Privacy Policy
Effective Date: January 15, 2025
Welcome to Discuno ("we", "us", or "our"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our peer-to-peer mentorship platform.
By using Discuno, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our platform.
Please also review our Terms of Service, which govern your use of Discuno.
1.1 Information You Provide to Us
- Account Information: Name, email address (.edu for mentors), profile photo, university affiliation, graduation year, major
- Profile Information: Bio, areas of expertise, experience, availability, pricing (for mentors)
- Payment Information: Stripe account details (stored by Stripe, not by us), billing address, transaction history
- Communications: Messages sent through our platform, support inquiries, feedback, reviews
- User Content: Posts, comments, reviews, and other content you create on the platform
1.2 Information Collected Automatically
- Device Information: IP address, browser type and version, operating system, device identifiers
- Usage Data: Pages visited, time spent on pages, click patterns, session duration, referring URLs
- Analytics Data: Collected through PostHog to understand user behavior and improve our services
- Cookies and Similar Technologies: Session cookies, authentication tokens, preference settings
1.3 Information from Third Parties
- OAuth Providers: Basic profile information from Google, Microsoft, or other authentication providers you use to sign in
- Stripe: Payment processing information, verification status, payout details
- Cal.com: Calendar availability, booking information, scheduling data
We use your information for the following purposes:
- Provide Services: Create and manage your account, facilitate bookings, process payments, enable mentorship sessions
- Communication: Send booking confirmations, payment receipts, platform updates, support responses
- Platform Improvement: Analyze usage patterns, conduct research, develop new features, improve user experience
- Safety and Security: Verify identities, prevent fraud, enforce our Terms of Service, protect user safety
- Legal Compliance: Comply with legal obligations, respond to legal requests, enforce our agreements
- Marketing: Send promotional materials about new features or services (you can opt out at any time)
- Personalization: Customize your experience, recommend relevant mentors, display relevant content
We may share your information in the following circumstances:
3.1 Public Information
- Mentor profiles (name, photo, bio, university, major, expertise, reviews) are publicly visible
- Posts and comments you make on the platform are visible to other users
3.2 Between Users
- Booking information is shared between mentors and mentees for scheduled sessions
- Calendar links and meeting details are exchanged to facilitate sessions
3.3 Service Providers
- Stripe: Payment processing, identity verification, payout processing
- Cal.com: Calendar management, booking coordination, scheduling
- PostHog: Analytics and product insights (anonymized when possible)
- Railway: Database hosting and infrastructure
- Vercel: Application hosting and deployment
- Upstash: Redis caching and rate limiting
3.4 Legal Requirements
- When required by law, regulation, or legal process
- To protect our rights, property, or safety, or that of our users
- In connection with fraud prevention or security investigations
- To enforce our Terms of Service or other agreements
3.5 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
3.6 With Your Consent
We may share your information for any other purpose with your explicit consent.
We do not sell your personal information to third parties.
We retain your information for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal, tax, or accounting requirements
- Resolve disputes and enforce our agreements
- Maintain business records and analytics
Account Deletion: When you delete your account, your personal information and public profile will be deleted or anonymized within 30 days. Content that others have interacted with (such as reviews, posts, or public comments) may remain visible in anonymized form to preserve the integrity of community interactions.
Transaction records and payment history may be retained for up to 7 years to comply with tax and financial regulations. Deleted content may persist in backups for up to 90 days before permanent removal.
Depending on your location, you may have the following rights:
5.1 Access and Portability
- Request a copy of your personal information
- Download your data in a portable format
5.2 Correction
- Update or correct inaccurate information through your account settings
- Request that we correct information we hold about you
5.3 Deletion
- Delete your account and associated data
- Request deletion of specific information (subject to legal obligations)
5.4 Opt-Out
- Unsubscribe from marketing emails via the link in any email
- Disable cookies through your browser settings
- Opt out of certain analytics tracking
5.5 Object and Restrict
- Object to certain processing of your information
- Request restriction of processing in certain circumstances
To exercise these rights, contact us at support@discuno.com. We will respond within 30 days of receiving your request.
We implement industry-standard security measures to protect your information:
- Encryption: HTTPS/TLS encryption for data in transit, database encryption at rest
- Authentication: Secure OAuth 2.0 flows, session management, password hashing
- Payment Security: PCI-compliant payment processing through Stripe (we do not store credit card numbers)
- Access Controls: Limited employee access to personal data, role-based permissions
- Monitoring: Security logging, intrusion detection, regular security audits
- Infrastructure: Secure cloud hosting with reputable providers (Vercel, Railway)
Despite our efforts, no security system is impenetrable. We cannot guarantee the absolute security of your information. If you believe your account has been compromised, contact us immediately.
We use cookies and similar technologies to:
- Essential Cookies: Authentication, security, session management
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Understand how you use our platform (PostHog)
- Performance Cookies: Monitor platform performance and errors
You can control cookies through your browser settings. Note that disabling certain cookies may limit platform functionality.
We may use artificial intelligence, machine learning tools, and algorithms to improve our platform and services. These technologies help us:
- Improve search functionality and mentor recommendations
- Enhance platform performance and user experience
- Detect fraud and ensure platform security
- Analyze usage patterns to develop new features
- Moderate content and maintain community standards
These tools operate primarily on aggregated, anonymized data. When personal data is processed, it is done in accordance with this Privacy Policy and applicable data protection laws. We do not use your personal information to train third-party AI models without your explicit consent.
If we integrate third-party AI services (such as OpenAI or similar providers) in the future, we will update this policy and implement appropriate safeguards to protect your privacy.
Our platform may contain links to third-party websites or integrate with third-party services (Stripe, Cal.com, video conferencing platforms). We are not responsible for the privacy practices of these third parties.
We encourage you to review the privacy policies of any third-party services you use. Your interactions with these services are governed by their respective privacy policies.
Our platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we discover that we have collected information from a child, we will delete it immediately.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@discuno.com.
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
Our servers are located in the United States. We use service providers that may process data globally. By using our platform, you consent to the transfer of your information to the United States and other countries.
We take appropriate safeguards to ensure your information is treated securely and in accordance with this Privacy Policy.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request information about the personal information we collect, use, and share
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the sale of personal information (we do not sell personal information)
- Right to Non-Discrimination: Not receive discriminatory treatment for exercising your rights
To exercise these rights, contact us at support@discuno.com. We will verify your identity before processing your request.
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
Our legal basis for processing your information includes: performance of a contract, compliance with legal obligations, legitimate interests, and your consent.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
We will notify you of material changes by email or prominent notice on our platform. The "Last Updated" date at the top of this policy indicates when it was last revised.
Your continued use of the platform after changes become effective constitutes acceptance of the updated Privacy Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Discuno
Email: support@discuno.com
Privacy Inquiries: privacy@discuno.com
Ann Arbor, MI 48104
We take privacy concerns seriously and will respond to your inquiry within 30 days.
- We collect information you provide and usage data to operate our platform
- We use your information to facilitate mentorship, process payments, and improve our services
- We share information with service providers (Stripe, Cal.com, PostHog) and as required by law
- We do not sell your personal information
- You have rights to access, correct, and delete your information
- We implement industry-standard security measures
- We use cookies for essential functionality and analytics
- Contact us at support@discuno.com with privacy questions