My College Trail ← Back to home

Privacy Policy

Little Orange Lamb, LLC (d/b/a My College Trail) Effective Date: July 16, 2026 Last Updated: August 17, 2026


1. Introduction

The My College Trail website and application (the "Service") are operated by Little Orange Lamb, LLC ("My College Trail," "we," "our," or "us"). This Privacy Policy describes what information we collect, how we use it, when we share it, and the choices available to you regarding your personal information. This Privacy Policy applies to all users of the Service.


2. Information We Collect

2.1 Information You Provide

When you create an account, we collect:

To build your profile and generate college matches, you may also provide:

2.2 Payment Information

Payments are processed by third-party payment processors. We do not receive or store full payment card details. We receive limited billing metadata such as transaction identifiers and the last four digits of the payment method for subscription management.

2.3 Automatically Collected Information

When you use the Service, we and our service providers may automatically collect technical and usage information, including:

This information may be collected directly by us or through infrastructure, hosting, or database service providers as part of operating the Service.


3. How We Collect Information

We collect information:


4. How We Use Your Information

We use personal information to:

We do not sell student data, period. Beyond the specific statutory meanings of "sell" and "share," we do not disclose student personal information to any third party for that party's own use, and we never trade, rent, or make it available to advertisers or data brokers. Stated in the terms applicable law uses: we do not sell personal information or share personal information for cross-context behavioral advertising, as those terms are defined under applicable law.

4.1 How We Use Profile Information to Improve the Service

We use structured signals derived from student profiles to develop, evaluate, and improve the matching, recommendation, and profile-building features of the Service.

What we train on. Our models are trained only on structured profile signals — defined, categorical fields extracted from profile responses, such as preferred school size, region, and areas of academic interest — after those signals have been de-identified as described below. We do not train models on the raw text of student responses, on open-ended narrative answers, or on generated profile summaries.

What we exclude. We do not use the following to train or improve our models, in any form: responses to questions concerning race or ethnicity, household income or financial aid, disability, religion, citizenship or immigration status, or first-generation college status; free-text responses; and profile summaries generated by the Service. Sensitive categories are excluded at the question level, before any training data is assembled.

De-identification. Before any signal is used for model development, we remove identifiers — including name, email address, and account identifiers — and apply technical measures designed to ensure the resulting data no longer reasonably identifies, and cannot reasonably be linked to, a particular student. We maintain de-identified datasets separately from the identifiers that could link them to an account, we do not attempt to re-identify de-identified information, and we require any recipient of de-identified information to commit contractually to the same. A student's identifiable information is used in this process only to perform the extraction and de-identification itself.

Minors. Because most students using the Service are minors, the restrictions in this Section apply to all profiles. Where consent is required for this use under applicable law — including parental or guardian consent for a student aged 13 to 17, and a minor's own informed consent where required — we obtain it before a student's signals are included in model development.

Retention. De-identified, aggregated datasets and the models developed from them are proprietary to My College Trail and, because they are no longer personal information about any student, may be retained and used to operate and improve the Service after an account is closed or deleted. The underlying profile responses themselves remain personal information and are deleted in accordance with Section 7 when an account is deleted; they are not retained under this Section.

Relationship to our AI provider. This Section describes model development performed by or for My College Trail. It is distinct from the processing performed by our third-party artificial intelligence service provider described in Section 6.2, which remains contractually prohibited from using any information we send it to train or improve its own models.

[DRAFTING NOTE — model training: every sentence in this Section is a claim about the data pipeline, and each needs a corresponding artifact in place before this text ships. All five are now built and covered by offline tests: (1) a structured-signal whitelist so training reads only categorical fields, never raw text; (2) a question-level sensitivity taxonomy that marks and excludes the named sensitive categories before training data is assembled; (3) a de-identification transform plus separated storage and access controls; (4) a consent record where consent is required — see below; and (5) deletion of the profile_events intake stream on account deletion. Item (4) is implemented as an affirmative, opt-in, unchecked-by-default consent at account creation: granting it stamps trainingConsentAt, trainingConsentVersion, and policyVersion on the user record AND writes an append-only compliance event (TRAINING_CONSENT_GRANTED; withdrawal or re-grant writes TRAINING_CONSENT_WITHDRAWN / GRANTED) carrying the notice and policy versions plus an opaque subject key and no profile data. That event store is never deleted with the account, so which notice a student agreed to, and when, stays provable after deletion. This resolves former open item (a): consent is captured as an explicit opt-in specific to this use, not relied upon from the Terms Section 3 account-creation consent. Remaining open items for counsel: (b) PRE-ACCOUNT INTAKE — the Service currently collects profile responses before an account or consent exists, which needs its own age gate / purge job and a disclosure; (c) whether de-identified signals actually leave My College Trail (if not, the "any recipient" clause is precautionary, not describing a live program). Confirm compatibility with applicable state minor-privacy laws, and confirm the consent notice version and policy version referenced by the consent record match this document at ship time.]


5. Minors and Age Requirement

My College Trail is used primarily by high school students, and many of our users are minors. We take the privacy of minors seriously.

5.1 13-and-Older Requirement

The Service requires all users to be at least 13 years old. We do not permit registration by, and do not knowingly collect personal information from, children under 13. If we learn that we have collected personal information from a child under 13, we will delete that information promptly. Consistent with this requirement, we do not operate the verifiable-parental-consent process that the Children's Online Privacy Protection Act (COPPA) requires for services directed to children under 13, because the Service is not directed to and does not permit users under 13.

