What we store
We store your account details, application profile, scholarship workspace, writing versions, preferences, and the documents you upload. Private documents are stored in a non-public Cloudflare R2 bucket under account-scoped keys.
Text extraction and OCR
Text-based PDF and DOCX files are extracted directly. Scanned PDF pages and JPG/JPEG/PNG files are processed by local OCR inside the ScholarshipLift backend. Document bytes are not sent to a separate OCR provider.
AI processing
AI writing requires at least one OCR-ready document. Extracted document text is sent to DeepSeek only when you explicitly select that document for a particular writing request. Verified scholarship facts and guided answers for motivation, goals, contribution, and voice may also be processed. ScholarshipLift AI does not submit applications.
Optional analytics
Anonymous analytics is off until you choose to allow it. Allowed events are limited to public calls to action, demo completion, signup start, onboarding progress and completion, and the first application start. We never send identity, scholarship IDs, profile data, filenames, document or writing contents, prompts, or provider responses.
Maps and distance estimates
The embassy map loads map tiles from OpenStreetMap, so ordinary network information such as your IP address and page referrer may be visible to that service. Published mission coordinates retain their official or open-data source and attribution; Google Places is used only by catalogue administrators to help discover candidates, and its names, addresses, coordinates, and Maps links are not stored. Selecting a Pakistani city is processed only in your browser. If you explicitly allow browser location access, your coordinates are used locally to calculate straight-line distance and are not saved or sent to ScholarshipLift analytics or the API.
Your controls
You can download an account export, delete individual documents, disable reminders or analytics, and permanently delete your account from Settings. Account deletion removes database records and private objects subject to operational backup retention.
Security
Ownership is enforced through verified Supabase identities, row-level policies, backend authorization checks, private object storage, short-lived upload and download links, and file signature, checksum, size, ownership, and quota validation. Production does not currently claim malware scanning.