Got In! — Privacy Policy
Last updated: June 12, 2026
Got In! ("Got In!", "we", "us", "our") helps prospective college applicants import their own college-application data and compare admissions outcomes with peers, under their control. The service has two parts:
- the Got In! Chrome extension, which reads a small set of application data from pages you open on supported application platforms and college portals, and
- the Got In! web app at
https://www.got-in.app, where your data is stored and the comparison and social features live.
This policy explains exactly what we collect, how we use it, who we share it with, and the choices you have. It applies to both the extension and the web app. If you don't agree with it, please don't install the extension or use the web app.
1. Single purpose of the extension
The Got In! extension has one purpose: to let you export your own college application data from the application platforms you use (the Common Application, the University of California application, and Cal State Apply) into your Got In! account, and to optionally save and autofill your college-portal logins so you can check your admission decisions. Everything the extension does serves that purpose.
2. Information we collect
2.1 Application data you choose to import
We practice data minimization: the extension reads and stores only the specific fields the product uses, and nothing else. When you are signed in and import (or have enabled automatic import on your first run), we collect, from the application pages you have open:
- Name — your first and last name.
- High school — name, city/state, CEEB code, and expected graduation year.
- College list — the colleges on your application and your intended / first-choice major for each.
- Academics — GPA; SAT, ACT, and AP test scores.
- Application status & decisions — whether an application was submitted, and any admission decision you record or that is detected on a college portal.
That is the complete list of application data we collect.
We explicitly do not collect — and our servers do not store — your date of birth, sex, gender, or pronouns, race or ethnicity, citizenship or immigration status, birthplace, military status, languages, fee-waiver status, home address or phone number, family / parent / sibling information, individual course lists, class rank or class size, your application essays, or your extracurricular activities and awards. The extension does not read those sections of your application.
We read this data only on the supported application platforms and college portals listed in the extension's permissions, and only while you are signed in to Got In!. We do not read your email, your browsing history, or your activity on other websites.
2.2 Account information
- Your email address and password, to create and sign in to your account. Authentication is handled by Amazon Cognito; your password is managed by Cognito and is never visible to us.
- A screen name that you choose — your public, anonymous alias. You can change it at any time.
2.3 Saved college-portal logins (optional)
If you ask Got In! to remember a college-portal login, we store the username and password you entered for that portal so we can autofill it on your return. Saved passwords are encrypted with AWS Key Management Service (KMS), are never shown to other users, and can be deleted by you at any time. We only offer to save a login after you have successfully signed in to a portal yourself; we never capture a login you have not entered.
2.4 Profile images (optional)
- Avatar. If you upload an avatar, we store the image and show it on your profile and next to your name everywhere in the app, including to strangers — it is your anonymous public identity.
- Real photo. You may optionally add a "real photo" in addition to your avatar. It is shown only to your accepted friends and active group co-members — the same people who can see your real name — and never to strangers. It is only ever shown on top of an avatar (you must have an avatar first), and you can remove it at any time.
Both are automatically screened for objectionable content using Amazon Rekognition before they are saved, and either can be removed at any time.
2.5 Content you create
The discussion and direct messages you post, and the friend requests and groups you create or join.
2.6 Technical information
- Authentication tokens stored locally in your browser (the extension's
storagepermission) so the extension can call the Got In! API on your behalf. These stay on your device. - Standard server and error logs generated when your browser or the extension calls our API.
3. How we use your information
We use the information above to:
- build your Got In! profile and show you your own application data;
- power the comparison and sharing features so you can see peer outcomes for the colleges you applied to;
- save and autofill your college-portal logins, if you ask us to;
- send you service emails (for example, "someone wants to be your friend");
- screen uploaded avatars and real photos for objectionable content; and
- operate, secure, debug, and improve the service.
We do not sell your personal information. We may show advertising in the future as the service grows; if we do, we will not use the college-application data collected through the extension to target or personalize those ads. We have no current plans to use your data to train machine-learning or AI models — if that ever changes, we will update this policy first. In all cases, data obtained through the Chrome extension and through Google APIs is used only in ways consistent with the Limited Use commitments in Section 6.
