Privacy Policy
Macademia lets business schools discover and contact candidates who complete a profile. We use only the data needed to run that service, keep primary production data in the EU, and never sell personal data.
1. Who we are
Macademia is operated by Macademia UG (haftungsbeschränkt), Wiener Str. 61, 60599 Frankfurt am Main, Germany, registered at the Amtsgericht Düsseldorf under HRB 114262 ("we", "us") — see our Imprint · Image credits for full details. We are the data controller for the personal data described in this policy. Macademia was previously run by its three founders as a company under civil law (Gesellschaft bürgerlichen Rechts, "GbR"); the UG has taken over the operation of the service, and personal data collected before then is now held by it. For questions about your data or to exercise your rights, contact privacy@macademia.education.
2. The data we collect
If you joined our early-access list before the platform opened for sign-up
This channel is now closed. Before open sign-up launched, we collected early-access registrations through our website and, for a period, through lead-generation forms on Meta (Instant Form) and TikTok (Lead Generation). We are no longer running those ad campaigns and no longer collect new registrations this way — this section describes what was collected during that period, because we still hold some of those records (see section 6 for how long). The channels asked for slightly different fields:
- Website sign-up form: your email address (required), and optionally your first and last name, the programme type you're aiming for (e.g. MBA, MiM, MiF), and your country of residence.
- Meta / TikTok lead ads: your name and email address (auto-filled from your Meta/TikTok account), the programme type you're aiming for, when you plan to start, and, optionally, your preferred study destination(s) in Europe.
- Consent (both channels): whether you opted in to receive the free guide and early-access / launch updates.
- Metadata attached automatically by the ad platform (lead ads only, not typed by you): your approximate location/country, the submission timestamp, and an identifier for the ad/campaign that led you to sign up.
If you came to us through one of our Meta or LinkedIn lead forms
Some of our adverts on Facebook and Instagram open a short lead form inside the app, run by Meta, and some of our adverts on LinkedIn open a LinkedIn lead form, run by LinkedIn. This is a current channel, separate from the early-access forms above. When you submit the form, your answers reach us (from Meta directly; from LinkedIn directly too, as our server reads them from LinkedIn itself, see section 4) and we keep the following:
- What you gave on the form: your first and last name, your email address and phone number, your country of residence, what you want after your MBA (one of three goals), where you would like to study, and your tuition budget. Meta or LinkedIn fills in some of these from your account there.
- What the platform adds: its own number for your form answer (the lead id) and when you submitted it; from Meta, also which form, campaign, ad set and advert it came from, and from LinkedIn, which form and campaign. From a LinkedIn form we also keep whether you ticked its required consent box, and from either form whether you ticked its optional second box. We keep these fields only, not the rest of what we are sent.
- The CV you add on our page. The form’s last screen links to a page of ours where you type your email address and upload your CV as a PDF. Our AI provider reads it in the EU, with every image removed first, as in onboarding (section 4, Optional AI tools), and you see and correct what it read before you confirm. If the form you answered does not ask where you would like to study, your tuition budget or what you want after your MBA, the page asks it, and we use your answer only where no form answer of yours gave one. No photo is taken from a CV added on this page. Until you confirm and your form answers have reached us, the upload is not a profile; it expires 24 hours after you made it (section 6).
- When you confirm. If the email address you confirm is one a lead form gave us, we create your Macademia account and your profile from your form answers and your CV, and publish it (section 4). You do not choose a password then: we email you a link to set one. The page shows links to this policy and to our Terms of Service above the button, and confirming is where you accept the Terms; we record their versions with your account when it is created. Your phone number from the form is not treated as confirmed: it is held for our team to confirm with you by hand, and nothing is sent to it until then. We count your profile as active from the moment it is created. If no form answer with that email address reaches us before your upload expires, no account is made. If the address already has an account, nothing on that account changes: the upload is deleted, and we may email the address a link to open that account.
- Showing the CV file itself to a university that unlocks you needs the same separate, unticked box as in onboarding, on the same terms (see the note at the end of the next list).
From then on you are a candidate like any other, and the rest of this policy applies to you. What we tell Meta or LinkedIn about your lead afterwards is described in section 4.
If you signed up through a partner's link
Some people and organisations we work with, such as content creators, share a personal link to Macademia. If you create your account through one of these links, we record which partner's link it was and when you signed up. We use this to know how many people each partner brought to Macademia, how many of them completed and published their profile, and how many meet the profile we look for (a bachelor's degree or higher, at least three years of work experience, and a phone number), so that we can measure these partnerships and settle what we owe our partners. We tell a partner only totals, never who you are or anything from your profile. If you delete your account, we keep only the partner, the dates and those yes-or-no answers, with nothing that identifies you. Apart from the sign-in cookie that Google or LinkedIn sign-up already uses for a few minutes, nothing is stored in your browser for this.
If you are a candidate (student) on the platform
- Account: your email address, and either a securely hashed password (we never store your raw password) or, if you choose to sign in with Google or LinkedIn instead, the confirmation from that provider that you own the email address it hands us — we do not receive or store your Google/LinkedIn password. When that sign-in creates your account, we also take your first and last name and your profile photo from the provider, so you do not have to re-enter them; the photo is copied into our own storage and from then on is yours to replace or delete like any other (see Photo below). We ask that provider for nothing else — never your contacts, connections, posts or anything beyond those fields — and we take them only when the account is first created, not on later sign-ins.
- Profile: name, country of residence, region, preferred study destinations, the target programme and intended intake you may have given before 14 September 2026 (no longer asked since; kept where you gave them), and, as you choose to add them, your sector, employer, role, years of experience (worked out from the years of your roles, never asked as a number), education (each role and degree with its organisation, the country it was in and its years), the country of your last degree, languages, admissions-test scores — or, if you have not sat a test, whether you intend to and roughly when — the goals you choose for after the programme (one or more of three: change industry, seeking a promotion, start your own; since 16 September 2026 these are shown to universities in place of any written motivation answers, which stay visible to you alone), whether you already have the right to study in the EU, in the UK and in Ireland — a passport or a residence permit that lets you study without a student visa; three answers you give yourself, stored as whether a student visa would be needed, and we hold nothing about your citizenship and never infer it — and your financial picture: how you plan to finance your studies (one or more of the options offered), your budget, and your current salary — the amount, whether it is per month or per year, or that you have no income today. Your salary is stored as you typed it, in the currency of the country you live in, together with the same amount converted to international dollars at purchasing-power parity using the World Bank's yearly factor for your country; we keep the year of the factor used so the figure can always be re-derived. Be aware that these financial answers are not private notes to us. How you plan to finance your studies is shown to universities and is one of the three inputs to the readiness figure in section 4; it, your visa answers and the goals you chose for after the programme also feed the FT and QS scores described there. Your salary itself is never shown to a university: it is used only inside the FT and QS scores in section 4, turned into comparisons against other candidates and against what this programme's own graduates earn before anything leaves our systems, and no salary amount and no percentile of it ever reaches a university. Treat the rest as part of what you publish.
