Privacy Policy
Who we are
NewPaths.ai is operated by North Jersey Creative Services LLC, a New Jersey limited liability company. We built NewPaths to help people — students, working adults, and the educators and advisors who support them — navigate how artificial intelligence is changing careers. This policy explains what information we collect about you, how we use it, who we share it with, how long we keep it, and the rights you have over it.
This policy applies to the NewPaths.ai website, our serverless API, and any related services we operate. It does not apply to third-party sites we link to.
If you're a student, working adult, advisor, counselor, or an administrator at a college, university, or district with questions about how we handle data, email us at grant@newpaths.ai. We'll respond within a reasonable time.
What we collect
What we collect depends on which part of NewPaths you use. NewPaths has three primary surfaces: the public assessment, the counselor/advisor dashboard (for institutional staff), and the shared-report viewer (for someone opening a link sent by a learner or advisor).
From everyone who takes an assessment
- Assessment responses. The career, major, or industry you tell us you're exploring, plus your answers to the short profile questions on the track you choose.
- Generated report content. The AI-generated career report we produce in response to your assessment, including the salary, AI-impact, and roadmap content shown on screen. The salary, AI-exposure, and career-growth figures are grounded in published data sources (U.S. BLS wage and employment-projections data, Tufts University Digital Planet, and the Anthropic Economic Index) rather than generated by the AI — see our Methodology for details.
- Region or location preference. The U.S. region or city you select so we can adjust salary and labor-market estimates.
- Browser-local usage data. Your free-report count, dismissed dialogs, and similar interaction state. This is stored in your browser's localStorage and is not transmitted to our servers unless you sign in to a counselor/advisor account.
- Analytics. Aggregated page views, click events, and basic device information (browser, screen size). We use Google Analytics for this, configured to anonymize IP addresses. Analytics data is not used to identify individuals.
If you provide your email
- Email address. You provide this voluntarily at certain points in the flow: to unlock additional free reports, to share a report by email, to request access to the dashboard demo, or to sign up as a counselor/advisor.
- Optional first name. If you provide one alongside your email.
- The role you indicated. Such as student, counselor, or counselor-lead, depending on which surface you provided your email through.
If you make a payment
NewPaths is free to start. If you choose the optional one-time paid unlock (additional reports for a single $4.99 charge — no subscription), payment is processed by Stripe. We do not see or store your full card number, CVC, or other raw card data — Stripe handles that directly and is PCI-DSS compliant.
- Payment record. We store a record of the transaction: the Stripe charge and session identifiers, the amount and currency, the email address associated with the payment, and how many reports it unlocked. We use this to apply your unlock, to provide support, and to handle any refund.
- Linkage to your reports. Because a paid unlock has to attach to you, the payment record is linked to the email address you unlocked reports under. This is a deliberate, narrow exception to our otherwise email-optional model: paying necessarily involves a payment identity. If you have not made a payment, none of this applies to you.
If you are a counselor or advisor with an account
When a college, university, district, or other institution licenses NewPaths and you are issued an account by your administrator, we additionally collect and store:
- Your work email. Used as your account identifier and for magic-link sign-in.
- Your organization affiliation. The institution that licensed NewPaths and that controls your account.
- Learner roster records you create. When you add learners to your roster — individually, in bulk, or through a cohort code — we store the learner labels (typically first name plus last initial, or whatever convention your institution uses), the unique learner codes we generate, and your association as their counselor/advisor.
- Assessment reports tagged to your account. When a learner you've rostered completes an assessment, or when someone uses one of your cohort codes, the resulting report is tagged to your account and to that learner record so you can review it later.
- Aggregate insights. We compute aggregate statistics across the reports tagged to your account (top careers, top majors, AI-exposure distribution) and show them in your dashboard.
If you sign in via magic-link
We use Supabase to handle authentication. When you request a sign-in link, Supabase issues a one-time token tied to your email. We store the resulting session token (which expires) so we can recognize you on return visits. We do not store your password — there is no password.
How we use it
- To generate your report. We send your assessment responses and location to Anthropic's API, which returns an AI-generated career analysis. We display the result and, in some cases, save it so it can be loaded again from a shareable URL. The salary, AI-exposure, and career-growth figures shown are grounded in published data sources, not generated by the AI — our Methodology explains exactly how.
- To remember your work as a counselor or advisor. Your roster, cohort codes, and the reports tagged to you persist across sessions so you can return to them.
- To send transactional email. Magic-link sign-ins, shared report links you initiate, and occasional product updates (which you can opt out of).
- To improve NewPaths. We look at aggregated analytics to understand which tracks are used, where people drop off, and which features work. This is done on aggregate data, not individual identifiable records.
- To respond to you. If you email us, we use your email to reply.
We do not sell personal information. We do not share email addresses with third-party marketers. We do not use your data to train AI models — see the AI training section below for specifics.
Third parties we use
NewPaths is built on a small set of vendors. We do not share data with anyone outside this list. All of our infrastructure and data storage is located in the United States.
- Anthropic (anthropic.com) — generates AI career analyses from your assessment input. Anthropic processes the prompt content and returns a response. We send Anthropic the career or major you're exploring, your assessment answers, and your selected region — we do not send Anthropic your name or email. See Anthropic's privacy policy.
- Supabase (supabase.com) — hosts our database. Counselor/advisor accounts, learner rosters, cohort codes, captured emails, and saved reports are stored in a Supabase Postgres instance under our account. Data is encrypted at rest and in transit. See Supabase's privacy policy.
- Netlify (netlify.com) — hosts the NewPaths website and our serverless functions. See Netlify's privacy policy.
- Google Analytics — aggregated usage analytics, configured to anonymize IP addresses. See Google's privacy policy.