4. How your information is shared with other users
Got In! is a peer-comparison product, so some data is shown to other users — but only according to a tiered model based on your relationship to them, which you control:
| Data | Anyone (strangers) | Group co-members | Accepted friends |
|---|---|---|---|
| Screen name + avatar | Shown | Shown | Shown |
| High school | Shown | Shown | Shown |
| College list + intended major | Shown | Shown | Shown |
| Real name | Hidden | Shown | Shown |
| Real photo (optional) | Hidden | Shown | Shown |
| City, state (on your profile) | Hidden | Shown | Shown |
| GPA, SAT/ACT/AP scores, admission decisions | Reciprocal * | Reciprocal * | Shown |
Why your high school is public. Got In!'s core feature is comparing outcomes within and near your high school, so your high-school name is shown alongside your anonymous screen name to everyone (including in the school-grouped comparison and applicant lists). Your finer location — city and state — is not public; it is shown only to group co-members and accepted friends.
* Reciprocal decision sharing. If and when you share your admission decision for a college, you also share your GPA and test scores — and in exchange, you can see the GPA, test scores, and decisions of other students who have shared their decision for that same college. Accepted friends see your GPA, test scores, and decisions directly, without this exchange.
You decide who your friends and group co-members are; removing a friend or leaving a group withdraws the corresponding access. Never shared with other users: your saved portal logins, email address, and password.
5. Service providers (sub-processors)
We use a small number of reputable providers, which process data only to provide their service to us:
- Amazon Web Services (AWS) — hosting, database, file storage, encryption (KMS),
authentication (Cognito), avatar screening (Rekognition), and transactional email (SES). Data is stored in the
AWS US West (Oregon,
us-west-1) region. - Supabase — stores and delivers discussion and direct-message content in real time.
We do not otherwise share, rent, or sell your personal information. We may disclose information if required by law, to protect the rights and safety of our users, or as part of a business transfer (in which case we will notify you).
6. Limited Use
Got In!'s collection and use of information from the application platforms adheres to applicable Limited Use requirements, including the Chrome Web Store User Data Policy. We collect and use this data solely to provide and improve the single purpose described in Section 1. Specifically, the data obtained through the extension is never sold, never used to target or personalize advertising, and never used to train AI/ML models — even if we introduce advertising or AI features elsewhere in the product.
7. Data retention and deletion
- You can delete your account at any time from the web app. This removes your profile, imported application data, saved logins, avatar, real photo, and messages from our active databases.
- You can delete individual saved portal logins and remove your avatar or real photo without deleting your account.
- Routine backups and server logs may persist for a limited period before being overwritten.
To request deletion or ask a privacy question, contact us (Section 12).
8. Security
- All traffic between your browser/extension and our servers is encrypted in transit (HTTPS/TLS).
- Saved portal passwords are encrypted at rest with AWS KMS.
- Your account password is managed by Amazon Cognito and is never stored by us.
- Databases run in a private network segment that is not publicly reachable.
No method of transmission or storage is 100% secure, but we protect your information using industry-standard safeguards.
9. Children's privacy
Got In! is intended for prospective college applicants, who are generally 16 or older. The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are under 18, please review this policy with a parent or guardian before using Got In!. If you believe a child under 13 has provided us personal information, contact us and we will delete it.
10. Your choices and rights
- Access / correction — view your imported data in the web app; edit your screen name, avatar, and real photo; re-import to refresh your application data.
- Deletion — delete saved logins, remove your avatar or real photo, or delete your entire account, as described in Section 7.
- Depending on where you live, you may have additional rights (for example, under the CCPA/CPRA or GDPR) to access, correct, delete, or port your data, or to object to certain processing. Contact us to exercise these rights.
11. International users
We operate in, and store data in, the United States. If you access Got In! from outside the U.S., you understand your information will be processed in the U.S.
12. Changes to this policy & contact
We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, provide a more prominent notice. Continued use of Got In! after a change means you accept the updated policy.
Questions, requests, or concerns about privacy:
Email: privacy@got-in.com
Got In!
← Back to Got In!