ScheduleBud Privacy Policy
Last Updated: August 18, 2026
Effective Date: August 18, 2026
Important: This privacy policy is designed to comply with CCPA/CPRA (California Consumer Privacy Act) and GDPR. ScheduleBud is a personal productivity tool, not a service contracted by or administered through any school, so FERPA's institutional rules do not directly govern our relationship with you — we describe how we apply similar data-protection principles voluntarily in Section 4. ScheduleBud is exclusively for users 18 years of age and older.
1. Introduction
ScheduleBud ("we," "us," or "our") is committed to protecting the privacy and security of adult student educational information. This Privacy Policy explains how we collect, use, protect, and share information when you use our academic task management application. This service is exclusively available to users 18 years of age and older.
2. Information We Collect
2.1 Account Information
- Identity Data: Email address, name, and profile information
- Authentication Data: Encrypted passwords and login credentials
- Contact Information: Email address for notifications and account management
2.2 Educational Information
- Academic Records: Class schedules and assignments
- Course Information: Class names, course codes, instructor information, and academic calendars
- Assignment Data: Task descriptions, due dates, and completion status
- Canvas LMS ICS Data: Calendar information fetched from your Canvas LMS ICS feed URL via secure connections
2.3 Usage Information
- App Usage: Features used, time spent, and interaction patterns
- Device Information: Browser type, operating system, and device identifiers
2.4 File Uploads
- Syllabus Documents: PDF files and documents uploaded for AI-powered task extraction
- Class Materials: Study materials and reference documents you choose to upload
2.5 Smart Assistant Conversations
- Chat Messages: The questions you ask the Smart Assistant, its responses, and any unsent message drafts, stored so you can revisit your conversations
- Conversation History: Recent turns of a conversation, used to give the assistant context. You can turn this off in your settings
2.6 AI-Derived Data (Embeddings & Knowledge Graph)
- Vector Embeddings: Numerical representations of your uploaded documents and course materials, generated so the Smart Assistant can search them by meaning
- Knowledge Graph: A structured map of entities (such as courses, assignments, topics, dates, and instructor names) and the relationships between them, automatically extracted from your uploaded materials and tasks
2.7 Assistant Memory (Optional)
- Inferred Facts & Preferences: When enabled, the Smart Assistant may infer and store a small set of facts and preferences you state about yourself (for example, your major, or a preference for shorter answers) to personalize its responses
- Your Control: Long-term memory is optional. You can view, disable, or delete stored memories at any time in your settings
3. How We Use Your Information
3.1 Core Educational Services
- Provide academic task management and scheduling services
- Generate study schedules and workload analysis
- Fetch and parse Canvas LMS ICS calendar feeds via secure connections to import assignments
- Process syllabus documents to extract assignment information using AI
- Generate embeddings and a knowledge graph of your materials to power semantic search and the Smart Assistant
- Answer questions about your uploaded course materials using the Smart Assistant
- When enabled, remember conversation context and a small set of stated facts and preferences to personalize Smart Assistant responses
- Send assignment reminders and notifications
3.2 Service Improvement
- Analyze usage patterns to improve app functionality
- Develop new features based on student needs
- Ensure service reliability and performance
3.3 Communication
- Send service-related notifications and updates
- Respond to support requests and feedback
- Provide important service announcements
4. How We Treat Your Academic Information
Not a School-Contracted Vendor: ScheduleBud is a personal productivity tool you sign up for and use directly — we have no contract with your school and are not designated as a "school official" under FERPA. As a result, FERPA's institutional disclosure rules do not directly govern our relationship with you. We voluntarily apply data-minimization and access principles in that spirit for academic information including course schedules, assignments, and syllabus content.
4.1 Academic Information We Handle
- Course Information: Class names, course codes, and academic calendars from Canvas LMS
- Assignment Data: Task descriptions, due dates, and completion status
- Syllabus Content: Academic documents and AI-processed course requirements
4.2 Your Rights Over This Information
- Access: You can view and export all your academic information through account settings
- Correction: You may request correction of inaccurate academic records
- Consent: We do not disclose your academic information to third parties without consent
5. Information Sharing and Disclosure
5.1 No Sale or Marketing of Student Data
We do not sell, rent, or trade student educational information to third parties for any purpose. We do not use your information for marketing purposes of any kind.
5.2 Limited Disclosure
We may share your information only in these specific circumstances:
- With Your Consent: When you explicitly authorize us to share specific information
- Service Providers: With trusted vendors who provide essential services (hosting, email, analytics) under strict data protection agreements
- Legal Requirements: When required by law, court order, or to protect safety and security
- Emergency Situations: To prevent harm to student safety or institutional security
5.3 Third-Party Services
- Supabase: Database and authentication services (GDPR and SOC 2 compliant)
- Google Gemini AI: Powers document processing, knowledge-graph extraction, and the Smart Assistant chatbot. Content you submit to these features is sent to Google for processing
- Hugging Face: Generates text embeddings from your uploaded materials so they can be searched by meaning
- Stripe: Payment processing for subscriptions (we never store your full card details)
- Resend: Sends transactional email notifications (task reminders, account emails) on our behalf
6. Data Security
6.1 Security Measures
- Encryption: All data transmitted and stored is encrypted using industry-standard protocols
- Access Controls: Strict access controls and authentication requirements
- Regular Audits: Periodic security assessments and vulnerability testing
- Staff Training: Regular privacy and security training for all personnel
6.2 Data Breach Response
In the event of a data security incident affecting student educational records, we will:
- Notify affected students within 72 hours (GDPR requirement) or as required by applicable law
- Cooperate with investigations and provide necessary remediation
- Implement additional security measures to prevent future incidents
7. Data Retention
7.1 Retention Period
- Active Accounts: Data is retained for as long as your account is active.
