Privacy Policy
Last updated: June 2026
Overview
Nodegent is a campus-aware AI assistant built by students at UC Santa Cruz. This policy explains what data we collect, how we use it, and how you can control or delete it. We collect only what is necessary to provide the service.
Data We Collect
- Google account:Name, email address, and profile picture, provided through Google Sign-In via Clerk. We do not store your Google password.
- Google Calendar:Calendar events from your connected Google account. Nodegent reads your existing events to display them alongside your Canvas assignments, and creates or updates events in your calendar when syncing Canvas assignment due dates. Only events created by Nodegent are modified; we do not alter events you created yourself.
- Canvas academic data:Courses, assignments, due dates, and grades, fetched via your Canvas session cookies. These cookies are stored server-side and never exposed to the browser. We do not access or store your CruzID password beyond the duration of the login session.
- AI chat messages:Messages you send to the Nodegent AI assistant. These are processed by a third-party LLM provider (Groq / Anthropic / OpenAI depending on configuration) and may be stored in our database to provide conversation history.
- Activity log:A record of actions taken on your behalf (calendar reads, Canvas fetches, AI tool calls) with timestamps, shown to you in the dashboard for full transparency.
How We Use Your Data
- Display your academic dashboard and upcoming deadlines
- Provide the AI assistant with context about your courses and schedule
- Sync assignment due dates with your Google Calendar
- Show you an audit log of everything the assistant has done on your behalf
We do not sell your data, share it with advertisers, or use it to train AI models.
Third-Party Services
- Clerk:Handles authentication and OAuth token management. See clerk.com/privacy.
- Convex:Stores your academic data, chat history, and activity log. See convex.dev/privacy.
- Groq / Anthropic / OpenAI:Processes AI chat messages. Messages sent to these providers are subject to their respective privacy policies.
- Vercel:Hosts the application. See vercel.com/legal/privacy-policy.
Data Retention
Your data is retained as long as your account is active. Canvas session cookies are stored only while your Canvas connection is active and are deleted when you disconnect Canvas in the dashboard. You may request full deletion of your account data at any time by contacting us.
Your Controls
- Revoke Google Calendar access — Dashboard → Settings → Connected Accounts → Disconnect Google Calendar
- Revoke Canvas access — Dashboard → Settings → Connected Accounts → Disconnect Canvas
- Delete all your data — Email us at lucas.rafe.abdulali@gmail.com and we will remove your account and all associated data within 30 days.
Security
All data is transmitted over HTTPS. Canvas session cookies and OAuth tokens are stored server-side and are never sent to the browser. Access to your data requires authentication via Clerk. We follow the principle of least privilege for all API scopes and tokens.
Changes to This Policy
We may update this policy as the product evolves. Significant changes will be communicated by updating the date at the top of this page. Continued use of Nodegent after changes constitutes acceptance of the updated policy.
Contact
Questions about this policy? Email lucas.rafe.abdulali@gmail.com.