What we keep,
and what we don't.
ScholarAB is a free directory built by a high school student in Medicine Hat. You can use the directory without an account or an email address. The details below explain what is collected when you browse, allow analytics or ask for a reminder.
Last updated October 2, 2026
What we collect
- When
- Only if you ask for deadline reminders.
- Why
- To email you 30, 14 and 3 days before a deadline, whichever of those you picked.
- How long
- Until you unsubscribe, or until 60 days after the deadline passes, whichever comes first. If you never confirm the sign-up, it is deleted within 30 days.
- When
- Stored alongside the email address above.
- Why
- A reminder has to know what it is reminding you about.
- How long
- Same as the email address.
- When
- Each time a confirmation email is sent to an address, including when someone else typed it into the sign-up form.
- Why
- To cap confirmation emails at five a day per address, at least 15 minutes apart, so the sign-up form cannot be used to flood someone’s inbox. It is a SHA-256 hash of the address rather than the address itself, which is enough to recognise the same address when it comes back.
- How long
- 30 days after the last confirmation email sent to it. Delete all my data removes it straight away.
- When
- On requests to the sign-up, confirm, unsubscribe and counter endpoints.
- Why
- Rate limiting. It stops someone signing up thousands of addresses or guessing the admin password. The address is put through a salted one-way hash before it is written, so what is stored cannot be turned back into your IP.
- How long
- Swept on a rolling basis, usually within 24 hours, and the daily cleanup deletes anything older than two days.
- When
- On every page, through Cloudflare Web Analytics.
- Why
- To know how many people reach the site at all, which the counts below cannot tell us, because they only fire once you interact with something.
- How long
- By Cloudflare, on their retention schedule. It sets no cookie, stores no identifier, and does not follow you between sites; what it records is the page, the referrer, and rough timing and device information.
- When
- Never, unless you press Allow on the banner that asks. Until you answer, and forever if you answer no, the Google script is not loaded at all and nothing is sent to them.
- Why
- To see which pages people arrive on and where they came from, so the site gets pointed at the students who are looking for it. This is the one thing here that involves a company whose business is advertising, which is why it is the one thing we ask permission for.
- How long
- By Google, on their retention schedule. If you allow it, Google sets a cookie on your browser, gives it a randomly generated ID that lasts between visits, and receives your IP address. We have turned off ad personalisation and asked Google to shorten your IP, but we cannot promise you what a company that size does with what it holds, so we are not going to. Press No thanks and none of this happens. Changed your mind either way? Add ?ga=ask to any page here and the question comes back.
- When
- Only when what you typed matches no listing anywhere in the directory, not on searches that find something, and not on anything you type into Build my combo.
- Why
- An empty search is the clearest signal that the directory is missing an award someone is looking for. It is what tells us what to go add next.
- How long
- 180 days, in the same table as the counts below and with the same nothing attached to it: no IP address, no cookie, no session. Anything email-shaped is discarded rather than stored, and only the first 120 characters are kept. Even so, please don’t type anything private into a search box, here or anywhere else.
- When
- When you open a listing, click through to apply, save something, mark a saved scholarship as started, submitted or won (which records the listing and that one word), run Build my combo, and once per visit if you arrived from one of our own tagged links, such as the one in an Instagram or TikTok bio, which records only which of those it was.
- Why
- To know which listings matter and which way of telling people about the site works, so the directory gets better. What was searched for is the row above; this row is counts.
- How long
- 180 days, including previously recorded walkthrough counts. These rows carry no IP address, no cookie, no account and no session. There is nothing in them that points back to a person, which also means they cannot be traced to you in order to delete them.
What we don't collect
- No name, school, or grades. Every answer you give Build my combo, including the questions about family income, Indigenous or BIPOC identity, foster care and gender, stays in your browser and is never sent to us. We are told only that a quiz was started and that one was finished, and nothing whatsoever about what was in it.
- No saved listings, and nothing about what you mark them as or which city’s list you last opened: those live in your browser’s local storage, on your device. Your browser also keeps a small note of which counts it has already sent, so one visit is not counted twice; that note stays on your device and is never sent anywhere.
