Section 1
Overview and scope
In plain terms
This Privacy Policy tells you what we collect, why, who we share it with, and the choices you have.
This Privacy Policy describes how Be Belong Group Corp, a Delaware corporation with a principal place of business at 2980 NE 207 Street, Miami, FL 33180 ("Company," "we," "us"), processes personal information in connection with the CollegeGain.AI website, mobile application (where applicable), and related services (the "Service").
Capitalized terms used but not defined here have the meanings given in our Terms of Service. See also our Cookies Policy and Accessibility Statement.
Section 2
Categories of information we collect
- KYC and identity-verification data, including government-issued identification, date of birth, address, and, where applicable, a selfie/biometric liveness image and derived biometric identifiers used solely for identity verification. See Section 4 for biometric-specific disclosures.
- School and enrollment data: Institution name, enrollment status, expected graduation date, and (if collected) student ID number.
- Financial and tuition-credit data: linked bank account or card details (if applicable), transaction history, Credit balances, Tuition Credit disbursement/application records, and related nonpublic personal financial information within the meaning of the Gramm-Leach-Bliley Act (GLBA).
- Behavioral, engagement, and analytics data: app/web usage, session data, activity completions across all Earning Buckets, gameplay and promotional-mechanic data, mobile attribution/measurement data (if a mobile app exists), device identifiers, and IP address.
- Advertising, matching, and personalization data: ad interaction and brand-campaign engagement data used by the Company's AI matching/optimization features, including the earnings optimizer, brand-matching engine, predictive earnings dashboard, and AI shopping/lifestyle assistant.
- AI feature interaction data: the messages you type into the AI Support Chat ("Alice") or the AI Mediator, any files you choose to attach to those conversations (images, PDFs, documents, and video), the earlier messages in that same conversation, and the technical context needed to return an answer to your session (a pseudonymous session and account identifier, app version, and language/locale). We collect this data directly from you, at the moment you send a message, attach a file, or submit a dispute for mediation. Section 9 sets out exactly what is transmitted to our third-party AI provider, who that provider is, every use made of it, and how we obtain your consent first.
- Institutional-source data: limited directory-type contact information (e.g., name, school email address) that an Institutional Partner may have provided to facilitate outreach to you (see Section 3).
- Referral and social data (if a referral program is offered).
- Communications data: your notification preferences, opt-ins/opt-outs, and message metadata.
Section 3
Institutional Partners, directory-type data, and FERPA
In plain terms
Some students first hear about CollegeGain.AI because their school shared basic contact info with us. Your school — not us — is responsible for making sure that sharing follows FERPA.
Some Users may first learn about and be invited to CollegeGain.AI because an Institutional Partner has provided limited directory-type contact information (for example, name and school email address) to facilitate outreach. Where this occurs:
- The Institutional Partner (not the Company) is solely responsible for ensuring that any disclosure of student information to the Company complies with the Family Educational Rights and Privacy Act (FERPA) and the Partner's own FERPA-compliant policies — including, where applicable, treating any such disclosure as "directory information" under a FERPA-compliant public-notice-and-opt-out process, or, alternatively, ensuring the Company operates under a FERPA "school official" / legitimate-educational-interest arrangement pursuant to a separate written agreement. The specific FERPA basis is documented in each Institutional Partner's written data-sharing agreement with the Company.
- The Company is not responsible for the Institutional Partner's own compliance with FERPA or other student-privacy law in connection with the Partner's decision to share directory-type data with the Company.
- Once you create your own CollegeGain.AI account, your ongoing relationship, consents, and data are governed directly by these Company documents — the Terms of Service and this Privacy Policy — independent of how you were first invited.
Certain state student-data-privacy statutes (including California's Student Online Personal Information Protection Act, or SOPIPA) are primarily K-12-facing. Their applicability to a postsecondary product like CollegeGain.AI, including in dual-enrollment contexts involving minors, is fact-specific. The Company applies SOPIPA-equivalent safeguards where it processes data on behalf of an Institutional Partner in connection with dual-enrollment minors.
Section 4
Biometric information
In plain terms
If your KYC includes a selfie liveness check, we treat that biometric data with extra care and don't sell it.
Where KYC includes a selfie/biometric liveness check, the Company (directly or through an identity-verification vendor) collects a facial image and may derive a biometric identifier or biometric information (as those terms are defined by laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and Washington's biometric statute).
- Purpose. Solely to verify your identity, confirm liveness, prevent fraud, and satisfy applicable KYC obligations.
