Secure by design.
Private by default.
Your documents, assessments and conversations are protected by the same standards universities demand — and governed by one rule: nothing about you moves without you.
Six promises,
kept in code.
Not a policy page — an architecture. These are enforced in code rather than in a document, and where a promise is still being wired the promise says so.
- You own everything
Delete your account and everything goes with it — profile, documents, assessments, chats — immediately, with no waiting period. Uploaded files are erased in the same action as the records that describe them, not on a separate request. And if any part of an erasure fails, we stop and tell you rather than delete the account anyway.
- Consent gates every share
Nothing is shown to a university without your explicit yes — enforced every time a university reads a record, and reversible from your settings the moment you change your mind. Employers additionally sit behind four visibility levels you set and can change any time.
- Your answers never train AI
AI providers process your data transiently for your session only — never for model training, never retained.
- Hosted in the EU
Production data lives in Frankfurt under GDPR. Nothing leaves the EU without legal basis and your knowledge.
- Minors are protected
Under-16s require verified parental consent, and minors are never visible to employers without guardian approval.
- Receipts for everything
Every claim, share and system action leaves an audit trail you can read. Read one in full ↓
The hard layers
Encryption
At rest & in transitAES-256 at rest, TLS 1.3 in transit, SSL-enforced database connections. Secrets live in encrypted vaults — never in code or logs.
Privacy policyIsolation
Database-levelRow-Level Security means your data is invisible to anyone else at the database layer. A compromised page cannot query what it was never allowed to see.
Ask for the architecture notesAI safety
Ephemeral by designMojo's AI calls are scoped to your session and forgotten after. Derived insights are stored with provenance; raw prompts are not.
How Mojo worksOne receipt,
in full.
This is what "every claim carries its receipt" means in practice: one programme, one verdict, and every rule behind it with the document line it was read from. Nothing here is summarised for the marketing page — these are the fields the engine stores.
Worked example · an illustrative student and an illustrative programme · the fields, the rule sources and the verdict grammar are the real ones
- Your document said
- Bằng tốt nghiệp THPT — upper-secondary diploma, 2026
- Found at
- Diploma · p.1
- The rule requires
- Completed upper-secondary education
- Rule
- Bedömningshandboken · 2026 · Vietnam
- Your document said
- IELTS Academic 6.5 overall, no band below 5.5
- Found at
- IELTS certificate · p.1
- The rule requires
- IELTS 6.0 overall, no band below 5.5
- Rule
- universityadmissions.se · English 6 equivalence
- Your document said
- Toán 12 — 8.6 / 10
- Found at
- Transcript · p.2, line 4.2
- The rule requires
- Matematik 3c or equivalent
- Rule
- Bedömningshandboken · 2026 · Vietnam · Math
- Your document said
- not present in the documents you uploaded
- Found at
- — no source, so no claim
- The rule requires
- Matematik 4 (särskild behörighet A9)
- Rule
- Bedömningshandboken · 2026 · A9
One upper-secondary maths course stands between this student and a green verdict. Every other rule on this programme is already met — which is the only reason we can say that with a straight face.
Solid means a rule said yes. Anything we estimate is drawn dashed and labelled an estimate — no receipt, no claim. Your own verdicts look exactly like this, one per programme, and they update when the rules do.
Who touches
your data
| Service | Purpose | Region |
|---|---|---|
| Supabase | Database, auth, file storage | EU · Frankfurt |
| Vercel | Hosting & edge delivery | EU edge |
| Anthropic (Claude) | AI analysis — transient, no training | US · SCCs |
| OpenAI | Backup AI provider — transient, no training | US · SCCs |
| Perplexity | Market & job research — transient, no training | US · SCCs |
| PostHog | Product analytics | EU · Frankfurt |
| Stripe | Payments (universities only) | EU / US |
| Sentry | Error tracking — PII scrubbed | US |
| Resend | Transactional email | US |
| Loops | Lifecycle email & lead events | US |
| Inngest | Background jobs — task metadata includes user identifiers | US |
| PDFShift | Report rendering — receives report HTML, and a session on the export path | US |
| Upstash | Rate limiting | EU |
These are the processors we have verified as touching personal data; the list that is contractually complete travels with the Data Processing Agreement, which is available on request along with every sub-processor DPA. Standard Contractual Clauses govern the US transfers, and the AI providers process prompts transiently — nothing stored, nothing used for training.
Your rights, in full
| Right | What it gets you |
|---|---|
| Access | A complete copy of every piece of personal data we hold about you. |
| Rectification | Correct anything inaccurate or incomplete, at any time. |
| Erasure | Delete the account and the records in it, permanently and without a waiting period. Uploaded files go in the same action. |
| Restriction | Freeze processing while a complaint is being resolved. |
| Portability | Export your data in a structured, machine-readable format. |
| Objection | Object to processing based on legitimate interests or direct marketing. |
Erasure and portability are one action each from your dashboard. For anything else — or if you have no account and want an address erased — write to privacy@iimaginer.com. GDPR gives us one month to respond and we aim to be well inside it.
Fair questions
Where is my data stored?
Production data is stored in the EU (Frankfurt). Requests are served from EU edge locations, and nothing is replicated outside the EU without explicit legal basis.
Do you use my data to train AI?
No. Prompts, assessment answers and documents are processed transiently by our AI providers for your session and are never used for model training.
Who can see my child’s documents?
Only your child — until they explicitly consent to share. Universities see verified profiles only after that consent, and minors are never exposed to employers without guardian approval.
How do I delete everything?
One action from your dashboard: the records go immediately and permanently, with no waiting period, and your uploaded files go in the same action — there is nothing separate to ask for. If any part of an erasure fails we stop and tell you, and your account stays open so it can be finished, rather than deleting the account over an incomplete erasure.
How do you handle a breach?
Incident response with notification to affected users within 72 hours as GDPR requires, with full impact and remediation detail.
How do I report a vulnerability?
Write to security@iimaginer.com with the details. We do not pursue legal action against good-faith security researchers.
Nothing about you,
without you.
Read the privacy policysecurity@iimaginer.com · privacy@iimaginer.com