Privacy Policy
Last updated: August 3, 2026
The short version
- We collect what we need to turn syllabi into calendars — nothing more.
- We never sell your data. No ads, no data brokers.
- Connected accounts (Canvas, Google) are used only to do the thing you asked for.
- Delete your account and your data goes with it.
What we collect
Account info: email, name, school, timezone — what you give us at signup and onboarding.
Your academic content: syllabi you upload and the assignments, exams, and events we extract from them; courses and calendar events you create. Syllabus files processed through the free tool are parsed on the fly; extracted events are stored only when you save them to an account.
Connected services: if you connect Canvas we store an access token and course/assignment data needed to sync; if you connect Google Calendar we use the token to write the events you ask us to. We request the narrowest scopes that work.
Usage and technical data: standard logs (IP, browser type, pages) and privacy-respecting analytics (Vercel Analytics) to keep the Service fast and debug problems.
What we use it for
Running the product (parsing, calendars, reminders, sync), emailing you the things you signed up for (deadline reminders, product updates — every marketing email has an unsubscribe link), preventing abuse of free-tier limits, and improving the Service. That's the list.
What we never do
- Sell or rent your personal data.
- Use your syllabi or grades to target advertising.
- Read your connected accounts beyond what the feature you used requires.
Who touches your data
We run on trusted processors: Supabase (database & auth), Vercel (hosting & analytics), Stripe (payments — we never see your card number), Anthropic (AI syllabus parsing; content is processed to extract dates, not to train models on your data), and our email providers (Loops/Resend) for the emails described above. Each processes data only to provide their service to us. We disclose data beyond that only if the law requires it.
Google user data
What we access. If you choose to sync a syllabus to Google Calendar, you grant Classmaite the calendar.app.created scope — the narrowest calendar permission Google offers. It lets us create a new calendar of our own and put events on it. It gives us no ability to see, edit, or delete anything on the calendars you already have. We also receive your email address and basic profile (name, profile picture) if you sign in with Google.
How we use it. We create one calendar per course, named for that course, and add the assignment, exam, reading, and class-session events you reviewed and approved on screen. Nothing else. Because we can only touch the calendar we made, your existing events are structurally out of our reach — and deleting that one calendar removes everything we added. We do not use Google data for advertising, profiling, credit, or lending decisions.
How we transfer it.We do not sell, rent, or transfer Google user data to third parties. It is not shared with data brokers, advertisers, or analytics providers. The only transfer is the one you initiate: your event data going to Google's own Calendar API.
How we retain it. Your Google access token lives in your signed-in session only — we never write it to our database. The calendar we create belongs to you and stays in your Google account until you delete it there; removing it in Google is always the final word. Revoke our access anytime in Settings or at Google Account permissions.
Limited Use.Classmaite's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google Workspace API data — raw, derived, or aggregated — to develop, improve, or train generalized AI or machine learning models, and we do not transfer it to any third-party service that would. Our AI syllabus parsing runs only on the file you upload, before any calendar is touched; the AI never receives Google Calendar data.
How we protect your data
All traffic runs over TLS, and data at rest in our database is encrypted by our infrastructure providers. Access to production data is limited to the people who need it to operate the Service and is protected by multi-factor authentication. Row-level security rules in our database scope every record to its owner, so one student's syllabi and events are not readable by another. Access tokens are never written to application logs.
How long we keep it
Syllabi run through the free tool are parsed in memory and not retained — extracted events are stored only if you save them to an account. Account data (your profile, courses, syllabi, and events) is kept for as long as your account is open. Delete your account and we remove that data from our live systems within 30 days; encrypted backups containing it age out within 30 days after that. Standard server logs are retained for up to 30 days. Disconnecting Google or Canvas immediately discards the associated token.
Your controls
You can edit or delete courses, events, and syllabi in the app; disconnect Canvas or Google anytime in Settings; unsubscribe from any marketing email with one click; and delete your account entirely — which removes your data from our systems (backups age out on a short schedule). For any data request, email hello@myclassmaite.com and we'll handle it.
Age, changes, contact
Classmaite is for students 13 and up. If we change this policy in a material way, we'll notify you before it takes effect. Questions: hello@myclassmaite.com. See also our Terms of Service.