Privacy
Privacy Policy
This policy explains how Schedulr handles information when you convert a class-schedule image into recurring Google Calendar events.
Effective and last updated: September 15, 2026
1. Scope of this policy
This policy applies to the Schedulr website, its Google Calendar connection, and the backend services used to process schedule images. In this policy, "Schedulr," "we," and "our" refer to the operator of the Schedulr service.
2. Information Schedulr processes
Information you provide
- The schedule image you choose to upload and the information visible in it, which may include course names, sections, meeting days, times, instructors, buildings, and room locations.
- Your selected timezone and optional calendar color theme.
Google authorization information
- A short-lived Google OAuth access token that permits Schedulr to view and edit events on calendars you own.
- Technical authorization information required to complete and secure the OAuth flow, including OAuth state, PKCE verification data, granted scopes, and token expiration time.
Schedulr does not request Google profile, email, contacts, Drive, or Gmail permissions. Schedulr does not need to read your existing Calendar events to extract your uploaded schedule.
Technical information
Vercel, Render, and other infrastructure providers may automatically process basic request information such as IP address, request time, browser or device information, requested route, response status, and security events. This information is used to deliver the service, diagnose failures, protect Schedulr, prevent abuse, and administer service limits.
3. How Schedulr uses information
Schedulr processes information only as needed to:
- read the schedule image you intentionally submit;
- extract and validate class details;
- create the recurring Google Calendar events you explicitly request;
- display submission success or error feedback;
- operate, secure, troubleshoot, and prevent abuse of the service;
- administer the one-use-per-four-month service allowance; and
- comply with applicable law and enforce the Terms of Service.
4. Schedule processing and service providers
Schedulr uses the following providers to perform the conversion you request:
- Google Cloud Vision processes the uploaded image to recognize visible text.
- OpenAI processes the image and recognized text to identify class names, meeting days, times, and locations.
- Google Calendar receives the validated event details and creates the requested recurring events.
- Vercel and Render host the application and process requests needed to provide it.
Schedulr does not send your Google OAuth token or the contents of your existing Calendar events to Google Cloud Vision or OpenAI. These providers process information under their own applicable terms, privacy policies, security controls, and configured retention settings.
5. Google API data and Limited Use
Schedulr uses information received from Google APIs only to provide the user-facing Calendar feature you choose. Schedulr's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Schedulr does not sell Google user data, use it for advertising, retargeting, credit decisions, surveillance, or unrelated analytics, or permit humans to read it except when required for security, support with your affirmative permission, or legal compliance.
6. Cookies and OAuth security
Schedulr uses strictly necessary cookies to secure the Google connection:
- OAuth state and PKCE cookies expire after approximately ten minutes and protect the authorization flow from interception and request forgery.
- The Google access token is encrypted in a Secure, HttpOnly cookie in production, is unavailable to page JavaScript, and expires in approximately one hour.
Schedulr does not request or retain a Google refresh token and does not use advertising or cross-site tracking cookies.
7. One-use-per-four-month allowance
Schedulr currently permits one successful schedule conversion per individual during each rolling four-month period. A successful conversion occurs when Schedulr creates at least one requested event in Google Calendar. A failed attempt that creates no events does not use the allowance.
Schedulr does not request Google identity scopes solely to administer this limit. Where usage controls are applied, Schedulr may use the minimum technical or pseudonymous signals reasonably necessary—such as a last-success timestamp, session or authorization signal, or network-based abuse indicator—to determine eligibility and prevent attempts to evade the limit. These signals are not used for advertising or general profiling.
8. Storage and retention
- Google access tokens: retained only in the encrypted browser session cookie until expiration, disconnection, or revocation.
- Schedule images and extracted class details: processed for the requested operation and not intentionally stored in a Schedulr application database.
- Usage and security information: retained only as long as reasonably necessary to operate the rolling four-month limit, protect the service, investigate abuse, comply with law, and maintain operational records.
- Provider logs: may be retained by hosting and processing providers according to their configured settings and policies.
Schedulr does not intentionally write OAuth tokens, schedule contents, classroom locations, or Google Calendar event links to application logs.
9. Sharing and disclosure
Schedulr does not sell or rent personal information. Information is disclosed only to the service providers described above as necessary to complete your request, to investigate security or abuse, to comply with applicable law, or as part of a business transfer where legally permitted and subject to appropriate notice.
10. Your choices and deletion
- Use Disconnect on the setup page to revoke the active Google token and delete the Schedulr session cookie.
- Remove Schedulr through your Google Account connections.
- Do not upload a schedule if you do not want it processed by the providers described in this policy.
See the data deletion instructions for additional details. Deleting information does not create a new usage allowance or permit circumvention of the four-month limit.
11. Security
Schedulr uses HTTPS in production, OAuth state validation, PKCE, encrypted short-lived sessions, authenticated server-to-server requests, restricted file types, upload limits, and dependency security checks. No internet service can guarantee absolute security, but Schedulr limits the data and authorization it retains.
12. Children
Schedulr is not directed to children under 13, and users under 13 must not use the service. If you believe a child has submitted personal information, contact Schedulr so the issue can be reviewed.
13. Changes to this policy
This policy may be updated when Schedulr, its providers, or applicable requirements change. The revised date will appear at the top of this page. Material changes to how Google user data is used will be disclosed before the new practice begins where required.
14. Contact
For a non-public privacy or deletion request, use the user-support contact displayed on Schedulr's Google OAuth consent screen. General questions may also be submitted through the Schedulr support tracker. Do not include OAuth tokens, schedule images, class locations, or other private information in a public issue.