Privacy

Use the tools without handing over your loan account.

RepayPilot does not ask for a StudentAid.gov or servicer password. This page describes current behavior, including features that are not enabled.

Calculator inputs

The SAVE deadline checker receives the notice date you enter and stores the calculation result and rule provenance in the application database without associating it with a RepayPilot user account. Calculator inputs for RAP and IBR run in your browser and are not saved by RepayPilot. Do not enter account numbers, Social Security numbers, or other sensitive information.

My RepayPilot profiles

If you create an account and save a profile, RepayPilot stores the current repayment-plan selection, planning goal, PSLF status, and an optional date you provide from a notice. The profile is available only through an authenticated, user-scoped server route. You can delete the saved profile from My RepayPilot. Account-wide deletion is not currently available. The profile form does not ask for income, loan balance, account numbers, addresses, or loan identifiers.

Student-loan documents

Notice upload and extraction are not enabled. The notice page does not accept or store files. Do not email or paste a notice into RepayPilot; a future upload feature requires private storage and review protections first.

Analytics

Selected events may record an event name, landing page, first tool, destination, and UTM campaign parameters. RepayPilot profile values, calculation inputs, and document contents are not included in these application analytics events. Vercel Analytics may run on production pages.

Accounts, email, and payments

Optional email-and-password accounts use Neon Auth for authentication and session handling; account email and authentication data are processed there. RepayPilot never requests your federal account credentials. Email capture, report checkout, and subscription monitoring are not enabled; their presence in the database schema does not mean those products are live.

Retention

Saved profiles remain in the application database until you delete them. Calculation and analytics records are also stored, but a retention period and privacy contact have not yet been configured for this deployment. The project owner should publish those details before inviting production users to submit information.