Privacy Policy
Last updated: June 13, 2026
CoursePlanner.ai (“CoursePlanner”, “we”), a product of Athena AI, LLC, a Wyoming company, is built privacy-first. This policy explains what we collect, why, and the control you have. We do not sell your personal data.
1. Local-first by default
Your workspace — courses, deadlines, notes, aid items, and similar — is stored in your own browser (local storage) on the device you use. By default it never reaches our servers. You can export it as a file or delete it entirely at any time from the in-app data menu.
2. What we collect (only if you choose)
- Account (optional): if you create an account for cloud sync, we store your email address and a securely hashed password (PBKDF2; we never see your plain password), plus an encrypted copy of your workspace so it can sync across your devices.
- Waitlist (optional): if you join the waitlist we store your email and the role/school you provide, only to notify you about the product.
- Tutor profiles (optional): if you list yourself as a tutor, the details you enter (name, subjects, rate, contact, school, state) are shown to logged-in students.
- Parent access (optional): if you generate a share code, a parent can view only the scopes you explicitly grant; you can revoke it anytime.
3. What we never collect
We never ask for or store your Social Security number, your FSA ID password, or your bank/account numbers. We do not auto-submit the FAFSA. If you connect Canvas, your Canvas access token stays in your browser and is used only to fetch your data through our proxy — it is never stored on our servers.
4. Cookies
We use a single essential cookie (cp_sess) only after you sign in, to keep you logged in. It is HttpOnly, Secure, and SameSite=Lax. We do not use advertising or cross-site tracking cookies. Site analytics are provided by Cloudflare Web Analytics, which is cookieless.
5. Third parties
- Cloudflare — hosting, security, cookieless analytics, and the AI model that powers Athena.
- Stripe — payment processing, only if/when you subscribe to Premium. We never see your full card details.
- Canvas / Google — only if you choose to connect them, and only with the access you grant.
6. Google Calendar data
Connecting Google Calendar is entirely optional. If you choose to connect it, we ask only for the https://www.googleapis.com/auth/calendar.events scope so we can do one thing: keep the deadlines and events in your CoursePlanner workspace in sync with your Google Calendar (creating, reading, updating, and removing the calendar events that correspond to your plan). We do not read or modify calendar events that CoursePlanner did not create, and we request no other Google scopes.
We store only the OAuth tokens needed to maintain the connection and the minimal event identifiers needed to keep the two sides in sync. We do not use Google Calendar data for advertising, do not sell or share it, and do not use it to train AI models. You can disconnect at any time from the in-app data menu or by revoking access at your Google account permissions; disconnecting deletes the stored tokens.
CoursePlanner’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. AI (Athena)
When you use AI features, we send a compact, relevant summary of your request to the AI model to generate a response. We don’t use your content to train models. Athena is not a medical, mental-health, legal, or financial professional; its output is informational.
8. Your rights
You can export or delete your data at any time. To delete a cloud account or request data removal, email our contact form. Depending on where you live (e.g., GDPR/CCPA), you may have rights to access, correct, or delete your information; we honor these requests.
9. Children
CoursePlanner is intended for college students who are 18+ or enrolled in a postsecondary institution. We do not knowingly collect data from children under 13. A separate, consent-compliant flow is required for younger users.
10. Changes & contact
We’ll update this policy as the product evolves and revise the date above. Questions? our contact form.
This is a pre-launch policy provided for transparency and is not legal advice. See also our Terms of Service.