Skip to privacy policy
SemCalBack to homepage

Privacy Policy

Effective date:
September 7, 2026
Last updated:
September 7, 2026

On this page

  1. 1. ABOUT THIS PRIVACY POLICY
  2. 2. PRIVACY AT A GLANCE
  3. 3. INFORMATION WE COLLECT
  4. 4. HOW WE USE PERSONAL INFORMATION
  5. 5. COURSE-OUTLINE EXTRACTION AND OPENAI
  6. 6. GOOGLE FEATURES
  7. 7. PAYMENTS AND SUBSCRIPTIONS
  8. 8. BROWSER STORAGE, COOKIES, AND ANALYTICS
  9. 9. WHEN WE DISCLOSE INFORMATION
  10. 10. INTERNATIONAL PROCESSING
  11. 11. HOW LONG WE KEEP INFORMATION
  12. 12. YOUR PRIVACY RIGHTS AND CHOICES
  13. 13. SECURITY
  14. 14. AGE REQUIREMENT
  15. 15. THIRD-PARTY SERVICES AND LINKS
  16. 16. CHANGES TO THIS PRIVACY POLICY
  17. 17. CONTACT US

1. ABOUT THIS PRIVACY POLICY

SemCal (“SemCal,” “we,” “us,” or “our”) is an Ontario, Canada sole proprietorship that operates the SemCal website and web application.

SemCal helps students convert course outlines and syllabi into editable calendar events and, when they choose, copy those events to a new Google Calendar.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you:

  • visit semcal.app;
  • create or use a SemCal account;
  • upload or process a course outline;
  • use Google Sign-In;
  • export events to Google Calendar;
  • purchase or manage a paid subscription;
  • contact support; or
  • submit a privacy request.

In this Privacy Policy, the website, application, and related services are collectively called the “Service.”

This Privacy Policy does not control how independent third parties, such as Google or Stripe, handle information in their own services. Their own privacy policies apply when you interact with them.

2. PRIVACY AT A GLANCE

SemCal’s current practices include the following:

  • Course outlines are processed to identify possible calendar events. The current converter does not save uploaded course outlines as a permanent document library in your account.
  • Course-outline content is sent to OpenAI for automated extraction. SemCal sets store=false on these extraction requests and has disabled optional provider data-sharing settings. This does not mean that OpenAI provides Zero Data Retention, and limited provider retention may still occur for security, abuse monitoring, or legal reasons.
  • The editable review draft is primarily stored in your browser. The draft expires after 24 hours and may be cleared sooner by signing out, uploading another outline, clearing browser data, or using the relevant in-app controls.
  • Google Sign-In is separate from Google Calendar authorization. Signing in with Google does not give SemCal permission to access your Google Calendar.
  • Google Calendar access is requested only when you choose to copy reviewed events. SemCal requests a limited permission intended to create and manage a secondary calendar created through SemCal, rather than broad access to all of your existing calendars.
  • SemCal does not maintain continuous Google Calendar synchronization and does not store a long-lived Google Calendar refresh token for this export feature.
  • SemCal does not sell or rent personal information. We do not share personal information for targeted or cross-context behavioural advertising.
  • SemCal does not currently use advertising trackers or optional product-analytics services. Essential browser storage and infrastructure logs are still used to operate and secure the Service.
  • You may request access, correction, account closure, or deletion by emailing privacy@semcal.app.

3. INFORMATION WE COLLECT

The personal information we collect depends on how you use the Service.

3.1 Account and profile information

When you create or use an account, we may collect:

  • your email address;
  • your display name, if provided;
  • your account or profile identifier;
  • your selected time zone;
  • your authentication method;
  • account creation, sign-in, and security timestamps;
  • account status and subscription status; and
  • information needed to maintain and secure your authenticated session.

If you create an account using email and password, authentication is handled through our authentication provider. SemCal does not store your plaintext password.

If you use Google Sign-In, Google may provide information such as your Google account identifier, name, email address, and profile image, depending on your Google account settings and the information Google makes available through its standard identity scopes.

