Privacy Policy
Last updated: July 15, 2026
1. Information We Collect
We collect the following categories of information:
- Account information — email address, name, and profile picture provided by your OAuth provider (Google, Microsoft, Apple, or GitHub), or the email address for an account that ScholarCal creates for authorized review or support use. Authentication passwords are stored as one-way credentials by Supabase Auth.
- Contact and notification information — a phone number you choose to verify for SMS, email notification preferences, push notification device tokens, reminder settings, and opt-in or opt-out timestamps.
- Calendar data — events, assignments, and calendar metadata imported from connected sources (Google Calendar, Microsoft 365, Canvas LMS, iCal feeds).
- Usage data — feature usage, AI assistant conversations, weekly allowance counters, and interaction patterns used to operate, secure, and improve the Service.
- Subscription data — your logical plan, purchase provider, subscription status, renewal period, and product identifier. Payment-card details are collected by Stripe or Apple and are not stored by ScholarCal.
- Shared workspace data — contacts, shared-calendar memberships, event invitations and responses, availability preferences, and agent messages you choose to exchange with another ScholarCal user.
- Notes and study data — notes you create or explicitly import, note revisions, transcripts, courses, study sessions, and study timer activity.
- Meeting and lecture data — recording titles, recording consent confirmation, audio you choose to capture, transcripts, summaries, and related meeting artifacts.
- Integration tokens — OAuth access and refresh tokens for connected services, stored encrypted per-user.
2. How We Use Your Data
- Display your calendar events in a unified view on web, mobile, desktop, and extension clients
- Power the AI scheduling assistant
- Sync events between connected calendar providers
- Send reminders and notifications you configure
- Save notes, track study sessions, and transcribe recordings you start
- Improve service reliability and features
3. ScholarCal Browser Extension
The ScholarCal browser extension brings your ScholarCal workspace into a browser side panel and adds ScholarCal calendar context to supported Canvas LMS pages. On first use, it shows a data disclosure and waits for you to choose "Agree and continue" before connecting your account, loading workspace data, or activating the Canvas enhancement. It does not collect your general browsing history.
- Canvas page access — on supported Canvas pages, the extension reads the page URL and the assignment or calendar information needed to show the calendar embed and assignment quick actions. Canvas assignment details are sent to ScholarCal when you ask ScholarCal to schedule study time for that assignment.
- Local extension storage — the extension stores a ScholarCal refresh credential, a short-lived event cache, unsaved note drafts, study timer state, and workspace preferences in Chrome extension storage. Authentication credentials and cached workspace data are restricted to trusted extension contexts. Signing out removes the credential and event cache; removing the extension clears its local storage.
- Notes and imports — pasted notes or transcripts are sent to ScholarCal only after you explicitly confirm an import or save action.
- Microphone and shared-tab audio — the recorder starts only after you press the recording control, approve the browser's media prompt, and confirm that the people being recorded have consented. Shared-tab audio is captured only when you select that option and choose a tab in Chrome. Audio segments are sent securely to ScholarCal and its transcription processor to create transcripts and summaries. Stopping a recording releases the selected media sources.
- ScholarCal account data — the extension retrieves the calendars, events, notes, study data, and meeting artifacts needed for the features you choose to use. It sends event edits, AI requests, study entries, note changes, and recording data when you perform those actions.
- Plan and allowance data — the extension may receive your ScholarCal plan, feature usage, remaining weekly allowances, and reset time so it can explain a limit and offer a contextual upgrade link. It does not receive card details or payment history.
ScholarCal does not sell extension data, use it for personalized advertising, or transfer it for credit or lending decisions. The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
4. Data Storage and Security
ScholarCal account data is stored in Supabase with row-level security (RLS) enforcement. Data is encrypted in transit (TLS) and at rest. OAuth tokens are stored per-user and are never shared between accounts. The installed mobile app stores its refresh credential and local drafts in operating-system-protected application storage. Local browser-extension data is described in Section 3.
5. Third-Party Processors
We use the following third-party services:
- Supabase — database, auth, and edge functions
- Stripe — checkout and subscription billing for web, browser-extension, and directly distributed desktop purchases
- Apple — StoreKit subscription billing for purchases made in App Store versions of ScholarCal
- Apple Push Notification service — delivery of mobile notifications to devices you register
- OpenAI — AI assistance, recording transcription, and meeting artifact generation
- Twilio — SMS reminders (phone number and message content)
- Google and Microsoft — calendar integrations you connect, including events you direct ScholarCal to create or update
- Canvas — read-only assignment and calendar data from the education integration you connect
5a. SMS and Mobile Information
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Your mobile phone number and your SMS consent are collected only to deliver the calendar reminders you asked for, and are never sold or rented. Twilio is listed above solely as the carrier gateway that transmits those messages; it is a processor acting on ScholarCal's instructions, not a recipient of your consent. The full messaging program disclosure — including opt-in steps, message frequency, and opt-out instructions — is on our SMS Reminders page, and the governing terms are in section 6 of our Terms of Service.
Message frequency. Message frequency varies. ScholarCal sends SMS reminders only for calendar items you created or subscribed to, at the reminder times you choose, so the number of messages depends entirely on your own schedule. Message and data rates may apply. ScholarCal does not charge for SMS reminders; your mobile carrier may. Reply STOP to any message to unsubscribe, or HELP for help.
6. Data Retention and Deletion
Your data is retained as long as your account is active. When you disconnect an integration, associated tokens and sync state are deleted immediately. When you delete your account, all data is permanently removed within 30 days.
7. Your Rights
You have the right to:
- Access your data via the API or Settings export
- Correct inaccurate information
- Delete your account and all associated data
- Disconnect any integration at any time
- Export your events via iCal feed
- Revoke browser media permissions or remove the extension at any time
8. Education Data (FERPA)
When used with Canvas LMS, ScholarCal reads assignment and calendar data in read-only mode. We do not write to or modify any LMS data. Canvas data is treated with the same security and retention policies as all other user data.
9. Changes to This Policy
We will notify you of material changes via email or in-app notification. The "last updated" date at the top of this page reflects the most recent revision.
10. Contact
Privacy questions? Contact us at xynprize@gmail.com.