- Retention and destruction. Biometric identifiers are retained only for as long as reasonably necessary for the initial and ongoing purpose above and, in any event, no longer than three (3) years after your last interaction with the Service or as otherwise required by law, and are then destroyed in accordance with our written retention schedule.
- No sale. The Company does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
- Consent. Where required, we obtain your written release/consent prior to collection.
- Vendors. Where an identity-verification vendor processes biometric data on our behalf, it does so under contract and with equivalent restrictions.
Section 5
How we use information
- Provide the Service, including creating and maintaining your account, verifying identity and enrollment, and operating Earning Buckets and Tuition Credit disbursement.
- Prevent fraud, gaming of Earning Buckets, and misuse.
- Personalize offers and recommendations through the Company's AI matching and optimization features (see Sections 8 and 9).
- Send transactional and (with your consent) marketing communications by email and SMS (see the Terms of Service, Section 9).
- Answer your support questions and help resolve task disputes through our AI features, which transmit the inputs you submit to a third-party AI provider as described in Section 9.
- Measure and improve the Service.
- Comply with legal, tax, accounting, and regulatory obligations.
Section 6
Legal bases (GDPR/UK GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract — to provide the Service you have requested.
- Consent — for marketing communications, non-essential cookies, processing of biometric data as a special category under Article 9, and use of the AI features that transmit your inputs to a third-party AI provider (Section 9).
- Legal obligation — for KYC, financial-privacy, and tax obligations.
- Legitimate interests — to secure and improve the Service and prevent fraud, balanced against your rights.
International transfers of personal data out of the EEA or UK rely on approved mechanisms, including the European Commission's Standard Contractual Clauses and the UK IDTA/Addendum, as appropriate.
Section 8
Automated decision-making and profiling
In plain terms
We use AI to recommend offers, but we don't use it alone to make legally significant decisions about you.
The Service uses automated processing to personalize Earning Bucket recommendations and to detect fraud. The Company does not use solely-automated decision-making to make decisions that produce legal or similarly significant effects on you, except that KYC eligibility determinations, fraud-based suspensions, and Credit-eligibility determinations may involve automated components. Where applicable state law provides an opt-out from targeted advertising, profiling in furtherance of legally-significant decisions, or the sale/sharing of personal information, you may exercise those rights under Section 11.
Human review and appeal. If an automated determination adversely affects you — including KYC ineligibility, a fraud-based account suspension, or a Credit-eligibility denial — you may request human review by emailing info@bebelong.life within 30 days of the adverse decision. Our review team will re-evaluate the determination taking into account any additional information you provide, and will respond substantively within 45 days.
Section 9
AI features, third-party AI providers, and your consent
In plain terms
Some features send what you write to Google's AI service so it can answer you. We ask your permission before anything is sent, we tell you exactly what goes and to whom, and if you say no you can still get help from a person.
This Section is the controlling disclosure for every part of the Service — including the CollegeGain.AI iOS and Android applications — that transmits your information to a third-party artificial-intelligence ("AI") provider.
(a) Who the data is sent to.
The only third-party AI provider that receives your data is Google LLC, including its Google Cloud Platform / Vertex AI and Gemini API services, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States ("Google"). Processing takes place on Google infrastructure in the United States. Google acts solely as our service provider and processor — it does not receive your data for any independent purpose of its own. We do not send your data to any other AI provider. If we add or replace an AI provider, we will update this Section, name the new provider here, and, where the change is material, request your renewed consent before any data is sent to it.
(b) Which features send data, and exactly what is sent.
- AI Support Chat ("Alice") and AI Help Center. When you send a message, we transmit to Google: the text you typed; any file you chose to attach (image, PDF, document, or video, up to five per message); the earlier messages in that same support conversation, so the answer follows the context; and a pseudonymous session identifier, app version, and language/locale.
- AI Mediator (task and payment disputes). When you ask for a mediation proposal, we transmit to Google: the dispute description you wrote; the messages in the disputed conversation thread that you submitted for mediation; and the reference identifier, type, and status of the related task or offer.
- AI matching and optimization (earnings optimizer, brand-matching engine, predictive earnings dashboard, and AI shopping/lifestyle assistant). These features transmit pseudonymous engagement signals — the categories of Earning Buckets you have completed, offer and campaign interactions, and stated category preferences. They do not transmit your name, email address, identity documents, or financial-account data.
