Privacy Overview
Last updated: July 14, 2026
About this page. This is a plain-language product privacy overview. It does not replace any notice or agreement required by a university.
MyFutureSelf builds Swoop, an AI mentor for students at the Farmer School of Business at Miami University. This page explains, in plain language, what we collect, how we use it, and the choices you have. The short version: the implemented institutional analytics surface exposes only authorized, privacy-stabilized aggregates, not student-level rows, and you can delete your MyFutureSelf account at any time.
What we collect
When you use Swoop, we store:
- Account details. Your name and email (or your Google sign-in). You can also use Swoop as a guest without an email.
- Your onboarding profile. Major, career interests, target cities, hometown, salary target, and your goal. Optional identity signals (for example gender) are matcher-only: they are used solely to weight alumni matches, they are never required, you can change or remove them, and they are never used as a reporting dimension.
- Your work in the app. Chats with Swoop, memories you ask Swoop to keep, tasks and roadmap progress, contacts you save, and outreach you log.
- Product usage events. Which features you use (for example that an upload succeeded or a task was completed). These events go through a strict blocklist so free text and personal details, such as names, emails, message text, or resume text, are never recorded in them.
Files you upload
When you upload a file (like a resume, degree audit, or PDF), it is sent to OpenAI's API so Swoop can read it and personalize your plan: files are stored with OpenAI and, for documents, indexed in a private vector store used only for your account. Resume and degree audit text is also kept privately on your profile so your plan stays personalized between sessions.
Your files stay private to you. Vector stores used for file search expire automatically after 30 days of inactivity on OpenAI's side, and under OpenAI's API terms this data is not used to train OpenAI's models.
AI processing and the technical log
Swoop's replies are generated through OpenAI's API. To debug reliability problems we keep a technical log of AI requests and responses. That log has a 30-day retention target. The database includes a purge function, but the scheduled retention job is installed separately and must be verified in each environment.
Optional public-profile suggestions (not enabled in production)
We have designed an optional feature that can look for a student's own public professional and educational presence. Live production searching remains disabled while provider, university, privacy, and legal review is pending. It will not run merely because you created an account or finished onboarding.
If this feature is approved and enabled, it will first show a separate disclosure and ask you to confirm both your eligibility and your authorization. Only approved public professional, portfolio, project, publication, GitHub, and university-profile sources may be searched. LinkedIn content is not fetched or scraped. The search may use your name, Miami University affiliation, major, graduation year, and any canonical URLs you choose to provide. Optional profile links you enter are used only to resolve your identity for that authorized search.
Suggestions are limited to professional or portfolio links, projects, publications, awards, organizations, education, work experience, skills, and interests explicitly stated by you or a source. Suggestions include a source link, access date, and confidence information. Nothing changes automatically. You accept, edit, or reject every suggestion independently. The feature is not used for employment, admissions, credit, insurance, housing, disciplinary, or other eligibility decisions, and it blocks sensitive or high-risk inferred fields.
Raw fetched pages are not retained. Unaccepted suggestions and their provenance have a 30-day deletion target; the scheduled deletion job must be installed and monitored before activation. Accepted facts and their provenance stay on your private profile until you remove them or delete your account. You can cancel a running search, withdraw future-search authorization, reject any field, remove an accepted field, delete pending results, or delete your account.
What the university sees
Under the implemented institutional analytics design, individual student data is not available in the university reporting surface. There is no student drill-down: not chats, profiles, contacts, messages, or private progress.
This describes the current product design, not an unconditional legal guarantee. Any different institutional sharing would require its own approved notice, agreement, and authorization.
Institutional reporting is aggregate-only with minimum-cohort and complementary suppression designed to reduce identification risk. Student-reported career outcomes include only students who explicitly opted in. Sharing is off by default, and you can change your choice in account settings; changes apply to later weekly reports. The exact list of what the school can see is below.
What Farmer sees
Authorized Farmer staff can see only the aggregate reporting listed here. Never your name, your chats, your contacts, your notes, or any individual row.
- Activation and engagement. Eligible aggregate cohort size, Onboarding completion rate, Active and returning student aggregates. Aggregates may use rolling 7-day, 30-day, and 90-day windows and only privacy-safe cohort-year filters.
- Career readiness. Readiness-action completion rate, Aggregate activation-to-outcome funnel stages. Aggregates may use rolling 7-day, 30-day, and 90-day windows and only privacy-safe cohort-year filters.
- Networking progress. Students attempting outreach, Aggregate student reply-or-meeting rate. Aggregates may use rolling 7-day, 30-day, and 90-day windows and only privacy-safe cohort-year filters.
- Consented student-reported outcomes. Students with student-reported career outcomes under active outcome-sharing consent. Aggregates may use rolling 7-day, 30-day, and 90-day windows and only privacy-safe cohort-year filters.
These are counts or rates with a privacy-qualified contributing-student count attached. Every released cell has at least 10 contributing students, with additional suppression when totals or neighboring cells could reveal a smaller group. Farmer sees "Privacy-suppressed" for a missing cell or "No reportable aggregate cells in this view" when the whole view is withheld, instead of those numbers. That floor is enforced inside the database itself, not in the page that displays the numbers.
Student-reported career outcomes are only counted for students who turned on outcome sharing, and only as counts. Outcome sharing stays off until you turn it on, and you can change your choice anytime in Settings.
Reports are frozen weekly. A sharing change applies to later publications and does not rewrite an already frozen aggregate.
How long we keep things
- Your profile, chats, tasks, and saved contacts are kept while your account is active.
- The AI technical log has a 30-day retention target. Automatic deletion depends on the scheduled retention job being installed and monitored in that environment.
- OpenAI vector stores for uploaded documents expire after 30 days of inactivity.
- If optional public-profile suggestions are approved and enabled, raw fetched pages are not stored, and unaccepted suggestions have a 30-day deletion target. Activation depends on the scheduled deletion job being installed and monitored.
Deleting your account
You can delete your account at any time from your account settings (Delete my account). Deleting the account removes the profile, chats, tasks, saved contacts, upload records, and consent records controlled by MyFutureSelf. Before removing the account, the service also attempts to delete linked files from private storage and OpenAI. Those external cleanup steps are best-effort: a failure is logged for follow-up and does not stop the MyFutureSelf account deletion. Account deletion cannot be undone.
Cookies and local storage
We use local storage in your browser to keep you signed in. We do not run third-party advertising trackers.
Changes and contact
If this policy changes, we will update this page and the date at the top. Questions or requests, including data export requests, go to hello@myfutureself.ai. Our terms of service are at /terms.