3.2 Course outlines and extracted calendar information

When you use the converter, we may process:

  • the PDF, PNG, or JPEG file you upload;
  • visible text and images contained in the file;
  • the original filename, file size, and media type;
  • course names, course codes, sections, dates, deadlines, schedules, and other information contained in the outline;
  • proposed event titles, descriptions, event types, dates, times, recurrence information, and time zones;
  • corrections, additions, or deletions you make to the proposed events;
  • your chosen calendar name; and
  • technical validation results and extraction errors.

A course outline may contain personal information about instructors, teaching assistants, classmates, or other individuals. Please avoid uploading unnecessary personal information, student numbers, financial information, health information, government identifiers, or other sensitive information that SemCal does not need to create calendar events.

You should upload only documents that you are permitted to use and process.

3.3 Browser-held review information

To allow you to refresh the page or recover an unfinished review, SemCal may store a temporary draft in your browser. It may include:

  • your SemCal profile identifier;
  • source filename, size, and media type;
  • proposed or edited event information;
  • calendar name and time zone;
  • temporary export identifiers; and
  • draft creation and expiration timestamps.

The browser draft does not contain the original uploaded file bytes.

This browser-held information remains on the device and browser profile you used. SemCal cannot remotely erase copies that you downloaded, copied, or stored outside the Service.

3.4 Google Sign-In information

When you choose “Continue with Google,” SemCal uses Google and our authentication provider to authenticate you.

Google Sign-In is used only to create, link, or authenticate your SemCal account. SemCal does not request Google Calendar permission as part of Google Sign-In.

The Google account used to sign in to SemCal does not have to be the same Google account you later choose for a Calendar export.

3.5 Google Calendar export information

When you choose to copy events to Google Calendar, we may process:

  • the calendar name and time zone you selected;
  • the final reviewed event snapshot;
  • an authorization request and related security state;
  • a short-lived Google access token used to perform the export;
  • the identifier and name of the secondary Google Calendar created through SemCal;
  • identifiers for events copied to that calendar;
  • export status, counts, timestamps, retry information, and outcome information; and
  • cryptographic fingerprints used for integrity, security, duplicate prevention, and recovery.

SemCal does not store a long-lived Google Calendar refresh token for this export feature.

SemCal does not use this feature to continuously monitor your calendar, synchronize changes, read your primary calendar, or browse unrelated existing calendars.

3.6 Billing and subscription information

Paid subscriptions are processed by Stripe.

Stripe may collect payment-card information, bank or payment-method details, billing contact information, billing address, tax information, and transaction information directly from you. Stripe handles that information under its own privacy policy and terms.

SemCal may receive and store limited billing information, including:

  • a Stripe customer identifier;
  • a Stripe subscription identifier;
  • subscription status and creation timestamps;
  • the SemCal plan associated with your account;
  • billing-event identifiers used to prevent duplicate processing; and
  • information needed to provide account, billing, cancellation, dispute, or support assistance.

SemCal does not store your complete payment-card number or card security code.

3.7 Usage, security, and technical information

When you access the Service, SemCal and its infrastructure providers may automatically process:

  • IP address;
  • browser and device information;
  • operating system;
  • request date and time;
  • pages, routes, or service functions requested;
  • authentication and session status;
  • response status and timing;
  • error and diagnostic information;
  • rate-limit and usage-allowance information; and
  • security, abuse-prevention, and fraud-prevention signals.

SemCal also maintains usage records needed to apply free or paid usage limits, prevent duplicate processing, settle operations, and investigate service failures.

Routine retention-worker logs contain operational counts and fixed error or skip categories. They are designed not to include course titles, calendar names, event content, OAuth values, access tokens, or other user content.

3.8 Communications and privacy-request information

If you contact us, we may collect:

  • your name and email address;
  • the contents of your message;
  • attachments you provide;
  • support history;
  • information used to verify your identity;
  • the nature and outcome of a privacy request;
  • delivery and response records; and
  • limited records needed to document account closure, deletion, a complaint, a dispute, or a legal requirement.

Please do not send passwords, access tokens, payment-card details, or other unnecessary secrets by email.

4. HOW WE USE PERSONAL INFORMATION

We use personal information to:

  • create, authenticate, secure, and administer accounts;
  • process course outlines and generate proposed calendar events;
  • allow you to review and edit extracted information;
  • generate downloadable calendar files;
  • create a new Google Calendar and copy events when you authorize us to do so;
  • provide usage allowances, paid features, and subscription management;
  • process and reconcile billing events;
  • respond to support questions and privacy requests;
  • troubleshoot errors and maintain reliability;
  • prevent fraud, abuse, unauthorized access, and security incidents;
  • enforce our Terms of Service and technical limits;
  • comply with legal obligations and lawful requests;
  • establish, exercise, or defend legal claims; and
  • improve the safety and operation of the Service using appropriately limited operational information.