- Phone number — required to finish onboarding since 14 September 2026: the onboarding asks you for a mobile number and confirms it with a one-time code, by text or by a call that reads the code out; you cannot finish without it. It is used for one thing first: proving the number is yours, so that a proven number belongs to exactly one account (section 3). We only keep a number as yours once it has been confirmed. While a code is on its way we hold the number you gave us so we can check the code against it, and we record which channels were tried (a text, a call) and when. If a code does not reach you, you can ask us to contact you instead: the option appears once a text or a call has been asked for — whether it went through or was refused — or at once when your number is in a country our provider says it cannot serve. We then keep the number and the time you asked, and a member of our team contacts you to confirm it within three working days. Your profile is published in the meantime, like everyone else's; what waits for the confirmation is WhatsApp messaging, not your visibility. A university never sees the number itself; it sees only that a number is on file, and that it has been confirmed once it has. Two notifications also reach you by text, from 17 September 2026: when a university unlocks your profile, and when a university replies to you. We do not ask your permission for those two, and we will not pretend we did. They rest on the same legitimate interests as their email versions — the basis belongs to the message, not to the pipe — they are never marketing, and the reminder before your profile is hidden and the notice that a university became verified are deliberately not among them. Each of the two has its own switch in Settings, on until you turn it off, and a link to that switch travels inside every message we send you. Nothing is ever sent to a number that has not been confirmed: your permission is not what we ask for, but proof the number is yours is. Giving us your number is not permission to message you on WhatsApp. That is a channel you switch on yourself. We ask once, on the screen that tells you your profile has gone live — after onboarding is finished and the profile published, so saying no costs you nothing and is not a condition of anything — and the two buttons there, Enable WhatsApp and Not now, are equally available. You can change it at any time in Settings. Ticking it turns on two messages, and only those two — a university unlocking your profile, and a university replying to you. Four other notifications can also travel this way — a reference being submitted, a session you registered for changing, a university you shortlisted becoming verified, and the reminder before your profile is hidden for inactivity — and each has its own switch in Settings, off until you turn it on. Whatever you do not switch on still reaches you by email and in the app — and never marketing; the message-template categories our messaging provider assigns do not change what we send, and every message under this permission is one of those. It takes effect only once your number is confirmed, by a code or by us, and turning it on adds a recipient: WhatsApp is operated by Meta Platforms Ireland Ltd, so a message sent that way passes through Meta as well as Infobip, and both your number and the message itself reach them. That is true of WhatsApp whoever sends it, and it is the reason this is a channel you switch on yourself rather than one we assume for you. Nothing travels this way until you do. You can delete the number at any time.
- Photo: either one you upload, or — if you created your account with Google or LinkedIn — the profile photo that provider gave us, which we copy into our own storage at that moment (see Account above), or — if the CV you upload carries a photograph — that photograph. Since 16 September 2026 we find it this way: our own code lifts every image out of the PDF, and a separate request to our AI provider (section 4, Optional AI tools) asks one question about them — which of these, if any, is a portrait photograph of a single person. The answer is a position in the list or nothing; no description of the person is asked for or kept. During onboarding that portrait becomes your profile picture at once — the profile panel shows it next to your name, with the control to change or remove it — because during onboarding your CV builds your profile. From your profile page, after onboarding, it is only proposed: it replaces nothing until you click. The provider can say “this is a portrait of one person”, not “this is you”: you confirm by keeping it. Whichever way it arrived, your photo is shown to universities once you publish your profile, and you can replace or delete it at any time. We strip location and camera metadata (EXIF/GPS) from every image on upload. We run no face recognition and identify no one from a picture: that one question is the only thing ever asked about an image, and nothing from the answer is stored except the picture itself, when it becomes your profile photo.
- Documents you upload — CV, academic transcript: the files themselves are stored, not just the fact that they exist. They are held in private storage and are readable by a university only after it has unlocked your profile — as with the rest of an unlock (see section 4), a university that unlocked you keeps access to your documents even if you later unpublish; unpublishing prevents any new unlock, not ones already made. You can download your own copy, replace it, or delete it at any time, and we record every time a university opens one. A university reads your documents inside Macademia: we do not offer it a download. Every page it looks at carries the name of the person looking, and every opening is recorded. That makes taking a copy harder and traceable — it cannot make it impossible, because anyone who can see a document on a screen can photograph it. What a university may do with what it reads, and for how long it may keep it, is set by the contract it signs with us. We verify nothing: a document is recorded as provided by you, never as authenticated by us.
- Files you send in a conversation: PDFs you attach to a message with a university are stored in the same private storage and are readable only by the two sides of that conversation.
- Activity: the schools that express interest in you, your application stages, and messages exchanged through the platform.
- When you were last active: we record when you last used the platform so that schools see candidates who are likely to be available. If you have not been active for 60 days, your profile stops being shown to schools. Nothing is deleted, and you become visible again when you sign in. We email you before this happens.
Telling a school that people are interested in it
Some schools we talk to are not yet our customers. To help make the case for joining Macademia, we may tell such a school a single number: how many candidates on Macademia have shown interest in it, by shortlisting it or applying through the platform — for example "seventeen candidates have shortlisted your MBA this term."
- We never state a number small enough to identify anyone. We only ever share a count of at least ten people; below that we tell the school nothing at all — not a smaller figure, and not anything that would let one be worked out.
- It is a count, never a person. No names, no contact details, no individual profiles. The school is told how many, never who.
