Privacy Policy
Last updated: 6 October 2026 · Version 2026-10-06 Status: in force for the beta. Takes effect for the public on the day Bema opens.
Bema is a workspace for organizing a college application. This policy explains what we collect, why, who can see it, and how to get it back or delete it. It is written to be read, not to be survived.
If anything here is unclear, write to getbemaai@gmail.com and we will answer
in plain language.
1. Who we are
Bema is operated by Bema's founders, Lars Kellner, Manuel Teijeiro, Ian de Haan and David Nocero, in Miami, Florida. Once Bema's company is registered, it takes their place here and we will update this page. For the purposes of data-protection law we are the controller of the information described below.
Bema is not affiliated with the Common Application, the College Board, ACT, or the U.S. Department of Education. We do not submit applications on your behalf, and we never ask for your login to any of those services.
2. Who can use Bema
Bema is for students aged 13 and over and their parents or guardians. At signup we ask your age range; if you tell us you are under 13 we do not create an account and do not keep what you typed. We do not knowingly collect information from anyone under 13. See our Children's Privacy notice for the detail, including what happens if we learn a younger child has signed up.
3. What we collect
Information you give us
Account — your name, email address, whether you are a student or a parent, for students, your age range (13–17 / 18 and over) and birth year. You type your date of birth at signup so our server can work out your age; the full date is never stored. Parents are not asked their age. We also keep the version of these policies you agreed to and when, whether you have confirmed your email address, and a password. We never store your password itself, only a bcrypt hash of it.
Student profile — high school, graduation year, GPA, class rank, SAT/ACT scores, whether you are applying test-optional, intended major, and your application deadlines.
Your application work — your college list and everything you record about each school, your checklist, tasks, deadlines, campus visits, scholarships, recommendation tracking, admission decisions and aid offers.
Your essays — drafts, prompts, word counts, and the comments and suggested edits left on them.
Your Common App workspace — the fields you choose to fill in, which mirror the Common Application itself. Some of these are sensitive, and all of them are optional:
- demographic information (race and ethnicity, religion, gender identity, sexual orientation, military service)
- citizenship and immigration status, country of birth, visa status
- family information, including your parents' occupations and education
- financial indicators, including fee-waiver eligibility and your Student Aid Index
- disciplinary history
We ask for these because the Common Application asks for them, and drafting them in Bema first is the point of the product. You are never required to enter any of them to use Bema, and you can clear any field at any time.
Conversations with the AI — what you type to the AI counselor and the essay coach, and its replies. When you ask Bema to change your lists ("remove Stanford"), it asks you to confirm before removing anything, and keeps a copy of what it removed for 30 days so you can undo it. If a message triggers our crisis protocol, the protocol's reply is stored in the same conversation.
AI usage counts — how many AI requests your account has made today and this week, so we can apply the allowance shown in Settings. A number, not the content. Your device also tells us its timezone with each request, so "today" is your day rather than the server's; it is used for that and nothing else.
Documents you upload for scanning — a transcript or score report you choose to upload so that Bema can read it.
Information we collect automatically
Technical data needed to run the service: your IP address, browser type and the timestamps of requests, kept in server logs, and used in memory to limit how fast one connection can sign up, sign in, or request emails.
A security log — when you sign in, a wrong password is tried on your account, your password changes, or your data is downloaded, we record the event, the time and the IP address it came from. It holds no content and no email address. You can see your own recent entries in Settings, and we keep it for one year to investigate misuse.
Bug and crash reports — when a screen fails, the app sends us the error, the page you were on, your device type and app version, and, if you choose to add them, your own words about what happened. These are tied to your account so we can follow up, and are read only by the founders.
The human check — signup and repeated failed sign-ins use hCaptcha (Intuition Machines, Inc.) to check that a person, not a bot, is there. hCaptcha receives your device and browser information and how you interact with the check, under its own privacy policy (https://www.hcaptcha.com/privacy). It does not receive your name, email, essays or profile. Where hCaptcha is unavailable, a picture or written check drawn by our own server is used instead.
