Privacy Policy
Upwind ("Upwind," "we," "us," or "our") is a recruiting command center for college students. This Privacy Policy explains what information we collect when you use Upwind at joinupwind.app, why we collect it, who we share it with, and the choices you have.
Upwind doesn't yet operate as a formally incorporated company. Until it does, "Upwind" refers to the product operated by its founder, reachable at mahmoud@joinupwind.app for anything in this policy.
By creating an account, or by continuing to use an existing account after being asked to accept an updated version of this policy, you agree to it. If you don't agree, don't use Upwind — see "Your choices" below for what happens to an account that doesn't accept an update.
Information we collect
Account information. When you sign in with Google, we receive your name and email address through Google and Supabase, our authentication and database provider. We don't collect or store a password — Google handles sign-in.
Profile information you provide. School, expected graduation year, majors, and your recruiting preferences — target roles, industries, locations, season, experience level, work mode, and, only if you choose to answer, whether you'll need visa sponsorship. Every one of these is optional and never required to use Upwind.
Files and links you add. Resumes, cover letters, transcripts, and other documents you upload to your Asset Vault, plus any links you save — portfolio, LinkedIn, GitHub, personal site. Files are stored in a private location only you can access.
Your application pipeline. The companies and roles you're tracking, the stage each one is in, notes you write, next actions, and dates. This is entirely self-reported — we don't verify it and don't obtain it from any employer.
Recruiting contacts and interview notes. If you choose to track a recruiter's name, email, or LinkedIn URL, or notes about an interview — prep notes, a debrief, a schedule, a location — that's stored against the specific application you added it to.
Club membership. Which clubs, if any, you join through Upwind.
Product usage. We log a small set of internal events — like which tab you viewed, or that you marked something as applied — to understand how the product is used. These events carry codes and counts, never the content you typed. See "Who else sees your information" below.
Feedback you send us. Anything you submit through Upwind's in-app feedback form, plus the page you were on when you sent it.
How we use your information
To operate Upwind — to run your dashboard, pipeline, reminders, and every other part of the product you interact with directly.
To send you reminder emails about deadlines and next actions, if you haven't turned them off. Every reminder links back to your Profile, where you can turn them off at any time.
To respond to feedback and support requests you send us.
To maintain and improve Upwind — understanding usage patterns, fixing bugs, and deciding what to build next.
To generate aggregate, group-level analytics that we may share with, or sell to, partner clubs and, in the future, partner institutions. This is the one use of your data that isn't purely about running the product for you, so we describe it on its own below rather than folding it into a general sentence.
Aggregate analytics we share with clubs and institutions
If you join a club through Upwind, the club's officers can see aggregate statistics about the club's members as a group — for example, how many members applied to a given company this cycle, or which industries are most common among members. These statistics are never about you individually.
Concretely: a club's dashboard stays locked until it has at least 10 members, and any individual data point in a breakdown — a company, a major, an academic unit — is grouped into a range rather than shown as an exact small number when the group is small. No club officer, and no institution, can see your name, your email, your specific applications, your notes, your files, or your resume through this feature — only counts and ranges about the group as a whole.
We may share or sell this kind of aggregate, group-level information — never your individual, identifiable activity — with partner clubs and, as Upwind grows, partner institutions such as schools and career centers. We're disclosing this plainly because it's a real part of how Upwind may generate revenue, and because it's a condition of using Upwind through a club or institutional partner, not a setting you can opt out of feature-by-feature.
We do not sell your personal information to employers, and we do not give any employer visibility into your individual activity before you choose to apply. What's described here is limited to aggregate, group-level statistics shared with clubs and institutions — not individual data, and not employers.
Anyone we share this aggregate information with agrees not to attempt to re-identify an individual student from it.
Who else sees your information
We use a small number of outside services to run Upwind. None of them may use your information for their own purposes — they process it only to provide their service to us.
We don't use any third-party advertising or analytics trackers, and we don't use tracking cookies. The product-usage analytics described above are recorded to our own database, not sent to any outside analytics company.
- Google — handles sign-in (OAuth). Google sees that you're signing into Upwind; it doesn't see your Upwind data.
- Supabase — our database, authentication, and file-storage provider. Nearly everything described above is stored there.
- Vercel — hosts Upwind and runs the scheduled job that sends reminder emails.
- Resend — sends your reminder emails on our behalf. It sees your email address and the reminder content; it doesn't get access to your account.
- Sentry — helps us catch and fix errors. It's configured to not collect personal information, and request details, cookies, and page content are stripped before an error is ever sent to it — it only ever sees a bare account identifier.
Your choices
Update or correct your profile, preferences, files, and pipeline data at any time from within Upwind.
Turn off reminder emails at any time from your Profile.
Ask us for a copy of your data, or ask us to delete your account and data, by emailing mahmoud@joinupwind.app. We don't yet have a self-service export or delete button in the product — until we do, this is a manual request we'll handle by email, and we'll respond within a reasonable time.
If we ever update this Privacy Policy or our Terms of Service in a way that requires renewed acceptance, an account that doesn't accept isn't deleted — it's paused. Your data stays exactly as it is, you're signed out, and you can come back and accept whenever you're ready to keep using Upwind.
How long we keep your information
We keep your information for as long as your account exists — including a paused, not-yet-re-accepted account, which we keep rather than delete, exactly as described above. We may also keep some information for a period after an account is closed where we have a legitimate business, legal, or security reason to — for example, to comply with the law, resolve a dispute, or maintain security logs.
If you ask us to delete your data, we'll do so within a reasonable time, except for anything we're required to keep.
Security
Your data is protected by row-level security in our database — code that enforces your data belongs to you, not just application logic that happens to check it. Files you upload are stored in a private location that only you can access, and are only ever shared with you through short-lived, signed links. Our error-monitoring tool is configured to never see request content, cookies, or personal data. No method of storing or transmitting data is perfectly secure, but Upwind's data model is built around minimizing what could go wrong.
If we ever experience a security incident that puts your personal information at risk, we'll notify affected users, and any regulators or authorities the law requires, without unreasonable delay.
Children's privacy
Upwind is built for college students and isn't directed at children. We don't knowingly collect information from anyone under 13. If we learn we've collected information from a child under 13, we'll delete it. If you're under 18, using Upwind means you have the legal capacity to agree to this policy and our Terms of Service, or a parent or guardian's permission to do so.
If Upwind is acquired or merged
If Upwind is ever acquired, merged with another company, or has its assets sold, your information may transfer as part of that transaction. Whoever receives it remains bound by this Privacy Policy, or will give you notice if they intend to handle your information differently.
Changes to this policy
We may update this Privacy Policy as Upwind changes. If we make a material change, we'll ask you to accept the updated version the next time you use Upwind — the same acceptance flow that applies today. Every version is dated, and we keep a record of which version you accepted and when.
Your rights under state privacy law
Depending on where you live, a state privacy law may give you rights beyond what's described above — for example, the right to know exactly what we've collected about you, correct it, delete it, or opt out of a "sale" of your personal information as that state defines it. Whether a given law currently applies to Upwind depends on things like how many residents of that state use Upwind, which changes as Upwind grows. If one ever applies to you, we'll update this policy and add the tools it requires, like a "Do Not Sell or Share My Personal Information" option, rather than assume the aggregate-analytics description above is sufficient on its own.
Nothing in this policy or in our Terms of Service waives any right a state privacy law gives you. If anything here ever conflicts with a right you're legally entitled to, the law wins.
Contact us
Questions about this policy, or a data request: mahmoud@joinupwind.app.