Privacy Policy
Last updated August 22, 2026
ClassOS is a student-facing academic productivity tool. We take your privacy seriously, especially when it comes to your educational records. This policy explains exactly what we collect, how we use it, and your rights.
ClassOS is operated by Peyton Paske, an individual sole proprietor, doing business as ClassOS. That is the party responsible for the data described here, and "we" means him throughout this policy.
Jump to a section
FERPA notice
ClassOS is not a school official and does not act as an agent of your educational institution. We are a third-party tool that operates under your explicit authorization. By connecting your Canvas account, you are using your own student credentials to access your own educational records, no different from logging into Canvas yourself.
We do not share your educational records with your institution, with employers, or with anyone for advertising or data brokerage. The one way your records leave your account is a link you create yourself and send to someone, which is described under Links you can share below. We do not use your academic data for advertising, data brokerage, or any commercial purpose beyond providing ClassOS features to you.
If you believe your FERPA rights have been violated, you may file a complaint with the U.S. Department of Education: studentprivacy.ed.gov.
What we collect
- Account information
- Your email address and the password you choose, held by Supabase authentication. Used to identify your account and sign you in.
- Your name from Canvas
- The first time your Canvas data syncs, ClassOS reads the name on your Canvas profile and saves it as your display name if you do not already have one. This happens automatically, without asking you first. That name is what appears next to you on the ClassOS leaderboard and on a Parent Link if you create one.
- Canvas credentials
- Your Canvas personal access token. This token is encrypted with AES-256 before storage and is never logged, never shared, and never transmitted except to your school's Canvas server on your behalf.
- Academic data
- Course names and codes, assignment names and due dates, points possible, your scores, and your submission status, pulled from Canvas with your token. Alongside the tidy fields, ClassOS stores the complete record Canvas returns for each course, assignment, and announcement. For assignments that includes whether the work was submitted, when it was submitted, and whether Canvas flagged it late or missing. Announcement text is stored in full.
- Syllabus data
- ClassOS looks for a syllabus in your Canvas courses on its own and reads it with AI. It stores the raw syllabus text plus what it extracted: grading weights, the grading scale, late and attendance policies, exam and other important dates, weekly topics, required materials, and your professor's name, email address, and office hours. Your professor's contact details are stored because they appear on the syllabus.
- Transcript data
- If you import an unofficial transcript, ClassOS keeps the course names, codes, terms, final grades, and credit hours it read out of the document as past-course records on your account. The file itself is not stored. It is held in memory only long enough to read, then discarded. Reading it involves sending it to Anthropic, which is described under Third-party services below.
- Scout conversations
- The full text of your Scout conversations, both what you asked and what Scout answered, is saved to your account so you can reopen a thread later. These transcripts are kept for as long as your account exists. Nothing expires them on a timer.
- AI usage counts
- Separately from the transcripts above, we count how many AI generations and Scout messages you use each month so we can enforce your plan's limits. Those counters hold numbers and dates only.
- Study activity
- When you use the study timer, ClassOS records which course you studied and when you started and stopped. Flashcard reviews record how well you knew each card and when it is due again. Your streak record holds your streak length, XP, level, and the last time you opened ClassOS.
- Notification records
- If you turn on push notifications, ClassOS stores the notification address your browser issues for your device plus the two encryption keys needed to send to it. For email, ClassOS keeps a log of every message it sent you: the type, the subject line, and the time. Subject lines name assignments. They do not contain your scores.
- Billing information
- If you subscribe to a paid plan, Stripe collects and stores your payment details. ClassOS never sees or stores your card number. On your account we store two things: which plan tier you are on, and the customer id Stripe uses to identify you. Everything else about the subscription lives at Stripe.
- IP address
- On signup, waitlist joins, feedback, and a few other unauthenticated actions, ClassOS reads the IP address your request arrives from and uses it as a counter key so one source cannot flood the service. Those counters live at Upstash and age out on their own. We do not store your IP address alongside your account or your coursework.
- Timezone
- If you set a timezone in Settings, we store it so deadlines are shown in your local time. Until you set one, ClassOS falls back to US Central time.
- Referrals
- If you use a referral code, we record which account referred which account. That link is what makes the reward possible, and it means our records show a connection between you and the student who invited you.
- Waitlist emails
- If you join the waitlist without creating an account, we store the name and email address you entered and which form you used. We send one email to that address to confirm you're on the list. There is no .edu requirement on the waitlist.
