Privacy Policy
Last updated: September 2, 2025
This Privacy Policy explains how SpikeClinic AI (“SpikeClinic”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards information when you visit or use our website, products, and services (collectively, the “Services”). By using the Services, you agree to the practices described here. If you do not agree, please do not use the Services.
1) Information We Collect
- Account and Contact Data: name, email address, school year, country/region, parent/guardian contact (where applicable).
- Assessment Inputs: responses you provide, preferences, extracurricular history, academic data you choose to share, and feedback.
- Technical Data: device/browser info, IP address, approximate location (derived from IP), pages viewed, referrer, and cookies.
- Communications: messages, support requests, survey responses.
- Payment-Related Data: if/when payments are enabled, limited billing details handled by our payment processor (we don’t store full card numbers).
2) How We Use Information
- Provide, personalize, and improve the Spike Assessment and related recommendations.
- Operate AI models and analytics to generate insights and product improvements.
- Communicate with you (service notices, invitations, updates, and marketing with your consent where required).
- Maintain safety, security, fraud prevention, and enforce our Terms.
- Comply with law, legal process, and protect our rights and users.
3) Legal Bases (EEA/UK where applicable)
- Performance of a contract (to deliver the Services you request).
- Legitimate interests (to secure and improve the Services, prevent abuse).
- Consent (for certain processing like marketing emails or optional cookies).
- Legal obligations (to comply with applicable law).
4) Children’s Privacy (COPPA)
Our Services are intended for use by students and parents. We do not knowingly collect personal information from children under 13 without verifiable parental consent, as required by the U.S. Children’s Online Privacy Protection Act (COPPA). If you believe a child under 13 has provided personal information to us without consent, contact us at support@spikeclinicai.com and we will promptly delete such information. Where required, we will obtain parental consent before processing a child’s data.
5) State Privacy Rights (e.g., CA/VA/CO/CT/UT)
Depending on your state of residence, you may have rights to access, correct, delete, or receive a copy of your personal information; opt out of targeted advertising, selling or sharing personal data; and limit use and disclosure of sensitive personal information. To exercise these rights, contact support@spikeclinicai.com. We will verify requests and respond consistent with applicable law, including the California Consumer Privacy Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), and Utah Consumer Privacy Act (UCPA).
- We do not sell personal data as defined by applicable law.
- You may opt out of targeted advertising where applicable by contacting us.
- We process sensitive data only as reasonably necessary to provide the Services or with consent.
6) Data Retention
We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. We use criteria like account status, the nature of the data, and legal requirements to determine retention periods. We may anonymize data for research and product improvement.
7) Data Security
We use administrative, technical, and physical safeguards designed to protect personal information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8) Cookies and Similar Technologies
We use cookies and similar technologies for core functionality, analytics, and to remember preferences. You can control cookies via your browser settings. Some features may not function properly without certain cookies.
9) Disclosures and Transfers
- Service Providers and Partners: e.g., analytics, hosting, AI-model providers, payment processors—bound by confidentiality and data protection obligations.
- Legal and Safety: to comply with law, enforce policies, or protect users and our rights.
- Business Transfers: in connection with a merger, acquisition, or sale of assets, subject to appropriate safeguards.
- International Transfers: data may be processed in countries with different laws; we use appropriate safeguards where required.
10) Your Choices
- Access, correct, or delete your information by contacting support@spikeclinicai.com.
- Opt-out of marketing emails via unsubscribe links in those emails.
- Control cookies via your browser settings.
11) AI Processing
The assessment leverages AI models and expert-informed algorithms. We review and improve models using aggregated and/or de-identified data where possible. AI outputs may not be perfect; we continuously improve quality and fairness.
12) Changes to this Policy
We may update this Policy from time to time. The “Last updated” date reflects the latest changes. We will take appropriate steps to notify you of material changes, as required by law.