Privacy Policy
Last updated: April 2026
Introduction
iimaginer ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.
We operate in compliance with the General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and other applicable data protection laws in the Nordic and EU regions where we operate.
1. Data Controller
iimaginer Oy
Helsinki, Finland
For data protection inquiries, please contact us at: privacy@iimaginer.com
2. Information We Collect
2.1 Information You Provide Directly
- Account registration information (name, email, password)
- Profile information (education level, interests, career goals)
- Assessment responses and academic credentials
- Communication with our support team
- Payment information (processed via Stripe, see Section 5)
2.2 Information Collected Automatically
- Log data (IP address, browser type, pages visited)
- Device information (device type, OS, screen resolution)
- Usage analytics via PostHog (interaction patterns, feature usage)
- Error and crash reports via Sentry (to improve service stability)
- Cookies and local storage data (see Cookie Policy below)
3. Lawful Basis for Processing (GDPR)
We process your personal data based on the following lawful bases:
- Consent: When you sign up, opt into analytics, or accept our terms
- Contract Performance: To provide our services and manage your account
- Legal Obligation: To comply with applicable laws and regulations
- Legitimate Interest: To improve service quality, prevent fraud, and maintain security
4. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve our platform and services
- Process your assessments and deliver personalized recommendations
- Manage user accounts and authenticate access
- Process payments and billing (via Stripe)
- Communicate with you about service updates, newsletters, and offers
- Analyze usage patterns to optimize user experience (via PostHog)
- Detect, investigate, and prevent fraud, security breaches, and technical issues
- Comply with legal and regulatory obligations
5. Third-Party Data Processing
We share personal data with carefully selected third parties to deliver our services:
5.1 Supabase (Backend & Database)
Your account data, assessment responses, and user profiles are stored on Supabase servers hosted on AWS in EU regions. Supabase provides database, authentication, and real-time infrastructure. All data is encrypted in transit and at rest.
5.2 Stripe (Payment Processing)
For university and employer subscription payments, we use Stripe. Payment information is NOT stored on our servers. Stripe handles all credit card data securely and complies with PCI-DSS standards. We only store payment records and transaction IDs.
5.3 PostHog (Analytics)
We use PostHog to understand how users interact with our platform. PostHog collects anonymized usage data (not linked to personal identity by default). You can opt out of analytics via our cookie consent banner.
5.4 Sentry (Error Tracking)
Sentry captures error logs and crash reports to help us identify and fix bugs. Error logs may include technical context but do not intentionally capture personal identifiers. You can opt out of error tracking via our cookie consent banner.
5.5 Anthropic Claude & OpenAI (AI Processing)
Our Mojo AI engine uses Claude (Anthropic) as the primary provider and OpenAI as a backup. When you use AI-powered features (chat, recommendations, insights), relevant data is processed by these providers' APIs. We use API-level processing (data is not retained for model training). Both providers comply with data protection standards. You can decline AI processing features; you'll still have access to the core platform.
5.6 Resend & Loops (Email)
Transactional emails (account confirmations, password resets) are sent via Resend. Marketing communications are managed via Loops. You can unsubscribe from marketing emails at any time.
5.7 Inngest (Background Jobs)
Inngest handles scheduled background tasks (weekly briefs, data exports, notifications). Task metadata may include user identifiers to route messages correctly.
6. Data Retention
We retain your personal data for as long as necessary to provide services and meet legal obligations:
- Active Accounts: Retained while your account is active
- Deleted Accounts: Data is securely deleted within 30 days of account deletion
- Analytics Data: Retained for 12 months then aggregated/deleted
- Payment Records: Retained for 7 years (tax and legal compliance)
- Error Logs: Retained for 90 days then deleted
- Assessment History: Retained throughout account tenure; deleted upon account closure
7. International Data Transfers
Where we transfer personal data outside the EU/EEA (e.g., to OpenAI or Anthropic in the US), we rely on:
- Standard Contractual Clauses (SCCs): Approved mechanisms ensuring GDPR-compliant transfers
- Privacy Shield / Adequacy Decisions: Where applicable
- Your explicit consent: For optional services like AI processing
We minimize transfers and select processors with strong data protection records.
