HomeSearchScheduleSubjectsSavedAsk the advisor
Your account 
Pricing
Sign in
  • Home
  • Search
  • Schedule
  • Advisor
  • Profile

Privacy

Short version: your schedule stays on your device, we count which pages and controls get used, we do not sell anything to anyone, and you can have your data removed by asking.

What you can do about it

  • Turn on Do Not TrackIt is a setting in your own browser, and we treat it as a refusal: no id is created, and nothing is recorded from that point on. It switches off the advertising pixel below as well.
  • Clear your browser dataThat deletes the random id and everything this site kept on your device, your schedule included. The next visit is a different person to us.
  • Your page historyThe log kept for a signed-in account, on one page, with a button that empties it.
  • Ask us to delete what is storedClearing your browser does not reach the records on our side. Write to us and we will act on it. That is the Data Privacy Act right spelled out at the foot of this page.

What we hold, and where

Nine answers, the biggest store first. Every row states its own claim closed; open it for the detail.

We count what you do here

We record which pages you open, roughly how long you stay, which tagged controls you tap, and the words you type into search.

This is on by default and there is no banner asking you to accept it. It is how we find out which parts of the app are used, which ones are quietly broken, and what students are actually looking for.

We also record which platform you arrived from: that your visit came from Facebook, Reddit, a Google search, and so on. Your browser tells every website this; what we keep is the platform name alone, chosen from a fixed list. We do not store the link you came through, so the post you tapped, the search you ran on someone else’s site, and anything those addresses carried are not written down. If your browser sends nothing, we record that as “direct” and learn no more than that.

Those records are tied together by a random id stored in your browser, so we can tell that several actions came from one visit. The id is generated from nothing about you: not your name, not your email, not your device, not a fingerprint. We also keep a one-way hashed form of your IP address, salted, so we can catch abuse; the address itself is never written down.

We keep these records for 180 days and then delete them. Turning on Do Not Track stops all of it, and clearing your browser data ends the id.

What stays on your device

Your schedule, your painted free hours, your recently viewed pages and the search index never leave your browser.

They live in your browser’s local storage and are not uploaded. Clearing your browser data clears them, and nothing on our side changes.

What we never record

What you type into a comment box before you submit it is never sent, and no control name can carry a professor's name.

Search terms are recorded, because that is how we see what the roster is missing. The names of controls still come from a fixed list we wrote, never from the words on your screen, so a professor’s name cannot fall out of a button by accident. We do not record what you read as an individual profile, and we never link it to your name or your school email.

What we store when you sign in

Your school email, who invited you if you arrived on an invite link, a Season Pass record if you bought one, and your comments.

The email address is how we confirm you are a student at your university and attribute comments you submit. If you sign in through someone’s invite link, we store that they invited you. If you buy a Season Pass, a record that you did. Comments you submit are stored with the moderation decision attached.

Pages you opened while signed in

A signed-in account keeps a log of the pages it opens, and that log is yours to read and to empty.

Sign in and this log starts: every page you open is stored against your account, and you can read it back or empty it on your history page.

The path is stored, never the query string, so a search you typed is not in this table. We keep these records for 180 days and then delete them.

This is an account feature, not the usage records above. Do Not Track does not stop it. Signing out stops new rows; it does not erase the ones already stored. Deleting your account erases them.

When you submit a comment

A comment submission is kept with a salted hash of your IP address and a hash of your browser characteristics, to cap abuse.

Submitting a review is a voluntary write about a named person, so we keep an abuse-prevention record of it. The browser characteristics are the user-agent string, language, and the client hints your browser already sends. We do not run a fingerprinting script, and we do not probe your display or typefaces. Stored alongside them is a count of how many of your previous comments were published or rejected. We use the record to cap unsigned writes and to order the moderation queue. It is not shown on any page and it is never joined to the comment a reader sees.

We keep these submission records for 180 days and then delete them, on the same cadence as the usage records above.

This record is not turned off by Do Not Track. DNT governs the behavioural analytics described above: which pages you opened, which controls you tapped. An abuse-prevention record of a comment you chose to submit is not that, and we keep it whether or not DNT is on, because the page names a real person.

Advertising measurement

We load the Meta pixel on our marketing pages only. It never runs on a professor page, a course page, or the search page.

We advertise this site on Facebook, and we measure whether those adverts work. The marketing pages are the home page, About, Help, the advisor, the schedule builder and the subject tools; on those, the pixel tells Meta that a visit happened and which of those pages it was on. That is a third-party advertising tracker, and Meta may use it to measure and target adverts.

The excluded addresses name a real person, and we are not willing to tell an advertising network which professor you read. Nothing you read about a named individual on this site is reported to Meta. The pixel is also off entirely whenever Do Not Track is on, the same refusal that stops our own usage records, and it can be blocked by any content blocker without affecting the site.

Comments about people

Professor pages carry no contact details, and a comment naming anyone other than the professor is withheld for review.

Pages are about professors in their professional capacity: no email, no phone, no address. Comments are screened before publication for names of anyone other than the professor being discussed.

What we do not do

We do not sell or share personal data, and we run no third-party analytics service.

The usage records described above are our own and stay on our own server. We do not build advertising or marketing profiles ourselves; the advertising measurement described above is limited to the marketing pages named there.

Your rights under the Data Privacy Act

You can ask what we hold about you, ask us to correct it, and ask us to delete it. Write to us and we will act on it. If a page or comment concerns you and you want it gone, say so. We remove first and review after. Every way to reach us is on Contact and reports, and what you agree to by using the site is on Terms.

Sign in

Sign in and this log starts: every page you open is stored against your account, and you can read it back or empty it on your history page.