How Blueprint protects your data
Encryption, access controls, and our commitment to student privacy.
Updated August 6, 2026 · 1 min read
Your data security is not negotiable. Blueprint uses enterprise-grade encryption and strict access controls to protect every piece of information you share with us.
Security measures
We use 256-bit AES encryption for data at rest and TLS for data in transit. Our team operates under role-based access controls, so no individual has unrestricted access to your data.
What we never do
We are committed to protecting your trust. We never sell your personal data to third parties, never share your essays or application data with colleges, and never train AI models on your personal content. One narrow exception is worth stating in full: when you join the waitlist, we send Meta a conversion event so we can measure which advertisements brought people to Blueprint. That event carries a hashed version of your email address, the time of the signup, a reference number for the event, a short source label, and, when your browser provides them, your IP address, your browser's user-agent string, and the address of the page you signed up on. It carries nothing else. We never send your quiz answers, essays, college list, or any other work you do in Blueprint, and nothing outside waitlist signup is sent at all. You can turn this off on the Do Not Sell or Share My Personal Information page, and if your browser sends a Global Privacy Control signal we honour it automatically, without you having to do anything.