Last updated: September 19, 2026
Privacy Policy
CarryOver, operated by RitzyLabs LLC ("CarryOver," "we," "us"), helps students understand how their college credits transfer. We take the privacy of your academic records seriously. This policy explains what we collect, how we use it, and the choices you have.
Information we collect
- Account information: your email address, and any name or profile details you choose to provide.
- Transcript and academic data: when you upload a transcript, we read the courses, grades, credits, and institutions it contains to build your transfer map. You review and confirm the course list before it becomes your saved transcript. The original upload is temporary; see "How we handle transcripts" for cleanup timing and provider retention.
- Saved Texas comparisons: if you choose to save a report, we store your course entries, selected field and destinations, scope confirmation, and a dated report snapshot in your account. The unsaved worksheet runs in the page; saving sends entries to CarryOver and Supabase. This comparison does not require a transcript upload or send your entries to an AI provider. You can delete reports individually or erase your student data.
- Usage data: request counts, feature-use events and technical error logs to keep the service running and improve it. Operational logs may include account identifiers, request paths and connection information. We do not use third-party advertising or cross-site tracking.
- Purchase acknowledgments: we retain the recipient, purchased scope, email content, delivery attempts and provider message identifier to deliver and support your purchase. These billing records remain when you erase student planning data.
- Payment data: when you buy a paid plan, payment is processed by our payment provider (Stripe). We do not store your full card number; Stripe handles card data under its own security standards.
How we use your information
- To parse your transcript and generate your transfer maps and degree-requirement analysis.
- To operate, maintain, and improve CarryOver, including improving parsing accuracy.
- To communicate with you about your account, including sign-in links and service or product updates you've opted into.
- To process payments and prevent fraud.
How we handle transcripts
- Upload: the file goes into a private storage bucket. Our server issues a temporary upload link for your account and reads the file to process it; the bucket does not expose a public file listing.
- Reading it: we send the document to Anthropic through its commercial API to extract courses. Anthropic states that commercial API content is not used for training without express permission. We do not authorize training on your transcript. Its standard API retention is up to 30 days, with exceptions for policy enforcement, legal requirements and some services or models. Deleting a file from CarryOver does not immediately delete a processor's retained copy. See Anthropic's retention policy.
- What we keep: the course list you confirm (course codes, titles, units, grades, terms, and the issuing school). We attempt to remove the original file immediately after processing. Leftover or abandoned uploads can remain if cleanup does not complete. Verification of scheduled cleanup is still in progress, so we cannot currently promise an automatic deletion deadline. You can request deletion or confirmation of removal by emailing support@getcarryover.com.
- What we do with it: match your courses against published articulation and transfer rules for the schools you choose. If you use the planning assistant, the confirmed course list is included in what is sent to Anthropic to answer your question.
- Improving accuracy: when we look at parsing mistakes to fix them, we use anonymized or aggregated information that does not identify you.
You can delete your transcript at any time from your account settings, or by emailing us.
Sharing and disclosure
We share personal data only with the service providers below, only as needed to provide the service, and each under its own contractual terms:
- Supabase — hosts our database, sign-in, and the private storage bucket that holds transcript uploads.
- Vercel — hosts the application and provides cookieless page-view and feature-use analytics. Custom event properties use fixed categories, such as the selected field, campaign, public guide or referring service (for example, a search engine, AI assistant or social platform); they do not include your email, course entries, account identifier or full referring URL.
- Anthropic — reads uploaded transcripts and powers the planning assistant, as described above.
- Stripe — processes payments; we never see your full card number.
- Resend — delivers sign-in links and account emails.
We may disclose information if required by law or to protect our rights and users' safety. We do not sell or share your personal information for advertising, and we do not use it for cross-context behavioral advertising.
Cookies
We use essential cookies to keep you signed in and secure your account. Clearing them signs you out. We do not use advertising or cross-site tracking cookies. Vercel Web Analytics and Speed Insights measure page visits, feature use and performance without analytics cookies; our feature events contain counts and planning choices, not uploaded document text or chat messages. See Vercel's analytics privacy documentation. Stripe may use its own cookies to process payments and prevent fraud, under its privacy policy.
Data retention and security
We keep your data while needed to provide the service, meet recordkeeping obligations and prevent abuse. Data is encrypted in transit; transcript uploads are private, and server-side access checks limit each student's access to their own records. No method of transmission or storage is 100% secure. Backups and service-provider logs can retain information after deletion from the active application, subject to their retention schedules.
Erasing your data
"Erase my data" in your account settings removes your confirmed transcript, saved schools, majors and minors, planned courses, saved Texas reports and home college, and attempts to remove remaining transcript uploads. Storage cleanup can fail even when saved plan data has been removed; contact support@getcarryover.com if you need confirmation that an uploaded file was removed. The action does not close your account or immediately purge backups and provider logs. These records are kept:
- Your sign-in identity (your email address), so that you can sign back in to an empty account. Email us if you want the account itself closed.
- Billing records, only if you have ever bought a paid plan — the plan you hold, its dates, and the identifiers our payment processor uses — so that you keep the access you paid for, can still reach the billing portal, and a refund or cancellation can still find your account. We also keep these as long as tax and accounting rules require.
- Usage and abuse-prevention records — account-linked transcript-read and assistant-message counts and rate-limit records. New allowance periods start automatically; erasing plan data does not reset today's allowance or delete historical quota records.
Your choices and rights
- Delete your transcript, or erase your plan data, yourself from your account settings (see "Erasing your data" for the three records that are kept, and why).
- Access or correct your personal data, or request deletion, by emailing us.
- Opt out of non-essential emails using the unsubscribe link or by contacting us.
Children's privacy
CarryOver is intended for college and prospective transfer students. It is not directed to children under 13, and we do not knowingly collect their personal information.
Changes to this policy
We may update this policy from time to time. We'll post the new version here and update the "Last updated" date above; material changes will be communicated where appropriate.
Contact us
Questions about privacy or a data request? Email support@getcarryover.com.