Privacy policy
What we collect, what we don't, and why.
This policy covers utern.ai, the UTern agent you can text and talk to, the seats firms and professors fill through UTern, and the UTern Apply Mode Chrome extension. We wrote it in plain English because a privacy policy you can't read isn't a privacy policy.
Last updated: September 15, 2026
The short version
One paragraph if you’re in a hurry
UTern is one agent on both sides of an internship hire. Students bring what they know once (school, year, a project, a GitHub, courses, a LinkedIn), and UTern keeps it as a record, labeled by what it could verify. Firms and professors hand UTern a seat. UTern reads records against a seat only for students who said yes to that seat, scores them without a name, photo, school rank or graduation year, and shows the firm five. We do not sell your data. Nothing about you reaches a firm before you say yes. AI and infrastructure providers process data to run these features; their retention depends on the service. Advertising measurement is on (see below) and you can turn it off for your browser.
What we collect
Information you give us
- Account info: email, password (hashed), and authentication tokens.
- Profile info: name, phone, school, major, graduation year, work authorization, where and when you can work, and the other fields you choose to save.
- Your record: what you bring once. The links you give us (LinkedIn, GitHub), the projects, courses and past work you describe, a resume if you upload one and the text we extract from it, and anything you tell UTern in chat, by text or on a call about what you know and what you want next.
- Checks you take: if you prove a skill on UTern, your answers to the task, the three follow-up questions and the link or upload you show, plus the score and its reasons.
- People you name: if you ask a professor, advisor or manager to vouch for one claim, their name and email address, the one question we sent, and their yes or no.
- Seats you answer: which seats invited you, your yes or no to each, the eligibility facts you gave for that seat, and the intro times you picked.
- Saved roles: the internships you save and pass on, used to improve what UTern shows you.
- Voice samples: short writing samples you may provide so anything drafted for you sounds like you.
Information collected automatically
- Usage analytics: page views, button clicks, and feature usage on utern.ai, used to operate and improve the product. Internal records may be linked to your account; they are not necessarily anonymous.
- Advertising measurement: utern.ai loads a TikTok pixel and Vercel Analytics to measure which pages people see and whether a visit from an ad became a signup. The signup event carries a hashed account id, your IP address and browser type; never your email, phone or anything from your record. It never runs on the Skills or proof pages. Turn it off for your browser with an ad blocker or your browser's tracking protection; we honor that.
- Device info: browser type, operating system, and a session ID. Used for debugging and to keep you signed in.
- Application form contents (extension only): when you click “Fill All” on a supported ATS apply page, the extension reads the form fields on that page so it can fill them. The form structure and the questions are sent to our AI service to generate draft answers. We don't store the page contents after the fill completes.
Gmail connection
If you connect your Gmail (optional)
You can optionally connect your Gmail so UTern can keep your application tracker current automatically. This is off by default and only happens if you explicitly click “Connect Gmail” and approve access on Google's consent screen.
- What we access: read-only access (
gmail.readonly). We cannot send, delete, or modify your email. - What we look at: only messages that look like application updates - confirmations, interview invitations, rejections, and offers from employers and applicant tracking systems. We extract the application status and update your tracker.
- What we store: your encrypted OAuth grant and the derived status events (e.g. “Stripe application moved to interviewing”). We do not store your inbox or message bodies.
- What we never do with it: Gmail data is never used for advertising, never sold, and never used to train generalized AI models. No human reads your messages except with your explicit permission for support, or where required for security or by law.
- Disconnecting: revoke access any time from your profile or at myaccount.google.com/permissions. We delete the grant and stop reading immediately.
UTern's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we use it
What the data is for
- Reading your record against a seat: when you say yes to a seat, UTern checks the eligibility facts the firm set, then scores your record against the firm's rubric. The scoring never sees your name, photo, school rank or graduation year. Every score is logged with its reasons.
- Verifying what you bring: anything you wrote verifies nothing on its own. To mark a claim verified, UTern looks for a page published about you by a school, employer, judge or platform (a dean's list, a club roster, a competition result, your public GitHub activity, a certificate's verification page) and keeps the page address and an excerpt. It reads public pages only and never logs in anywhere as you.
- Vouching and checks: if you name someone to vouch, we send them one email with one question. If you take a check, your answers are scored against the rubric by our AI processor. Do not submit confidential or restricted work.
- Introductions: when a firm asks to meet you and you say yes, UTern sends one introduction to both of you with the time you picked, and follows up until there is an outcome.
- Filling applications (optional): if you use Apply Mode, your profile, resume and voice samples are used to fill apply pages and to draft answers you review before anything is sent.
- Personalizing what you see: your saves and passes shape which internships and seats UTern shows you first.
- Keeping you signed in: auth tokens and session cookies tell the extension which UTern account is yours.
- Sending you product updates: if you opt in. You can unsubscribe from any email with one click.
- Improving the product: internal usage records and aggregate statistics helps us understand which features matter.
What we never do
The bright lines
- We never sell your data to third parties.
- We do not send your record, resume or answers to advertisers or data brokers. A firm sees you only after you said yes to its seat, and then only your name, your email and the evidence on your record for that seat. Saying yes to one seat is never a yes to another.
- We do not use your personal data to train our own general-purpose AI models. Provider training and retention controls depend on the selected service and account arrangement. We do not promise universal zero retention.
