Pathly Legal / Trust
Data inventory
Everything the Pathly platform collects, why it is collected, who can see it, and how long it is kept. One inventory covers every channel: students who come to Pathly on their own, students connected to an independent counselor, and students at a partner school. This page is Exhibit A to the Counselor Data Processing Addendum and to the Pathly Partner School Student Data and Privacy Addendum, and is maintained as part of both.
- Version
- 1.0
- Last updated
- July 30, 2026
- Applies to
- All channels
- Prior versions
- Archive
The short version
- Pathly collects what it needs to give a student personalized guidance, and not more.
- No Social Security numbers, no date of birth, no demographics, no official transcripts, no health data, no biometrics, no precise location.
- GPA and test scores are self-reported, and the student can always edit or delete them, whoever entered them.
- Conversation content is stored for the student to reread. It is never visible to a counselor.
- A counselor's own roster and notes belong to that counselor, separate from the student data they can see.
- The same inventory applies whether a student arrives alone, through a counselor, or through a partner school.
01 Collection summary
| Category | Examples | How it is collected |
|---|---|---|
| Account information | Name, email, graduation year, school name if provided | Registration and profile setup by the student |
| Usage data | Login times, features used, last active | Automatic platform tracking |
| Conversation data | Student questions, AI responses | Student-initiated conversations |
| Assessment responses | Interest, values, personality, EQ | Student-completed assessments |
| Academic data | Self-reported GPA and standardized test scores | Entered by the student, or by a connected counselor |
| Profile and preferences | Goals, interests, saved colleges and careers, roadmaps | Voluntary student entries |
| Communication data | Email address for notifications and verification | Account creation |
| Counselor practice data | Counselor account details, connected roster, tags, notes, billing contact | Counselor account setup and use |
02 Student account data
2.1 Account fields
| Field | Required | Purpose |
|---|---|---|
| First name | Yes, at onboarding | Personalization |
| Last name | No | Identification where the student chooses to provide it |
| Email address | Yes | Authentication and notifications |
| School name | No | Relevant recommendations. Often absent for students who come to Pathly independently. |
| Graduation year | No | Calculate grade level and planning timeline |
| Institution ID | Automatic | Associate a student with a partner school, where one exists |
| Counselor connection record | Automatic on connection | Record which counselor the student authorized, the scope shown, and when |
| Account creation date | Automatic | Account age and analytics |
| User role | Automatic | Access control |
2.2 Usage data
| Field | Purpose | Retention |
|---|---|---|
| Login timestamps | Engagement and last-active signal | Per Section 5 |
| Page views | Product analytics | Anonymized in PostHog |
| Feature usage | Product analytics | Anonymized in PostHog |
| Device type | Mobile versus desktop analytics | Anonymized in PostHog |
| IP address | Rate limiting and security | Not stored long term, anonymized in analytics |
2.3 Conversation data
| Field | Purpose | Visible to counselor |
|---|---|---|
| Student messages | Provide guidance, maintain context, let the student reread their history | No |
| AI responses | Student's own conversation history | No |
| Message timestamps | Conversation flow | Aggregate only |
| Message count | Engagement signal | Yes, count only |
De-identified conversation data, meaning aggregated themes and anonymized patterns that cannot reasonably identify a student, may be retained longer for platform improvement.
2.4 Assessment responses
| Assessment | Data collected | Visible to counselor |
|---|---|---|
| Interest inventory | Questions and student answers | Completion status only |
| Values | Scores across dimensions | Scores and tags |
| Personality | Five-factor scores | Scores and tags |
| Emotional intelligence | Dimension scores | Scores and tags |
| Raw question responses | Retained to compute and re-display scores | No |
2.5 Academic data
All academic data in Pathly is self-reported. Pathly does not receive official transcripts, verified score reports, or feeds from a school information system or a testing agency.
| Field | Who can enter it | Who can edit or delete it |
|---|---|---|
| Grade point average | The student, or a connected counselor | The student, at any time |
| Standardized test scores | The student, or a connected counselor | The student, at any time |
A value entered by a counselor is Student Account Data, not counselor data. The student can see who entered it and change it. Pathly will not restore a counselor-entered value over a student's correction.
03 Counselor practice data
This is data a counselor creates inside their own Pathly account, distinct from the student data they can view. The counselor is its controller, and Pathly processes it on that counselor's instructions under Section 2.1 of the Counselor DPA. It exists only where a paid Counselor plan is in place.
| Field | Purpose | Retention |
|---|---|---|
| Counselor name and email | Authentication, notifications, support | Life of account, then per Addendum Section 10 |
| Practice or firm name | Account identification | Life of account |
| Seat assignments | Access control across associates | Life of account |
| Connected student roster | Determine dashboard visibility | Until the connection ends |
| Connection records | Audit trail of student authorization and scope shown | Retained for audit after the connection ends |
| Tags and notes | Your own advising records | Until you delete them, or per Addendum Section 10 |
| Billing contact and subscription status | Payment processing and account management | As required for tax and accounting |
| Dashboard access logs | Security audit of student detail views | Retained for audit |
Payment card details are handled by Pathly's payment processor. Pathly does not store full card numbers.
