My Student DeskAcademic Command Center
Home Privacy Terms

Legal & privacy

Privacy Policy

This policy explains what information My Student Desk handles, why it is used, how it is protected, and the choices available to you.

Effective: July 31, 2026 Last updated: August 20, 2026
On this page 1. Scope 2. Information we collect 3. How we use information 4. How information is shared 5. Google API data 6. Cookies and local storage 7. Security 8. Retention 9. Account closure 10. Your choices and rights 11. Children's privacy 12. International users 13. Changes 14. Contact
Plain-language summary: My Student Desk uses information to provide your academic workspace, does not sell personal information, and gives you a 30-day recovery period when you close your account.

1. Scope and who we are

This Privacy Policy applies to the My Student Desk website, web application, support services, and related features available through mystudentsdesk.com (collectively, the “Service”). “My Student Desk,” “we,” “us,” and “our” refer to the operator of the Service.

This policy does not apply to third-party websites or services that you choose to connect to or visit. Those third parties process information under their own terms and privacy policies.

2. Information we collect

Information you provide

  • Account information: name, username, email address, authentication identifiers, and profile preferences.
  • Academic information: classes, assignments, grades, GPA information, credits, notes, academic history, goals, schedules, events, and related records you choose to enter.
  • Content: documents, attachments, messages, and files you upload or create.
  • Support information: support tickets, correspondence, issue details, and feedback.
  • Account-management information: account status, closure reason, deactivation date, scheduled deletion date, reactivation date, and lifecycle audit events.

Information collected automatically

  • Device, browser, operating system, language, and general connection information.
  • IP address, approximate location derived from IP, request timestamps, diagnostic logs, error reports, and security events.
  • Usage information such as features opened, actions taken, and session activity needed to operate, secure, and improve the Service.

Connected services

When you voluntarily connect Google Calendar, we request the calendar.events.readonly permission. We receive Google account identifiers and authorization tokens, together with event identifiers, titles, descriptions, locations, start and end dates and times, recurrence information, and related Calendar event metadata available through that permission. The integration is read-only and cannot create, edit, or delete events in your Google Calendar.

3. How we use information

We use information to:

  • create, authenticate, maintain, and secure user accounts;
  • provide dashboards, classes, notes, grades, calendars, support, notifications, and other requested features;
  • save, synchronize, display, and restore user-created academic information;
  • send service-related notices, security alerts, and support communications;
  • detect abuse, investigate security incidents, prevent fraud, and enforce our Terms;
  • diagnose errors, measure reliability, maintain the Service, and improve usability;
  • process account closure, reactivation, retention, and deletion requests; and
  • comply with applicable legal obligations and valid legal requests.

We do not use your academic content to make official academic decisions on behalf of a school, college, university, employer, or government agency.

Google Calendar data is used only to connect the calendar selected by the user and to import, synchronize, organize, and display Calendar events within the user's academic workspace. We do not use Google Calendar data for advertising, credit or lending decisions, or any unrelated purpose.

4. How information is shared

We do not sell personal information. We may disclose information in the following limited circumstances:

  • Service providers: hosting, database, authentication, storage, email-delivery, monitoring, and infrastructure providers that process data for us. Current providers include Supabase (database, authentication, storage, and server functions), Vercel (application hosting and delivery), Resend (transactional email), Sentry (error monitoring), and OpenAI when a user requests transcript extraction that cannot be completed reliably on-device.
  • Connected services: when you direct us to exchange information with an integration such as Google Calendar.
  • Legal and safety reasons: when reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate abuse, or secure the Service.
  • Business changes: as part of a merger, financing, reorganization, acquisition, sale of assets, or similar transaction, subject to appropriate confidentiality and legal safeguards.
  • With your direction or consent: when you ask us to share information or clearly authorize the disclosure.

Staff access is limited according to assigned roles and permissions and should occur only when needed for support, security, maintenance, or administration.

5. Google API data and Limited Use

Google API Services User Data Policy. My Student Desk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Data accessed

The optional Google Calendar integration accesses only the read-only Calendar event information described in Section 2 and the account and authorization information required to establish and maintain the connection. My Student Desk does not request permission to create, change, or delete Google Calendar events.

Data use

We use Google Calendar data only to provide and improve the user-facing calendar functionality requested by the connected user, including importing, synchronizing, and displaying events in My Student Desk. We do not use Google user data for targeted or personalized advertising, to determine eligibility for credit or lending, to sell to data brokers, or for purposes unrelated to this functionality.

Data sharing and transfer

We do not sell Google user data. Google Calendar data may be processed by Supabase for authentication, server functions, and database storage, and by Vercel for application hosting and delivery, only as necessary to operate and secure the Service. We may also disclose information when required by applicable law, for security purposes, or when the user expressly directs us, subject to the Google API Services User Data Policy.