SemCal does not:

  • sell or rent personal information;
  • share personal information for targeted or cross-context behavioural advertising;
  • use Google user data for advertising;
  • use course-outline content to build or sell a SemCal training dataset; or
  • intentionally submit user content for optional model-training or model-improvement programs.

5. COURSE-OUTLINE EXTRACTION AND OPENAI

SemCal uses OpenAI’s API to help extract dates, deadlines, course information, and possible events from uploaded course outlines.

Depending on the file, SemCal may send relevant text, images, or rendered document pages to OpenAI. OpenAI returns structured information that SemCal converts into a reviewable event draft.

Automated extraction may be incomplete or incorrect. You are expected to review and correct the resulting events before downloading or exporting them.

For extraction requests:

  • SemCal explicitly sends store=false;
  • SemCal has disabled optional OpenAI data-sharing settings for model improvement;
  • SemCal does not intentionally contribute your input or output to model-training programs; and
  • SemCal does not claim that these controls provide Zero Data Retention.

OpenAI states that API data is not used to train or improve its models by default unless the API customer opts in. OpenAI may still retain limited API content or related information in abuse-monitoring logs for up to 30 days by default, or longer where legally required, subject to OpenAI’s current policies and account-specific controls.

OpenAI’s practices and retention rules are controlled by OpenAI and may change. SemCal will update this Privacy Policy if a material change affects how we use OpenAI or disclose course-outline content.

6. GOOGLE FEATURES

6.1 Google Sign-In

Google Sign-In is an optional authentication method.

SemCal requests only the standard identity information needed to authenticate your account. We do not request Calendar access, offline Calendar access, or a Calendar refresh token when you sign in to SemCal.

You may instead use an available non-Google authentication method.

6.2 Google Calendar authorization

Google Calendar authorization is requested separately and only after you choose to copy your reviewed events.

SemCal requests the Google Calendar permission identified as:

https://www.googleapis.com/auth/calendar.app.created

This permission allows SemCal to create secondary Google calendars and see, create, change, and delete events on calendars created through the application. It does not provide the broad permission used to access every calendar in your Google account.

SemCal uses this permission only to:

  • create the new secondary calendar you requested;
  • copy your final reviewed events to that calendar;
  • determine the result of that export;
  • recover or safely settle an interrupted export; and
  • report the result to you.

SemCal does not use Google Calendar data for advertising, credit decisions, surveillance, or unrelated analytics.

6.3 Google API Limited Use disclosure

SemCal’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Human access to Google user data is restricted. It may occur only when you specifically ask for support and authorize the access, when reasonably necessary to investigate security or abuse, when required by law, or in another circumstance permitted by Google’s Limited Use requirements.

6.4 Information already copied to Google

Once SemCal successfully creates a calendar or event in your Google account, that copy is held by Google under your Google account.

Deleting SemCal’s temporary export record or closing your SemCal account does not delete the calendar or events already created in Google Calendar.

You can view, edit, or delete those calendars and events using Google Calendar.

7. PAYMENTS AND SUBSCRIPTIONS

Stripe processes subscription checkout, recurring payments, billing management, and payment-related records.

SemCal uses Stripe-provided identifiers and subscription status to determine whether an account has access to paid features.

Canceling a subscription through the Stripe customer portal ordinarily stops renewal at the end of the current billing period. Subscription cancellation does not automatically delete your SemCal account or all information associated with it.

Account closure or deletion also does not automatically create a refund. Refunds and billing rights are governed by the Terms of Service and applicable law.

Stripe may retain invoices, payments, disputes, tax records, and other payment information for its own legal, accounting, fraud-prevention, and operational obligations.

8. BROWSER STORAGE, COOKIES, AND ANALYTICS

SemCal uses essential browser storage and similar technologies to:

  • maintain authentication sessions;
  • complete secure sign-in and authorization flows;
  • protect against request forgery and account misuse;
  • save an unfinished event-review draft;
  • bind a browser session to an export; and
  • remember limited service state.