(c) What we never send to an AI provider.
We do not transmit to Google or to any other AI provider: government-issued identification documents, images, or numbers; selfie/biometric liveness images or derived biometric identifiers (Section 4); bank account, debit or credit card numbers, or other payment credentials; Social Security or taxpayer identification numbers; KYC verification records; your login credentials; or precise geolocation. Because you control what you write into a conversation, please do not type information you do not want an AI provider to process; the app repeats this reminder where you enter AI chat.
(d) How the data is collected.
AI feature inputs are collected directly from you, in the moment you submit them — when you tap send on a message, attach a file, or submit a dispute for mediation. The Service does not scan your device, your photo library, your contacts, your microphone, or your other messages to build AI inputs, and it does not transmit anything to an AI provider in the background while you are not using an AI feature. Matching signals under (b) come from your own in-app activity as described in Section 2.
(e) Every use made of the data that is sent.
- To generate the answer, summary, or mediation proposal displayed back to you.
- To classify and route your request, including escalation to a human support agent.
- For safety and abuse filtering applied by Google to the request itself.
- On our own systems (not by Google for its own purposes): quality review of support conversations by our support staff, and aggregated, non-identifying analytics used to improve the Service.
The data sent to an AI provider is not used for advertising targeting, is not sold or shared for cross-context behavioral advertising, is not disclosed to brand partners, Institutional Partners, or Advertisers, and is not used to make decisions producing legal or similarly significant effects about you (Section 8).
(f) Confirmation that our AI provider gives the same or equivalent protection. We confirm that Google is contractually bound to protections that are the same as or equivalent to those described in this Policy:
- Written contract. Our use of Google is governed by the Google Cloud Data Processing Addendum and the service-specific terms for Vertex AI / the Gemini API, which restrict Google to processing the data only on our instructions and only for the purposes stated in (e).
- No training on your data. Under those terms, your inputs and the generated outputs are not used to train or improve Google's foundation models and are not used to develop other Google products or services.
- Limited retention at the provider. Inputs are processed to produce the response and are not retained by Google for its own purposes; any abuse-detection logging is time-limited under Google's terms. The record kept in your account is governed by Section 10.
- Security. Encryption in transit and at rest, access controls, and independently audited certifications (including ISO/IEC 27001 and SOC 2).
- Onward transfers and subprocessors. Bound by equivalent obligations; international transfers rely on the Standard Contractual Clauses and the UK IDTA/Addendum as described in Section 6.
- Deletion and cooperation. Google is required to assist us in responding to your access, correction, and deletion requests under Section 11 and to delete data on termination of our contract.
(g) We ask your permission before any data is sent. We request your affirmative, opt-in consent before your information is transmitted to an AI provider:
- The first time you open an AI feature, the app presents a consent screen that names Google as the recipient, lists the categories of data that will be sent, and links to this Section. No data is transmitted to an AI provider unless and until you tap the affirmative control on that screen.
- This consent is specific to AI features. It is separate from creating an account and from accepting the Terms of Service, and it is not bundled with any other permission.
- Declining costs you nothing. If you decline, the AI feature stays off and every other part of the Service — Earning Buckets, Credits, Tuition Credit disbursement, and human support — remains fully available to you.
- Human alternative. You can always reach a person instead, by emailing support@collegegain.ai or info@bebelong.life, or through the human support option in the app's Help menu.
- Withdrawing consent. You can turn AI features off at any time in Settings → Privacy → AI features, or by emailing us. Withdrawal stops all further transmission to an AI provider; it does not affect processing already carried out.
- Minors. For dual-enrollment users aged 13–17, AI features are enabled only where consent has been given through the verifiable parental-consent pathway described in Section 13 and Terms of Service, Section 4.
(h) Your AI conversations, and how to delete them. AI Support Chat and AI Mediator conversations, including attachments, are stored in your account so you can return to them. You can delete any individual conversation from within the app at any time; deletion removes it from our active systems within 30 days, with backups purged on our ordinary cycle. Retention periods are set out in Section 10, and you may also exercise your access, correction, portability, and deletion rights under Section 11.
(i) Human review. AI output is assistive. It does not by itself decide KYC eligibility, Credit eligibility, disbursement, or account suspension, and you may request human review of any determination that adversely affects you as described in Section 8.
Section 10
Retention and security
We retain personal information for as long as your account is active and for such additional period as is necessary for legal, accounting, fraud-prevention, or dispute- resolution purposes. Biometric data has a separate retention schedule (Section 4). We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest. No system is perfectly secure; we cannot guarantee absolute security.