Cookies and local storage
We do not use advertising trackers, third-party analytics pixels, or cross-site tracking cookies. We set no cookies at all. Bema stores a few things in your browser's or the app's local storage: your sign-in token, which student a parent last viewed, whether you have seen the onboarding, your sidebar preference, the "share my progress with the counselor" switch, and when your current AI session started (for the break reminder shown to under-18s). None of it leaves your device except the token, which identifies you to our server.
4. Why we use it
| What we use it for | Why we are allowed to |
|---|---|
| Running your account and keeping you signed in | To provide the service you asked for |
| Building your checklist, readiness score and timeline | To provide the service you asked for |
| Showing a connected parent your progress and your work | Your consent, given by accepting their request |
| Sending password resets and parent invitations | To provide the service you asked for |
| Answering your questions through the AI features | To provide the service you asked for |
| Keeping the service secure and debugging faults | Our legitimate interest in a working, safe product |
| Understanding which features are used, in aggregate | Our legitimate interest in improving Bema |
We do not sell your personal information, and we do not share it with advertisers. That includes selling or renting lists of students to colleges, scholarship services or anyone else. We do not use your essays, your Common App answers, or your conversations to train any AI model, ours or anyone else's.
This promise covers everything collected while it is in force. If we ever offered a way to connect you with a college or scholarship, it would be a separate choice you switch on yourself (or, under 18, with a parent), for that one connection, and never something we turn on for you.
5. Who can see your information
Your parents or guardians
This is the part of Bema most worth understanding, so it is set out precisely.
A parent sees nothing until the student accepts their request. A parent enters a student's email address; the student receives an invitation and either approves or declines it from their own account. Sending an invitation on its own grants no access at all, and an invitation expires after 14 days if it is never answered.
Once the student accepts, that parent can see the student's progress, college list, checklist, deadlines, financial-aid information, and the content of the student's essays — they can read drafts, leave comments and propose specific wording changes.
Three limits hold regardless:
- A parent cannot change the student's work. A suggested edit is a proposal. Only the student can accept it, and only accepting it changes a word of the essay. This is enforced in the server, not in the interface.
- A parent cannot read the student's conversations with the AI coach. Those are the student's own thinking, and they stay private.
- Each parent connects independently. Where parents are separated or divorced, neither can see the other's account, and disconnecting one has no effect on the other.
A student can disconnect any parent at any time, and that parent's access ends immediately.
Service providers
We use a small number of companies to run Bema. Each processes data only on our instructions:
| Provider | What they do | What they see |
|---|---|---|
| Anthropic (US) | Powers the AI counselor, essay coach, Common App and FAFSA explanations, scholarship and grant search, fit quiz, college summaries, cost estimates and document scanning | The text of the question you ask and the context Bema sends with it — which can include your essay draft, your profile, your college list, and any document you upload for scanning. Never your password, and never an SSN or FSA ID (the server refuses those) |
| Render (US) | Runs the API server and stores the database | All stored data, encrypted at rest |
| hCaptcha (Intuition Machines, US) | The "are you human" check at signup and after failed sign-ins | Device, browser and interaction signals from the check itself. No name, email or profile |
| Google (Gmail) (US) | Delivers password resets, email confirmations and parent invitations | Your email address and the content of those messages |
| Wikimedia Foundation | Supplies the photo and short description on college profile pages | Your device fetches these directly from Wikipedia, so Wikipedia sees your IP address and which college you looked up — not your account |
| Google Maps | The campus map on a college profile, shown only after you open it | Your device loads the map directly from Google, so Google sees your IP address and the campus location — not your account |
| Apple | Distributes the iOS app | What Apple's own App Store privacy policy describes; we receive no personal data from Apple |
Anthropic does not use data submitted through its API to train its models.