- Graduated or Closed Accounts: Educational records are retained for 3 years from the date of graduation or formal account closure, after which they are permanently deleted.
- Inactive Accounts: Accounts inactive for 2+ years are moved to an archived state and may eventually be closed, triggering the 3-year retention period for closed accounts.
7.2 Data Deletion
Students may request deletion of their educational records at any time by contacting us. Upon request, we will:
- Delete all personal and educational information within 30 days
- Provide confirmation of deletion
- Maintain only de-identified usage statistics for service improvement
8. Student Rights and Controls
8.1 Access and Portability
- View and download all your data through account settings
- Request copies of all information we maintain about you
8.2 Correction and Updates
- Update personal information through your account settings
- Request correction of inaccurate educational records
- Add statements of disagreement to disputed records
8.3 Privacy Controls
- Control notification preferences and frequency
- Manage Canvas LMS ICS feed URL settings.
- Enable or disable Smart Assistant conversation history and long-term memory
- View and delete stored Smart Assistant memories and conversations
- Set data retention preferences within legal limits
9. Canvas LMS Integration (Optional)
Optional Integration: Canvas calendar sync is an entirely optional feature that you control. You can enable or disable it at any time in your settings.
9.1 How Canvas Integration Works
When you choose to enable Canvas calendar sync, you voluntarily provide your Canvas ICS calendar link. We use this link, generated by Canvas, solely to import your assignment due dates into ScheduleBud. We do not generate this link; we leverage the existing feature provided by Canvas to extract relevant information. This integration:
- Is entirely optional and user-initiated - You must manually provide your Canvas ICS link
- Leverages Canvas's standard ICS calendar feeds - We simply use the link provided by Canvas, similar to how Google Calendar, Outlook, and Apple Calendar integrate
- Can be disabled at any time in your settings - Full user control with instant disconnection
- Does not access your Canvas account directly - We never ask for or store Canvas login credentials
- Only accesses publicly available calendar data - Data that you choose to share via your ICS link
9.2 Industry-Standard Integration Method
- ICS Calendar Standard: Uses the same iCalendar (ICS) format supported by all major calendar applications
- Calendar Feed Only: The calendar (ICS) integration never logs into or accesses your Canvas account
- Secure CORS Proxies: Calendar data is fetched through secure proxy services to protect your privacy
- Read-Only Access: We can only read assignment dates, never modify anything in Canvas
- User-Controlled Data: You decide what calendar information to share by providing the ICS link
9.3 Third-Party Platform Security Disclaimer
THIRD-PARTY RISK NOTICE: ScheduleBud integrates with third-party platforms (such as Canvas LMS) solely to provide optional features you request. We do not operate, control, or manage the security practices, data policies, or infrastructure of these third-party platforms. By enabling any optional integration, you expressly acknowledge and accept that you are solely responsible for all risks associated with third-party platform security vulnerabilities or data breaches, including those originating from or affecting Canvas LMS. ScheduleBud assumes no liability or responsibility for any data compromise, system failure, or loss resulting from the acts, omissions, or security posture of any third-party platform provider.
10. Age Requirements (Adults Only)
ADULTS ONLY: ScheduleBud is exclusively for users 18 years of age and older. We do not knowingly collect personal information from anyone under 18 years of age.
10.1 Adult Users Only Policy
- Age Requirement: Users must be at least 18 years old to create an account
- Age Verification: We require age verification during account registration
- Account Termination: Accounts created by users under 18 will be immediately terminated upon discovery
- Data Deletion: All data associated with under-age accounts will be promptly deleted within 30 days
- No Minor Protections: This service is not designed for or directed toward minors
10.2 Social Media Login Age Verification
- OAuth Age Confirmation: Users who register via Google, GitHub, or Discord confirm they are 18+ by proceeding with social login
- Platform Terms Compliance: Social media platforms generally require users to be 13+, but our service requires 18+
- Additional Verification: We may request additional age verification for OAuth users if needed
- Account Termination: OAuth accounts that cannot verify 18+ age will be terminated immediately
10.3 Reporting Under-Age Users
- Report suspected under-age accounts to: tony@schedulebud.cc
- We investigate all reports within 1 week
- Confirmed under-age accounts are terminated immediately with full data deletion
11. California Privacy Rights (CCPA/CPRA)
California Residents: Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have specific rights regarding their personal information.