AI and machine-learning restrictions

My Student Desk does not use raw, derived, aggregated, or anonymized Google Calendar data to train, improve, or develop generalized artificial-intelligence or machine-learning models, and does not transfer Google Calendar data to third parties for those purposes.

Storage, retention, and deletion

Google OAuth access and refresh tokens are encrypted in a restricted server-side database table and are available only to the authenticated Supabase server function responsible for token exchange, refresh, Calendar requests, and revocation. Calendar events that a user imports are stored in the user's My Student Desk account so they remain available as academic records. Disconnecting Google Calendar revokes the authorization and removes locally stored connection tokens, but does not automatically delete events already imported into My Student Desk. Users may delete imported records through the Service, request their deletion, or delete them through the account-deletion process described below.

6. Cookies, session storage, and local storage

The Service uses essential browser storage technologies to maintain authentication, remember preferences, protect sessions, and support application functions. These technologies may include cookies, session storage, and local storage.

We do not currently describe advertising cookies or cross-site behavioral advertising as part of the Service. If analytics, advertising, or other non-essential tracking is introduced, this policy and any required consent controls should be updated before those technologies are enabled.

7. Security

We use administrative, technical, and organizational safeguards designed to protect information. These measures may include encrypted network connections, authentication controls, row-level security, role-based permissions, restricted service credentials, logging, and account-status enforcement. Google OAuth client secrets are restricted to server-side functions and are not included in public browser code.

No system can guarantee absolute security. You are responsible for using a strong password, protecting your sign-in credentials, signing out of shared devices, and promptly reporting suspected unauthorized access.

8. Data retention

We retain information for as long as reasonably necessary to provide the Service, maintain security, resolve disputes, enforce agreements, comply with law, and fulfill the purposes described in this policy.

Data category General retention approach
Active-account data Retained while the account remains active and as needed to provide the Service.
Closed-account data Preserved during the 30-day recovery period so the account may be restored.
Imported Google Calendar events Retained in the user's account until the user deletes them, requests deletion, or the account is permanently deleted. Disconnecting Google Calendar stops future access but does not automatically delete previously imported records.
Google authorization tokens Retained while the integration remains connected and removed from local browser storage when the user disconnects. Authorization is also sent to Google for revocation.
Support and security records Retained under the documented data-retention schedule for support, fraud prevention, legal compliance, and system security. Some records may be retained longer when required for an active dispute, investigation, or legal obligation.
Backups and logs May persist temporarily in protected backups or system logs until rotated or securely deleted under the documented backup and data-retention schedules.
Minimal deletion record A limited non-content record containing a one-way user identifier hash, deletion completion time, deletion type, and retention reason is retained to document that an account was deleted and support compliance or abuse prevention.

9. Account closure, recovery, and deletion

30-day recovery period. When you confirm account closure, your account is deactivated immediately and scheduled for deletion. Your data remains preserved during the recovery period so you can reactivate your account.

During the recovery period

  • You cannot normally use the active application while the account is deactivated.
  • You may sign in and choose to reactivate before the displayed deadline.
  • Successful reactivation restores the account to active status and cancels the pending deletion schedule.

After the recovery period

After the deadline, the account becomes eligible for permanent deletion. The deletion process is designed to remove or anonymize account information and user-created data from active systems, subject to legal obligations, security needs, technical limitations, and temporary backup retention.

A minimal deletion audit record may be retained without academic content, notes, files, grades, or other ordinary profile information. Permanent deletion cannot be undone once completed.

10. Your choices and privacy rights

Depending on where you live and which laws apply, you may have rights to request access, correction, deletion, or a copy of certain personal information, and to appeal or complain about how a request was handled.

  • You may update available profile information through the Service.
  • You may close and reactivate your account through Account Management during the recovery period.
  • You may disconnect Google Calendar from the Calendar screen. This revokes future access and removes connection tokens.
  • You may contact us to request access, correction, deletion, or information about our processing.

We may need to verify your identity before fulfilling a request. We may deny or limit a request where permitted or required by law, including to protect other users, preserve security, comply with legal obligations, or retain evidence of abuse.

11. Children's privacy

The Service is not directed to children under 13, and children under 13 may not create or use an account. We do not knowingly collect personal information from a child under 13. If you believe a child under 13 has provided personal information, contact us so we can investigate and delete or otherwise handle the information as required by law.

12. International users

The Service may be operated and hosted in the United States. If you access it from another country, your information may be transferred to, stored in, and processed in the United States or other locations where our service providers operate. Applicable privacy protections may differ from those in your home country.

13. Changes to this policy

We may update this Privacy Policy to reflect changes in the Service, technology, law, or our practices. The “Last updated” date will identify the newest version. When required, we will provide additional notice of material changes.

14. Contact us

Questions, privacy requests, and account-deletion concerns may be sent to:

My Student Desk
Email: support@mystudentsdesk.com
Website: www.mystudentsdesk.com

© 2026 My Student Desk. All rights reserved.
Privacy Policy Terms of Service Return to My Student Desk