New Paths.ai ← Back to NewPaths
Legal

Privacy Policy

Last updated: June 10, 2026 · Version 2.3
The short version: NewPaths collects only what's needed to help people explore careers and to give counselors a useful view of their work. We do not sell personal information. We do not allow AI providers to train on the data we send them. Student records held under a school or institutional account are controlled by that institution, not by us. You can request a copy or deletion of your data at any time by emailing grant@newpaths.ai. Institutional buyers can request our Security Statement, a Data Processing Agreement, and a completed vendor security assessment.
Jump to Who we are What we collect How we use it Third parties AI training Retention Institutions & minors Your rights Security Changes Contact

Who we are

NewPaths.ai is operated by North Jersey Creative Services LLC, a New Jersey limited liability company. We built NewPaths to help people — students, working adults, and the educators and advisors who support them — navigate how artificial intelligence is changing careers. This policy explains what information we collect about you, how we use it, who we share it with, how long we keep it, and the rights you have over it.

This policy applies to the NewPaths.ai website, our serverless API, and any related services we operate. It does not apply to third-party sites we link to.

If you're a student, working adult, advisor, counselor, or an administrator at a college, university, or district with questions about how we handle data, email us at grant@newpaths.ai. We'll respond within a reasonable time.

What we collect

What we collect depends on which part of NewPaths you use. NewPaths has three primary surfaces: the public assessment, the counselor/advisor dashboard (for institutional staff), and the shared-report viewer (for someone opening a link sent by a learner or advisor).

From everyone who takes an assessment

If you provide your email

If you make a payment

NewPaths is free to start. If you choose the optional one-time paid unlock (additional reports for a single $4.99 charge — no subscription), payment is processed by Stripe. We do not see or store your full card number, CVC, or other raw card data — Stripe handles that directly and is PCI-DSS compliant.

If you are a counselor or advisor with an account

When a college, university, district, or other institution licenses NewPaths and you are issued an account by your administrator, we additionally collect and store:

If you sign in via magic-link

We use Supabase to handle authentication. When you request a sign-in link, Supabase issues a one-time token tied to your email. We store the resulting session token (which expires) so we can recognize you on return visits. We do not store your password — there is no password.

How we use it

We do not sell personal information. We do not share email addresses with third-party marketers. We do not use your data to train AI models — see the AI training section below for specifics.

Third parties we use

NewPaths is built on a small set of vendors. We do not share data with anyone outside this list. All of our infrastructure and data storage is located in the United States.

A current list of subprocessors is available to institutional customers on request. We may also disclose information if required to do so by law, by valid legal process, or to protect the safety of our users.

AI training and your data

This is a question we get often, especially from institutions, so we want to be explicit.

We do not use any data submitted to NewPaths to train AI models, our own or anyone else's.

How long we keep data

Different categories of data have different retention timelines:

Institutional customers, students, and minors

NewPaths serves both individual adults using the public product and institutions — colleges, universities, and districts — that license NewPaths for their students. Where an institution's use involves minors (for example, high-school students in a district deployment), we handle that data with extra care.

When an institution licenses NewPaths

When a college, university, or district licenses NewPaths and issues accounts to its staff, the institution is the data controller for the learner records created under those accounts. We act as a service provider (a "data processor," or in U.S. K-12 terms a "school official" under FERPA's school-official exception). Practically, this means:

Where FERPA applies to an institution's use of NewPaths, we operate within FERPA's school-official exception: we use student records only for the educational service the institution engaged us to provide, we do not redisclose those records, and we follow the institution's instructions on retention and deletion. We recognize that, for postsecondary students, FERPA rights generally belong to the student rather than a parent.

Students under 18

NewPaths can be useful to high-school students, who are typically minors, and we take that seriously. For the public, non-institutional flow, we ask that students under 13 not provide an email address without a parent or guardian's involvement. For students 13–17, we encourage parental involvement but do not technically gate it. For institution-licensed deployments, parental notice and consent are the responsibility of the institution, consistent with how schools handle other educational software; we will support institutions in providing parents with clear information about NewPaths on request.

Students under 13

NewPaths is not directed at children under 13. We do not knowingly collect personal information from children under 13 outside of an institution-licensed deployment where the institution has appropriate consent. If you believe we have inadvertently collected information from a child under 13, please email grant@newpaths.ai and we will delete it.

Your rights

Depending on where you live, you may have legal rights over the personal information we hold about you, including the right to access, correct, delete, object to or restrict processing, request portability, withdraw consent, and lodge a complaint with your local data protection authority.

If you are a learner whose data was added to a counselor's or advisor's roster as part of an institutional license, your rights to access, correct, or delete are exercised through your institution, not directly with us. We will, however, help your institution respond to your request.

To exercise any of these rights, email grant@newpaths.ai. We will respond within 30 days.

California residents

If you are a California resident, you have the rights described above under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We do not sell personal information as defined under California law.

EU / UK / other GDPR-style jurisdictions

NewPaths is primarily intended for U.S. users. If you access NewPaths from outside the U.S., you do so at your own initiative and consent to the transfer of your data to the U.S. Our legal bases for processing under GDPR are contract (where we provide the service to you), legitimate interests (for analytics and product improvement), and consent (where you have given it, such as for marketing email).

Security

We use security practices appropriate to the data we hold: data is encrypted in transit (HTTPS) and at rest (Supabase database encryption); authentication uses passwordless magic links with expiring tokens; application secrets and database credentials are stored server-side and are never exposed to the browser; and access to learner records is scoped to the authenticated counselor or advisor and their organization. A fuller, plain-language description — including our infrastructure, access controls, application-security measures, and the items on our security roadmap — is in our Security Statement.

Incident notification. No system is perfectly secure. In the event of a confirmed data breach affecting personal information, we will notify affected institutional customers without undue delay and cooperate with them in meeting any notification obligations, consistent with our Data Processing Agreements and applicable law. If you become aware of a security issue, please report it to grant@newpaths.ai and we will investigate promptly.

Changes to this policy

We may update this privacy policy from time to time, particularly as the product evolves. We will revise the "Last updated" date at the top of this page and bump the version number. For material changes that affect existing accounts, we will provide notice in the dashboard or by email. Continued use of NewPaths after a change constitutes acceptance of the updated policy.

Contact us

Privacy questions, requests, complaints, or anything else:

Grant Salmon, Founder
North Jersey Creative Services LLC
Email: grant@newpaths.ai