- Working out that number is processing of your data, and we do it on our legitimate interests (Art. 6(1)(f)) — understanding and showing demand is how a marketplace of this kind reaches the schools you want on it. Not consent: a consent you could withdraw cannot be honoured once a number has been spoken aloud to a school, and a promise we cannot keep is worse than none. You can object at any time under Art. 21 — write to us and we will stop counting you.
If you are a recruiter (university)
- Your name, work email, role/title, and the institution you represent.
- Recruitment activity you carry out on the platform (notes, saved views, outreach, audit events).
3. Why we use it, and our lawful basis
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Sent the free guide and early-access updates to sign-ups (discontinued channel, see section 2 — we no longer send these) | Performance of your request (Art. 6(1)(b)); consent for optional marketing updates (Art. 6(1)(a)) |
| Understood the early-access audience in aggregate (programme, timing, destination) to inform product development and school partnerships (discontinued channel, see section 2) | Legitimate interests (Art. 6(1)(f)) |
| Count how many candidates have shown interest in a school, so we can tell that school the total when it is not yet a customer (see section 2) | Legitimate interests (Art. 6(1)(f)) — producing the count is itself processing of your data, so it gets a basis of its own rather than resting on the count being anonymous once made. You can object under Art. 21 and we stop counting you. Deliberately not consent: a withdrawal cannot be honoured once a figure has been given to a school. |
| Create and operate your account | Performance of a contract |
| Show your profile to relevant schools / show candidates to recruiters | Legitimate interests (Art. 6(1)(f)) for candidates. This one is on by default once you finish onboarding, so it is not consent, and we will not call it that. We tell you before it happens. Your profile is shown without your name, your initials, your photo and your uploaded documents until a school spends a credit to unlock you; the rest of it, including your employer and your role, is shown from the moment you publish, and it is not anonymous — see section 4. Unpublish any time from your Profile page, or object under Art. 21 — either stops it. Legitimate interests also for recruiters. |
| Create your account and profile from a Meta or LinkedIn lead form and the CV you add on our page, and publish it (see section 2) | Performance of a contract (Art. 6(1)(b)) for the account, which you ask for by confirming on our page. Publishing rests on legitimate interests (Art. 6(1)(f)), as in the row above: the page tells you, before you confirm, that what you see there is what schools will see. Unpublish from your Profile page once you have signed in, or object under Art. 21 by writing to us; either stops it. |
| Tell Meta how a lead from its form progresses, so that we can measure our adverts and show them to people more like those who go on to add a CV (see section 4) | Your consent (Art. 6(1)(a)), given on the Meta form by ticking the optional second box that says so; the form can be sent without it, and without it we send nothing. We send nothing for a lead whose form text we have not recorded. You can withdraw it at any time by deleting your account in Settings (once you have signed in) or by writing to privacy@macademia.education; either way we send nothing further about you. This does not depend on your cookie choices, because the form, not a cookie, is how you reached us. |
| Tell LinkedIn how a lead from its form progresses, so that we can measure our LinkedIn adverts (see section 4) | Your consent (Art. 6(1)(a)), given on the LinkedIn form by ticking the optional second box that says so; the form can be sent without it, and without it we send nothing. We send nothing for a lead whose form text we have not recorded. You can withdraw it at any time by deleting your account in Settings (once you have signed in) or by writing to privacy@macademia.education; either way we send nothing further about you. This does not depend on your cookie choices, because the form, not a cookie, is how you reached us. |
| Keep you on a programme's cohort list once your application reaches ACCEPTED or ENROLLED, including after you unpublish (see section 4) | Legitimate interests (Art. 6(1)(f)) — not the publishing basis above, which you can withdraw by unpublishing. That school already knows who you are, because it admitted you; the list adds no disclosure, and an intake whose members can remove themselves from it cannot be administered. You can object under Art. 21 — write to us and we will weigh your grounds against those reasons. |
| Calculate the readiness, FT and QS, and cohort-fit figures shown to schools (see section 4) | Legitimate interests (Art. 6(1)(f)) — the same basis as publishing itself, on data you gave us. Unpublish and they stop being shown. |
| Show your first name, initials, country and points to other students in the league table | Legitimate interests (Art. 6(1)(f)). This one is on unless you switch it off, so it is not consent, and we will not call it that. Never your surname, never your photo, never anything else from your profile. Switch it off in Settings, or object under Art. 21 — either stops it. |
| Verify a phone number, or confirm it ourselves when you ask us to contact you | Legitimate interests (Art. 6(1)(f)) — not consent, and we will not call it that. We verify a number for one reason: so that a proven number belongs to exactly one account. The database enforces that rule, and it is how we stop one person from running several profiles and keep the code-sending route out of abuse. Since 14 September 2026 a number is part of finishing onboarding — confirmed by a code, or handed to us to confirm (see section 2). Deleting the number in Settings ends this processing, and you can object under Art. 21. |
| Measure where students stop during onboarding — which screen, whether a CV upload or a phone code went through or was refused and why, and whether you signed up on a phone or a computer — so we can fix the screens where people give up | Legitimate interests (Art. 6(1)(f)). Counts and fixed labels only, never the contents of your CV or your number; the per-event records are deleted after 90 days. |
| Message you on WhatsApp when a university unlocks your profile or replies | Legitimate interests (Art. 6(1)(f)) — the same basis as the email version of the very same notification, because the basis belongs to the message, not to the pipe it travels down. This is not consent, and we will not call it that. Switch it off in Settings, or object under Art. 21 — either stops it. You still have to switch the channel on before anything is sent: WhatsApp requires the person to have asked for its messages, whatever the sender’s lawful basis, so we ask you plainly after your profile is live, with declining as easy as accepting, and send nothing until you have said yes. That tick is a channel preference, not the ground of the processing, and it turns on only the two notifications it names; the others are switched on one at a time, by you, in Settings. Marketing is separate, off by default, and never sent here. |
| Show the CV file you uploaded to a university that unlocks you | Explicit consent (Art. 9(2)(a)) — separate from the upload, which is part of finishing onboarding and rests on the contract. A CV can carry special-category data we never extract; showing the document is the one thing that needs your own “yes”, and you can say no without losing anything: the profile the CV filled is published either way. Switch it off in Settings at any time; from then on no university can open the file, including one that unlocked you earlier. |
| Text you when a university unlocks your profile or replies | Legitimate interests (Art. 6(1)(f)) — again the same basis as the email version of the same notification. This is not consent and we did not ask for any, because neither message is marketing: each one reports something a university did to your profile, which is the service you signed up for. Switch either off in Settings, or object under Art. 21 — either stops it, and a link to that switch is inside every message. Unlike WhatsApp there is no channel to switch on first: a confirmed number is the whole condition. The reminder before your profile is hidden for inactivity, and the notice that a university you shortlisted became verified, are never sent this way — those are the two whose trigger reads as marketing, and marketing by text would need your consent, which we have not asked for and do not have. |
| Email you: address verification and password resets; product notifications; marketing updates | Performance of a contract for the first (you cannot have an account without a recoverable address); legitimate interests for notifications, with a one-click switch-off; your consent for marketing |
| Record which partner's link you signed up through, and count the results for that partner | Legitimate interests (Art. 6(1)(f)): measuring and paying for our partnerships. You can object at any time; the counts shared with partners never identify you. |
| Keep the service secure and prevent abuse | Legitimate interests |
| Comply with legal obligations | Legal obligation |
Where we rely on consent, you can withdraw it at any time (see section 7). This does not affect processing carried out before withdrawal.
