Privacy & AI
Plain answers about your family's data.
What we store
As a guest, decision content you enter stays in this browser. With an account, your family workspace is stored securely so it can sync across devices and family members.
Tour photos and optional application documents are private, family-scoped files opened through expiring links. Guest photos remain on that device. BrightSift does not scan application files for malware or send them to AI.
Provider verification requests store the requested fields, an expiring one-way-hashed token, and the response. Providers see only the school name and questions—not your child, notes, documents, or workspace.
Advisor briefs use a redacted snapshot and an expiring one-way-hashed token. They omit child identity and birth date, family contacts, private notes, photos, documents, and provider responses, and can be revoked.
Family research, verification history, logistics, reminders, and approved intake suggestions remain private family records. Raw pasted email and calendar files are not saved.
If push reminders are enabled later, BrightSift stores reminder preferences, the browser push endpoint and encryption keys, and a delivery ledger used to prevent duplicates. Push remains disabled during beta pending operational approval.
Product analytics
Where analytics has been approved and enabled, BrightSift records a limited set of coarse events to understand whether the workflow works.
Analytics excludes child names, school IDs, notes, document details, family IDs, and IP addresses. It is not used for advertising.
AI features
The AI Coach is unavailable while BrightSift defines and approves a bounded input contract.
BrightSift does not send questions, presets, notes, or family decision data to an AI provider while this gate is closed.
School data
Catalog and licensing records can lag reality and do not prove attendance assignment, admission, transportation, openings, quality, or fit.
Official inspection fields retain their dates and terminology. BrightSift does not turn them into a safety score, and missing imported actions are not an official all-clear.
Facts your family records are private and are never presented as public provider claims.
Your controls
Export your family workspace as JSON from Family → Data. Operational credentials, private document files, and another member’s private ballot are never embedded in that export.
Delete cloud or guest data from Family → Data. Paid plans remain disabled during beta until the applicable terms are approved.
Support & status
Questions, a data request, or a problem? Email support@brightsift.com.
This is a beta. The current Beta Terms explain the operating boundaries. Final retention, subprocessor, refund, and jurisdiction provisions still require legal approval before a paid public launch.