Privacy Policy
Short version: we collect the minimum needed to run your account. We never sell your data. We never train models on it. You can export or delete everything at any time.
1. What we collect
Account information
When you sign up, we store your email address, an encrypted (hashed) form of your password, and the name you chose. That's it.
Dashboard content
Tasks, courses, classes, exams, notes, flashcards, focus sessions, GPA history, and your preferences (theme, accent, etc.) are stored in your account so you can sign in from any device. Each row is tied to your user ID and is invisible to anyone else.
Technical data
Standard server logs (IP address, browser, timestamps) are kept briefly for debugging and security. We don't run third-party analytics or trackers.
2. Where it lives
All data is stored in Supabase (hosted on AWS) under encryption at rest and in transit. Row-Level Security policies enforce that only your account can read or modify your data.
3. What we don't do
- We don't sell your data, to anyone, ever
- We don't train AI models on it
- We don't run ad networks, retargeting pixels, or third-party trackers
- We don't share data with marketing partners
4. Cookies
We use a session cookie (and a refresh token in localStorage) to keep you signed in. That's the only cookie. There's no analytics, no fingerprinting, no advertising IDs.
5. Your rights
You can:
- Export all your data as JSON from Settings → Data → Export
- Delete your dashboard data from Settings → Data → Reset all data
- Delete your account entirely once a contact channel is set up (coming soon). For now, resetting your data above is the privacy-equivalent action while we get that wired up
6. Children
Semester is intended for users 13 and over. If we learn we've stored data from a younger user, we'll delete it.
7. Security
No system is perfectly secure, but we follow the basics: HTTPS everywhere, short-lived JWTs, server-side row-level security, and Supabase-managed secrets. If we ever experience a breach affecting your data, we'll notify you within 72 hours.
8. Changes
If we change this policy, we'll update the date above. Material changes get an email so you can review before they take effect.
9. Contact
A dedicated privacy contact address is coming once we have a custom domain. Until then, please reach out wherever you originally heard about Semester.
See also: Terms of Service.