4. Who can see your data
Nothing is shown to any university until you publish your profile. Publishing happens automatically at the end of onboarding: the last screen says so above the button that finishes it, and pressing that button is what publishes. If you asked us to confirm your phone number ourselves (section 2), your profile is published all the same; what waits for that confirmation is WhatsApp messaging, not your visibility. You can unpublish, or republish, at any time from your Profile page. We never sell your personal data, and we never give it to anyone so that they can advertise to you. What does leave Macademia for advertising is exactly the narrow, scrambled trace of our own adverts working that section 8 describes — only with your consent, nothing else, to no one else.
Once you publish, a university browsing candidates sees your profile in full, without your name, your initials and your photo — those three wait until it unlocks you, and so do the documents you uploaded (a school is told a CV is on file, and cannot open it until it unlocks you). In your photo's place it sees a heavily blurred version of it: we shrink your photo to eight pixels a side and blur it on our servers, and only that small image is ever sent to a school before the unlock. It keeps the colours and rough outline of your picture — skin, hair, background — and none of your features, and it cannot be turned back into your photo, because the detail is gone before it leaves us. We will not call it anonymous: a school that already knows you and has seen your photo might guess it is you from the colours alone. If you would rather not be shown even that, remove your photo from your profile and schools see your initials instead. Everything else is there, exactly as you wrote it: your role and your employer, your work history, your education, your skills and certificates, the goals you chose for after the programme (your written motivation answers, where you gave any, stay visible to you alone), your self-description, your exact admissions-test score — or, if you have not sat a test, whether you intend to and roughly when — and years of experience, your country of residence, the country of your last degree, your languages, your international experience, how you plan to finance your studies, where you want to study and your tuition budget (both since 26 September 2026), whether a visa is part of your plan, whether a phone number is on file and confirmed, and roughly how recently you were active.
This changed on 1 September 2026, and it changed in the direction of showing more. Your role, your employer, your headline, your work history, your education, your written answers and your exact scores used to wait for the unlock as well. They no longer do. A school can now read everything about you before it decides whether to pay to learn who you are.
This is not anonymous data, and we will not call it anonymous. A job title and an employer, next to a work history and a set of scores, will identify many people to anyone who cares to look, even with the name removed — and that is now the ordinary case rather than a corner of it. Under the GDPR this is personal data about you, it is not anonymised, and every right in section 7 applies to it in full. What withholding your name still does is stop a school addressing you, contacting you, or acting on you until it unlocks you; it is not a promise that you cannot be recognised. If you would rather not be seen on these terms, the Public/Private switch on your Profile page is the control, and it takes effect for every university at once.
Publishing puts you in front of every university on Macademia, not only the ones you are interested in. That is the whole point of the platform — schools find you rather than the other way round — and you control it entirely through the Public/Private switch on your Profile page. Your shortlist tells a school that you are interested in it; it does not decide who can see you. A school you rank among your top three is told that it is in your top three, and nothing more about your ranking; a school ranked lower is told nothing. Unpublishing removes you from every university's search at once.
How your identity is unlocked. A university that has you in its candidate list can unlock your name, your photo and the documents you uploaded by spending one of its credits. That is the university's decision alone — you are not asked to approve each unlock, and we do not require the interest to be mutual. What you control is the gate in front of it: if you are not published, no unlock is possible; unpublishing prevents any further unlock; and withdrawing from a school removes you from what that school can act on. A university that unlocked you before you unpublished keeps what it already unlocked, and we record every unlock and every time a document is opened.
Once you are admitted, unpublishing no longer hides you from that school. When your application with a programme reaches ACCEPTED or ENROLLED, you appear on that programme's own cohort list — your name, your photo, and the professional fields listed above — and you stay there whether or not your profile is still published. This is deliberate: at that point the school is not searching for you, it is admitting you, and a school cannot run an intake whose members can make themselves disappear from it. It is limited to the one programme that admitted you: no other university sees any of it, and unpublishing still stops every school, including that one, from unlocking anything new.
Figures we calculate about you. So that universities can sort and compare candidates, we calculate a small number of figures from data you have given us and show them alongside your profile:
- Readiness — how ready you are to start, as 40% how you plan to finance your studies, 40% your visa position and 20% your admissions test. If any one of the three is missing, we show no figure at all rather than guessing at it.
- FT and QS scores: two figures modelled on the published FT and QS MBA ranking methodologies, one for each ranking, worked out separately for every programme where you appear. They compare parts of your profile against the other published candidates on the platform who remain recently active (when you are yourself published and recently active, you are part of that comparison group too), including your salary position, how your current salary compares with what this programme's own graduates go on to earn, your work experience abroad, your sector, the goals you chose for after the programme, how you plan to finance your studies, your visa position, and your current employer. The salary comparisons are made on the purchasing-power figure, not on the amount you typed, so a salary in Lahore and one in Lisbon are compared by what they buy where you live rather than by an exchange rate. What reaches a school is the result: the two scores out of 100, a score for each of their three areas (earnings and return, career and employability, international and diversity), which of the individual measures could be worked out and which rest on typical figures, the two measures where you are strongest, and, when the programme's cohort is full, whose place you would take. Never the amount, and never the individual comparisons behind the scores. Each of these comparisons needs at least five candidates with a usable answer, or that part is left out rather than shown as a guess; without a salary of your own, and enough other candidates to measure it against, there is no FT score at all, and without enough of the same figures to work out a return on your investment, there is no QS score either. Your work experience abroad here means the countries of your roles, not your degrees: a role in another country counts, however short.
