Privacy Policy

Effective Date: February 7, 2025

This Privacy Policy describes how Circlio ("Company," "we," "us," or "our") collects, uses, discloses, and protects your information when you use our school network platform ("Service"). We are committed to protecting your privacy and handling your personal information responsibly.

1. Information We Collect

Personal Information You Provide

  • Account Information: Name, email address, username, password, profile photo
  • Profile Information: Bio, location, company, job title, social media links, interests, graduation year
  • Content: Posts, comments, messages, photos, videos, and other content you create or share
  • Communications: Messages, emails, and other communications with us or other users through the Service
  • Event Information: Event attendance, RSVPs, and calendar data

Information We Collect Automatically

  • Usage Data: Pages visited, features used, time spent, click patterns, search queries
  • Device Information: IP address, browser type and version, operating system, device identifiers, screen resolution
  • Log Data: Server logs, error reports, performance metrics, access times
  • Location Data: Approximate location based on IP address (we do not collect precise GPS geolocation)
  • Cookies and Similar Technologies: See our Cookie Policy for details

Information from Third Parties

  • Social Authentication: When you sign in using Google or another OAuth provider, we receive your name, email address, and profile photo as permitted by your provider settings
  • Analytics Providers: Aggregated usage statistics and performance data

Information We Do Not Collect

We do not knowingly collect: Social Security numbers, financial account numbers, government-issued identification numbers, health or medical information, biometric data, or precise geolocation data.

2. How We Use Your Information

We use your information for the following purposes:

  • Provide and Operate the Service: Account creation, authentication, content delivery, messaging, and core platform functionality
  • Communicate with You: Service announcements, security alerts, account notifications, and responses to your inquiries
  • Improve the Service: Analyze usage patterns, diagnose technical issues, develop new features, and conduct research
  • Safety and Security: Detect and prevent fraud, abuse, and violations of our Terms of Service and Community Guidelines
  • Personalization: Customize your experience, including content recommendations and community suggestions
  • Legal Compliance: Comply with applicable laws, regulations, legal processes, and government requests

We do not use your personal information for automated decision-making or profiling that produces legal effects or similarly significant effects on you.

3. Lawful Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area (EEA) or United Kingdom (UK), we process your personal data under the following lawful bases:

  • Contract Performance: Processing necessary to provide you with the Service under our Terms of Service
  • Legitimate Interests: Processing necessary for our legitimate interests (improving the Service, ensuring security, preventing fraud), provided these interests do not override your rights
  • Consent: Where you have given specific consent (e.g., optional analytics, marketing communications). You may withdraw consent at any time
  • Legal Obligations: Processing necessary to comply with legal requirements

4. Information Sharing and Disclosure

We do not sell your personal information. We may share your information in the following limited circumstances:

With Your Consent

We share information when you explicitly consent or direct us to do so.

Public Content

Content you post publicly (posts, comments, profile information you choose to make public) may be visible to other users of the Service. You control your profile visibility through your privacy settings.

Service Providers

We share information with third-party service providers who process data on our behalf and are contractually obligated to protect your information:

  • Supabase: Database hosting and authentication services
  • Vercel: Application hosting and deployment
  • Google: OAuth authentication
  • PostHog: Privacy-focused product analytics

Legal Requirements

We may disclose information if we believe in good faith that disclosure is necessary to:

  • Comply with applicable laws, subpoenas, or court orders
  • Protect the rights, property, or safety of Circlio, our users, or the public
  • Prevent or investigate possible wrongdoing or safety issues
  • Enforce our Terms of Service

Business Transfers

In the event of a merger, acquisition, bankruptcy, or asset sale, your information may be transferred as part of the business assets. We will notify you via email or prominent notice on the Service before your information becomes subject to a different privacy policy.

Aggregated Data

We may share aggregated, de-identified information that cannot reasonably be used to identify you for research, analysis, or other purposes.

5. Data Security

We implement technical and organizational measures designed to protect your information, including:

  • Encryption: TLS/SSL encryption for data in transit; encryption at rest for stored data
  • Access Controls: Role-based access controls and authentication requirements for all systems
  • Row-Level Security: Database-level access controls ensuring users can only access their authorized data
  • Security Monitoring: Automated monitoring for suspicious activity and potential security threats
  • Secure Development: Security-conscious development practices and regular code review

While we strive to protect your information, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents.

6. Third-Party Services

Our Service integrates with third-party services that have their own privacy policies. We encourage you to review their policies:

  • Google: OAuth authentication and related services
  • Supabase: Database and authentication infrastructure
  • Vercel: Application hosting and content delivery
  • PostHog: Privacy-focused product analytics

We are not responsible for the privacy practices of third-party services. Our Service may also contain links to external websites that we do not control.

7. Data Retention

We retain your information only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required by law:

Data TypeRetention Period
Account dataUntil account deletion, then retained for 90 days before permanent deletion
User content (posts, comments)Until deleted by you or account deletion; removed from public view immediately, permanently deleted after 90-day retention period
Direct messagesUpon account deletion, message content is immediately replaced with a deletion notice; sender attribution is permanently removed after the 90-day retention period
Server logs90 days
Analytics data24 months (aggregated and de-identified)
Security logs12 months
Backup copiesUp to 30 days after source data deletion

Post-Deletion Retention Period

When you delete your account, we immediately remove your profile, content, and data from public view. However, we retain your data in our systems for a period of 90 days before permanent deletion. During this retention period:

  • Your profile, posts, and comments are hidden from all users and cannot be accessed through the Service
  • Your data is retained solely for legal compliance, safety investigations, fraud prevention, and dispute resolution
  • You cannot recover your account or data during or after this period

After the 90-day retention period, your data is permanently and irreversibly deleted from our systems, including all associated records across our database. Backup copies may persist for up to an additional 30 days.