- Nothing is sent on your behalf without your authorization: not an application, not an introduction, not a request to someone to vouch.
- We never auto-answer voluntary self-ID or EEO questions (race, gender, veteran status, disability). Those stay yours to fill.
- We never log in to LinkedIn, Handshake or any other network as you or as anyone else. UTern reads public pages only.
- We never use your data for purposes unrelated to UTern's single purpose: bringing the right internships and seats to you, and bringing you to the firms that fit.
- We never determine creditworthiness or use your data for lending decisions.
Before you sign up
If UTern found you on the open web
When a firm hands UTern a seat, UTern looks for students who fit among the students already on UTern and on the open web: public LinkedIn profile results, GitHub, Devpost, club and school pages. For a person who has not signed up, UTern holds only what the open web showed (a name, a school, a headline, the page address, and a public email address if one was published) and the fact of one email we sent.
- One email, then silence. First contact is a single email from a named person at utern.ai, with an unsubscribe link and a postal address. No reply means you never hear from us about it again. We never text a number we found; texts happen only after you opt in.
- Saying no is remembered. An unsubscribe, a bounce or a complaint puts your address on a suppression list so no seat contacts you again.
- Nothing more until you say yes. No record exists about you until you sign up, and then it holds only what you chose to bring.
The extension specifically
What the Chrome extension does on your machine
UTern Apply Mode runs on five domains only:
- utern.ai - to read your signed-in session and sync your profile to the extension.
- *.myworkdayjobs.com, *.workday.com - Workday apply pages.
- boards.greenhouse.io, *.greenhouse.io - Greenhouse apply pages.
- jobs.lever.co, *.lever.co - Lever apply pages.
- jobs.ashbyhq.com, *.ashbyhq.com - Ashby apply pages.
The extension does not load on any other website. It does not track your browsing. It does not see what other tabs you have open.
The cookies permission is requested only when you click “Sign In” in the extension — never at install time. It's used to read the Supabase session cookie from utern.ai so the extension knows which signed-in account to autofill with. You can revoke it anytime in Chrome’s extension settings.
All JavaScript in the extension is bundled at build time. We do not load or execute remote code.
Storage and security
Where your data lives
- Database: hosted on Supabase (Postgres) in the United States. Encrypted at rest and in transit (TLS 1.2+).
- Resume files: stored in Supabase Storage with private access. Authorized server processes also access files to provide the features you request.
- AI inference: providers may retain request data for abuse monitoring or features such as search grounding. Disabling training or response storage does not by itself provide zero data retention. Zero-retention treatment applies only where the provider has approved it and the feature supports it.
- Local browser storage: the extension caches your profile in
chrome.storage.localso autofill is instant. Clearing the extension's data or uninstalling it removes the local cache.
Your rights
What you can do with your data
- Access: view everything in your profile at utern.ai/profile.
- Edit: change any profile field, re-upload your resume, update voice samples.
- Delete: email contact@utern.ai or use Settings to request account deletion. We disable the account and queue removal from active systems, including stored files and connected Gmail credentials. Failed steps are retried. Provider records, backups, legally required records and copies already received by employers may persist separately; we do not promise complete deletion within seven days.
- Export: download your account data in JSON from Settings, or contact contact@utern.ai for help. Credentials and private records belonging to other people are excluded.
- Revoke extension permissions: right-click the UTern icon in Chrome → Manage Extension → Permissions.
Third parties
Services we use to run UTern
- Supabase — database, authentication, file storage.
- Vercel — hosting and edge functions.
- Google Gemini / OpenAI / Anthropic — AI inference: the agent's conversations, reading a record against a seat, scoring a check, grounded web search for verification, and drafts you review.
- GitHub's public API — your public repositories and commit activity, read only to verify a claim you made about them.
- Address verification providers (NeverBounce or ZeroBounce, and People Data Labs, each only where enabled) — checking that a public email address a seat found on the open web is real before one email is sent. Never for students who signed up.
- Public job sources, employer job boards and applicant tracking systems — internship listings, and, for a seat, the five names a firm receives written into its own ATS (Greenhouse, Lever or Ashby, with the firm's key).
- Resend — delivery of the email we send: account mail, seat invitations and introductions, the one-line vouch request, and the newsletter if you asked for it.
- Sendblue and Vapi — texts and calls with the agent, only after you opted in and only from the number we publish.
- Stripe — the $250 seat deposit a firm pays. We never see card numbers.
- Browserbase — browser sessions used for approved application assistance. New sessions disable recording and session logs.
- TikTok and Vercel Analytics — advertising measurement and page analytics, as described above.
Each provider's contract and configuration govern its processing and retention. Employers also handle applications under their own policies. Contact us about access, deletion, or provider-specific retention.
Children
Age requirement
UTern is for college students and job seekers aged 18 or older. Users must affirm that they are at least 18 before accessing AI features. We do not permit use by people under 18. If you believe we have, email contact@utern.ai and we'll delete it.
Changes
Updates to this policy
If we change this policy, we'll update the “last updated” date at the top and, for material changes, notify signed-in users by email before the change takes effect.
Contact
Questions?
Email contact@utern.ai. We respond within one business day.
UTern is operated by UTern Corp.
