Privacy Policy
Last updated: March 2026
1. What We Collect
When you create an account, we collect:
- Account info — name, email address, and profile picture (provided via your login provider)
- Profile preferences — nationality, budget range, timeline, preferred regions, citizenship goals, profession, and languages (provided during onboarding)
- Favorites — countries you save to your favorites list
- Chat history — messages exchanged with our AI Pathway Advisor
- Activity data — pages visited, countries viewed, searches performed, comparisons made, and pathway results (only when logged in)
If you use PassportPathways without an account, we do not collect any personal data. Favorites are stored locally in your browser.
2. How We Use Your Data
- Personalize citizenship pathway recommendations based on your profile
- Sync your favorites across devices
- Save AI advisor chat history so you can resume conversations
- Improve our platform through aggregated, anonymized analytics
We do not sell, rent, or share your personal data with third parties for marketing purposes.
3. Third-Party Services
- Clerk — handles authentication (sign-up, login, session management). See Clerk Privacy Policy.
- Neon (via Vercel) — hosts our PostgreSQL database where your profile and activity data is stored.
- Anthropic — powers the AI Pathway Advisor. Your chat messages are sent to Anthropic's Claude API for processing. See Anthropic Privacy Policy.
- Vercel — hosts the application. See Vercel Privacy Policy.
4. Cookies
We use essential cookies for authentication session management (provided by Clerk). We do not use advertising or third-party tracking cookies.
5. Your Rights
- Access — view all data we hold about you from your Profile page
- Correction — edit your profile information at any time
- Deletion — request complete deletion of your account and all associated data
- Export — download a copy of your data in a portable format
To exercise these rights, visit your Profile page or contact us.
6. Data Retention
We retain your data for as long as your account is active. If you delete your account, all personal data is permanently removed within 30 days. Anonymized, aggregated analytics may be retained indefinitely.
7. Data Security
Your data is encrypted in transit (TLS) and at rest. Database access is restricted to authenticated server-side operations only. We follow industry-standard security practices.
8. Contact
For privacy-related questions or concerns, please reach out through the contact information on our About page.