We may retain information longer if required by law (e.g., for tax, legal, or regulatory purposes) or to resolve disputes and enforce our agreements.

8. Your Rights and Choices

Regardless of your location, we provide all users with the following rights:

Account Management

  • Access: View and download your personal information through your account settings
  • Correction: Update or correct your profile information at any time
  • Deletion: Delete your account and associated data through account settings or by contacting us. Your data is removed from public view immediately and permanently deleted after a 90-day retention period
  • Portability: Request your data in a machine-readable format

Privacy Controls

  • Profile Visibility: Control who can see your profile information through privacy settings
  • Communication Preferences: Manage email and notification preferences
  • Content Visibility: Control the audience for your posts and content
  • Cookie Preferences: Manage cookies through your browser settings

Additional Rights (EEA/UK Users)

If you are in the EEA or UK, you may also have the right to: restrict or object to processing, withdraw consent, lodge a complaint with a supervisory authority, and request erasure under applicable law. Contact us at zhangj1@wharton.upenn.edu to exercise these rights.

We will respond to verified requests within 30 days (or within the time frame required by applicable law). We will not discriminate against you for exercising any of these rights.

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

Your CCPA Rights

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purposes, and the categories of third parties with whom we share it
  • Right to Delete: You may request that we delete your personal information, subject to certain exceptions
  • Right to Correct: You may request correction of inaccurate personal information
  • Right to Opt Out: You have the right to opt out of the sale or sharing of your personal information (see Section 14)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

Categories of Information Collected

In the preceding 12 months, we have collected the following categories of personal information: identifiers (name, email, username, IP address); internet activity (usage data, browsing history within our Service); geolocation data (approximate location from IP address); and inferences drawn from the above categories.

How to Submit a Request

To exercise your rights, email zhangj1@wharton.upenn.edu with the subject line "CCPA Request." We will verify your identity before processing your request.

10. Additional State Privacy Rights

Residents of certain states (including Virginia, Colorado, Connecticut, Utah, Oregon, Texas, and others with comprehensive privacy laws) may have additional rights, including the right to access, correct, delete, and port their personal data, as well as the right to opt out of targeted advertising and profiling.

To exercise rights under your state's privacy law, contact us at zhangj1@wharton.upenn.edu. If your request is denied, you may have the right to appeal. We will provide instructions for appeal in our response.

11. International Data Transfers

Your information may be transferred to and processed in the United States and other countries where our service providers operate. These countries may have different data protection laws than your country of residence.

When we transfer personal data internationally, we implement appropriate safeguards, including standard contractual clauses approved by relevant authorities, to ensure your information receives an adequate level of protection.

12. Children's Privacy

Our Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. Users between 13 and 18 must have parental or guardian consent to use the Service.

If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us immediately at zhangj1@wharton.upenn.edu. If we discover we have collected personal information from a child under 13 without verified parental consent, we will promptly delete such information and terminate the associated account.

We do not knowingly sell or share the personal information of users under 16 years of age.

13. Cookies and Tracking Technologies

We use cookies and similar technologies for essential platform functionality. For a detailed explanation of the cookies we use, how they work, and how to manage them, please see our Cookie Policy.

In summary, we use the following categories of cookies:

  • Essential Cookies: Required for authentication, security, and basic platform functionality. These cannot be disabled.
  • Analytics Cookies: Help us understand how the Service is used so we can improve it. We use privacy-focused analytics tools.
  • Preference Cookies: Remember your settings and preferences (such as dark mode).

We do not use advertising or tracking cookies. We do not display ads on the Service.

14. Do Not Sell or Share My Personal Information

Circlio does not sell your personal information to third parties. We do not share your personal information with third parties for cross-context behavioral advertising purposes.

We honor Global Privacy Control (GPC) signals and Do Not Track (DNT) browser signals as valid opt-out requests where required by applicable law.

If you believe your information has been sold or shared in violation of this policy, contact us at zhangj1@wharton.upenn.edu.

15. Data Breach Notification

In the event of a data breach that affects your personal information, we will:

  • Investigate the breach promptly and take steps to contain and remediate it
  • Notify affected users without unreasonable delay and in compliance with applicable state and federal notification requirements
  • Notify relevant regulatory authorities as required by law
  • Provide information about the nature of the breach, the types of information affected, and steps you can take to protect yourself

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes, we will:

  • Post the updated policy on this page
  • Update the "Effective Date" at the top
  • Notify you of material changes via email or in-app notification at least fifteen (15) days before the changes take effect
  • Obtain your consent for material changes where required by applicable law

Your continued use of the Service after the effective date of any changes constitutes acceptance of the revised policy. If you do not agree with the changes, you should stop using the Service.

17. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Privacy inquiries: zhangj1@wharton.upenn.edu

General support: zhangj1@wharton.upenn.edu

CCPA / state privacy requests: zhangj1@wharton.upenn.edu (subject line: "Privacy Rights Request")

We will respond to your inquiry within thirty (30) days or within the time frame required by applicable law. We may need to verify your identity before processing certain requests.