Semester

Privacy Policy

Last updated 25 August 2026

Semester builds you a set of Google Calendars from your class schedule, your Canvas or Blackboard assignment feed, your school's game schedule, and the campus and chapter calendars you choose to follow. This page describes exactly what it stores and why. It is written to be read, not to be skimmed past.

What Semester stores

Pictures of your schedule are never uploaded. If you import your classes from a screenshot, the image is read inside your own browser. The picture is not sent to Semester, to any other company, or to any server at all, and no copy of it is kept anywhere. Only the text that was read off it — course codes, days and times — is sent, and only so it can be shown back to you for checking before anything is saved.

All of it lives in a Supabase Postgres database in the US, protected by row-level security so one account cannot read another's rows. Your Google refresh token sits in a table that no signed-in user can query at all — only the server-side sync job can read it.

When something breaks

If Semester hits an error while you are using it, it records what failed, which part of the app it happened in, and the email address of the account it happened to, so the problem can be found and fixed without you having to report it. Feed URLs and access tokens are stripped out of that record before it is written. These entries are visible only to the person who runs Semester, and you can ask for yours to be deleted along with the rest of your data.

What Semester does with your Google account

Semester creates and maintains up to five calendars of its own: your classes, your assignments, your school's games, the campus calendars you follow, and your Greek chapter. It only writes to events it created itself, which are tagged so it can recognize them. Events you add by hand, on those calendars or anywhere else, are never modified or deleted.

Being precise about the permission. Semester requests exactly one Google permission: calendar.app.created — "make secondary Google calendars, and see, create, change, and delete events on them". It is the narrowest permission Google offers that can still create a calendar, and it applies only to calendars Semester itself made. Your other calendars are not merely left alone; Google never grants access to them, so Semester cannot read or change them even by mistake. You can revoke this at any time.

What Semester never does

Semester's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Who else is involved

Semester runs on three services, and none of them receive your data for their own purposes: Supabase (database and sign-in), Cloudflare (serves this site), and Google Calendar (where your events go). Semester also fetches public team schedules from ESPN, which involves none of your data.

Semester reads your assignment feed directly from your school's learning system using the link you provide — learn.uark.edu for Blackboard at the University of Arkansas, umich.instructure.com for Canvas at the University of Michigan. It has no other connection to those systems or to either university, and no relationship with them of any kind.

Campus and chapter calendars are fetched from whatever public address you paste in. Semester refuses links that point at private network addresses, and re-checks every redirect, so a pasted link cannot be used to reach anything but the public internet.

How long Semester keeps it, and how it is protected

Your rows stay for as long as your account exists. Revoke Semester in your Google account and the stored refresh token stops working immediately; it is discarded the next time a sync tries to use it. Assignment titles and campus events are replaced on every sync rather than accumulating, so the database holds the current term, not a history of it. Nothing is kept after you ask for deletion.

Everything is served over HTTPS. The database is Supabase's managed Postgres, which is encrypted at rest, and every table is behind row-level security keyed to your account. The Google refresh token sits in a table with no client-readable policy at all — a signed-in browser cannot query it under any circumstances, only the server-side sync job can.

Deleting your data

Revoke Semester at myaccount.google.com/permissions and it immediately loses all access to the calendars it created. To have the stored rows deleted as well, email the address below and say so — everything tied to your account will be removed. The calendars Semester created stay in your Google account, and are yours to keep or delete.

Contact

lafarve09@gmail.com

Terms of Service