CalSherpa

Privacy Policy

Effective September 24, 2026

This policy explains what CalSherpa collects, why, who helps us process it, how it is protected, and how you can remove it. CalSherpa is operated by Carter Medved, an individual doing business as CalSherpa ("CalSherpa," "we," "us"). You can reach us by email; see Contact.

In short: CalSherpa reads your own Canvas coursework and your Google Calendar so it can put work blocks on your calendar. We use that data only to run CalSherpa for you. We don't sell it, we don't use it for advertising, and we don't use it to train AI models.

1. What we collect

1.1 Canvas content, read by the CalSherpa extension

The CalSherpa Chrome extension runs in your browser. It only has access to your school's Canvas site (currently uncch.instructure.com). It reads Canvas using the session you're already signed in with, the same way the Canvas website does. It never sees or stores your university password. We never ask you for a Canvas access token, and none is used anywhere in CalSherpa.

For each course you're enrolled in, the extension reads:

Removed before anything leaves your browser: names, email addresses, login and student (SIS) IDs, pronouns, profile pictures, and the names of people who posted announcements or discussions. The extension also removes the session links Canvas puts inside course content (tool-launch tokens and document-viewer links) and your private Canvas calendar-feed address. Our server rejects any upload that still contains one of these identifying fields.

What's left is sent to our server over an encrypted (HTTPS) connection, checked against a strict format, and saved to your CalSherpa account. Your uploads are stored in our database under your account and can only be read on behalf of your account (see Security).

Stored in your browser by the extension: sync progress and timing, your extension settings, and a random install ID. Once you sign in through the extension, it also stores its CalSherpa sign-in token and your account email address so it can show which account you're signed in as. This token is issued by CalSherpa, not by Google. The extension never holds a Google token.

Install event: when you install the extension, it sends us a single message with its random install ID, its version number, and the time you installed it. We use this to count how many people who start setup finish installing. The ID is randomly generated. It's not based on anything about you or your device, and it doesn't contain any Canvas data.

1.2 Your Google account identity

You sign in to CalSherpa with Google. On the same Google screen where you allow calendar access, you also let CalSherpa know who you are (the openid and email permissions). From that we store your email address and your Google account ID, a number Google uses to identify your account. Your account is tied to that ID. We check with Google that your email address is verified, but we don't store that check. We don't request your name, profile photo, contacts, or any other Google data for sign-in.

1.3 Google Calendar

1.4 Gmail: when you choose to connect (launching later)

Gmail connection isn't available yet. When it launches, it will be optional and off until you turn it on with a separate Google permission screen. If you connect Gmail, CalSherpa will read your email messages to find course-related tasks and deadlines, such as an instructor's email moving a due date. Each task it finds is shown to you as a suggestion, with the email it came from. Nothing from email is added to your schedule unless you accept it. Raw email content, and extracted items you don't accept, are deleted within 7 days after they're processed. Tasks you accept become part of your schedule and are kept like your other account data.

1.5 Microsoft 365 / Outlook mail: when you choose to connect (launching later)

Outlook connection isn't available yet. When it launches, it will work the same way as Gmail: optional, off until you connect your Microsoft account, read to find course-related tasks, and shown to you as suggestions you accept or dismiss, with the same 7-day deletion rule.

Before these connections launch, this policy will be updated to list the exact permissions requested and which messages are read. You will not be asked to connect either until then.

1.6 Cookies

This website (calsherpa.com) sets no cookies and runs no scripts or analytics. The CalSherpa app at api.calsherpa.com uses one sign-in cookie to keep you signed in. It lasts 30 days from your last visit, and you have to sign in again at least every 90 days. During Google sign-in it also sets a short-lived security cookie that expires after 10 minutes. Both are needed for sign-in to work. We don't use tracking or advertising cookies.

1.7 Payment information

Payments are handled by Stripe. Stripe collects and stores your payment details, including the card you provide when you start your free trial, under its own privacy policy. CalSherpa never sees or stores card numbers.

1.8 Technical and support information

Like any website, our hosting provider processes your IP address and basic request details (such as time and browser type) to deliver the service and protect it from abuse. Our hosting providers keep operational logs (such as request times and errors) for debugging and security. We keep them no longer than 30 days. If you email us, we keep the conversation so we can help you.

1.9 What we never collect

2. How each Google permission is used

Permission (scope)What CalSherpa uses it for
openidSigns you in: Google confirms which Google account is yours, and CalSherpa uses its ID for that account to find your CalSherpa account.
emailReads your verified email address so we can show which account you're signed in as and contact you about your account.
https://www.googleapis.com/auth/calendar.eventsReads events on your calendar to find free time, and creates, updates, and deletes only the work-block events CalSherpa made. Google doesn't offer a narrower permission for writing events, so CalSherpa's own code enforces that it never changes events it didn't create.

