Privacy Policy
Effective date: July 26, 2026 · Updated September 6, 2026 (sections 1, 3, 4, 6 and 7)
This policy explains what data Second Read collects, what we do with it, and how to get it deleted. The short version: we collect the minimum needed to give you essay feedback, we never train AI models on your essays, we never sell data, and you can delete everything by sending one email.
1. What we collect
- Account data. Your email address and name.
- Essays and drafts. The essay text you submit for review, including earlier draft versions you save.
- Review results. The feedback, scores, and flags the service generates for your drafts.
- Purchase status. Which plan you bought (Starter, Season 40, or the Season Pass), received from Creem, our payment provider. We never see your card number or full payment details.
- Minimal technical logs. We keep hashed IP addresses for abuse prevention. Raw IP addresses are not stored.
2. How your essays are used
When you request a review, your essay text is sent to Anthropic’s Claude API solely to generate your feedback. Under Anthropic’s API terms, API inputs and outputs are not used to train their models.
On our side, the commitment is plain: we never use your essays to train any AI model, we never sell your data, and we never share your essays with any third party beyond the processors listed below — each of which handles data only to run the service.
3. Processors we use
These are the companies that process data on our behalf, and why:
- Vercel — hosting the application.
- Neon — the database where your account, essays, and reviews are stored.
- Resend — sending sign-in emails.
- Creem — payments, as our merchant of record.
- Anthropic — generating review feedback via the Claude API.
- GitHub — storing the nightly database backup, which is deleted after 90 days (see section 6).
- Sentry — error monitoring. When something breaks, Sentry receives the error and technical details of the request (the page or route, method, headers), not essay text. Errors only: no session replay, no performance tracing.
That is the whole list. If it changes, this page changes.
4. Minors
Second Read is designed for college applicants aged 13 and up, and many of our users are 16 or 17. That shapes how we operate: we collect the minimum data needed to run the service and nothing more. Parents and guardians may contact us at any time about their child’s data — to review it, correct it, or have it deleted.
For parents, guardians, and counselors — in plain words
- Who reads the essay. Software does, to produce the feedback. Second Read has no staff; the founder opens a specific essay only when the student emails asking us to investigate a problem with their review.
- What schools and counselors see. Nothing. No counselor, school, or university can see what a student submitted, and we never tell a university who used Second Read.
- Under 18 in Brazil (LGPD, Art. 14).Brazilian law requires a minor’s data to be handled in the minor’s best interest, with a parent or guardian’s consent where required. A parent or guardian may exercise every right in section 5 on the student’s behalf — ask what we hold, correct it, or have it deleted — by emailing support@getsecondread.com in Portuguese or English. The founder answers personally.
- Schools that prohibit AI.Second Read turns off school-specific reviews for the schools whose published policies effectively prohibit AI help; the student sees the school’s own words instead, on any plan. Protecting a student includes not helping them break a rule that could cost an admission.
5. Your rights
Every user, in every country, has the same rights here — we do not make you cite a statute:
- Access and export. Ask for a copy of your data.
- Correction. Ask us to fix anything inaccurate.
- Deletion. Ask us to delete your account, your essays, or everything. Deletion is honored promptly, and essays are deleted on request.
To exercise any of these, email support@getsecondread.com from your account address.
6. Retention
Account data, essays, and reviews are kept for the application season plus 12 months, then deleted. Nightly database backups are kept for 90 days, so a deleted record can survive in a backup for up to 90 days before it is gone everywhere. If you request deletion earlier, we delete earlier.
7. Cookies
We set only first-party cookies, two of them. The session cookie keeps you signed in. A referral cookie (sr_ref) records, for 30 days, which link brought you to the site the first time — for example one of our own posts, or a paid ad we ran — so we can tell which of our efforts people actually find useful. It holds a short label, never personal data. It is read when you create an account, and that label is saved to your account so we can count sign-ups by source. It is not shared with anyone. There are no ad trackers and no third-party analytics cookies.
8. Changes and contact
If we make a material change to this policy, we will notify you by email before it takes effect. Questions: support@getsecondread.com.