Privacy
What we keep, and what we never see.
Written to be read rather than to be defensible. If something here is unclear, treat the stricter reading as the one we meant.
Your syllabus file
A PDF you upload is opened and read by code running in your own browser. The file itself is never transmitted to us, is never sent to any third party, and is never used to train anything. Closing the tab is enough to be rid of it.
Counting, not tracking
When a schedule is read, we record that one was: whether it came from a PDF, a scan, pasted text or Canvas, how many pages it had, how many dates came out, how long it took, and whether the person was signed in. That row has no account attached to it, no address, and nothing lifted out of the document — not the filename, not a single line of the text. The browser is told not to send your session with it, so it cannot be tied back to you on our end either. It exists so we can tell whether the parser is getting better or worse, which is not something we could otherwise know.
If you sign in and save
Saving a schedule stores the list of events — their titles, dates, times, kinds and notes — together with your account. It does not store the source PDF. Each saved schedule also gets a long random subscription token, which is what makes its calendar feed address unguessable.
Your account
An account is an email address, an optional display name and picture if you signed in with Google, your timezone, your reminder preferences, and the date and version of the terms you agreed to when you signed in. There is no password to leak, because we do not use passwords: sign-in is either Google or a one-time link sent to your email.
Canvas
A Canvas access token you paste is used to make the requests you asked for and is then discarded. It is not written to the database and it is not logged. It travels through our server only because your browser is not permitted to call Canvas directly.
Calendar subscriptions
A subscription address is public in the sense that anyone holding the exact URL can read that schedule's events. That is how calendar subscriptions work everywhere — the protocol has no way to sign in. The token is long and random, it appears nowhere but in your own account, and you can revoke it, which immediately breaks the old address.
We send you three things and no more: the one-time link that signs you in, the reminder digest you turned on, and — rarely — a service notice, which is what an account holder is owed in writing when the terms change or the service is going away. There is no fourth category, no newsletter, and nothing that carries an offer. Every reminder carries an unsubscribe link that works without signing in; a service notice is not a mailing list and the way to stop getting them is to delete your account, which the notice itself tells you how to do.
Reminders are best-effort. They can be late, they can be filtered by your mail provider, and they can quote a date the parser read wrong. They stop entirely if the service does.
When you report a problem
The feedback form sends one email to one person, and that email is the only place your report is kept — it is not stored in the database and it is not on any dashboard. What travels with it is listed in the form itself, under "Exactly what gets sent with this", before you press send: what you wrote, the name and address you chose to give or leave blank, the page you were on, what your browser is, and — when you are reporting a failed import — the file's name and size and what the error was. Nothing from inside your syllabus is in that list.
The syllabus PDF itself goes only if you tick the box that says so, and that box is never ticked for you. It is one of exactly two places in SyllabusSpy where "the file never leaves your device" can be set aside — the other is the next section, and both of them are a checkbox you tick yourself. It exists because a PDF our parser cannot read is unfixable from a description of it, and it is yours to refuse — a report without the file still arrives and is still worth sending.
We do record that a report was filed: the day, what it was about, whether a file came with it, and whether there was an address to reply to. That row exists to stop the form being used to send a thousand emails, and it holds a one-way hash of your network address rather than the address, which is enough to count and not enough to identify.
When you send us a syllabus
The review step offers to take the document itself, and it offers hardest when the parser has visibly struggled with it. That offer is the other exception to "the file never leaves your device", and it is a bigger one than a bug report: a contributed syllabus is kept, tested against, and may end up in the sample documents that ship alongside the code.
Nothing is removed from it first, and we will not pretend otherwise. The PDF goes exactly as you uploaded it — a PDF is a layout, and a mark drawn over a name leaves the name in the file underneath — and the text goes exactly as our parser read it. A pattern that hid email addresses and phone numbers would still miss a name written on a line of its own, and calling that "anonymised" would be worth less to you than this sentence is.
So the whole of it is shown to you first: before the checkbox, the dialog prints the text exactly as it will arrive, all of it, scrollable. Read it, and do not send a document that carries personal or sensitive information — yours or anybody else's — that you would not want us to have. What you do send is kept and used to improve the parser. The checkbox is never ticked for you, there is no setting that makes it stick, and nothing else in the app changes if you close the dialog.
What the database records is a tally and nothing more: the day, how the document was read, how many pages and events came out of it, how many the parser was unsure of, how big the file was, and whether there is an address to thank. Not the text, not the filename, and nothing out of the document — those live in the same single inbox a bug report goes to.
What we do not do
No advertising. No third-party analytics, no tracking pixels, no cookies that follow you anywhere. No selling or sharing of anything with anyone. No profile built from your coursework — the counts above are totals, and there is nothing in them to build one from.
Deleting things
Deleting a schedule removes its events and its subscription token. Deleting your account removes the account, every schedule under it, and every reminder record. Both take effect immediately, and neither leaves a copy behind.