- Cohort fit — how your profile relates to the intake composition a programme has published targets for. Where a programme has published none, we show nothing rather than inventing a fit.
These are ordinary arithmetic on the fields listed above. No artificial intelligence is involved in any of them, none of them uses special-category data, and none of them decides anything: they order and describe, and every actual admissions decision is taken by a person at the university. You are therefore not subject to a decision based solely on automated processing within the meaning of Article 22 GDPR. You can see and correct every input to these figures in your profile, and you can ask us for them under your right of access.
What other students see. The student app has a league table that ranks students by the points they earn using Macademia. It shows your first name, your initials, your country of residence, and the points and level you have reached — never your photo, your employer, or anything else from your profile. Your surname is never shown, but your initials are derived from your full name, so they carry its first letter; we would rather say that than let “never your surname” suggest more protection than it gives. This is the one place where another student, rather than a university, sees something about you, and unlike your profile it does not wait for you to publish: everyone who has earned points appears in the ranking. If you would rather not, switch “Show me in the league” off in your Settings — you keep every other part of the app and simply stop appearing to other students.
We use the following providers to operate Macademia. They handle data under our instructions or, where they run their own lead form, under their own privacy terms as well. The location and transfer safeguards are summarised in section 5.
- Hosting & database: Render and Supabase provide our primary production infrastructure in Frankfurt / eu-central-1.
- Sign-in with Google or LinkedIn (optional): if you choose either instead of a password, that provider confirms your identity to us via our authentication provider, Supabase. We do not receive your Google/LinkedIn password, and we only ever receive it if you actively choose that sign-in option.
- Lead-ad platforms (historical): if you responded to our now-discontinued Meta or TikTok early-access lead-ad campaigns, that information first passed through Meta Platforms Ireland Ltd. or TikTok Technology Limited before reaching us. We no longer run those early-access campaigns; the Meta lead forms we run today are the next item.
- Meta lead forms, and what we tell Meta afterwards: the lead form described in section 2 runs on Meta. Meta Platforms Ireland Ltd processes what you type into it under its own privacy policy and passes your answers to us. Afterwards our server tells Meta how your lead progressed, at up to four moments: that we received your form, that you added your CV and we created your profile, that your profile meets the profile we look for (a bachelor’s degree or higher, at least three years of work experience, and a phone number on your profile, confirmed or not), and that a university unlocked your profile for the first time. Each message carries which of those moments it is, when it happened, Meta’s own number for your form answer (the lead id), and a scrambled, one-way version (a SHA-256 hash) of your email address and, if you gave one, of your phone number. Nothing from your CV or the rest of your profile travels with it. Meta uses it to count which of our adverts led to profiles, and to show our own future adverts to people more like those who went on to add a CV. We hold no copy of the scrambled versions: they are produced at the moment of sending and not stored. This does not depend on your cookie choices; its basis is in section 3, and we send nothing for a lead whose form text we have not recorded, or who left the second box unticked. Processing also takes place at Meta Platforms, Inc. in the United States, on the terms described in section 8.
- LinkedIn lead forms, and what we tell LinkedIn afterwards: the LinkedIn lead form described in section 2 runs on LinkedIn. LinkedIn Ireland Unlimited Company processes what you type into it under its own privacy policy. Our server reads your answers from LinkedIn directly, with no other service in between: LinkedIn tells our server that a new answer exists, in a message our server accepts only when LinkedIn has signed it, and our server then fetches the answer from LinkedIn; it also asks LinkedIn every hour for any answer it missed. Afterwards our server tells LinkedIn how your lead progressed, at the same four moments as for Meta above: that we received your form, that you added your CV and we created your profile, that your profile meets the profile we look for (a bachelor’s degree or higher, at least three years of work experience, and a phone number on your profile, confirmed or not), and that a university unlocked your profile for the first time. Each message carries which of those moments it is, when it happened, LinkedIn’s own reference for your form answer, a reference code made of our internal number for your lead and the moment (so that LinkedIn counts a repeated message once), and a scrambled, one-way version (a SHA-256 hash) of your email address. Your phone number is not sent to LinkedIn, and nothing from your CV or the rest of your profile travels with it. We hold no copy of the scrambled version: it is produced at the moment of sending and not stored. This does not depend on your cookie choices; its basis is in section 3, and we send nothing for a lead whose form text we have not recorded, or who left the second box unticked. Under LinkedIn’s terms with advertisers, LinkedIn is a controller of what it receives this way and also uses it for its own purposes, such as reporting and improving its products; where it processes it is described in section 8.
- Optional AI tools: Google Cloud (Vertex AI), in the EU, processes a CV or prompt only after you choose to use a tool. When you upload a CV for autofill, the model reads the whole document — every page, as text and as an image — so we remove every embedded image from the PDF on our servers before its text is sent. Since 16 September 2026 the images travel separately: our own code lifts them out of the file, and at most a few small copies go in a request of their own that carries no name, no text and no page, with one closed question — which of these, if any, is a portrait photograph of a single person. The answer is a position in the list or nothing; nothing is asked or kept about the person in the picture, this is not biometric identification, and the model that reads your career never sees a face while the one that sees the images does not know whose they are (see Photo in section 2 for what happens to the portrait). From the text we keep only the fields listed for the profile above (roles, degrees and their countries, sector, skills, languages, test scores, highest degree, headline, summary, LinkedIn, city), each one shown to you to confirm or remove; the two things it may propose that we never write for you after onboarding are your country of residence and your phone number, which you confirm yourself. Two rules govern what a CV does to your profile: during onboarding the CV builds it — the roles, degrees, skills, certifications and languages it names replace what the panel held, so a second CV cleans up the first — and afterwards the CV adds and updates, never removes: what you typed by hand stays. Google Cloud is our processor under its Cloud Data Processing Addendum; Vertex AI does not use our prompts or outputs to train models, and keeps nothing at rest from the call. We keep only results you choose to save. The tools do not make admissions decisions or score you, and schools do not see them run.
