The short version: we design our review around artifacts rather than behavioral surveillance of the people who use the systems. CLAVA collects data only when it is needed, explains why it is needed, and keeps the purpose bounded. If we do not need data, we should not collect it; anything retained should have a documented reason. CLAVA does not require applicant, learner, or student records for the public site or a starter review, does not sell or rent personal data, and builds the front door to be as private as it is accessible.
1. What this covers
CLAVA is operated by CLAVA Labs LLC, a Connecticut limited liability company. This policy covers the public CLAVA website and the gated CLAVA workspace. It does not govern a client institution's own admissions platform or website — those are the client's, under the client's own privacy notice. Where CLAVA processes client-controlled data, the signed agreement defines each party's role and obligations.
2. What we collect — and what we deliberately don't
Our rule is data with a reason. If a field or artifact does not help us reply, deliver scoped work, protect a person, or maintain a trustworthy system, we should not collect it. When we do collect something, we explain the purpose in plain language and keep it tied to that purpose.
- The public site: if you email us (e.g., [email protected]) or use the interest form, we receive what you send. The public interest form routes to CLAVA's email inbox; the public site does not store form submissions, display third-party ads, use ad pixels, or use analytics cookies. Name and work email let a human reply; optional context helps us route the conversation; the safety acknowledgement reduces the risk of accidental confidential submissions. UTM tags (source, medium, campaign, content) from this URL or a same-origin referrer accompany the email only on submission. We do not write them to cookies or Web Storage or use them for cross-site tracking. Tags may remain in browser history. If Cloudflare Web Analytics is enabled, it is used for aggregate traffic and performance signals, not advertising or cross-site profiling. Cloudflare Turnstile processes a verification when you use the interest form to reduce automated abuse; see Cloudflare's Privacy Policy.
- The gated workspace: an access provider verifies identity under the configured access policy. We process the identity of an authorized person to grant and protect access, not to build a behavioral profile.
- Client work: we process the configuration, brand assets, and template / reusable content a client gives us to do the work. Starter audits and the current content tools are scoped to public, synthetic, client-approved, or reusable template material rather than submitted applications, recommender letters, or decision records. Any materially different data scope must be documented and approved in writing before work begins.
3. No surveillance of persons
Our releases carry integrity / version signals that identify the artifact (which authorized release a file is, and whether it's intact) — never the people who use or operate it. Any such signal carries no personal or behavioral data.
4. How we use it; who we share with
We use what we collect only to provide and improve the agreed service and to communicate with you. We do not sell, rent, or trade personal data. We share data only with providers needed for that service, such as website hosting, access, email delivery, abuse prevention, and, when included in a written scope, AI-assisted processing. We use providers only for the stated purpose; their handling is also governed by their terms. Before non-public material is sent to an AI provider, the written client scope must identify the approved material and purpose, provider category, retention or training terms where applicable, and human review. We may also disclose data where required by law.
5. Security and AI-assisted processing
Security reduces risk; it cannot eliminate it. The current public site limits its fields, routes the interest form to an inbox rather than a public-site submission database, checks for automated abuse, and applies browser rules that limit scripts, forms, framing, and device permissions. Do not send credentials, secrets, confidential records, or person-level learner data through that form. Any AI use on non-public material requires an agreed scope, appropriate provider disclosure, and human review.
6. Where it lives, retention, and deletion
Data may be hosted or processed by the providers described above. Retention varies by source and purpose. We retain information only for a documented business, contractual, legal, or security reason; client-work periods are set by the signed agreement. You may request deletion, subject to stated recordkeeping exceptions.
7. Your access, correction, and deletion choices
You may ask what we hold about you, request a copy, correction, or deletion, or ask us to stop emailing you — write to [email protected]. We honor applicable privacy rights (e.g., access, correction, deletion) under applicable law, and we may honor broader requests when we can. If a legal, security, or written client obligation requires us to keep a limited record, we will explain the reason and keep only what is necessary.
8. Children & equity
The public site is not directed at children. Because the systems we build are often a learner's first contact with an institution or program, we hold privacy to the same standard as accessibility: a right, designed in from the first pixel, never traded for convenience.
9. Changes & contact
We may update this policy; material changes will be posted here with a new version date. Questions or requests: [email protected].