Privacy Policy

How AbroadQ handles your data.

This policy explains the information we collect, how we use it, and the controls available for export, deletion, audits, evidence, and account support.

Last updated: July 13, 2026. This policy is written for the current AbroadQ product and may be updated as payment, support, AI, or provider integrations change.

Who operates AbroadQ

AbroadQ.com and the AbroadQ web application are operated by nan tech llc. nan tech llc is responsible for handling personal data as described in this Privacy Policy.

For privacy questions, rights requests, grievance redressal, or account concerns, contact support@abroadq.com.

Information we collect

nan tech llc collects the information you provide when you create an account, complete the questionnaire, save profile details, use the screener, upload evidence status information, generate route readiness, run simulations, or unlock audits.

This may include account email, age band, citizenship, current country, target countries, education history, work history, language scores, immigration history, cautions, sensitive planning notes you choose to provide, evidence checklist progress, uploaded files, audit content, payment records, support requests, consent history, product-event analytics if you opt in, and cookie-free site traffic analytics.

Meta lead forms and draft profiles

If you submit an AbroadQ Meta lead form, we may receive route-planning details such as name, email, phone, current country, destination, planning goal, and timeline. We use those answers to create a draft profile and provide a secure claim path.

Meta lead forms should not request passwords, usernames, passport numbers, government ID numbers, bank details, criminal history, health information, race or ethnicity, religion, or similar sensitive information. Do not include those details in free-text lead form answers.

A Meta lead form does not create a full AbroadQ account by itself. You must claim the draft profile through Facebook, Google, or verified email before it is attached to an account.

Sensitive planning details

Some planning details may be sensitive, including passport or identity evidence, refusal history, immigration history, legal cautions, medical cautions, family details, financial details, and uploaded documents.

Only provide sensitive planning details when they are relevant to your planning. Do not upload information about another person unless you are authorized to use it for your planning.

How we use information

We use your information to provide pathway screening, deterministic readiness scoring, evidence gap tracking, what-if simulations, source-backed audit generation, account support, abuse prevention, product analytics, and service improvement.

Scores and audits are generated from user-provided information, stored rules, source notes, and deterministic calculations. They are planning tools and do not represent an approval prediction.

Legal basis for processing

Where applicable privacy law requires a legal basis, we process account, profile, route, evidence, audit, and payment information to provide the service you request, perform our agreement with you, keep the service secure, respond to support and legal requests, and improve product reliability.

Document extraction is processed when you upload files for evidence, profile prefill, or review workflows so we can provide the service you request. Optional product analytics, marketing tracking, and optional marketing email are based on your consent where required. You can withdraw optional consent for future processing from Privacy Choices or by contacting us.

Some records may be processed or retained for legitimate interests such as security, fraud prevention, service debugging, audit integrity, payment dispute handling, and legal compliance.

Documents and uploaded files

Document uploads, when used, are stored in private storage and are associated with your profile. The application may create time-limited signed links when you view or manage files.

Do not upload passwords, government portal credentials, forged documents, or documents you are not authorized to use. Uploaded files are handled separately from generated audits and payment receipts.

When you upload a document for evidence or profile prefill, AbroadQ may use local text extraction or a configured AI extraction provider to extract visible planning fields for your review. Extracted fields are not treated as verified unless you review or confirm them. Raw OCR or AI text is not stored by default; reviewed fields, document status, and extraction metadata may be stored.

Audits, scores, and simulations

Generated audits, score runs, score factors, gate results, main review items, missing-input prompts, simulations, roadmap tasks, and source freshness metadata may be stored so you can review a stable result later.

If you update your profile, newer score runs may differ from older audits because your inputs, source freshness, or rule configuration may have changed.

Readiness scores, route rankings, scholarship signals, roadmap tasks, and what-if results are automated planning outputs. They do not produce legal, visa, admission, job, scholarship, or permanent residence decisions and should not be treated as final eligibility advice.

Payments and provider records

When you unlock a paid audit, we store payment-related records such as amount, status, provider reference, audit reference, and provider event logs.

Payments are processed by the payment provider shown at checkout. We do not store full card numbers, bank passwords, or complete payment credentials. The payment provider processes payment details under its own privacy terms.

Analytics, cookies, and sessions

We record product events such as questionnaire completion, route plan views, audit generation, simulations, source clicks, and payment events to understand usage and improve the service.

We use Vercel Web Analytics to collect privacy-preserving, cookie-free site traffic metrics such as page views, referrers, approximate location, browser, operating system, and device category. This helps us understand aggregate site usage and is separate from account-level product-event analytics.

Non-essential account product analytics are based on your consent preference. Authentication and session management may use cookies or local browser storage through Supabase and the application framework. These are used to keep you signed in and operate the service.

Meta Pixel is loaded only after both product analytics and marketing tracking consent are granted. When loaded, Meta Pixel may send PageView and browser event data to Meta for measurement, ad attribution, and retargeting.

AI and source-backed processing

The scoring engine is deterministic. AI is not the source of truth for calculating scores. Future AI features may help explain results, draft summaries, or improve support workflows.

Document extraction runs as part of upload and prefill workflows. Extracted fields remain reviewable and editable before they are used as profile or evidence details. Source-backed notes and official-rule references are used to improve audit transparency.