- Error monitoring: Sentry receives technical error reports. In the browser it loads only if you allow Error monitoring in Cookie settings. Server-side reports support service security and do not include an account name or identifier.
- Verifying your phone number (part of onboarding since 14 September 2026): verifying is how a number is added, so this happens whenever you give us one. We send it to Infobip — our contract is with Infobip Ltd, a company registered in the United Kingdom, which is covered by the European Commission’s adequacy decision for the UK (Art. 45 GDPR) — which texts you a one-time code, or reads it to you in a call, and tells us whether the code you typed back was the right one. Under our data processing agreement, your number is stored and processed in data centres inside the European Union by default, and cannot be moved outside the EU/EEA without our written instruction. We keep only the date you verified; the code itself never reaches us and we do not store it. Your number is also passed to your mobile operator, as it would be for any text message. Until September 2026 this verification was carried out by Twilio and numbers were processed in the United States under Twilio’s Binding Corporate Rules; that processing has ended.
- Sending you email: every message we email you — confirming your address, resetting your password, telling you a school has been in touch — is delivered by Brevo (the contracting entity is Brevo GmbH, Berlin, Germany). This processing happens in the European Union: our contract is with Brevo’s German company, and the message itself is handled on servers in France and Belgium. Two of Brevo’s own named sub-processors are US companies — a content-delivery network and a support-ticketing tool — and for those Brevo relies on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses; we say that here rather than rounding the picture down to “everything in the EU”. Until 1 September 2026 this delivery was performed by Resend (Plus Five Five, Inc., San Francisco) in the United States, as earlier versions of this page described; Resend retains its delivery logs for a limited period after termination under its own terms.
- When you write to us: our own mailboxes at
macademia.education— including privacy@macademia.education, the address named throughout this policy — run on Microsoft 365, bought directly from Microsoft under a Microsoft Customer Agreement. This changed on 14 September 2026: until then we bought the same mailboxes through GoDaddy, so our contract was with GoDaddy.com, LLC in the United States and we described the transfer safeguards accordingly. That reseller relationship has ended and the contract is now with Microsoft. GoDaddy remains our domain registrar and runs the DNS for this site, which is a different job and does not involve the contents of your message. We name the mailbox provider because a message you send us — a question, a complaint, a request to exercise your rights — passes through it, and a list of providers that omitted the one you reach us through would be the wrong list.
Your class directory: sharing with classmates, not universities
Separately from everything above, once your application has reached a committed stage (ACCEPTED or ENROLLED) at a programme, you can opt into a class directory that lets you find and be found by your classmates on that programme. This is a different recipient category from the rest of this section: the people who see this data are other candidates in your cohort, not universities, and it does not depend on publishing your profile or on any university unlocking you.
- This is off unless you switch it on. It is a separate, specific consent in your Settings, distinct from publishing your profile to universities. If you do not switch it on, nothing about you appears in the class directory, and you cannot see your classmates' entries either.
- It is reciprocal, and here is exactly what's shared: opting in shows your name, initials, photo, band, country of residence, sector, role, employer and years of experience to other candidates in the same committed cohort at the same programme who have also opted in — and shows you the same fields for them. Your photo is included whenever you opt in, if you have uploaded one: unlike the university-facing profile described above, where your photo stays hidden until a university spends a credit to unlock it, there is no separate consent step for the photo here.
- You can withdraw it at any time, and you stop appearing in the directory from that moment.
5. Where your data is stored
Your primary production data is stored in the European Union (Frankfurt, Germany).
Your mail to us is stored in the EU, and we can now say where. A qualification added here on 9 September 2026 said the opposite — that our mailboxes were bought through a United States reseller and that the region they sat in was not stated to us. Since 14 September 2026 we buy Microsoft 365 directly from Microsoft, and the admin centre reports the storage location for our mail: Italy, with Microsoft’s committed geography for data at rest set to the European Union / EFTA. So an e-mail you choose to send us is stored in the EU, not outside it. We are correcting this rather than leaving it, because the earlier wording told you your message might leave the EU when it does not.
Beyond that, no processor handles your data outside the EU in the ordinary course. Phone verification moved from Twilio (which processed numbers in the United States) to Infobip in September 2026: numbers are now processed in data centres inside the European Union, under a contract with Infobip Ltd, a United Kingdom company covered by the EU adequacy decision for the UK. Email is delivered by Brevo GmbH inside the European Union, since 1 September 2026.
EU storage does not mean every provider is established in the EU. Our hosting and error-monitoring providers are incorporated in the United States, as is Microsoft, whose mailboxes hold what you write to us; our database provider is in Singapore, and the support teams of the provider that sends your verification code work from outside the EU as well — we have dealt with its office in Bosnia and Herzegovina. Their authorised staff may reach those machines, and those records, to operate the service and to answer our support requests; under the GDPR, that access is itself a transfer. We use Standard Contractual Clauses for it. Where your phone number is stored has not changed: that provider has confirmed in writing that our account’s data sits in the European Union, in Frankfurt.
6. How long we keep it
Documents you upload — your CV, your transcript, files you send in a conversation — are kept for as long as your account is active, because their whole purpose is to be readable by a university that unlocks you. There is no automatic expiry: they stay until you remove them, which you can do at any time, or until you delete your account, which deletes them with it.
We keep account and profile data for as long as the account exists. If you delete your account, deletion is immediate: your profile, applications, messages, consents and uploaded files are erased together with your login. We retain only a de-linked audit entry showing that an action occurred, without the account link or its contents; it no longer identifies you. Audit and security logs linked to an active account are kept while that account exists, because they let us secure the service and show you who opened a document. Early-access data from our discontinued Meta/TikTok/website sign-up campaign (section 2) is kept until you unsubscribe or object, and is automatically deleted 24 months after you signed up — a scheduled job checks daily and removes records past that window. You do not need to ask; you can still email us to have yours removed sooner.
Onboarding events — the record that an upload was accepted or refused, a code sent or failed, a step held back — are deleted 90 days after they happen, by a daily job. What stays is only which screen you reached, with your profile.
