Legal

Privacy Policy

Last updated: 19 April 2026

Short version: we collect the minimum needed to run your account. We never sell your data. We never train models on it. You can export or delete everything at any time.

1. What we collect

Account information

When you sign up, we store your email address, an encrypted (hashed) form of your password, and the name you chose. That's it.

Dashboard content

Tasks, courses, classes, exams, notes, flashcards, focus sessions, GPA history, and your preferences (theme, accent, etc.) are stored in your account so you can sign in from any device. Each row is tied to your user ID and is invisible to anyone else.

Technical data

Standard server logs (IP address, browser, timestamps) are kept briefly for debugging and security. We don't run third-party analytics or trackers.

2. Where it lives

All data is stored in Supabase (hosted on AWS) under encryption at rest and in transit. Row-Level Security policies enforce that only your account can read or modify your data.

3. What we don't do

4. Cookies

We use a session cookie (and a refresh token in localStorage) to keep you signed in. That's the only cookie. There's no analytics, no fingerprinting, no advertising IDs.

5. Your rights

You can:

6. Children

Semester is intended for users 13 and over. If we learn we've stored data from a younger user, we'll delete it.

7. Security

No system is perfectly secure, but we follow the basics: HTTPS everywhere, short-lived JWTs, server-side row-level security, and Supabase-managed secrets. If we ever experience a breach affecting your data, we'll notify you within 72 hours.

8. Changes

If we change this policy, we'll update the date above. Material changes get an email so you can review before they take effect.

9. Contact

A dedicated privacy contact address is coming once we have a custom domain. Until then, please reach out wherever you originally heard about Semester.


See also: Terms of Service.