Privacy Policy

Last updated 2026-08-22.

What we collect

  • Your name, email, and profile image from Google OAuth sign-in.
  • The scheduling preferences you save on your profile page.
  • Completed and in-progress courses parsed from your own degree audit, including grades, GPA, and unit counts, once you choose to sync a confirmed audit to your account.
  • Which pages you open, and a short list of named actions - see PostHog under Subprocessors for exactly what that does and does not include.

What we do not collect

No SDSU credentials, and no authenticated scraping of any kind. The raw uploaded PDF or pasted audit text is never sent to or stored on our server - only the structured, student-reviewed record is synced, and only when you choose to sync it.

FERPA

CourseGrid is not a school official and does not act on SDSU's behalf. FERPA does not govern a student's own decision to share their own academic record with a third-party tool of their choosing.

Subprocessors

  • Google - authentication.
  • Stripe - payment processing.
  • Vercel - application hosting.
  • Neon - database hosting.
  • PostHog - product analytics: which pages are opened, and a short list of named actions such as exporting a schedule or a search returning nothing. If you are signed in, these are linked to your account's internal ID - never your name or email. Your search terms and filters are not sent. Your IP address is not stored. Screen recording is switched off in our code, so nothing on your audit page is ever captured. If your browser sends "Do Not Track", we send nothing at all.
  • Anthropic - the AI recommendation layer, which only runs if you have paid for it. What reaches Anthropic: your catalog year, program name, the requirement categories you still need with their unit counts, a summary of the classes on offer, and four preferences (what time of day you want, which days you can be on campus, whether you want in-person or online classes, and when you want to graduate). For one of the two model calls only, a shortened and cleaned-up excerpt of your work-schedule and free-text notes is included. Your grades and your GPA are never sent to Anthropic. Anthropic deletes API inputs and outputs within 30 days of receiving or generating them, and does not use them to train its models without express permission. That is Anthropic's published commercial policy, which is separate from the terms that cover its consumer chat products.

Deletion

Deleting your account from /account is a soft delete: your session is ended immediately, and your record is recoverable for 7 days by signing back in with the same Google account. After 7 days, a purge job permanently deletes your profile, courses, saved plans, and AI run history. Your purchase record is kept in a de-identified form (a one-way hash of your email) for tax and support purposes only, with your account no longer linked to it.

Data may be stale, and we take no enrollment action

Class and section data is pulled from SDSU's public Class Search and may be outdated or incorrect. CourseGrid never performs an enrollment, waitlist, or any other authenticated action on your behalf.

A note on the free-text fields

Do not paste sensitive personal information into the notes fields on your profile page, including accommodation or medical details. Keep it to scheduling context.