A valid review draft is ordinarily configured to expire 24 hours after the successful extraction that created it. Editing the draft does not extend that original expiration time.

Signing out is designed to clear the SemCal review-draft key from that browser. You may also clear browser storage using your browser settings. Clearing essential storage may sign you out, remove an unfinished draft, or prevent parts of the Service from functioning correctly.

SemCal does not currently use optional product analytics, advertising pixels, or third-party behavioural advertising trackers.

Our hosting, authentication, payment, and security providers may still use cookies or similar technologies that are necessary to deliver their services, prevent fraud, maintain sessions, or protect their systems.

9. WHEN WE DISCLOSE INFORMATION

We disclose personal information only for the purposes described in this Privacy Policy or as otherwise permitted or required by law.

9.1 Service providers

We use service providers to operate the Service, including:

  • Supabase for authentication and database services;
  • Vercel for frontend hosting and delivery;
  • Render for backend hosting and the retention worker;
  • OpenAI for course-outline extraction;
  • Google for Google Sign-In, Google Calendar authorization, and Google Workspace communications and restricted privacy-case storage;
  • Stripe for subscription checkout, payments, and billing management; and
  • domain, security, email, and infrastructure providers needed to operate semcal.app.

These providers process information according to their own service terms, privacy policies, security controls, and legal obligations.

We provide service providers only the information reasonably necessary for the function they perform.

9.2 Legal, safety, and security disclosures

We may disclose information when we reasonably believe it is necessary to:

  • comply with applicable law, a court order, subpoena, or lawful government request;
  • protect the rights, safety, property, or security of SemCal, our users, or others;
  • investigate fraud, abuse, unauthorized access, or a security incident;
  • enforce our agreements; or
  • establish, exercise, or defend a legal claim.

Where legally permitted and appropriate, we will seek to limit the scope of the information disclosed.

9.3 Business transfers

If SemCal is involved in a financing, sale, merger, acquisition, reorganization, or transfer of business assets, information may be disclosed as part of evaluating or completing that transaction.

Any recipient would be required to handle personal information consistently with applicable law and the commitments made in this Privacy Policy, unless users are properly notified of a lawful change.

To the extent information includes data obtained through Google APIs, SemCal will transfer that data as part of a merger, acquisition, or sale of assets only after obtaining the user’s explicit prior consent, as required by the Google API Services User Data Policy. SemCal will not disclose Google API user data merely for financing, transaction evaluation, or reorganization unless the disclosure is otherwise permitted by that policy.

9.4 No sale or targeted-advertising sharing

SemCal does not sell personal information.

SemCal does not disclose personal information to data brokers, advertising networks, or other parties for targeted or cross-context behavioural advertising.

10. INTERNATIONAL PROCESSING

SemCal is operated from Ontario, Canada.

SemCal’s core production database and backend infrastructure are hosted in Virginia, United States. Other providers may process information in Canada, the United States, or other countries where they or their service providers operate.

As a result, personal information may be transferred to and processed outside your province, state, or country. Information processed in another jurisdiction may be accessible to courts, law-enforcement agencies, or regulators under the laws of that jurisdiction.

SemCal remains responsible for personal information under its control and uses service providers and safeguards appropriate to the nature of the information and the services being provided.

11. HOW LONG WE KEEP INFORMATION

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to security, billing, dispute, backup, legal, and operational requirements.

Retention depends on the category of information.

11.1 Raw uploaded course outlines

The current launch converter does not create a permanent account library containing uploaded course outlines.

Uploaded files and rendered pages may exist temporarily in application memory, temporary processing locations, network transmission, and provider systems while extraction is performed. SemCal removes its temporary processing material after the operation, subject to technical completion, error handling, infrastructure behaviour, and any separate provider retention described in this Privacy Policy.

11.2 Browser review drafts

A browser-held review draft ordinarily expires 24 hours after the successful extraction that created it.

It may be removed sooner when you:

  • sign out;
  • upload another outline;
  • choose to start over;
  • complete or clear the relevant workflow; or
  • clear your browser storage.

SemCal cannot remove copies stored outside the Service, such as files you downloaded or information you copied into another application.