04 What Pathly does not collect
Not collected from any user
- Social Security numbers or government-issued identification numbers
- Date of birth
- Demographic information, including race, ethnicity, gender, and religion
- Official academic transcripts, verified score reports, or feeds from a school information system or testing agency. Self-reported GPA and test scores are collected, as described in Section 2.5.
- Financial information, including family income and bank accounts
- Health or medical records
- Family structure data
- Biometric data, including fingerprints and facial recognition
- Precise geolocation data
IP addresses are logged briefly for rate limiting and security. They are anonymized in analytics and are not retained long term.
05 Retention
| Category | Retention | Deletion method |
|---|---|---|
| Student account information | Life of the student's account | Hard delete from database |
| Student usage data | Life of the student's account | Hard delete from database |
| Usage data, anonymized | Indefinite | Not deleted, contains no personal information |
| Conversation data | Life of the student's account | Cascade delete from database |
| Conversation data, de-identified | Indefinite | Not deleted, contains no personal information |
| Assessment responses and scores | Life of the student's account | Cascade delete from database |
| Self-reported academic data | Until the student deletes it, or the life of the account | Cascade delete from database |
| Profile and preferences | Life of the student's account | Cascade delete, including stored files |
| Counselor practice data | Life of the counselor account, plus a 30-day export window | Hard delete from database |
| Email delivery logs | 30 days | Automatic, per Resend policy |
| Error logs | 90 days | Automatic, per Sentry policy |
| Database backups | 7 days | Automatic purge on rotation |
5.1 What triggers deletion
- A student deletes their account. A 15-day grace period, then permanent deletion from production within 2 business days and purge from backups within the 7-day rotation.
- A counselor cancels or is terminated. Student accounts are unaffected. Connections dissolve. Counselor practice data is available to export for 30 days, then deleted.
- A counselor deletes their account. Same 15-day grace period and timelines as a student account.
- Inactivity. Nothing. Inactivity alone does not trigger deletion of any account.
06 Who can see what
The authoritative statement of counselor visibility is Section 4 of the Counselor DPA. This table restates it alongside the other roles for comparison. The connected counselor column applies to school counselors and independent counselors alike; the rule that conversation content is never visible does not vary by channel. What differs between the two is set by the school's signed agreement, not by this table.
| Data | Student | Connected counselor | Pathly support |
|---|---|---|---|
| Own profile and account | Full | Name and graduation year | As needed for support |
| Email address | Full | No | As needed for support |
| Assessment scores and tags | Full | Full | As needed for support |
| Raw assessment answers | Full | No | As needed for support |
| Self-reported GPA and test scores | Full, and editable | Full, and can enter | As needed for support |
| Saved careers and colleges | Full | Titles | As needed for support |
| Roadmap | Full | Goal and progress | As needed for support |
| Conversation content | Full | Never | Documented support or security need only |
| Message count and timestamps | Full | Count and last active | As needed for support |
| Counselor notes about the student | No | Own notes only | Documented support need only |
Pathly personnel access data only as needed to operate the Platform, resolve a support request, or investigate a security issue. Access requires unique credentials, is logged, and is limited by role. Personnel with access are bound by confidentiality agreements.
07 What exports contain
Pathly produces two kinds of export. Neither contains everything in an account, and the difference matters, so both are itemized here.
7.1 Counselor roster export
A counselor can export a list of the students connected to them. The file contains these columns and nothing else:
| Column | Value |
|---|---|
| Name | First name, plus last name if the student provided one |
| Graduation year | Four-digit year |
| Onboarding | Yes or no |
| Quiz | Yes or no |
| Personality | Yes or no |
| EQ | Yes or no |
| Values | Yes or no |
| Roadmap | Yes or no |
| Last active | Date |
The assessment columns carry completion status only. No scores, no tags, no answers. The export is narrower than what the dashboard displays on screen: it excludes career goals, saved careers, roadmap detail, assessment scores, and self-reported academic data.
Never in any export
- Student email addresses
- Conversation content, in whole or in part
- Topics or themes drawn from conversations
- Raw answers to assessment questions
- Any student not connected to the exporting counselor
7.2 Institution analytics export
A partner school can export cohort analytics. This file contains no student names and no individual student records. It is counts and percentages: enrollment, onboarding and milestone completion, milestone distribution, career interest categories, completion rates by grade level, exploration activity, and the colleges and scholarships saved most often across the cohort.
Cohort analytics apply a minimum-count threshold. Where a category contains too few students to report safely, the count is withheld and the report shows that a value was suppressed rather than showing the number. The export states how many categories were hidden this way, so the reader knows suppression occurred and is not misled by an incomplete list.
This exists because aggregate reports on small groups can identify individuals. A category of one or two students in a small school is not anonymous.
Every institution analytics export carries the institution name, the reporting period, and the timestamp it was generated, so any copy in circulation can be traced to a point in time.
08 Changes to this inventory
Pathly will update this page as the Platform changes. Where a change materially expands what is collected or what a counselor can see, Pathly will give at least 30 days' notice by email and on this page before it takes effect, under Section 13.2 of the Addendum. Every version is dated and kept in the archive.
Questions: legal@pathly.com.