- Feedback
- Feedback you submit carries no account id, so it is anonymous unless you choose to add an email address for a reply. Either way we store your message, a category, and the page you were on. Leave the email box blank and nothing connects the submission to you, which also means we cannot find it later to delete it. Fill it in and we store that address next to your message, for writing back and nothing else. One exception, and only one: beta testers get an extra opt-in box, spelled out under "Beta program" below.
- Beta program
- If you are in the ClassOS beta, the feedback panel shows a box, ticked by default, that attaches your account, your plan, your browser, your screen size, and which build of ClassOS you were on to what you send. That is what lets us reproduce the bug and write back. Untick it and the submission is as anonymous as anyone else's. We also record beta testers' product sessions, with anything you type masked, and we use those recordings to fix bugs and make ClassOS better. Both of these apply to beta testers only. If you are not a beta tester, nothing here describes your feedback.
- Usage data
- Which pages and features you use, and error reports when something breaks, so we can fix it. Most of these events carry no academic content, but not all: starting or finishing a study timer sends the name of the course you studied.
What ClassOS does in Canvas
Your Canvas token is a full-power credential, so it is worth being precise about what ClassOS does with it. ClassOS reads your courses, assignments, grades, announcements, syllabus pages, and course files.
ClassOS can also write one thing, and only one: a submission you start yourself. If you use ClassOS to turn in text, a link, or a file, it sends that submission to Canvas as you. Nothing else in ClassOS writes to Canvas. It does not post to discussions, send Canvas messages, change your profile, or act on your behalf while you are away.
How we use your data
- Display your grades, deadlines, and GPA on your dashboard
- Power Scout features (study plans, grade coaching, deadline alerts)
- Send you deadline reminder notifications (if enabled)
- Understand which features get used, so we know what to build and fix
To be straight about that last one: product analytics events are tied to your account id, not anonymised. And the admin view the founder uses to run ClassOS shows account emails, display names, plan tiers, and per-account AI usage counts. It does not show your grades or your coursework.
We will never:
- Sell your personal or academic data
- Share your data with advertisers
- Provide your data to your school or institution
- Use your academic records for any purpose beyond operating ClassOS for you
Data storage & security
Your data is stored on Supabase infrastructure. Every table is protected by database row-level security policies, which match rows to the account that owns them, so one student's session cannot read another student's courses, assignments, grades, Scout conversations, or study guides. Canvas tokens are encrypted before storage. All data is transmitted over HTTPS. We do not store Canvas passwords, only the personal access token you generate.
Your streak data is covered by the same guarantee. The table that holds your streak count, your XP, your level, and the last time you opened ClassOS is readable only by the account it belongs to. Nothing about your streak is publicly readable.
Payments and subscriptions
Paid plans are billed through Stripe. When you subscribe, Stripe processes your payment and sends us a confirmation that your account is on a paid plan. Stripe's own privacy policy governs the payment data they hold.
You can cancel any time from the Billing page in your dashboard, which opens Stripe's billing portal. Cancelling stops future charges, and your account returns to the free plan at the end of the period you have already paid for.
Third-party services
- Supabase
- Database and authentication hosting.
- Vercel
- Web application hosting.
- Anthropic
- Powers Scout and every other AI feature. Scout receives your current courses, your assignments and due dates for roughly a 60-day window around today with your scores and submission status on them, your assignment group weights, your credit hours, a term GPA we calculate before asking, and your syllabus details including your professor's name and email address, plus the conversation itself. Other features send what they need to do their job: the essay text you paste along with the course it is for and your current grade in it, the text of documents you upload or open from Canvas, announcement text, syllabus text, and whole course and assignment records for grade recovery and study plans. If you import a transcript, the entire file is sent to Anthropic to be read, including your name and student ID as they are printed on it. We do not attach your account email address or your Canvas token to any AI request. Anthropic's API terms govern what they may do with what is sent.
- Stripe
- Payment processing for paid plans. ClassOS never sees your card number.
- Resend
- Sends the email ClassOS sends you. Because grade alerts and the weekly digest are about your grades, the messages contain them: individual assignment scores, points possible, the before and after of a changed grade, and your GPA in the weekly digest. Resend handles that mail on our behalf and their privacy terms govern what they hold.
- Push notification services
- If you turn on push notifications, your browser issues a delivery address at its own vendor: Google for Chrome and Android, Apple for Safari, Mozilla for Firefox. ClassOS sends notifications through that vendor, so the vendor handles the message on its way to your device. Grade notifications name the course and carry the actual score, including what it changed from and to.
