Privacy Policy

Effective: April 6, 2026 · Version 1.0

1. Information We Collect

Information you provide: Email address, date of birth, name, role (student/parent/counselor), grades, course selections, GPA goals, college targets, and test scores.

Automatically collected: IP address, browser type, device information, and usage analytics.

Payment information: Processed by Stripe. We do not store credit card numbers.

2. How We Use Your Information

We use your information to: provide the academic planning service, calculate GPA and track graduation requirements, send transactional emails (invites, notifications), process payments, and improve the service.

3. Information Sharing

We share data with the following third-party services, solely for service operation:

  • Stripe — Payment processing (email, name, payment method)
  • Resend — Transactional emails (email address)
  • Supabase — Authentication and database hosting (all user data)

We do not sell your personal information to any third party.

4. Children's Privacy (COPPA)

SAPS does not knowingly collect information from children under 13. Users must be at least 13 years old to create an account. Users aged 13-17 are minors; parents can monitor their academic data through the parent role within the same account.

5. FERPA Statement

SAPS is not a school official and does not receive education records from Stevenson High School or any educational institution. All academic information in SAPS is self-reported by users. SAPS is not subject to FERPA as it does not access school systems or official student records.

6. Your Rights

You have the right to:

  • Access — View all your data within the application
  • Correct — Edit your information at any time
  • Delete — Delete your account and all associated data from Settings
  • Export — Download a copy of your data before account deletion

California residents (CCPA/CPRA): You have additional rights including the right to know what personal information is collected, the right to opt out of sale (we do not sell data), and the right to non-discrimination for exercising these rights.

7. Data Security

We protect your data using encryption in transit (HTTPS), secure database hosting via Supabase, and role-based access controls. However, no method of transmission or storage is 100% secure.

8. Data Retention

We retain your data for as long as your account is active. Upon account deletion, all personal data is permanently removed. Anonymized consent records are retained for legal compliance purposes.

9. Cookies

SAPS uses essential session cookies for authentication. We do not use advertising or tracking cookies.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will notify you through the application and require you to review and accept the updated policy before continuing to use the service.

11. Contact

For privacy-related questions or to exercise your data rights, contact us at privacy@saps.app.

Terms of Service