Meta and LinkedIn lead forms and the page where you add your CV. A CV uploaded on that page, together with what was read from it, the email address you typed and the campaign details in the link, expires 24 hours after the upload unless it has become your profile, and a daily job then deletes it with the file. Answers from a lead form that never led to a profile are deleted 90 days after we received them, by the same daily job, together with our record of what we told Meta or LinkedIn about them. Answers that did lead to a profile are kept with your account, as the record of which advert brought you. If you delete your account, they go with it, at once: every form answer we hold under your email address, our record of what we told Meta or LinkedIn about them, and any CV you uploaded on that page that you confirmed under your email address and that has not yet become your profile, file included. Our record of what we told Meta or LinkedIn holds which moment it was, when, whether the platform accepted it, and its reply; the scrambled versions of your email address and phone number are made at the moment of sending and are not part of it. When we delete form answers, for either reason, we keep one thing so that Meta or LinkedIn cannot send them to us again: which platform they came from and a scrambled form of the platform’s number for your answer, with no name, address or answer. We keep that, in turn, for one more window counted from when we deleted your answers, not from when we first received them: 90 days for Meta, one year for LinkedIn, matching how long each platform could still hand that answer back to us. Once that window has passed, we delete it too. LinkedIn’s own copy of your form answers is kept by LinkedIn under its terms, which make it available to us for one year; deleting your data with us does not delete it.
Backups, and why deletion cannot reach into them. We keep security copies of the database so that a failure or a mistake cannot destroy your account along with everyone else's. A copy is a photograph of a moment: it cannot be edited afterwards without destroying the very thing that makes it a reliable copy. So when you delete your account the deletion is immediate in the live service — you disappear from it at once, and no copy is ever used to bring you back — but a record of you remains inside copies already taken until each one expires on its own. Copies of the database expire on their own: 48 hours, about 7 days, and at most 90 days. Files you uploaded follow a slightly different clock. Your CV, transcript, chat attachments and photo are also copied to a separate store in Frankfurt, so that a mistake in our own code deleting the original cannot destroy the only copy. When you remove a file, that copy is kept for up to 30 more days and then deleted automatically. The delay is deliberate and it is the whole value of the copy: a deletion nobody meant stays recoverable for a month. It is never read in the ordinary running of Macademia, and if you would rather not wait the 30 days you can ask us and we will remove it sooner. The copies held in Frankfurt sit with the same providers that run the service. The 90-day copy is held by GitHub (Microsoft) in the United States, deliberately at a different provider so that losing one account cannot cost us everything, and it is encrypted before it leaves us with a key GitHub does not have and cannot obtain, so it is unreadable to them.
7. Your rights
Under the GDPR you have the right to:
- Access: get a copy of the data we hold about you (Art. 15). The platform provides a machine-readable export.
- Rectify: correct inaccurate data (Art. 16); most fields are editable in your profile.
- Erase: delete your account and data (Art. 17).
- Portability: receive your data in a structured, common format (Art. 20).
- Object / restrict: object to or restrict certain processing (Arts. 18, 21).
- Withdraw consent at any time where processing is based on consent.
To exercise any right, email privacy@macademia.education. You also have the right to lodge a complaint with your local data-protection authority.
8. Cookies
We use essential cookies that do not require your consent because they are strictly necessary to provide the service, but we tell you about them up front: a secure, httpOnly session cookie that keeps you signed in, and, only while you are in the middle of signing in with Google or LinkedIn, two short-lived (15-minute) cookies that make that sign-in flow work (`oauth_pkce_state`, `oauth_next`) and are then discarded.
We also record your cookie choice itself on your device, including a refusal, so we can remember it. It contains only your choices and the time they were saved.
You choose each non-essential purpose separately. Google Analytics 4 helps us understand visits and product use. Google Ads measures whether an advertisement led to an account or a published profile. These services set cookies and share data with Google LLC in the United States, under the EU-US Data Privacy Framework and Google's Standard Contractual Clauses. Google measurement data is retained for 14 months. Meta Pixel measures whether a Meta (Facebook/Instagram) advertisement led to an account or a published profile, or, on the page where you add your CV after one of our lead forms, to a CV being added. It shares data with Meta Platforms Ireland Ltd., which may retain it for up to two years; processing also takes place at Meta Platforms, Inc. in the United States, under the EU-US Data Privacy Framework and the EU Standard Contractual Clauses in Meta's terms. For the collection and transmission of data through Meta's business tools we and Meta Platforms Ireland are joint controllers (Art. 26 GDPR); the essence of that arrangement is set out in Meta's Controller Addendum.
How far you get in onboarding. Since 16 September 2026 your account records which onboarding screen you reached last and when you first reached each one — four screens, named by what they ask, no more than that. It is written on your profile as a side effect of saving the screen, needs no cookie and no consent, and serves one purpose: seeing where people stop, so we can make the flow shorter. If you have allowed Analytics, Google Analytics also receives one event per screen carrying the screen's name and nothing about you; refuse Analytics and only the note on your account is kept.
If you allow Advertising and arrive from one of our ads, we keep the click identifier (Google's, Meta's or LinkedIn's) and the campaign, source and medium — and, since September 2026, the keyword, advert version and landing page as well — in your browser for 90 days. If you create an account, we copy them to it so we can understand which campaigns lead to published profiles — and the click identifier is deleted from your account after the same 90 days, leaving only the campaign it came from. It lives on the account exactly as long as it lived in your browser, and no longer. LinkedIn’s click identifier stays in your browser and is not copied to your account. They describe an advertisement, not information you typed. Refuse advertising cookies and none of this is written down; deleting your account deletes it too.
We send Google's click identifier back to Google Ads. Until 2026 this page said these identifiers were never sent outside Macademia, and while that was written it was true. It is no longer, and saying so plainly is the point of this paragraph. Most of what tells us an advert worked happens days after the advert was clicked — a profile finished on the second day, a school getting in touch on the ninth — long after your browser has stopped talking to Google. So our server now tells Google Ads that the click it already knows about led to one of those outcomes: the click identifier, which outcome, when, and a number representing how much that outcome matters to us. One more thing travels with it, and it is fair to name it: a reference code built from your account's internal identifier, which exists so that the same outcome reported twice — once by your browser, once by our server — is counted once. It is not your email, your name or anything you typed, and Google cannot read anything out of it. Nothing about your profile, your studies or your work travels with it. We keep the click identifier for 90 days after the outcome and then delete it from that record, keeping only the campaign it came from — Google itself stops accepting it after about two months, so past that it serves no purpose. Refuse advertising cookies and nothing is sent at all, and if you refuse them later we stop sending anything still queued.