- Stripe (stripe.com) — processes the optional one-time paid unlock. Stripe receives your card details and the payment amount directly; we receive only the transaction identifiers, amount, and the email associated with the payment. We never receive or store full card data. Used only if you choose to pay. See Stripe's privacy policy.
A current list of subprocessors is available to institutional customers on request. We may also disclose information if required to do so by law, by valid legal process, or to protect the safety of our users.
AI training and your data
This is a question we get often, especially from institutions, so we want to be explicit.
We do not use any data submitted to NewPaths to train AI models, our own or anyone else's.
- Assessment responses are sent to Anthropic's API to generate a report. Anthropic's commercial API terms commit Anthropic not to use API inputs and outputs to train their models by default. We are a commercial API customer and do not opt in to any training-data programs.
- We do not sell or license assessment content or reports to any third party for training purposes.
How long we keep data
Different categories of data have different retention timelines:
- Assessment responses sent to Anthropic. We do not retain these in our own database. Anthropic's retention is governed by their terms.
- Saved reports (for sharing). Reports saved to enable a shareable URL are retained while the URL is active. You can request deletion at any time.
- Captured emails. Retained until you ask us to remove them, or until you unsubscribe from product updates.
- Payment records. Retained as long as required for tax, accounting, and refund purposes (typically several years, as required by law), then deleted. Card data is never held by us — it lives with Stripe under their retention terms.
- Accounts and rosters. Retained for the duration of your institution's license, plus a brief wind-down period (typically 30 days) to allow data export. After that, records are deleted on request or after one year of license inactivity, whichever comes first.
- Analytics data. Aggregated; retained per Google Analytics defaults.
- Browser localStorage. Lives entirely in your browser. You can clear it at any time through browser settings.
Institutional customers, students, and minors
NewPaths serves both individual adults using the public product and institutions — colleges, universities, and districts — that license NewPaths for their students. Where an institution's use involves minors (for example, high-school students in a district deployment), we handle that data with extra care.
When an institution licenses NewPaths
When a college, university, or district licenses NewPaths and issues accounts to its staff, the institution is the data controller for the learner records created under those accounts. We act as a service provider (a "data processor," or in U.S. K-12 terms a "school official" under FERPA's school-official exception). Practically, this means:
- The institution determines what learner information is entered into NewPaths and which learners use it.
- We do not contact learners directly or use their data for any purpose other than providing the service to the institution.
- The institution retains the right to access, correct, or delete learner records at any time.
- We will execute a reasonable Data Processing Agreement with the institution as part of the licensing process, and can complete standard higher-education and K-12 vendor security and privacy assessments on request.
Where FERPA applies to an institution's use of NewPaths, we operate within FERPA's school-official exception: we use student records only for the educational service the institution engaged us to provide, we do not redisclose those records, and we follow the institution's instructions on retention and deletion. We recognize that, for postsecondary students, FERPA rights generally belong to the student rather than a parent.
Students under 18
NewPaths can be useful to high-school students, who are typically minors, and we take that seriously. For the public, non-institutional flow, we ask that students under 13 not provide an email address without a parent or guardian's involvement. For students 13–17, we encourage parental involvement but do not technically gate it. For institution-licensed deployments, parental notice and consent are the responsibility of the institution, consistent with how schools handle other educational software; we will support institutions in providing parents with clear information about NewPaths on request.
Students under 13
NewPaths is not directed at children under 13. We do not knowingly collect personal information from children under 13 outside of an institution-licensed deployment where the institution has appropriate consent. If you believe we have inadvertently collected information from a child under 13, please email grant@newpaths.ai and we will delete it.
Your rights
Depending on where you live, you may have legal rights over the personal information we hold about you, including the right to access, correct, delete, object to or restrict processing, request portability, withdraw consent, and lodge a complaint with your local data protection authority.
If you are a learner whose data was added to a counselor's or advisor's roster as part of an institutional license, your rights to access, correct, or delete are exercised through your institution, not directly with us. We will, however, help your institution respond to your request.
To exercise any of these rights, email grant@newpaths.ai. We will respond within 30 days.
California residents
If you are a California resident, you have the rights described above under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). We do not sell personal information as defined under California law.
EU / UK / other GDPR-style jurisdictions
NewPaths is primarily intended for U.S. users. If you access NewPaths from outside the U.S., you do so at your own initiative and consent to the transfer of your data to the U.S. Our legal bases for processing under GDPR are contract (where we provide the service to you), legitimate interests (for analytics and product improvement), and consent (where you have given it, such as for marketing email).
Security
We use security practices appropriate to the data we hold: data is encrypted in transit (HTTPS) and at rest (Supabase database encryption); authentication uses passwordless magic links with expiring tokens; application secrets and database credentials are stored server-side and are never exposed to the browser; and access to learner records is scoped to the authenticated counselor or advisor and their organization. A fuller, plain-language description — including our infrastructure, access controls, application-security measures, and the items on our security roadmap — is in our Security Statement.
Incident notification. No system is perfectly secure. In the event of a confirmed data breach affecting personal information, we will notify affected institutional customers without undue delay and cooperate with them in meeting any notification obligations, consistent with our Data Processing Agreements and applicable law. If you become aware of a security issue, please report it to grant@newpaths.ai and we will investigate promptly.
Changes to this policy
We may update this privacy policy from time to time, particularly as the product evolves. We will revise the "Last updated" date at the top of this page and bump the version number. For material changes that affect existing accounts, we will provide notice in the dashboard or by email. Continued use of NewPaths after a change constitutes acceptance of the updated policy.
Contact us
Privacy questions, requests, complaints, or anything else:
Grant Salmon, Founder
North Jersey Creative Services LLC
Email: grant@newpaths.ai