Everyone else
We disclose personal information outside the list above only when the law requires it, when we must in order to protect someone's safety, or as part of a merger or acquisition — and in that last case we will tell you first and give you the chance to delete your account.
6. Sensitive categories, said plainly
Some of what the Common Application asks for is genuinely sensitive: race, religion, sexual orientation, immigration status, disciplinary history, family finances.
- Every one of these fields is optional in Bema.
- We do not use any of them to make decisions about you or to target anything at you.
- If your immigration status is a concern for you, you can use every other part of Bema without entering it. Draft that section on the Common Application itself if you would rather it never sat in our database.
We think you should have that choice stated openly rather than buried.
7. How long we keep it
We keep your information for as long as your account is open. When you delete your account we delete your personal data within 30 days, except where we must keep something to comply with a legal obligation.
Server logs are kept for 90 days, and the security log for one year. Backups roll off within 35 days, so deleted data can persist in a backup for that period before it is gone for good. If nobody signs in to an account for two years, we email a warning and delete it 30 days later unless someone signs in.
Full detail is in our Data Retention & Deletion policy.
8. Your rights
Wherever you live, you can:
- See everything we hold about you
- Correct anything that is wrong
- Delete your account and your data
- Export your data in a portable format
- Withdraw consent — a student can disconnect any parent at any time
- Object to a particular use, or ask us to restrict it
Email getbemaai@gmail.com and we will respond within 30 days. We will never
charge you for exercising a right, and we will not treat you differently for
doing so.
If you are in California, the CCPA/CPRA gives you these rights by name, including the right to know what is collected, the right to correct, the right to delete, and the right to opt out of sale or sharing — we do neither, so there is nothing to opt out of. We do not sell or share the personal information of anyone, and specifically not of anyone under 16. We do not use or disclose sensitive personal information for any purpose beyond providing Bema. We honor Global Privacy Control signals as an opt-out even though we have nothing to opt you out of. If you are in the EEA or UK, the GDPR gives you the rights above plus the right to complain to your supervisory authority. If you are a student in a US state with a student-privacy law (California's SOPIPA and the laws modelled on it), we do not sell student data, do not use it for targeted advertising, and do not build a profile of you for any purpose except providing Bema.
9. Security
Passwords are hashed with bcrypt and cannot be one of the commonly leaked ones. Access is controlled by signed tokens that die when you change your password, and Settings lets you sign out every device at once. Every request for a student's data is checked against whether the requester is that student or a parent the student has connected with — there is no path through the API that returns one family's data to another. Signup, sign-in and email requests are rate-limited, and signup requires a human check we run ourselves. Identity numbers (SSN, FSA ID, ITIN, A-Number, license) are refused by the server and never stored.
9a. Extra care for users under 18
- The AI says plainly that it is an AI, and the app shows that above every conversation.
- If a message sounds like a crisis, the AI stops and gives the 988 Suicide & Crisis Lifeline and Crisis Text Line instead of an answer. The protocol is published in the AI policy.
- The AI is instructed never to produce sexual or romantic content, never to role-play a person, and never to encourage secrecy from parents.
- A user who told us they are 13–17 sees a "take a break" note after three hours of continuous AI use in one session.
- The essay coach and counselor are private from parents by design, and a parent cannot edit a student's work.
- We show no advertising and build no behavioral profile.
No system is perfectly secure, and we will not pretend otherwise. If you find a weakness, our Security policy tells you how to report it.
10. Where your data lives
Bema is operated from the United States and your data is stored there. If you use Bema from outside the US, you are sending your information to the US, where privacy law differs from your own.
11. Changes
If we change this policy in a way that matters, we will email you and show a notice in the app before it takes effect, and the app will ask you to agree to the new version before you continue. The date at the top always reflects the current version, and Settings shows which version your account agreed to.
12. Contact
getbemaai@gmail.com · Bema, Miami, Florida
If you are in the EEA or UK and want to complain to a supervisory authority, you may; we would rather you told us first.