Illustrative retention windows applied by the Company:
- KYC / identity records: retained for five (5) years after account closure to satisfy AML, tax, and fraud-prevention obligations.
- Biometric information: destroyed on the earlier of (i) satisfaction of the initial verification purpose and (ii) three (3) years since your last interaction with the Service, consistent with BIPA.
- Financial and wallet records: retained for seven (7) years, consistent with GLBA, EFTA/Regulation E, and applicable tax record-retention requirements.
- Earning Bucket engagement data: retained for up to twenty-four (24) months for partner reporting, fraud analytics, and Service improvement, then aggregated or deleted.
- AI Support Chat and AI Mediator conversations (including attachments): retained in your account for up to twenty-four (24) months after the last message in that conversation, then deleted or de-identified; you may delete any individual conversation sooner from within the app (Section 9).
- Marketing and communications logs: retained for up to twenty-four (24) months from the last interaction.
Section 11
Your rights and choices
In plain terms
You can see, correct, download, or delete your data. Depending on where you live, you may have additional rights.
Depending on your jurisdiction, you may have rights to:
- Access, correct, or delete your personal information;
- Port a copy of your personal information;
- Opt out of the "sale" or "sharing" of personal information and of targeted advertising;
- Limit the use and disclosure of sensitive personal information (including biometric and financial data);
- Opt out of certain profiling;
- Withdraw your consent to AI features at any time and delete your AI conversations (Section 9);
- Non-discrimination for exercising your rights;
- Appeal a denial of a rights request;
- Authorize an agent to submit rights requests on your behalf;
- Have your Global Privacy Control (GPC) signal recognized as a valid opt-out where required.
These rights are provided as required by applicable law, including the CCPA/CPRA (California), the VCDPA (Virginia), the CPA (Colorado), the CTDPA (Connecticut), the UCPA (Utah), other enacted comprehensive state privacy laws, the Florida Digital Bill of Rights (FDBR), the GDPR/UK GDPR, and, where applicable, PIPEDA (Canada). To exercise your rights, use Section 16 below. We will verify your request and respond within the time period required by law.
Section 12
FCRA note
KYC vendors used by the Company generally do not produce a "consumer report" as defined by the Fair Credit Reporting Act (FCRA), and the Company does not use KYC output to make employment, credit, insurance, or housing decisions covered by the FCRA. If a specific KYC component in the future could be construed as a consumer report, the Company will provide the required FCRA notices and obtain any required authorization.
Section 13
Children under 13 and dual-enrollment minors
CollegeGain.AI is not intended for and may not be used by anyone under 13. Consistent with the Children's Online Privacy Protection Act (COPPA), if we learn we have collected personal information from a child under 13 without verifiable parental consent, we will delete it and terminate the account. For dual-enrollment students who are minors but at least 13, use of the Service requires the verifiable parental-consent pathway described in Terms of Service, Section 4. Independent account creation requires age 18 (or the age of majority in your jurisdiction if higher); dual-enrollment users aged 13–17 may register only through the verifiable parental-consent pathway.
Section 14
Account continuity and RentGain
If you transition out of qualifying student status, we may offer you the opportunity to continue engagement through the Company's separate RentGain product. Unless the Company specifies otherwise, RentGain requires fresh account creation and fresh consent under RentGain's own Terms of Service, Privacy Policy, License Agreement, Cookies Policy, and Accessibility Statement; CollegeGain.AI data will not automatically carry over. CollegeGain.AI is part of the Company's broader platform ecosystem (which also includes Launchpad, POS, RentGain, and the DSP/Advertising Portal), each with its own consumer documentation.
Section 16
Contact us / Exercise your rights
To exercise any of your rights or contact us with privacy questions:
- Email: info@bebelong.life
- Mail: Be Belong Group Corp, Attn: Privacy, 2980 NE 207 Street, Miami, FL 33180
- In-product: submit a rights request from Settings → Privacy.
The Company does not currently maintain an EU/UK establishment and has not designated an EU/UK Representative or Data Protection Officer. If our processing activities change such that an appointment is required under Article 27 GDPR/UK GDPR, we will update this Policy with the designated representative's contact details.
Section 17
Changes to this Privacy Policy
We will update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, notify you by email, in-product banner, or other reasonable means. Where required by law, we will obtain your renewed consent before applying material changes to previously collected information.
