1. Who we are and scope
UniversityMatch (also known as UniMatch) is a university discovery and application-organization platform operated under the UniversityMatch brand at universitymatch.com.br. This policy applies to the website, account, and related features.
Our privacy contact is universitymatchbr@gmail.com. We may request information to verify your identity before fulfilling a request.
2. Data we process
- Account: name, email, language, picture and, for native accounts, a securely hashed password — never plain text.
- Google sign-in: account identifier, verified email, name, and picture through openid, email, and profile scopes. We do not access your Google password, Gmail, Drive, contacts, or calendar.
- Profile: study country, education, graduation year, GPA/grades, tests, certificates, activities, intended field, and financial, climate, and location preferences.
- Product use: saved schools, categories, comparisons, applications, statuses, deadlines, tasks, and notifications.
- Submitted content: bug reports and data found in PDFs voluntarily uploaded to import applications.
- Security: session cookie, browser/device, request identifiers, and hashes of IP and user agent in security events.
3. Why we use data
- Create and protect your account, authenticate access, and prevent fraud, spam, and abuse.
- Calculate explainable compatibility, personalize discovery, and organize your journey.
- Perform requested imports and send transactional messages or enabled reminders.
- Provide support, investigate failures, maintain availability, and improve the product.
- Meet legal obligations and protect users, UniversityMatch, and third parties.
4. Legal grounds
Depending on context, we process data to provide the service and perform our contract with you; with consent for optional features; for legitimate interests such as security, abuse prevention, and improvement; and to meet legal obligations. Optional consent may be withdrawn without affecting prior or necessary processing.
5. Google user data
When you choose “Continue with Google,” basic data is used solely to authenticate, create or link your UniversityMatch account, and refresh name and picture. We do not use Google data for advertising, sell it, or transfer it to data brokers.
Use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including Limited Use. Temporary tokens are not used for other Google products or retained for unrelated purposes.
8. International transfers
Some providers may process data outside Brazil. We seek reputable providers and mechanisms compatible with applicable law, limiting processing to what is necessary to operate the service.
9. Security
We use HTTPS, access controls, Argon2id password hashing, opaque sessions, protected logs, abuse limits, and encryption for temporary PDF payloads. Backups are protected and operational access is restricted. No system is infallible; relevant incidents will be handled and notified as required by law.
10. Retention and deletion
- Account and profile data remain while active or needed for the service and legitimate obligations.
- Authentication transactions expire and are removed; identifiable email-delivery metadata is anonymized after the configured operational period, currently 90 days.
- A Common App PDF is used for the requested import, not as a permanent library; it is protected during processing and removed within 24 hours after the job completes or fails.
- You can download a structured copy of your data and delete the account directly from Your account. After deletion, we delete or anonymize linked data except where law, security, fraud prevention, or legal claims require retention. Residual copies expire through backup rotation.
11. Your rights
Under Brazil’s LGPD, you may request confirmation and access, correction, sharing information, portability when regulated, anonymization, blocking or deletion where applicable, objection, consent withdrawal, and review or explanation of automated decisions. Contact us; after first trying to resolve the matter with us, you may also petition Brazil’s ANPD.
12. Automated matching
Compatibility percentages are recommendations based on your profile, preferences, and university data. They do not decide admission or replace official evaluation. You may view reasons in the product and request clarification or review through our contact.
13. Children and teenagers
Teenagers may use UniversityMatch with their best interests in mind and parent or guardian knowledge and authorization where required. The service is not intentionally directed to children under 13. Guardians may contact us about improperly submitted data.
14. Changes
We may update this policy for product, security, or legal changes. Material updates will be highlighted in the product or sent to the account email when appropriate. The date above identifies the current version.