1. Scope, Eligibility, and Definitions
This Privacy Policy explains how Application Review Co collects, uses, discloses, retains, and protects personal information through its website, free diagnostic, paid document reviews, private delivery pages, email communications, and privacy-request process.
By using the service, you represent that you have reached the age of majority where you live and have capacity to accept the Terms. In this policy, "applicant content" includes documents, extracted text, prompts, notes, communications, reports, and related application information. "Personal information" means information about an identifiable person, subject to the law that applies in context.
2. Information Categories, Sources, and Purposes
Depending on how you use the service, we may collect:
- identity and contact details, including name, email address and required cell phone number; location, application pathway, program, school, status, referral, and target information;
- document type, original and safe filenames, file metadata, checksums, source document, extracted text, prompts, limits, and notes;
- diagnostic reports, paid-review materials, revisions, delivery events, and service status;
- consent versions, timestamps, audit events, IP address, user agent, portal state, and security events;
- order, payment, refund, dispute, tax, and accounting records; and
- communications, privacy requests, complaints, identity-verification state, exceptions, and legal-hold records.
The diagnostic and paid-package forms require a cell phone number as part of your service contact record. We use contact information to administer your request or order and address service questions. Providing a number does not subscribe you to promotional calls or texts.
We receive information from applicants, their submitted files and messages, first-party website interactions, payment and delivery events, security systems, and service providers. We use it to assess requests, provide and deliver reviews, communicate, maintain records, protect the service, prevent abuse, resolve disputes, respond to privacy requests, and meet legal obligations.
3. Required Applicant Documents
A free diagnostic request requires one complete, structurally valid .docx file together with the intake details, prompt, limits, and instructions needed to assess the document. We may create a safe filename, checksum, extracted text, diagnostic report, service record, and delivery record to receive, evaluate, secure, return, and support the requested service.
The diagnostic form accepts only a Microsoft Word (.docx) file up to 4 MB. Paid-review uploads accept only Microsoft Word (.docx) files up to 20 MB each, subject to the selected package and file validation. For packages that allow reserved document slots, we store the slot details at checkout and receive the file when you upload it through your private portal. Applicant replacement and revision uploads also require .docx files. PDF, legacy .doc, TXT, RTF, and ODT submissions are not accepted. Follow-up uploads and returned reviews become part of that service record.
Every free diagnostic and paid full review receives substantive evaluation from two reviewers. Applicant content may be made available to assigned reviewers and authorized personnel for that evaluation and related quality, support, security, recordkeeping, or legal purposes.
Applicant content is not used for advertising, testimonials, public samples, research, or training without separate written permission for the exact use. We do not send applicant documents, narratives, filenames, school lists, medical details, report identifiers, or portal tokens to advertising platforms.
4. Access and Recipient Categories
Access is limited by role to authorized personnel, assigned reviewers, and providers that reasonably need information to operate or support the requested service. Reviewer assignment may consider field, document type, relevant experience, availability, and conflicts. No particular reviewer or exact specialty match is guaranteed.
Recipient categories may include cloud hosting and storage, email delivery, payment processing, operational communications, security and technical support, professional advisers, and authorities where disclosure is legally required. A recipient receives only the information reasonably needed for its role, subject to available contractual, organizational, or legal safeguards.
We may also disclose information when reasonably necessary to comply with law or legal process, investigate fraud or security incidents, enforce applicable terms, or protect applicants, reviewers, the operator, or others.
5. International and Cross-Border Processing
Applicants and service providers may be located in different countries. Information may be processed outside your country and may be subject to the laws, lawful access rules, and courts of the jurisdiction where it is processed.
We use reasonable measures appropriate to the information and processing relationship, but privacy rights, safeguards, and provider practices vary by jurisdiction. This policy does not represent that every jurisdiction provides the same protections as your home jurisdiction.
6. Cookies, Browser Storage, Analytics, and Attribution
We use cookies and browser storage for service functions such as remembering consent choices, maintaining private access, tracking request progress, and resuming an unfinished checkout. Checkout-resume information in browser session storage is accepted for up to 24 hours. The analytics-choice cookie is set for 180 days. Your browser may remove these records sooner.
We may collect first-party attribution and usage information actually generated through the current website, including referring page or domain, UTM and click identifiers, landing and public page context, device and browser context, form and navigation interactions, and performance or error information.
We use this information to understand how visitors find and use public pages, attribute request activity, improve form usability and service reliability, protect against abuse, and troubleshoot errors. We do not use applicant documents or private applicant identifiers as advertising-platform content.
When enabled, optional Meta Pixel and server-side marketing measurement operate only after you allow analytics. They help measure public-page visits, contact or diagnostic requests, checkout starts, and purchases. Measurement may include the public page, event type and time, an event identifier, a broad service category, and purchase value and currency. Meta's browser technology may also process IP address, browser or device information, and cookie identifiers under its own privacy policy.
