Privacy Policy
Last updated: 27 August 2026. SchoMatch is operated by Mohamed Alfaki, based in Doha, Qatar. This policy explains what we collect, why, and how you stay in control.
1. Data we collect
Account data: your name, email address and authentication identifiers (including Google sign-in identifiers if you use it).
Academic and profile data: study level, field of study, country of residence, target countries, education history, research interests, publications, skills, languages, awards and referee details you enter.
CV and documents: CV/resume files (PDF, Word or image), certificates, transcripts and any other documents you upload, plus the text extracted from them.
Generated content: cover letters, statements, improved CVs and supervisor or referee emails created for you, and the applications you track.
Waiting-list data: the details submitted in the early-access form.
Billing data: subscription status and transaction references. Card and bank details are collected and stored by Paddle, never by SchoMatch.
Technical data: log data and basic usage/diagnostic information needed to operate and secure the service.
2. How we use your data
To create and secure your account; to build your scholarship profile from your CV; to match and rank opportunities and explain eligibility gaps; to draft and improve application documents; to track deadlines and application progress; to send service and waiting-list emails; to process subscriptions; and to detect abuse, debug problems and improve the platform.
We do not sell your personal data and we do not use it for third-party advertising.
3. AI-assisted processing
Profile extraction, matching explanations, CV improvement and document drafting are AI-assisted. Relevant content — such as CV text, profile fields and the details of the opportunity you selected — is sent to third-party AI model providers through a secure gateway solely to produce your output. AI output can contain errors or omissions and must be reviewed by you before use or submission.
4. Storage, hosting and authentication
Accounts, database records and uploaded files are stored using Supabase infrastructure (managed via Lovable Cloud), which also provides authentication. Files are held in access-controlled storage and database rows are protected by row-level security so users can access only their own records. Data may be processed on servers outside your country of residence.
5. Payments
Subscription payments are processed by Paddle.com Market Limited, which acts as Merchant of Record and is an independent data controller for payment data. Paddle collects your payment method, billing address and tax information directly; SchoMatch receives only the subscription status and non-sensitive transaction metadata needed to activate your plan.
6. Retention
We keep account, profile and document data for as long as your account is active, and for up to 30 days after deletion in routine backups. Waiting-list entries are kept until launch communications are complete or you ask us to remove them. Billing and tax records are retained by Paddle for the period required by law.
7. Security
Data is transmitted over HTTPS/TLS, files are served through short-lived signed URLs, and access is restricted by authentication and row-level security policies. No system is perfectly secure; please use a strong, unique password.
8. Your rights and deletion requests
You may access, correct, export or delete your data. You can delete uploaded documents from your account at any time. To request full account and data deletion, or to exercise any other data right, email support@schomatch.com. We respond within 30 days.
9. Children
SchoMatch is not intended for users under 16 years of age.
10. Changes and contact
We will update this page when our practices change and adjust the "last updated" date. Questions: Mohamed Alfaki, Doha, Qatar — support@schomatch.com.