8. Your Data Protection Rights (GDPR)
Under GDPR, you have the right to:
- Access (Article 15): Request a copy of your personal data
- Rectification (Article 16): Correct inaccurate or incomplete data
- Erasure (Article 17): Request deletion ("right to be forgotten")
- Restrict Processing (Article 18): Limit how we use your data
- Data Portability (Article 20): Receive your data in a machine-readable format
- Object (Article 21): Oppose processing for marketing or profiling
- Withdraw Consent: At any time, for any processing based on consent
To exercise any of these rights, contact us at privacy@iimaginer.com. We will respond within 30 days.
9. Cookies & Local Storage
We use cookies and local storage to enhance your experience:
Essential Cookies
- Session tokens for authentication
- Security cookies (CSRF tokens, security flags)
- Language and theme preferences
- Always active; cannot be disabled
Optional Cookies
- Analytics: PostHog tracking (opt-in via consent banner)
- Error Tracking: Sentry error logs (opt-in via consent banner)
You can control optional cookies via our cookie consent banner and browser settings. See Section 9 below for our Cookie Policy.
10. Cookie Policy
Our cookie consent banner will appear on your first visit. Here's what each option means:
Accept All
Essential + Analytics + Error Tracking. We'll remember your preference for 365 days.
Decline Optional
Only essential cookies. We'll remember your preference for 365 days.
You can update your cookie preferences anytime via the "Cookie Settings" button in the footer or by clearing your browser cookies.
11. Weekly Pulse Communications
Upon completing your signup onboarding, you will receive weekly email summaries from Mojo that check your programmes, deadlines, and matches. This feature is on by default.
What You'll Receive
- Weekly Pulse Email: A summary of eligibility changes, approaching deadlines, and new program matches — sent Sunday evenings (Stockholm time)
- In-App Notifications: The same content appears in your Mojo dashboard
- Optional Push Notifications: Browser alerts for high-priority items (deadlines within 7 days, significant eligibility changes)
Your Control
You can manage weekly pulse settings at any time:
- Turn off emails: Settings → Notifications → Toggle "Email" off (messages still appear in-app)
- Adjust frequency: Set maximum messages per week (1–10, or unlimited)
- Manage all communications: Opt out of proactive insights, skill alerts, deadline reminders, or credential recommendations individually
- One-click unsubscribe: Every pulse email includes an unsubscribe link that toggles email delivery immediately
No penalties for opting out. You will never be penalized for disabling weekly pulse emails or any other proactive communications. Your access to the core platform remains unchanged.
12. Security Measures
We implement industry-standard security practices:
- End-to-end encryption (TLS 1.2+) for all data in transit
- Encryption at rest for sensitive data (passwords, assessment responses)
- Regular security audits and penetration testing
- Role-based access control for internal staff
- Incident response procedures for data breaches
While we strive to protect your data, no security is 100% guaranteed. You are responsible for maintaining confidential passwords and account information.
13. Contact & Data Protection Authorities
For privacy questions or to exercise your rights:
Email: privacy@iimaginer.com
Response Time: Within 30 days of your request
Data Protection Authority
If you believe your data protection rights have been violated, you may lodge a complaint with your local data protection authority:
- Finland: Office of the Data Protection Ombudsman
- Sweden: Datainspektionen
- Denmark: Datatilsynet
- EU: Your national Data Protection Authority
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by:
- Posting the updated policy on this page
- Updating the "Last Updated" date at the top
- Sending you an email notification (for major changes)
Your continued use of the platform after changes constitutes acceptance of the updated Privacy Policy.
This Privacy Policy is available in English. If there are conflicts between the English version and translations, the English version prevails.