Effective and last updated: September 1, 2026
Short version: Temporary student profiles and caseload records saved in the web workspace remain in your browser for up to 24 hours. When you request AI work, the information needed for that request passes through our server-side function and is sent to Anthropic. The live API follows the same model-processing path. By default, CounselorAI does not store request or response bodies, but it does keep account, usage, security, and billing records.
825 Consulting LLC, doing business as CounselorAI ("CounselorAI," "we," "us," or "our"), provides a web workspace and machine-readable API, MCP, and A2A services. This Notice covers counselorai.app, api.counselorai.app, related forms, account creation, payments, and support.
| Category | Examples | Why we use it |
|---|---|---|
| Account and contact data | Name, email address, organization or agent framework, account status | Create and support accounts, provide notices, prevent abuse |
| API credentials | Public key identifier, one-way hash of the secret, scopes, mode, last-used time, revocation time | Authenticate and govern access. We do not store the recoverable secret after issuance. |
| Submitted content | Prompts, counselor instructions, draft text, student context, source facts | Validate the request, produce the requested output, and apply quality checks |
| Usage and security metadata | Tool, transport, request and idempotency identifiers, status, token counts, rate-limit state, error code, timestamps, IP hash for signup throttling | Meter calls, prevent duplicate billing, enforce limits, diagnose failures, and protect the Services |
| Billing records | Credit balance and ledger, amount paid or refunded, Stripe checkout, payment-intent, charge, dispute, and event identifiers | Provide credits, reconcile charges, process refunds and disputes, prevent fraud, and meet accounting obligations |
| Website and device data | Consent choices, browser and device information, pages and events, approximate location derived from IP | Operate the website, remember choices, understand usage, and protect the Services |
| Messages and forms | Support requests, survey responses, founding-seat choices, and email delivery information | Respond to you and operate requested programs |
Temporary student profiles and caseload entries are stored in browser local storage for up to 24 hours. They are not synchronized to a CounselorAI account database. The workspace removes expired entries while it is open or the next time it loads. You can delete a selected entry sooner. Counselor identity fields are separate and remain until you replace them or clear browser storage. Counselor voice samples, signature images, uploaded files, and generated letter history are held only in the open browser-tab session.
When you click a generation, review, translation, or analysis function, the fields needed for that request are sent to a Netlify Function operated for CounselorAI. The function validates the request and sends a generated prompt to Anthropic's commercial API. The result returns through the function to your browser. Our application code is designed not to log request or response bodies.
A live request enters a Netlify Function, is authenticated against account records in Supabase, and is sent to Anthropic when model work is required. The request is metered in Supabase. The default account setting, retention_mode='none', does not store the request body or generated response body in CounselorAI's database.
For an account with a separate written agreement and retention_mode='store', a generated response may be stored for idempotent replay and is purged after 24 hours. Caller input is not stored in that response field. Test-key A2A tasks may retain only a canned fixture and terminal status for up to 24 hours. Test-task storage does not include caller input, live model output, student content, or payment data.
Background A2A tasks are a separately gated feature, disabled by default. If enabled, an account storage agreement plus explicit per-request consent permits temporary storage of both input and output in Supabase. Input is cleared when the task completes, fails, or is canceled while queued. Output stops being readable 24 hours after submission; scheduled cleanup clears expired or revoked bodies on its next successful run. Outages may delay physical cleanup. Task identifiers, input hashes, consent versions, status, timestamps, and billing records remain. Use opaque task and context identifiers without student information. Processor and backup retention remain subject to their separate policies.
Anthropic acts as a processor for commercial API content. Anthropic states that it does not use commercial API inputs or outputs to train generative models by default. Under Anthropic's standard commercial API retention, inputs and outputs are automatically deleted from its backend within 30 days, subject to exceptions for services with different retention, an agreed retention setting, usage-policy enforcement, or legal obligations. CounselorAI does not claim zero retention by Anthropic unless a separate written agreement expressly provides it.
