Privacy
Last updated 2 August 2026
Your degree evaluation is a real academic record. This page explains, without hedging, exactly what happens to it — including which parts of it are sent to an AI company in order to answer your questions.
The short version
- Your files are read on the machine running AutoCounselor. The PDF itself is never uploaded anywhere else.
- To answer a question, details from your audit are sent to an AI model provider — by default Google. That includes your name, program, GPA, unit counts and the grades relevant to the question.
- If Google's model is unavailable, the same question is automatically re-sent to Anthropic instead. See the fallback note below.
- You can switch to a model that runs entirely on this machine, and then nothing leaves it.
- Signing in stores your email address — used to send sign-in codes and run the beta waitlist, and for nothing else.
- "Delete my data" really deletes it — your files, your audit, your conversation.
- We never sell your data, and never share it with your university.
What we hold
Things you give us
- Documents you upload — your degree evaluation, and optionally a transcript, CV or other file.
- The parsed contents of your degree evaluation: requirement blocks, courses, grades, units, GPA and your name as printed on it.
- Any edits you make to that parsed text, kept so the parser can be improved.
- Your stated goals (graduation term, unit load, what you want to do).
- Your messages to the counselor and its replies.
- Feedback you choose to give: a thumbs up/down, or a reported answer (which stores the question and answer so the mistake can be investigated).
Things we record about usage
Timestamped events — that a document was uploaded, that a question was sent, how long a reply took, how many tokens it used. These are counts and timings only and never contain the content of your documents or messages. Because they hold nothing about you, they are kept after you delete your data so we can still tell whether the product works.
Signing in
During the beta the app is sign-in only. That works with your email address and a six-digit code we send to it — there is no password. We store the email itself, whether it has been approved off the waitlist, when you last signed in, and how much of your included answering budget you have used. Sign-in codes and session tokens are stored hashed. The only cookie is the session that keeps you signed in (about 90 days); your email address never appears in the usage events described above.
Things we do not collect
No password, no payment details, no tracking pixels, no analytics SDKs, no advertising identifiers. Your workspace is identified by a random ID stored in your own browser.
Where your data is processed
Two different things happen to your audit, in two different places.
1. Reading your document — always local
Extracting the text from your PDF and turning it into structured requirements happens entirely on the machine running AutoCounselor, using ordinary software with no AI provider involved. Your PDF file itself is never transmitted to a third party.
2. Answering your questions — depends on the model you pick
The counselor is an AI model. You choose which one under "Answered by" next to the message box, and that choice decides whether your details leave this machine.
| Model | Runs | What that means |
|---|---|---|
| Gemini 3.1 Flash-Lite | The default. Details from your audit are sent to Google's Gemini API to generate each reply. | |
| Claude Sonnet 5 | Anthropic | Same, but sent to Anthropic. Also used automatically as a fallback — see below. |
| Qwen3.6 27B | This machine | Nothing leaves the machine. No AI provider is contacted at all. |
The automatic fallback, stated plainly. When Gemini is selected and Google's API fails or is unavailable — an outage, a rate limit, a spend cap — AutoCounselor does not show you an error. It silently re-sends the same question, with the same details from your audit, to Anthropic's Claude Sonnet 5 and answers from there.
So choosing Gemini means your data may reach either Google or Anthropic, and you will not necessarily be told which one answered. If you want exactly one provider to ever see your data, pick Claude Sonnet 5 directly — it has no fallback. If you want no provider to see it, pick Qwen3.6.
What exactly gets sent
When a hosted model answers, it receives what it needs to answer you and nothing more — but that is still a lot about you:
- Your name, program, degree, minor and catalog year as printed on your audit.
- Your units earned, units in progress, units still needed and your SDSU GPA.
- The requirement blocks and specific courses and grades relevant to your question.
- The goals you entered and the text of your question.
Your uploaded file is not sent. Your other documents are not sent unless they are relevant to the question you asked.
What the providers do with it
AutoCounselor uses these providers' paid API tiers. Both state that data submitted through their APIs is not used to train their models, and both retain data for a limited period for abuse monitoring. We do not control those policies and they can change — read them yourself:
Other outbound requests
When you ask about an instructor, AutoCounselor may look them up on RateMyProfessors to show their public rating and link to it. That request contains the instructor's name only — never your name, your audit or your question. Course schedules and catalog data are already stored locally and require no outbound request.
For questions its data cannot contain — a registrar deadline, an office's hours — the counselor may run a web search (DuckDuckGo). What leaves is the search query only: a short topic phrase the model writes, never your name, your audit, or your conversation. Results are treated as unverified and cited with their links. The counselor is built to prefer its own verified data and refuses to search for anything that data already covers.
Keeping and deleting
- Your workspace stays until you delete it. There is no automatic expiry.
- Delete my data, on the Documents tab, removes your uploaded files, your parsed audit, your goals, your entire conversation and any answers you reported. It cannot be undone.
- Deleting your workspace keeps your sign-in (the email address), so you can start over. To erase the account and email too, ask at the contact address below — the whole record goes.
- Content-free usage events (see above) are kept, because they contain nothing about you.
- Deleting here does not reach back into the providers' own logs; their retention is governed by the policies linked above.
This is not official advising
AutoCounselor is not affiliated with, endorsed by, or operated by San Diego State University. It cannot register you for classes, change your record, or make any decision binding on the university. It reads the audit you give it. Always confirm decisions that matter with your campus advisor and the registrar.
Changes and contact
If this page changes in a way that affects where your data goes, the date at the top changes and the change will be called out in the app.
Questions, or want your data removed and you cannot reach the button? Contact autocounselor.support@gmail.com.