Legal

Last updated 9 August 2026

Privacy

The short version: you never give us a QU password, your GPA, degree-audit and schedule work stays in your own browser unless you sign in, and a signed-in account can be deleted in full from your account page at any time. Chat messages are the one thing a guest does that is stored on our server, and the section below says exactly what that means.


What we never collect

  • Your Banner or QU network credentials. There is no field to enter them and no feature that needs them.
  • Your name, student ID or date of birth. Nothing in the database has a column for them. If you upload a transcript the file does go to Anthropic in full, so their extraction step sees whatever the page shows, but it is instructed to record only course rows and there is nowhere for the rest to land.
  • Payment details. There is nothing to pay for.
  • Third-party advertising or analytics trackers. There are none on this site.

If you use it as a guest

You can use the assistant and all three tools without an account. In that case:

  • Your GPA, degree-audit and schedule work stays in your own browser’s local storage. It is never sent to us, and clearing your browser data removes it.
  • The schedule solver runs on your device, so your preferences (days off, times, instructors) are never transmitted.
  • Chat messages are the exception: they are processed on our server to produce an answer, and stored against a random guest identifier held in a cookie so a conversation can continue. That identifier is not linked to you.

If you create an account

An account exists so your work follows you between devices. Signing in with your QU email stores that address, and from then on we store what you choose to save:

  • Chat conversations and messages, and any thumbs up/down you leave.
  • Your academic profile: major, catalog year, the courses you enter or import, their grades, credits and status.
  • Roadmap adjustments and saved schedules, including any tags or share links you create.
  • Seat alerts: the sections you ask us to watch, and the last seat count we saw for each.

Transcript uploads

Uploading your QU Web Transcript is optional. The whole file, exactly as you upload it, is sent to Anthropic’s Claude API to extract the course rows; that is the only way a document can be read. You then review what was extracted, and only then is it merged into your profile. The file is never written to disk or to the database, and nothing but the course data you approve is kept.

Voice input

The microphone button is optional, and it only appears in browsers that support speech recognition. When you use it, your browser does the listening — the audio is never sent to our servers, and we never record or store it. What we receive is the text you then choose to send, exactly as if you had typed it.

Your browser, however, may not do the recognition on your device. Chrome sends the audio to Google and Safari sends it to Apple, under their privacy policies rather than ours. We have no control over and no access to that. If you would rather not have that happen, type your question instead — nothing in the app requires the microphone.

Cookies

  • A session cookie, if you are signed in, to keep you signed in.
  • A guest cookie holding a random identifier, so a guest conversation can continue across page loads.
  • Nothing else. No advertising, analytics or cross-site tracking cookies.

Keeping the service running

Answering a question costs real money, so the server has to be able to tell repeat requests apart to stop one person flooding it. It counts recent requests against your network (IP) address — but it stores only a scrambled, one-way fingerprint of that address, never the address itself. The fingerprint is enough to recognise repeat requests and cannot be turned back into your address by us or by anyone who obtained the data.

  • These counters exist to enforce a per-minute limit. They are not used to build a profile, are not linked to your account, and are not shared.
  • They are deleted after a day.

How long things are kept

  • Guest chat messages: 30 days, or immediately if you use “Delete my guest data”.
  • Account data (your conversations, courses, grades, saved schedules): until you delete it, or until you delete your account.
  • Seat alerts: until you remove them, until they finish, or until the term’s add/drop period closes. Finished ones are deleted 30 days later.
  • Staying signed in: a session lasts 90 days from the last time you used the app, and 180 days at the very most. You can end every session immediately from your account page with “Sign out on all devices”.
  • Sign-in codes: 10 minutes, and once used they are gone.
  • Request counters: one day. Cached Banner and LibCal lookups: one week.
  • A daily job enforces all of this; it is not done by hand.

Who else processes your data

Running the service means a small number of providers necessarily see data in transit: Anthropic (to generate answers and read uploaded transcripts), Voyage AI (to search QU’s crawled material), Vercel (hosting), Neon (the database) and Resend (to send sign-in codes, and seat alerts if you ask for them). Qatar University’s own Banner and LibCal systems are queried for live seat counts and booking availability; those queries carry no information about you.

Deleting everything

Your account page has a delete option that requires you to type DELETE to confirm. It removes your account, sign-in methods, conversations, messages, feedback, academic profile, courses, roadmap adjustments, saved schedules and seat alerts. The deletion cascades in the database, so nothing is left behind. This has been verified against the real database, not assumed.

As a guest, clearing your browser’s site data removes everything held on your device: your GPA, degree-audit and schedule work, which never left it. Chat messages are the exception, because they are processed on our server. Use “Delete my guest data” on the chat page to erase those — it deletes every message stored against the guest identifier this app is using, and clears that identifier. Guest messages are also deleted automatically after 30 days, which is how long the guest cookie lasts.

One caveat if you added Qumpanion to your home screen: on iPhone an installed app gets its own separate storage, so it has a different guest identifier from your browser. Guest work you did in Safari is not visible to the installed app and vice versa, and “Delete my guest data” only clears the one you are currently using. Run it in both if you have used both.

Questions

This is a student project, not a company with a privacy office. If something here is unclear or you want data removed, email ud2317922@qu.edu.qa and it will be dealt with.