We disclose information only as needed to operate the Services, process payments, comply with law, protect rights and safety, or complete a business transaction. We do not sell personal information. We do not use customer-submitted student content for targeted advertising.
| Provider | Role | Data involved |
|---|---|---|
| Netlify | Hosting, serverless functions, request routing, and operational logs | Requests in transit, network and operational metadata |
| Anthropic | AI model processing and optional model web-search tooling | Prompts, submitted context, generated output, and model usage metadata |
| Supabase | Account, authentication, metering, retention controls, and billing database | Account data, key hashes, usage metadata, billing records, opt-in response storage, and separately consented background-task input and output |
| Stripe | Checkout, payment processing, refunds, disputes, and optional postpaid metering | Payment and transaction data, customer and purchase identifiers |
| Resend | Transactional and operational email | Recipient email, message content, and delivery metadata. Agent operational digests contain counts and totals, not customer content. |
| Google Analytics and Termly | Website analytics and consent management | Website events, consent choices, and device or network metadata as permitted by your consent settings |
Provider terms and retention practices can change. We maintain the provider and legal-source record used for this Notice in our public repository.
| Data | Retention approach |
|---|---|
| Browser-local student profiles and caseload entries | Up to 24 hours, with earlier manual deletion available. Expired entries are removed while the workspace is open or the next time it loads. |
| Generated history, counselor voice samples, signature images, and uploaded files | Only for the open browser-tab session |
| Browser-local counselor identity fields | Until you replace them or clear browser storage |
| Default live API request and response bodies | Not stored in the CounselorAI database |
| Opt-in stored API responses | Up to 24 hours |
| Test A2A fixture and terminal status | Up to 24 hours |
| Usage, security, and billing records | For the account relationship and as reasonably needed for billing, reconciliation, fraud prevention, dispute resolution, tax, and legal obligations |
| Account and support data | For the account relationship and a reasonable period afterward for support, security, and legal obligations |
| Anthropic API content | Anthropic's standard period is deletion within 30 days, subject to its published exceptions or a separately agreed retention setting |
CounselorAI is designed to minimize storage, but AI requests can contain personally identifiable student information. Data minimization is required: submit only what the task needs, and omit last names, dates of birth, student identification numbers, Social Security numbers, account credentials, and unrelated records whenever possible.
A school or institution must approve its use of the Services. Before an institution submits personally identifiable information from education records, it must execute a written agreement with 825 Consulting LLC, including our Data Processing Addendum or an approved equivalent. That agreement establishes documented instructions, direct-control obligations, permitted purpose, redisclosure limits, security, deletion, and incident handling. An institution remains responsible for determining the FERPA exception or consent on which it relies and for limiting access to legitimate educational interests.
Without an executed institutional agreement, do not submit identifiable education records. Use synthetic or de-identified data instead. CounselorAI is not configured for protected health information under HIPAA.
Depending on the law that applies, we process information to perform a contract, take requested pre-contract steps, comply with legal obligations, pursue legitimate interests such as security and service operation, or act with consent. Institutions that determine the purposes of student-data processing act as controllers or the equivalent under applicable law. Under an executed Data Processing Addendum, 825 Consulting LLC acts as their processor or service provider for covered data.
We use browser storage for application state and use Termly to manage consent preferences. Google Analytics may operate according to those settings. You can use the Consent Preferences link below and browser controls to change cookie choices. Blocking storage may limit features.
We use safeguards designed for the risk, including server-side secrets, hashed API key secrets, scoped keys, rate limits, payload limits, row-level security, separate webhook verification, idempotent billing, data-minimized logs, and default no-body retention. No system is perfectly secure. Report suspected vulnerabilities through our Security Policy.
The Services are intended for adults and authorized professional users. We do not knowingly invite children under 18 to create accounts or buy Services. Students should not use the Services directly unless a parent, guardian, or authorized institution has approved and supervises that use.
Depending on your location, you may have rights to access, correct, delete, restrict, or obtain a copy of personal information, or to appeal a decision concerning a privacy request. Submit a data subject request or email outreach@counselorai.app. We may need to verify your identity. Some records may be retained where required for billing, fraud prevention, disputes, or law.
For data submitted by an institution, contact the institution first. We will assist the institution as required by the applicable agreement.
Our providers may process information in the United States and other locations where they operate. Where required, transfers are governed by the applicable provider agreement, data processing addendum, Standard Contractual Clauses, or another lawful transfer mechanism.
We may update this Notice as the Services, providers, and laws change. We will post a new effective date and provide additional notice when required.
Email: outreach@counselorai.app
825 Consulting LLC
771 Alison Way
San Jacinto, CA 92583
United States