LEGAL
Privacy Policy
Effective 19 July 2026
Scht is an invite-only academic workspace. This policy explains what information the service handles, why it handles it, and the choices available to students who use it.
Information Scht handles
- Account information: the email address and basic profile information supplied through Supabase authentication.
- Workspace information: academic terms, subjects, tasks, grades, notes, projects, and syllabus files a student chooses to add.
- Connected-service information: read-only Google Calendar events, unread Gmail message subjects/snippets, and Canvas courses/assignments only after the student explicitly connects each service.
- AI information: planning prompts and reviewed proposals. A user’s AI provider key is encrypted in the browser with the user’s passphrase before it is stored.
- Delivery information: reminder preferences and Apps Script delivery records for optional email reminders.
How Scht uses information
Scht uses this information to authenticate invited users, show their planning workspace, import information they request from connected services, calculate academic progress, deliver requested reminders, prevent misuse, and operate the owner-admin tools. Scht does not sell personal information or use connected-service data for advertising.
When information is shared
Scht uses service providers to operate the app: Supabase for authentication and database/storage, Vercel for hosting, and Google/Canvas only when a student connects those services. An AI prompt is sent only to the provider selected by the student. The optional Apps Script companion receives only the prepared email job needed to send a reminder; it does not receive Google OAuth, Canvas, or Supabase credentials.
Google data
Google Calendar and Gmail access is read-only and requested only after a user chooses Connect Google. Calendar events and unread Gmail subjects/snippets are used only to create the user’s Scht timeline or follow-up tasks. A user can revoke Google access from their Google Account permissions and can ask the Scht owner administrator to remove their workspace data.
Retention and security
Workspace information is retained while the account remains active, subject to legitimate operational, security, and backup needs. Scht uses access controls, encrypted integration credentials, and browser-side encryption for saved AI keys. No online service can promise absolute security; users should keep their passphrases and connected-service credentials private.
Your choices and rights
Users can choose whether to connect Google, Canvas, or an AI provider, and can disable reminder email in Settings. To request access, correction, export, or deletion of account data, contact the Scht owner administrator who issued the invite. Students in the Philippines may also have rights under the Data Privacy Act of 2012, including rights to be informed, access, correct, object, erase/block, and complain to the National Privacy Commission.
Changes and contact
Material changes to this policy will be posted on this page with an updated effective date. For questions or data requests, contact the Scht owner administrator associated with your invitation before using the service.