Privacy & Security Notice

Oveus is operated by Oveus Career Accelerator to help high school students explore careers and reach their next step. This notice explains what we collect, why we collect it, who can see it, how we protect it, and how you can exercise your choices. It is maintained by the platform owner and is a description of our practices — not a certification or independent audit.

Related pages: Trust Center · Terms of Service · Submit a request

Last updated: August 2026

What we collect

We collect only what the platform needs to work:

  • Account information — name, email address, password hash, role, and (for students) school and grade level.
  • Profile and career content — about-me text, interests, resume and uploaded documents, RIASEC interest results, goals, reflections, journal entries, and saved careers, colleges, and opportunities.
  • Activity in the platform — opportunities viewed and applied to, applications and their status, event registrations, and progress in interactive career experiences.
  • School roster data — when a school or coach uploads a cohort roster, that may include student name, email, grade level, and school assignment.
  • Employer information — organization name, description, contact details, and postings.
  • Technical and security data — sign-in events, audit records of privileged actions, and limited request metadata used to keep accounts safe.

We do not ask for Social Security numbers, bank or payment details, government ID images, medical records, or immigration documents, and employers may not request them through Oveus.

Why we collect it (and our legal basis)

  • To provide the service you or your school asked for — showing opportunities, saving your work, and delivering career activities.
  • To support students — so approved coaches and school staff at your school can help you plan your next step (a school-official function under FERPA).
  • To connect you with employers — but only after you actively apply to an opportunity.
  • To keep the platform safe — abuse prevention, audit logging, and account security.
  • To improve the platform — using aggregate, de-identified participation reporting.

We do not use your data for behavioral advertising, and we do not sell personal information.

Who can see your data

  • Students can view and edit only their own profile, applications, saved items, and career-development data.
  • Career coaches, principals, school administrators, and student support contacts can view student information only for the schools they have been approved for, and only to provide support. Staff approvals are bounded — a school administrator cannot approve staff outside their school, and a principal cannot approve platform administrators.
  • Employers see a limited view of a student — name, grade level, RIASEC theme, about-me, and resume — and only for students who applied to that employer's opportunity. Employers cannot browse the full student directory, cannot see other employers' applicants, and cannot export student lists.
  • Administrators have elevated access for operating the platform. Privileged actions are recorded in an audit log.
  • Access rules are enforced server-side at the database layer, so a user cannot reach another user's data by editing a URL or crafting a request.

Who we share data with

We share personal information only in these situations, and only the minimum needed:

  • Your school — approved staff at the school you are enrolled in.
  • An employer you apply to — the limited application view described above.
  • Service providers that run the platform on our behalf under contract: cloud hosting and database/authentication infrastructure, our email delivery provider for account and notification emails, and our document/PDF generation used for exports.
  • Legal requirements — when we must respond to lawful process or protect someone's safety.

We never sell personal information, never share it with data brokers, and never use it for third-party marketing.

Public data sources we read from

Career, wage, college, and apprenticeship information shown in Oveus is drawn from public sources — including the U.S. Bureau of Labor Statistics (OEWS wage data), the U.S. Department of Education College Scorecard, and Maryland apprenticeship program listings. These are read-only lookups: we do not send your personal information to them.

How we protect it

  • All traffic between your browser and our servers is encrypted with HTTPS/TLS.
  • Data is encrypted at rest by our backend infrastructure provider.
  • Passwords are stored as salted hashes — staff and administrators never see your password.
  • New and changed passwords are checked against the Have I Been Pwned database to block known-leaked credentials.
  • Row-level database policies scope every read and write to the requesting user's role and school.
  • Privileged operations run only on the server, and sensitive credentials are never exposed to the browser.
  • Shared success plans require a one-time code sent by email and record each access attempt.
  • Uploaded documents are access-controlled and are not publicly listable.

Student records (FERPA-aligned)

We treat student information — including grade level, school, profile data, applications, reflections, and cohort roster data — as education records and follow FERPA-aligned practices. Where a school district provides student data, we act as a school official performing a service the school would otherwise perform itself, under the school's direction. Student records are:

  • Accessible only to the student and to approved staff at that student's school.
  • Never sold, and never used for advertising or profiling.
  • Shared with an employer only after the student actively applies to that employer's opportunity.
  • Subject to the school's own records policies, including parent and guardian rights.

Students under 13 and parent rights

Oveus is designed for high school students and is provided through schools. We do not knowingly create accounts for children under 13 outside of a school relationship. Parents and guardians may ask what information we hold about their student, ask for a correction, or ask for deletion — through the school or by using our request form. When a request comes through a school-provided roster, we coordinate with the school before acting.

Cookies, storage, and analytics

We use browser storage and cookies that are strictly necessary to run the platform: keeping you signed in, remembering your language and atmosphere preferences, and protecting form submissions. We do not use advertising cookies, cross-site tracking pixels, or third-party ad networks. Any usage measurement we do is aggregate and tied to the platform itself, not to advertising profiles.

How long we keep data

  • Account and student career data is kept while the account is active and while the school's program continues.
  • Deletion requests are honored except where a school or law requires us to keep a record.
  • Security and audit records are kept longer than ordinary content because they exist to protect accounts.
  • Email suppression records (bounces and unsubscribes) are kept so we do not email someone who asked us not to.
  • Aggregate, de-identified reporting may be retained after individual data is removed, because it can no longer identify a student.

Your rights and controls

  • Update your profile information from your profile page.
  • Change your password and sign out of all devices from the "Account security" section of your profile.
  • Delete your own reflections, goals, applications, and saved items from your dashboards.
  • Reduce or disable environmental animations from your profile's atmosphere preference.
  • Unsubscribe from non-essential emails using the link in any message; account and security emails still send.
  • Request a copy of your data, a correction, or deletion of your account with our request form. We confirm receipt by email and aim to respond within 30 days.

Audit logging

Security-relevant events — sign-ins, password changes, opportunity postings, employer approval decisions, role changes, and administrator actions — are recorded in an audit log that only administrators can view. Audit entries cannot be edited or deleted by ordinary users.

If something goes wrong

If we become aware of a security incident affecting personal information, we investigate promptly, take steps to contain it, and notify affected users and partner schools as required by applicable law and district agreements. We do not promise that no incident can ever occur — no platform can — but we commit to transparency when one does.

Reporting a vulnerability

Good-faith security research is welcome. Please report findings through our request form using "Report a security issue," and include enough detail to reproduce. Please do not access, modify, or retain other people's data, do not run automated scans that degrade the service, and give us reasonable time to fix an issue before disclosing it.

Contact

Questions about your data, this notice, or a possible security issue? Use the request form, or speak with your school's Oveus career services staff. We take reports seriously and respond as quickly as we can.

This notice is maintained by Oveus Career Accelerator and may be updated as the platform evolves. It describes current practices and is not a certification, audit result, or legal advice.