We do not include applicant names, email addresses, phone numbers, documents, messages, or other private applicant content in the marketing event fields we send. Our marketing tracking does not run on private applicant, diagnostic, portal, or administrator routes. Operational records and security controls remain separate from optional marketing measurement.
You may decline optional analytics and still request or buy a review. To change a saved choice, clear this website's cookies in your browser and reload the website to choose again when the analytics prompt is available. Clearing browser storage may also remove saved checkout progress or require you to reopen a private access link.
7. Payments and Order Information
A free diagnostic does not require payment. You may purchase a paid package directly or accept a custom offer. We may keep order amount, selected service and document slots, currency, tax, payment status, transaction reference, refund, dispute, and accounting information needed to administer the order and meet financial or legal obligations.
Stripe processes checkout and receives information needed to process payment, including your email address and order references. Stripe may offer an eligible local-currency payment amount. Application Review Co does not store full payment card numbers, security codes, or full payment credentials; we retain limited transaction and status records.
8. Operational and Promotional Communications
Operational email may confirm a request, ask for a corrected file, provide status or delivery information, support an order, answer a question, address security, or respond to a privacy or legal matter. These communications are part of providing or administering the service.
Authorized staff may receive operational SMS or push alerts about requests, payments, and document activity. Those alerts may contain limited service information such as an applicant name, service type, or an administrator link and are handled by the relevant communications provider. They are not text messages to applicants.
Promotional email requires separate, optional consent and must provide the choices required by applicable law. We do not send applicant SMS in this workflow. Please avoid sending unnecessary sensitive information through email.
9. Sensitive and Third-Party Information
Application documents can contain sensitive personal narratives. Do not submit information that is unnecessary for the review, including patient names, government identifiers, payment credentials, complete health or immigration records, confidential employment records, or details about another person that are not needed to understand the application narrative.
You must have authority to share third-party information. Where a relevant story can be told without identifying another person, use non-identifying details. Do not submit unlawful, malicious, plagiarized, institutionally restricted, or improperly obtained material.
10. Retention, Deletion, and Legal Holds
Our current target schedule is:
- Failed or incomplete uploads: targeted for 7 days after the failed or incomplete attempt.
- Free-diagnostic materials: targeted for 12 months after delivery. A cancelled, declined, abandoned, or undelivered valid request uses 12 months after the last service activity.
- Paid-review documents, revisions, and deliverables: targeted for 24 months after completion. Cancelled, abandoned, or incomplete paid work uses 24 months after cancellation or the last service activity, whichever is later.
- Contact inquiries: targeted for 24 months after closure, or after the last inbound or outbound message if the inquiry is never formally closed.
- Consent, policy-version, dispute, and material service records: targeted for 7 years after the material service event.
- Payment, accounting, and tax records: targeted for 7 years after the applicable transaction or reporting period.
- Routine security and access logs: targeted for 12 months after creation.
- Backups: handled through the ordinary backup cycle, targeted at 90 days.
- Legal holds, fraud, disputes, and regulatory obligations: retained as reasonably necessary.
An error record that still references an uploaded object follows the failed-or-incomplete-upload target unless a legal hold or active incident investigation applies. Retention eligibility is reviewed separately from an authorized deletion action.
Deletion may be delayed or limited by legal duties, disputes, fraud or security investigations, provider capabilities, and technical recovery needs. Provider copies, email records, infrastructure logs, or backups may not be deleted immediately and may remain until an ordinary provider or backup cycle completes.
11. Security Safeguards and Private Links
We use reasonable administrative, technical, and organizational safeguards designed to protect applicant information, including access limits and private delivery controls appropriate to the current service. No online system or transmission method eliminates every security risk.
Private report links and credentials should be kept confidential and not forwarded or posted. Use care on shared devices and notify us if a private link may have been exposed. If an incident requires notice under applicable law, notice will be provided as that law requires.
12. Access, Correction, Export, and Deletion Requests
Depending on your location and the law that applies, you may request access to, correction of, export of, or deletion of personal information associated with you. Send a request to myapplicationreviewteam@gmail.com.
Requests use a human-supervised process led by the Privacy Lead, Application Review Co We may use proportionate identity verification and will avoid requesting unnecessary additional sensitive information. Our internal target of 30 calendar days does not replace a shorter or longer period required or permitted by applicable law.
A request may remain open while an internal store or known provider follow-up is unresolved. Access or deletion may be limited by identity concerns, another person's rights, legal holds, disputes, fraud, security, financial-record duties, or other exceptions allowed by law.
13. Changes, Complaints, and Contact
We may update this policy prospectively as the service, providers, practices, or law changes.
Questions or complaints may be sent to myapplicationreviewteam@gmail.com. We will review a complaint and explain available next steps. Where applicable, you may also contact the privacy or data-protection authority responsible for your jurisdiction.