11.1 Your California Privacy Rights
- Right to Know: Request information about personal information collected, used, disclosed, or sold
- Right to Delete: Request deletion of personal information we have collected
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt-out of the sale or sharing of personal information (we do not sell data)
- Right to Limit: Limit use and disclosure of sensitive personal information
- Right to Non-Discrimination: Not receive discriminatory treatment for exercising privacy rights
11.2 Categories of Personal Information (CCPA)
We collect these categories of personal information from California residents:
- Identifiers: Name, email address, account credentials
- Education Information: Academic records, assignments, class schedules
- Internet Activity: App usage patterns, device information, interaction data
- Professional Information: Student status, educational institution
- Sensitive Personal Information: Account login credentials (encrypted)
11.3 Business Purposes for Data Use
- Providing educational task management services
- Processing Canvas LMS ICS calendar feeds via secure connections for academic calendar imports
- Sending assignment reminders and educational notifications
- Improving app functionality and developing new features
- Ensuring security and preventing fraud
- Complying with legal obligations
11.4 Third-Party Data Sharing (California)
We do not sell personal information. We share data only with:
- Service Providers: Supabase (hosting), Google Gemini AI (document processing and Smart Assistant), Hugging Face (text embeddings), Stripe (payments), Resend (transactional email)
- Business Purpose: All sharing is for business purposes only, not commercial purposes
- Contractual Protections: All third parties are bound by strict data protection agreements
11.5 Exercising Your California Rights
- Submit Requests: Email tony@schedulebud.cc
- Verification Required: We will verify your identity before processing requests
- Response Time: We respond to requests within 5 business days for simple requests, up to 45 days for complex requests as required by California law
- No Fees: We do not charge fees for processing privacy rights requests
- Authorized Agents: You may use authorized agents to submit requests on your behalf
11.6 Student-Friendly Data Practices
California's student-privacy statutes (such as SOPIPA) are generally directed at K-12 vendors under contract with school districts, which does not describe ScheduleBud's direct-to-consumer, college-focused service. We follow the same practices anyway as a matter of principle:
- Educational records are not used for non-educational commercial purposes
- We do not build profiles of students for non-educational purposes
- Student data is not disclosed to third parties except as required for educational services
12. International Students & GDPR Compliance
12.1 Cross-Border Data Transfers
- Data is primarily stored in the United States
- International students are protected by the same privacy standards
- We comply with applicable international privacy laws (GDPR, PIPEDA, etc.)
12.2 GDPR Legal Basis for Processing (EU Users)
For users in the European Union, we process personal data based on the following legal bases:
- Contractual Necessity (Article 6(1)(b)): Processing necessary for providing educational task management services
- Legitimate Interest (Article 6(1)(f)): App improvement, security monitoring, and fraud prevention
- Consent (Article 6(1)(a)): Marketing communications, optional features, and analytics
- Legal Obligation (Article 6(1)(c)): Compliance with educational regulations and data protection laws
12.3 GDPR Rights for EU Users
- Right to Access: Obtain copies of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten"): Request deletion of personal data
- Right to Restrict Processing: Limit how we process your data
- Right to Data Portability: Receive your data in machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for consent-based processing
13. Local Storage and Tracking Technologies
We don't use cookies. ScheduleBud keeps you signed in and remembers your preferences (theme, settings) using your browser's local storage, not cookies. Some third parties we link out to may set their own cookies on their own sites — see below.
13.1 What We Use Locally
- Authentication: Your sign-in session is stored in your browser's local storage so you stay logged in
- App Preferences: Settings like theme and display options are saved to our Supabase database under your account (so they sync across your devices), with a local copy cached in your browser's local storage for fast loading
- Notification Preferences: Stored only in our Supabase database, not in local storage
- Canvas Calendar URL: Stored only in your browser's local storage and never sent to our servers, since the URL itself can be sensitive
13.2 Third Parties That May Set Cookies
- Stripe: When you're redirected to Stripe's hosted checkout or billing portal, Stripe may set cookies on stripe.com for payment processing and fraud prevention
- Google, Discord, GitHub: If you sign in with one of these providers, they may set cookies on their own sign-in pages during the OAuth flow
We do not use Google Analytics, Facebook Pixel, or any third-party advertising or tracking pixels. Our own usage analytics (session length, feature usage) is stored first-party in our database, not via cookies or beacons, and does not include your IP address.
13.3 Your Control
- You can clear local storage at any time through your browser settings (this will sign you out)
- Disabling local storage in your browser will prevent you from staying signed in
- We respect "Do Not Track" browser signals where technically feasible
14. Changes to Privacy Policy
14.1 Policy Updates
- We will notify users of material changes via email and in-app notification
- Students have 30 days to review changes before they take effect
- Continued use after notification constitutes acceptance of changes
- Previous versions of this policy are available upon request
15. Contact Information
16. Regulatory Information
16.1 State Privacy Rights
Residents of certain states may have additional privacy rights under state law. California residents should refer to Section 11 (California Privacy Rights). Contact us for information about your specific rights in other states.
This privacy policy is written in plain English to ensure students can easily understand their rights and our practices. If you have questions about any section, please contact our Privacy Officer.
Document ID: PP-2026-001
Version: 1.3