prevent recurrence; support correspondence while a matter is open and for a reasonable period afterwards; and copies inside encrypted backups until the backup rotates out of its retention window.
You can delete individual documents in the workspace. Privacy settings also let you request a JSON export and permanently delete the account after confirming a code sent by email. Export what you need before deleting — deletion is not reversible.
Security and data breaches
Access to the workspace requires authentication, uploaded documents stay blocked from protected workflows until they pass a security scan, and sensitive-looking values are kept out of product analytics. The Security page describes the controls the current product actually provides, without certification claims we cannot support.
If a personal data breach occurs, we assess it without delay. Where the law requires it we notify the competent supervisory authority within 72 hours of becoming aware, and where the breach is likely to result in a high risk to you we tell you directly and explain what happened and what to do. US state breach-notification laws are followed where they apply.
Your rights and how to use them
If you are in the EU, EEA or UK you have the rights below. Similar rights exist in many other countries. They can have lawful exceptions — for example we may keep data we need for a legal obligation or to defend a legal claim.
- Access a copy of your personal data, and information about how it is processed.
- Correct inaccurate data — most profile fields are editable in account settings.
- Delete your data, including permanent account deletion from Privacy & data settings.
- Portability: download a structured JSON export from Privacy & data settings.
- Restrict processing, or object to processing based on legitimate interests, including product analytics.
- Withdraw consent at any time, such as turning off optional product updates, without affecting processing already carried out.
- Complain to your national data-protection supervisory authority, or in the UK to the Information Commissioner's Office. You can complain in the country where you live, where you work, or where the issue arose.
Making a privacy request
Most requests can be completed in the product. For anything else, email support@eliteapply.net with the subject “Privacy request”. We may need to verify that the account belongs to you before acting, and we will not ask for more identifying information than the verification needs.
We answer within one month. If a request is complex or you have made several, we may extend that by up to two further months and will tell you why within the first month. Requests are free unless they are manifestly unfounded or excessive.
No automated decisions about you
EliteApply does not make decisions about you that produce legal effects or similarly significant effects and are based solely on automated processing, and it does not profile you for that purpose. Readiness, quality and interview scores describe a draft or a practice answer; they do not decide anything about you and are not shared with providers.
Admission, eligibility and funding decisions are made by scholarship providers and institutions under their own processes. The AI Transparency Notice explains what the AI features do and the limits they operate under.
United States privacy rights
This section applies if you live in a US state with a consumer privacy law, including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas and other states with equivalent laws.
The categories of personal information we collect, the purposes and the disclosures are described in the sections above. We disclose personal information only to service providers and contractors that process it on our behalf under contract. In the last 12 months we have not sold personal information, have not shared it for cross-context behavioural advertising, and have not disclosed it to third parties for their own purposes.
Application content can include sensitive personal information as California defines it. We use it only to provide the service you asked for and for the permitted purposes the law allows, never to infer characteristics about you — so there is nothing to limit under the “limit the use of my sensitive personal information” right, and we honour such a request as a restriction anyway.
Depending on your state you can ask to know, access, correct, delete or port your information, opt out of sale, sharing or targeted advertising, and appeal a refused request. Use the controls in Privacy & data settings, or email support@eliteapply.net with the subject “Privacy request”. An authorised agent may act for you with proof of authorisation. We will not discriminate against you for exercising these rights.
We treat a Global Privacy Control signal as an opt-out request, although we do not sell or share information in the first place. If we refuse a request, you can appeal by replying to our decision; we respond to appeals within the period your state's law requires and tell you how to contact your attorney general if you remain unsatisfied.
Children and younger users
EliteApply is not directed to children under 13 and they may not create an account. We do not knowingly collect personal information from them. Where the law of an EU or EEA country sets a higher age for consenting to online services — 14, 15 or 16 depending on the country — that higher age applies, and below it a parent or guardian must authorise the account.
If you are under the age at which you can enter a binding agreement where you live, a parent or legal guardian must review and authorise your use.
If you believe a child under 13 has provided personal information, contact support@eliteapply.net so we can investigate, delete the data and close the account. A parent or guardian can make that request directly.
Changes and contact
We may update this policy when the product, providers or legal requirements change. Material changes will be identified by a new effective date and, where appropriate, an in-product or account notice before they take effect.
For privacy questions or requests, email support@eliteapply.net with the subject “Privacy request”. Executive Precision Era, operating EliteApply at eliteapply.net, is the controller and the point of contact for this policy.