Privacy Policy
Who We Are
Student Loans Central is a free, self-reported student loan tracking and planning tool. You enter or upload your own loan information, and we help you see where you stand, model your options, and build a payoff plan. We are not a lender, a servicer, or a financial advisor, and we never move money.
Contact: support@studentloanscentral.com
What We Collect
- Account details — your email address and a password (stored hashed by our authentication provider), or your basic Google profile if you sign in with Google.
- Profile information you choose to provide. Every field below is optional except your first name and state, "Prefer not to say" is always available, and leaving a field blank only means the related guidance is skipped:
- Name, age, and state of residence — to address you, and because repayment and forgiveness programs are state- and age-specific.
- Occupation, employer name, employer type, work state, and years in your current role — to check Public Service Loan Forgiveness and employer-specific repayment benefits.
- Annual income, pay frequency, spending, and spouse income — to size income-driven repayment estimates and the extra payment your budget supports.
- Marital status and household size — both are direct inputs to federal income-driven repayment formulas.
- Credit score range — to indicate whether refinancing is realistic. It is a self-reported band; we never pull your credit.
- Veteran status and permanent-disability status — strictly optional, never required, and used only to surface programs tied to them (such as Total and Permanent Disability discharge and military benefits). Leave them blank and nothing else changes.
- Self-reported PSLF payment count and borrower role (for example Parent PLUS) — to model forgiveness timing. We do not have access to your official count at studentaid.gov.
- Loan and payment data — balances, rates, terms, servicers, loan names, payment history, and autopay schedules you enter or import.
- Files you upload — PDF or CSV statements and payment histories used to extract loan details and transactions.
- Servicer connection data — only if you choose to link an account through our connection provider.
- Device data for reminders — a push subscription endpoint and keys for each device you enable reminders on, plus whether you have installed or dismissed the Home Screen prompt.
- Server logs and first-party usage counts — our hosting and database providers log requests, IP addresses, and errors so the service can run and be debugged, and we record anonymous counts of a few product steps (for example, how many people reach the "add your first loan" step) in our own database. We do not load third-party analytics, advertising, or session-replay scripts in this app.
Guest Mode
You can try the product without creating an account. Guest mode uses a temporary anonymous session so you can add loans, log payments, and generate a report.
Guest data is not durable. It is purged when the session ends, when you close or reload the browser, or when you exit guest mode. The only way to keep it is to create an account, in which case the loans and payments from that guest session transfer to your new account.
How We Use It
To operate your dashboard, plan, and report; to run the calculations you ask for; to send the reminders and emails you opt into; and to fix bugs and improve the product.
We do not sell your data. We do not run ad targeting. We do not pass your information to lenders, refinancing companies, or lead buyers.
AI Processing
Two features use AI. When you upload a statement or payment history, the file contents are sent to our AI provider (Google Gemini, accessed through the Lovable AI Gateway) so loan details and transactions can be extracted. When you generate a report, the loan and profile fields needed for that report — including your state, occupation, and employer where you have provided them — are sent so programs and employer eligibility can be researched.
Employer research results may be cached so repeat reports are faster and more consistent. AI output is generated text and can be incomplete or wrong; treat it as a starting point, not a determination. Under our provider terms this data is not used to train third-party models.
Servicer Connections
If you link a servicer account, the connection is read-only. We cannot move money, make payments, or modify your loans. Access tokens are encrypted and stored server-side only and are never exposed to your browser. You can disconnect at any time in Settings.
Plaid's privacy notice: plaid.com/legal/privacy-notice
Notifications & Email
Payment reminders are opt-in and per device. When you turn them on, your browser creates a push subscription that we store so we can send a reminder when you have autopay confirmations pending. You can turn reminders off in Settings or revoke the permission in your browser or phone settings, and we stop sending to that device.
We send account and transactional email (sign-in, password reset, and similar). Any non-essential email includes an unsubscribe link.
Agent (MCP) Access
You can connect an AI assistant to your account through our Model Context Protocol endpoint. That connection always goes through an explicit consent screen where you sign in and approve it. The assistant receives a scoped token that can only read your own loans, payments, and portfolio summary and log payments you ask it to log. It cannot see other users' data, and you can revoke the connection at any time.
Retention & Deletion
We keep your data while your account is open so your history and projections stay accurate. You are in control: in Settings, Reset your portfolio clears all loans, payments, autopay schedules, and plans, and Account data deletes your account entirely. Deleting your account removes your data from our live systems and revokes any servicer connection; backups age out within 30 days. Guest sessions are purged as described above.
Security
Data is encrypted in transit and at rest. Row-level access controls at the database level mean each account can only read and write its own rows. Server-only credentials and API keys are never shipped to the browser. No system is perfectly secure, so please use a strong, unique password.
Your Rights
- See your data — it is all visible in the app
- Correct it — edit any loan, payment, or profile field in the app
- Export it — Settings → Download your data gives you the whole account as JSON or CSV, immediately, with no request needed
- Delete it — Settings → Reset your portfolio clears all loans and payments; Settings → Account data deletes the account itself
- Opt out of reminders and non-essential email at any time
Residents of California and other states with comparable laws have additional rights, including the right to know, delete, and opt out of the sale of personal information. We do not sell personal information. To exercise any right, email us.
Children
We do not knowingly collect data from anyone under 13.
Changes
We will update this page when our practices change and revise the date at the top. For material changes affecting account holders, we will notify you by email in advance.
Contact
support@studentloanscentral.com
Student Loans Central — West Orange, New Jersey