- Upstash
- Rate limiting. Holds short-lived counters keyed by account id or by IP address so the service cannot be flooded. No academic data.
- Telegram
- Sends the founder a daily operations summary. That message contains total AI message counts, and for the few heaviest accounts in a month, a shortened fragment of the account id next to a message count. No email addresses, no course data, and nothing you asked Scout.
- Sentry
- Error monitoring. Receives crash and error reports, which may include the page you were on and your account ID. Not your grades.
- PostHog
- The product analytics service ClassOS uses to see which screens and features get used. Events are tied to your account id. Session recording and automatic click capture are switched off, and email addresses and tokens are blocked from being sent. The one piece of course data that reaches analytics is the name of a course you start a study timer for.
Who actually sees academic data
Supabase stores all of it. Anthropic receives whatever an AI feature you use needs, as described above. Resend receives the grades that appear in the emails you asked for. Your browser's push service handles notifications that name courses and carry scores. Analytics receives a course name when you use the study timer. Anyone you hand a Parent Link or calendar feed to receives what that link shows.
Stripe receives billing data and no coursework. Upstash, Telegram, and Sentry receive no grades or coursework. We do not use data brokers or ad networks, and we do not sell anything to anyone.
Your rights
- Access and portability: Download your data as a file, yourself, from Settings. The export deliberately leaves out two credentials, your Canvas token and your push encryption keys, because handing those back in a downloaded file only creates a new way to lose them. The file itself lists what it left out
- Deletion: Delete your account and its data from Settings, or email us and we will do it
- Correction: Update or correct information in your account
- Cut off Canvas access: Delete or regenerate the token in Canvas itself, which is where the token lives and where you control it, or delete your ClassOS account, which deletes our copy. ClassOS has no disconnect button of its own, and updating your token in Settings replaces it rather than removing it
We will process all requests within 30 days. To exercise your rights, email privacy@classos.ai.
Data retention and deletion
We retain your data for as long as your account is active.
If you delete your account, the deletion runs immediately and completely. One removal from the authentication system cascades through every table that holds your data: your Canvas token, courses, assignments, announcements, syllabus records, Scout conversations, study guides and plans, flashcards, streaks, notification records, and your email log. Your address is also removed from our waitlist. If any part of that fails, ClassOS tells you it failed and that your data is still here, rather than reporting a success that did not happen.
Two honest limits. Feedback you sent without an email address, and without the beta program's box ticked, has no account id attached to it, so there is nothing connecting it to you and nothing for us to find and delete. Beta feedback sent with that box ticked does carry your account id, and deleting your account cuts that link, leaving the message behind with nothing pointing at you. If you did add an email address to a submission so we could reply, that address is the one thread back to you, and you can have it removed by writing to privacy@classos.ai. And when a background job fails, ClassOS writes a diagnostic line that includes your account id. Those lines sit in our hosting provider's logs rather than in the database, so deleting your account does not reach them. They contain no grades or coursework.
ClassOS does not keep separate backup archives of your data, so there is no second copy left behind for us to hold onto after a deletion.
Deleting your account also stops your billing. Any subscription that is still charging you is set to stop renewing first, and if that cannot be done ClassOS refuses to delete the account rather than leave you paying for something that no longer exists. The period you have already paid for is not cut short: it runs to its end at Stripe, and nothing renews after it.
That is not a refund. If you delete partway through a period you have already paid for, the remainder is not paid back to you automatically. If that is your situation, email us and we will sort it out.
One thing deletion does not reach: Stripe keeps its own customer record, payment history, and invoices, including the email address on them, under its retention rules and ours for tax and chargeback purposes. That is outside our database and outside our control, so a full ClassOS deletion still leaves your billing history at Stripe.
That surviving record is also how you come back. If you sign up again with the same email address while a plan behind it is still running, we email that address a link. Open it while signed in to the new account and we put you back on the plan you already paid for, so you do not pay twice for the same month. Until you confirm that way, the new account is an ordinary free one and nothing about the plan moves.
That confirmation step is there to protect you, not to slow you down. Creating an account with an email address does not prove the address is yours, so we do not treat it as proof: the link goes to the inbox, it expires, and it only works from the account it was sent for. If a link like that ever arrives and you did not sign up, do not open it. Email us instead and we will lock the plan down.
Contact
Questions about privacy or data? We respond to all requests.
Email: privacy@classos.ai