CalSherpa doesn't request broader calendar access (such as permission to create or delete whole calendars). Any future Google permission, like Gmail, will be listed here before we ask anyone for it.

3. How we use information

4. Processing and service providers

Finding tasks in your course content uses Anthropic's API (Anthropic makes the Claude AI models). CalSherpa sends the text of one course item at a time (for example, an assignment description or a course page), with the identifying fields listed in 1.1 already removed, and receives back a structured list of tasks and dates. That result is checked by our own software before it can affect your schedule.

These companies process data on our behalf, only to provide CalSherpa:

ProviderWhat they do for CalSherpa
CloudflareHosts this website and the CalSherpa app. All requests to CalSherpa pass through Cloudflare.
SupabaseDatabase that stores your account and CalSherpa data.
AnthropicAI model that finds tasks and deadlines in course content (and, once email connection launches, in the emails you connect).
GoogleGoogle sign-in and the Google Calendar API. Google is also where your calendar and the events CalSherpa creates are stored.
MicrosoftOnly if you connect Outlook, once that feature launches: Microsoft sign-in and access to your mail.
StripeProcesses payments and handles your payment details. CalSherpa never sees or stores card numbers.

We don't share your data with anyone else, except when required by law or to protect CalSherpa's users and systems.

5. Security

Your data is encrypted in transit, and our database provider encrypts it at rest. Only the founder has access to production data. If a breach affects your data, we will notify you by email without undue delay and as required by law.

No system is perfectly secure. If you find a security problem, please email privacy@calsherpa.com.

6. What we don't do

7. Google API Services: Limited Use

CalSherpa's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

This means information from Google is used only to provide and improve CalSherpa's features for you. It isn't transferred to others except as needed to provide those features, for security, or to comply with law. It isn't used for advertising. People don't read it unless you agree, it's needed for security or legal reasons, or it's combined and anonymized for internal operations. It isn't used to train general-purpose AI models.

Chrome Web Store. Data collected by the CalSherpa extension is handled under the Chrome Web Store User Data Policy, including its Limited Use requirements. It's used only for CalSherpa's scheduling features, and never sold, used for advertising, or used for credit or lending decisions.

8. Keeping and deleting your data

Disconnect Canvas

Uninstall the CalSherpa extension from Chrome (chrome://extensions). This immediately stops all Canvas reading and removes everything the extension stored in your browser, including its sign-in token. The extension's settings also have a "Clear local sync data" button that resets its sync progress without uninstalling. You can also end CalSherpa's access by emailing support@calsherpa.com or by revoking CalSherpa in your Google Account permissions (below).

Revoke Google access

Go to your Google Account's third-party connections page, choose CalSherpa, and remove its access. Google stops honoring CalSherpa's token right away, so CalSherpa can no longer read or change your calendar. Work blocks CalSherpa already added stay on your calendar until you delete them. The encrypted token and our records of the blocks we created stay, unused, while your account exists, and are removed when your account is deleted.

Revoke Microsoft access (once Outlook connection launches)

For a school or work account, go to My Apps. For a personal account, go to account.live.com/consent/Manage. Then remove CalSherpa.

Delete your account

Email privacy@calsherpa.com from the address on your account and ask us to delete it. Deleting your account removes your account record and everything linked to it: your saved Canvas uploads, courses, tasks, calendar-block records, your encrypted Google token, and your sign-in sessions. We delete your account data within 30 days of your request. Deleting your account doesn't remove events already on your calendar; they belong to you. Events CalSherpa creates include a link to the Canvas assignment they belong to, so they are easy to identify and delete. Deleted data may remain in backups for up to 30 days before it's overwritten.

How long we keep data

Other requests

You can email privacy@calsherpa.com to ask for a copy of your data or to correct it, and we'll answer within 30 days. We honor access, correction, and deletion requests from all users, wherever they live.

9. Age

CalSherpa is intended for college students. It isn't for anyone under 13, and we don't knowingly collect information from children under 13. If you believe a child under 13 has given us information, email privacy@calsherpa.com and we'll delete it.

10. Changes to this policy

If we change this policy, we'll post the new version here and update the effective date at the top. If a change significantly affects how we use your data, we'll let you know by email or in CalSherpa before it takes effect. If a change would use data we already have in a significantly different way, we'll ask for your permission first wherever the law or Google's policies require it.

11. Contact

Privacy questions or requests: privacy@calsherpa.com. Everything else: support@calsherpa.com.