Draft. Pending review by counsel.

Privacy policy

Last updated October 2026

CBOs of America is a workspace for community-based organizations (CBOs), schools, counselors, students, parents and universities. This policy explains what information the workspace holds and who can see it.

1. What we collect

  • Account details. Your name, email address, role and the organization you belong to.
  • Student records. Information that a student, a parent or the staff of a CBO or school enters, such as grade, graduation year, state, school, academic interests, GPA band, tasks, messages and completed forms.
  • Consent records. Who agreed to what, and when. This includes agreeing to be listed in the pool and agreeing to each release.
  • Waitlist details. Organization name, website, state, the number of students served, and the name, title and work email of the person who signed up.
  • Payment records. Payments are taken on a page hosted by Stripe. We keep the amount, the date and a reference from Stripe. We never see or store card numbers.
  • Security records. An audit log of sensitive actions, with the time, the account and basic request details such as IP address.

2. What we never collect

  • Race, ethnicity, nationality, ancestry, immigration status, disability or justice involvement.
  • FAFSA forms, tax returns or financial aid documents.
  • Information from anyone under 13. They cannot have an account.

3. Who can see a student record

A student record belongs to the CBO or school that works with the student. Staff of that organization can see it. The student can see their own. A linked parent or guardian can see their student's progress. Staff of other CBOs and schools cannot.

These limits are enforced by rules in the database on every table, not only by what the screens show.

4. How a profile is shared with a university

A university cannot read a student record. What happens instead:

  • A CBO may list a student in a pool, but only after a share consent is recorded. The adult student gives it, or the guardian of a minor. Staff cannot give it for a family.
  • In the pool, a university sees a de-identified block: a handle, graduation year, grade, state, student types, interests, GPA band and the name of the organization. There is no name, no contact detail and no free text.
  • A search that matches fewer than 10 students returns no results.
  • If a university asks for more information, the CBO decides first. Then the adult student, or the guardian of a minor, decides.
  • Only after both say yes can the university read the profile. Every read is written to the audit log.
  • A release can be revoked at any time, and access ends at once. Releases expire after 12 months.

5. No sale of data, no ads, no trackers

We do not sell or rent personal information. We do not use student information for advertising. No advertising or analytics trackers run on the site or in the workspace.

We use cookies only to keep you signed in and to protect forms. Where it is turned on, public forms use Google reCAPTCHA to stop automated abuse, and Google's own privacy policy applies to that check.

6. Companies that process data for us

We use a small number of service providers to run the workspace: Vercel for hosting, Supabase for the database and sign in, Stripe for payments and Resend for email. They process information on our behalf and only to provide those services.

7. Demo data

The public demo uses fictional people and organizations. Demo organizations and real organizations cannot see each other. Please do not enter real personal details in the demo.

8. Your choices

  • Students and guardians can decline any request and revoke any release from inside the workspace.
  • To correct or remove a student record, ask the CBO or school that manages it.
  • Time limits for keeping records, and how to make a formal request about your data, will be added here after review by counsel.

9. Security

The controls we use are listed on the security page.

10. Changes to this policy

If this policy changes, we will post the new version here with a new date.

Contact

Contact details will be published before launch.