Consent choices

We record consent history for Terms and Privacy acceptance, student privacy notice acknowledgement, optional product analytics, optional marketing tracking, and optional marketing email.

You can change optional consent choices from Privacy Choices or Settings. Withdrawing consent affects future optional processing; it may not undo processing already completed for account operations, payments, security, support, or legal compliance.

Service providers and sharing

We use service providers to operate the app, including authentication, database, private storage, document extraction for uploaded files, payments, and transactional email or support workflows.

Vercel provides hosting and Web Analytics services for site traffic measurement.

If you grant marketing tracking consent, Meta Pixel may receive PageView and browser event data for measurement, ad attribution, and retargeting under Meta's terms. You can withdraw this optional consent from Privacy Choices or Settings.

We do not sell uploaded documents or use uploaded documents for advertising.

We do not share passports, refusal history, criminal or medical cautions, questionnaire answers, uploaded files, or audit details with schools, recruiters, agents, lenders, advertisers, or unrelated partners unless you direct us to do so in a future sharing workflow or the law requires it.

Export, correction, deletion, and retention

You can manage privacy choices, receipt downloads, profile-owned data deletion, and full account deletion requests from Settings.

Full account deletion can be requested from Settings and completed through an admin flow. Some records may be retained, archived, anonymized, or detached where required for payment, audit integrity, security, fraud prevention, dispute handling, or legal compliance.

AbroadQ follows a minimization posture for sensitive planning data. Raw extraction text is not stored by default, and retention of optional analytics or extraction metadata should be periodically reviewed.

Your privacy rights

Depending on where you live, you may have the right to request access, correction, completion, updating, deletion, restriction, portability, objection, withdrawal of optional consent, or confirmation about whether we process your personal data.

You can also ask questions about automated planning outputs, request that optional marketing stop, or contact us about a privacy concern. We may need to verify your account before acting on a request.

Retention periods

Account and profile data are kept while your account is active or until deletion is completed, subject to legal and security exceptions.

Uploaded documents are kept until you delete them or request account deletion, unless retention is required for dispute, audit, security, or legal purposes.

Generated audits, score runs, simulations, roadmap history, and payment records may be retained to preserve paid audit integrity, explain previous outputs, handle refunds or disputes, and comply with applicable accounting or legal obligations.

Optional analytics and consent logs are kept only as long as needed for product improvement, consent proof, security, and compliance.

Security and access controls

We use Supabase row-level security, private storage controls, authenticated routes, and service-role separation to limit access to user-owned records.

No online service can guarantee absolute security. You are responsible for keeping your login credentials secure and notifying us if you believe your account has been accessed without authorization.

Audit sharing and exports

If you download, export, or share an audit, PDF, roadmap, or document summary, you are responsible for where that copy goes. Shared copies may contain sensitive planning details, route notes, evidence status, and score explanations.

Future advisor, family, school, or agent sharing workflows should ask for explicit user action before making account content available to another person or organization.

Marketing email

Marketing email is optional. Transactional messages about account access, payments, support, security, audit status, and legal notices may still be sent when needed to operate the service.

You can withdraw optional marketing consent from Privacy Choices, Settings, an unsubscribe link when available, or by contacting us.

Children and younger users

AbroadQ accounts are intended for users age 18 or older. AbroadQ does not currently provide a parent or guardian consent flow for users under 18.

If a younger student needs planning support, a parent, guardian, or trusted adult should manage the account and decide what information is appropriate to provide.

AbroadQ does not intentionally target children, sell or share children's personal data, or use child data for behavioral advertising.

International processing and transfers

Your information may be processed using service providers outside your country. Where transfer safeguards or additional notices are required, we will use appropriate contractual, technical, and organizational safeguards available for the relevant provider and jurisdiction.

For privacy questions, data requests, or transfer-related questions, contact support@abroadq.com.

Security incidents

If we become aware of a security incident that affects your personal data, we will investigate, take steps to reduce harm, and notify affected users or regulators where required by applicable law.

If you believe your account or uploaded evidence has been accessed without permission, contact us promptly.

Retention table

These periods are planning rules for the current product. Actual retention can be shorter when deletion is completed, or longer where legal, security, payment, or dispute obligations require it.

Data typeRetention periodReason
Account and profile detailsWhile your account is active, or until deletion is completedOperate your workspace, route ranking, dashboard, and support requests
Uploaded documents and evidence statusUntil you delete them or request account deletion, subject to legal or dispute exceptionsEvidence tracking, audit support, and roadmap-linked tasks
Audits, score runs, simulations, and roadmap historyAs long as needed to preserve generated outputs and explain prior decisionsAudit integrity, paid access, comparison, and user review
Payment and refund recordsAs required for accounting, tax, payment dispute, fraud prevention, and legal obligationsPayment processing, refunds, chargeback handling, and compliance
Consent, security, support, and product-event logsAs long as needed for consent proof, security, debugging, support, and complianceOperate the service safely and honor privacy choices
Meta lead forms and draft profilesUntil claimed, expired, deleted, or no longer needed for lead follow-up and service debuggingCreate a draft profile, support secure claim, prevent duplicate lead actions, and measure claimed route profiles
Raw extraction textNot stored by defaultMinimize sensitive document processing

Questions or requests

For data access, correction, deletion, or privacy questions, email support@abroadq.com or visit the Support page.