- No accounts, no passwords, no logins for students.
- No advertising cookies, no tracking pixels, no data brokers. Nothing on this site is a data broker and nothing here advertises to you. Two counting scripts can run: Cloudflare’s, which is cookieless and identifier-free and needs no permission because it identifies nobody, and Google Analytics, which does set a cookie and does identify your browser, and therefore runs only if you press Allow. If you have not answered, or said no, Google Analytics is not on the page.
- Nothing is ever sold, rented, or shared for marketing. There is no business model here that would want it.
Turning the counts off
The counts in the last two rows above carry nothing that points back to a person, so there is
nothing in them to identify you by. Even so, you can switch them off: visit any page on the site
with ?nt=1 on the end of the address, for example
www.scholarab.ca/?nt=1, and this browser stops sending them.
The setting is a single note in your browser's own storage; it never reaches us, so it lasts
until you clear your site data, and it has to be set once per browser and device.
?nt=0 turns them back on.
The same switch also stops Cloudflare's page-view count from loading in this browser. A content
blocker that blocks static.cloudflareinsights.com does the same,
and the site works exactly the same without it.
Google Analytics is separate again, and is the only thing here that asks first. It does not load
until you press Allow, so doing nothing is the same as saying no. If you want to change the answer
you gave, add ?ga=ask to any address on the site, for example
www.scholarab.ca/?ga=ask, and the banner comes back so you can
answer again. A browser you have switched the counts off on with
?nt=1 will not load Google Analytics either, whatever it answered
before: one switch, everything off.
Reminder emails
Reminders are double opt-in. Signing up creates a pending row and sends you one confirmation email; nothing else is ever sent unless you click the confirm button in it. That is deliberate: the sign-up form is a public endpoint, so anyone could type in a stranger's address, and this makes sure only the person who can read the inbox can turn reminders on.
Every email we send carries an unsubscribe link, including the confirmation email, and also the header your mail app reads to put its own unsubscribe button at the top of the message. Either one deletes the row outright. We don't keep a suppression list of people who left.
Deleting your data
The unsubscribe link at the bottom of any ScholarAB email has a Delete all my data button next to it. It removes every reminder set up with your address, the address itself, and its fingerprint, immediately.
You can also email contact.scholarab@gmail.com to ask what we hold about an address, to correct it, or to have it deleted. Expect a reply within a few days; the legal maximum is 30.
Where your data goes
ScholarAB runs on five services. Each one only ever sees what it needs to do its job. What each may do with it is set by its own terms, not by us; where a service lets us limit that, we have, which is why Google Analytics runs with ad personalisation and Google signals turned off. Because they are based in the United States, information stored with them may be subject to US law, including lawful access requests by US authorities.
- Role
- Serves the site, blocks abuse, and counts page views.
- Where
- Global, including the United States
- Role
- Hosts the database holding reminder sign-ups.
- Where
- United States
- Role
- Delivers reminder and confirmation emails.
- Where
- United States
- Role
- Runs the scheduled job that works out whose deadline is close and hands those reminders to Resend. Your address passes through it each time that job runs.
- Where
- United States
- Role
- Two separate things. Gmail carries email sent to our contact address, which is where questions, corrections and deletion requests arrive; if you write to us, Gmail holds that message. Google Analytics counts page visits, but only for people who pressed Allow on the banner.
- Where
- United States
If you're under 18
Most people using ScholarAB are high school students, and that is who it was built for. We ask for as little as it is possible to ask for: an email address, for a reminder you requested, deleted the moment you say so. We don't build profiles, don't advertise, and never sell or trade what we hold; the only outside companies that see any of it are the five services listed above. If you're under 13, please ask a parent or guardian before signing up for reminders. And if a parent or guardian wants a sign-up removed, email us and it's done, no questions asked.
Changes
If what we collect ever changes, this page changes with it and the date at the top moves. Every version of this page is in the site's public source history, so you can check what it used to say.
Contact
ScholarAB · Medicine Hat, Alberta, Canada
contact.scholarab@gmail.com