5.2 Minors Aged 13 to 17

Students aged 13 to 17 may use the Service only with the consent of a parent or legal guardian, as described in our Terms of Service. A parent or legal guardian may also create an account and manage a 13-to-17-year-old student's profile.

The same data practices described in this Privacy Policy apply to minors' information, including the limited AI disclosure described in Section 6.2, the de-identified model-improvement practices described in Section 4.1, the retention practices in Section 7, and our commitments not to sell personal information, direct marketing based on their data, or use their information for advertising.

Where applicable state law affords additional protections to the personal information of minors — for example, restrictions on targeted advertising, sale, or certain profiling — we extend those protections to minor accounts regardless of the state in which the minor resides.

5.3 Parent and Guardian Requests

Parents or guardians of a minor may, with respect to the minor's information:

Requests may be made through the account settings or by contacting us at [email protected]. For requests made by email, we will verify the requester's identity through the email address associated with the account before taking action. There is no charge for exercising these rights.


6. How We Share Information

We share personal information only as necessary to operate the Service.

6.1 Service Providers

We share personal information with the following categories of service providers, in each case only the information necessary for the provider to perform its function:

Each provider is contractually required to use personal information only to perform services for us, and to maintain its confidentiality and security. A current list of our service providers is available upon request at [email protected].

6.2 AI Processing

To generate the personalized college matches that are the core function of the Service, we disclose student profile and preference information to our artificial intelligence service provider. This information consists of: age or grade level, academic interests and intended areas of study, priorities and preferences, location and setting preferences, campus size and community preferences, athletic interests, affordability considerations, and academic record where provided (such as GPA, coursework, or test scores). We do not share the student's name with our AI provider.

Our AI provider processes this information solely to provide the Service. It is contractually prohibited from using submitted information for any other purpose, including training or improving general-purpose AI models, and is required to maintain the confidentiality and security of this information.

Because the Service is used by minors aged 13 to 17, this processing may include information about minors. This disclosure is integral to providing the Service.

6.3 Legal Requirements

We may disclose information if required by law or to:

6.4 Business Transfers

If we are involved in a merger, acquisition, or asset sale, personal information may be transferred as part of that transaction. Any successor will be required to honor the commitments in this Privacy Policy with respect to previously collected personal information, including minors' personal information, or we will provide notice and obtain any legally required consent before minors' personal information is transferred.


7. Data Retention

7.1 General Retention Practices

We retain personal information for as long as your account is active and as needed to provide the Service, manage your subscription, and meet legal, tax, and accounting obligations.

If you close your account or request deletion, we delete your personal information from active systems within 30 days, except for limited billing records we are required to retain for legal and accounting purposes and records of deletion requests and their fulfillment, which we retain as needed to demonstrate compliance with our legal obligations.

Personal information may persist in encrypted backups for up to 7 days after deletion from active systems, after which it is overwritten in the ordinary backup cycle. Backup data is not used for any purpose other than system restoration.

De-identified and aggregated information, and the models we derive from it, are not personal information and are not deleted when you close your account or request deletion, as described in Section 4.1. Deletion removes your personal information from active systems; it does not require us to unwind models that were trained on de-identified data before your request.

7.2 Retention of Minors' Personal Information

We retain a minor's personal information while the account is active because refining matches and tracking applications over the course of the college-search process is a core function of the Service and requires this data. We do not retain minors' personal information indefinitely. A minor's personal information is deleted as follows:

Deletion requests are honored by our service providers as well: when we delete a minor's personal information, we instruct our service providers, including our AI service provider, to delete corresponding information they hold on our behalf.

We retain records of deletion requests and their fulfillment as needed to demonstrate compliance with our legal obligations. A minor's personal information in backup systems is overwritten within the backup cycle described in Section 7.1.


8. Security

We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encrypted communications (HTTPS/TLS), secure password storage, and access controls.

These safeguards are appropriate to the volume and sensitivity of the personal information we maintain — including the heightened sensitivity of minors' personal information — and to the size and complexity of our business.

We maintain internal procedures intended to identify and respond to potential security incidents involving personal information and will take reasonable steps to mitigate harm and comply with applicable legal obligations.

No system is completely secure, and we cannot guarantee absolute security.


9. Your Privacy Rights

Depending on your location, you may have rights to:

Requests may be sent to [email protected]. We will respond within the timeframe required by applicable law.


10. California Privacy Rights

California residents may have rights under applicable law, including the right to:

We do not sell personal information or share personal information for cross-context behavioral advertising. We do not sell or share the personal information of any known minor (any user under 18), and we do not use the personal information of a known minor for targeted advertising. We apply these minor protections to every student account regardless of the state in which the student resides.

Requests may be submitted to [email protected].


11. International Users

My College Trail is operated from the United States and is intended primarily for users located in the United States.

If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from your jurisdiction.

By using the Service, you acknowledge this transfer. Where required by applicable law, we will take reasonable measures to protect personal information.


12. Cookies and Similar Technologies

We use cookies and similar technologies that are necessary for the operation and security of the Service.

We may also use limited analytics tools to understand and improve Service performance. We do not use advertising cookies or cross-site behavioral tracking technologies.

Our Service does not currently respond to Do Not Track browser signals.


13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last Updated" date and provide additional notice where required by law. Where required by law, if we make material changes to how we collect, use, or disclose a minor's personal information, we will obtain renewed parental or guardian consent before applying those changes to existing minor accounts.


14. Contact Us

Little Orange Lamb, LLC (d/b/a My College Trail) 826 Onslow St., Durham, NC 27705 (919) 322-9935 [email protected] mycollegetrail.com