The same goes to Meta. If you allow Advertising and you arrived from a Facebook or Instagram advert, our server tells Meta the same one thing it tells Google: that the click Meta already knows about led to a completed profile, when, and a number representing what that is worth to us — together with the scrambled, one-way version of your email address, for the same purpose and in the same form. Meta's click identifier was already being kept alongside Google's, and was described above; until September 2026 nothing was ever done with it. It now leaves for this, and for nothing else, on the same terms: 90 days, then deleted from that record. Refuse advertising cookies and nothing is sent at all.
What Google and Meta may do with those signals. Where you have allowed Advertising, they are permitted to use them not only to count our adverts but also to improve the targeting of our own future adverts — never anyone else's, and never to build a profile of you that other advertisers can reach. We say this because the signals we send them carry that permission, and a notice that described only the counting would be describing less than we actually do. Refuse advertising cookies and this does not arise, because nothing is sent.
Two exceptions, if you came through one of our Meta or LinkedIn lead forms. The advertising measurement described above follows your cookie choices; these two do not. First, what our server tells Meta or LinkedIn about a lead from its form (section 4) rests on the form’s own optional box (section 3), because the form, not a cookie, is how you reached us. Second, the page where you add your CV reads the source and campaign details in its own link (src and the utm_ parameters: source, medium, campaign, content and term) and keeps them with your upload whatever your cookie choice. They are not copied to your account if one is created from the upload, and they are deleted with the upload after 24 hours (section 6). No click identifier is kept from that page. The paragraph above about copying campaign details to an account describes sign-up on our site, not this page.
Sentry, hosted in the EU, is a separate optional Error monitoring choice. It helps us diagnose a page failure. It does not set a cookie, record your screen or record your typing. It receives only technical error information and a page address with anything after ? removed.
Sentry is not downloaded until you agree to Error monitoring. Google's measurement script loads as soon as you visit the site, but it starts — and stays — in a signals-denied state: it does not set a cookie, store an identifier, or record anything tied to you until you separately agree to Analytics or Advertising. Until then, it can only send Google an anonymous signal it cannot connect to you, which Google uses in aggregate across visitors, not about you individually. Refusing one category does not enable another. You can change your mind at any time through Cookie settings.
Meta's measurement script is not requested from your browser at all until you allow Advertising — unlike Google's, which loads immediately in a signals-denied state (see above). Refusing Advertising means no Meta script is ever downloaded, and nothing is sent.
LinkedIn Insight Tag. If you allow Advertising, the sign-up and sign-in pages load LinkedIn’s measurement script, the LinkedIn Insight Tag. The page where you add your CV does not load it, because that page collects your CV. It shares data with LinkedIn Ireland Unlimited Company: in LinkedIn’s own description, the address of the page, the page you came from, your IP address, your browser and device type and the time of the visit, and it may set LinkedIn’s own cookies. LinkedIn uses this to measure which of our LinkedIn adverts bring visitors to these pages, and may use it to improve the targeting of our own future adverts. LinkedIn says it truncates or hashes the IP address, removes a LinkedIn member’s direct identifiers within seven days and deletes the rest within 180 days. We decide to put the tag on these pages and ask for your consent to it; under LinkedIn’s terms with advertisers, LinkedIn is a controller of the data the tag sends it and also uses that data for its own purposes, such as reporting and improving its products, under LinkedIn’s privacy policy, where you can also exercise your rights over it with LinkedIn. Your data may leave the EU there: LinkedIn says it processes data both inside and outside the United States, relying on the transfer mechanisms the law provides, and its terms with us use the EU Standard Contractual Clauses for data passed between us for processing outside the European Economic Area. The same applies to what LinkedIn receives from its lead forms and from our server (section 4). LinkedIn’s measurement script is not requested from your browser at all until you allow Advertising. Refusing Advertising means no LinkedIn script is ever downloaded, and nothing is sent.
Meta as joint controller. For the collection of these events on our pages and their transmission to Meta, we and Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland) are joint controllers under Article 26 GDPR, under Meta’s Controller Addendum. Between us, we are responsible for this notice and for the consent that gates the script; Meta is responsible for your rights of access, rectification, erasure, restriction and portability over the data it holds after transmission, which you can exercise directly with Meta. Meta’s own privacy policy, including the legal bases it relies on, is at facebook.com/about/privacy. Any request you send us about this processing we forward to Meta within seven days. What Meta does with the data after transmission, it does as an independent controller.
Google Ads and your email. If you allow Advertising, Google Ads receives a scrambled, one-way version of your email address (a SHA-256 hash) alongside the outcomes described above — when you create your account, when you publish your profile, and at the later points our server reports. It uses this for one purpose: recognising that the person who clicked the advert and the person who reached the outcome are the same, when the click identifier alone no longer says so. We do not send a readable email address, your name, your telephone number, or anything you typed into your profile — not when you sign in, and not while you fill it in. We hold no copy of the scrambled version: it is produced at the moment of sending and not stored. Refuse advertising cookies and none of this is sent.
9. Security
We protect your data with measures including encrypted connections (HTTPS), hashed passwords, strict separation between institutions (tenant isolation), and security headers. No system is perfectly secure, but we work to keep your data safe and to notify you and the relevant authority if a breach ever affects you.
The automated check on the sign-up form. When you create an account, your browser is asked to solve a small calculation before the form is accepted. It is there to make mass automated sign-ups expensive, and it runs only on sign-up — never when you sign in, and nowhere else on the site. You do nothing and, since 15 September 2026, you see nothing: it finishes on its own in a couple of seconds. We use ALTCHA, which we run on our own servers: the puzzle comes from us, your device solves it, and the answer comes back to us. No third party is involved and nothing about you is sent anywhere — not to the makers of ALTCHA, not to Google, not to anyone else. It sets no cookie and does not identify you. Alongside the answer we record only how long the calculation took, rounded into coarse bands, so that we can tell whether the check has become too slow for ordinary phones.
10. Children
Macademia is intended for prospective graduate and postgraduate applicants and is not directed at children under 16. We do not knowingly collect data from anyone under 16.
11. Changes to this policy
We may update this policy when our product or processing changes. We will show the effective date and communicate material changes to registered users. If a change needs fresh consent, we will ask before enabling that processing.
See also our Terms of Service and Imprint · Image credits.