11.3 Temporary Google export records

When you begin a Google Calendar export, SemCal temporarily stores the final reviewed event snapshot and related export information so that the export can survive the authorization redirect and recover safely from an interrupted request.

The configured retention periods are:

  • newly created active export: 24 hours after creation;
  • completed export: 7 days after completion;
  • failed export: 7 days after failure;
  • export with an uncertain calendar-creation outcome: 7 days after that outcome is recorded; and
  • abandoned export: 24 hours after abandonment.

A background retention worker routinely deletes eligible expired export records and their dependent temporary items.

Deletion may occur after, rather than at the exact instant of, the stated expiration because processing is performed in bounded batches and may be delayed by a service outage, a valid execution lease, an operation already in progress, a database lock, state recovery, or another safety condition.

These retention rules affect SemCal’s temporary records only. They do not delete calendars or events already created in your Google account.

11.4 Account and profile information

We retain account and profile information while your account remains active and as needed to provide the Service.

After a verified account-deletion request, SemCal may need to:

  • preserve information required to respond to an access request;
  • stop or verify billing;
  • resolve an active operation;
  • delete or revoke the authentication identity;
  • allow already-issued session tokens to expire;
  • remove temporary storage objects;
  • resolve an applicable legal or dispute-related hold; and
  • delete the associated application records.

These steps may not happen simultaneously.

Canceling a paid subscription is not the same as requesting account deletion.

11.5 Usage and billing records

Usage, subscription, and billing records may be retained while needed to:

  • apply service limits;
  • provide paid access;
  • prevent duplicate charges or duplicate processing;
  • reconcile payments;
  • handle refunds, disputes, support, fraud, or abuse;
  • meet accounting or legal obligations; and
  • document the resolution of a request.

We do not treat every technical usage record as a permanent financial record. When a record is no longer needed for an identified purpose, we will delete it or reduce it where reasonably possible.

11.6 Support, privacy-request, and security records

Support communications, privacy-request records, complaint records, and security evidence are retained only as long as reasonably necessary for the relevant request, follow-up, complaint, dispute, security purpose, backup-deletion process, or legal obligation.

Privacy-request files are kept in restricted storage. Access packages and delivery copies are shared through restricted methods and removed when no longer required.

11.7 Operational logs

Operational logs are kept for a limited period consistent with reliability, security, fraud prevention, incident investigation, and legal requirements.

Retention may vary by infrastructure provider and log type.

11.8 Backups

Information deleted from active systems may remain temporarily in encrypted or access-restricted backups until those backups expire or are overwritten under the applicable backup schedule.

SemCal may not be able to selectively delete one individual record from an existing backup immediately.

If a backup is restored, SemCal will take reasonable steps to reapply completed deletion records before restored information is returned to ordinary active use.

11.9 Legal and preservation exceptions

We may retain limited information longer when reasonably necessary to comply with law, respond to a dispute or complaint, prevent fraud or abuse, protect safety, or establish, exercise, or defend legal claims.

Any such exception should be limited to the information and period required for the identified purpose.

12. YOUR PRIVACY RIGHTS AND CHOICES

Depending on where you live and the law that applies, you may have the right to:

  • request access to personal information we hold about you;
  • request a copy of that information;
  • request correction of inaccurate or incomplete information;
  • request deletion or account closure;
  • withdraw consent where processing is based on consent;
  • object to or restrict certain processing;
  • request portability of certain information;
  • receive information about our collection, use, and disclosure practices;
  • appeal or challenge a decision concerning your request; and
  • complain to an applicable privacy regulator.

These rights are not absolute. Applicable law may permit or require us to refuse, limit, or delay a request in certain circumstances.

12.1 Submitting a request

Submit privacy requests to:

privacy@semcal.app

Please describe what you are requesting and identify the SemCal account involved.

We may ask you to verify control of the account email address or provide other proportionate information needed to confirm your identity. Do not send passwords, authentication tokens, or full payment-card information.

An authorized representative may submit a request where permitted by law. We may require evidence of the representative’s authority and may still need to verify the account holder’s identity.

12.2 Access delivery

When we provide an access copy, we may use a restricted, viewer-only, time-limited delivery method.

We may exclude or redact:

  • information about another person;
  • security-sensitive information;
  • confidential commercial information;
  • information protected by privilege; or
  • information that applicable law permits or requires us to withhold.

Where required, we will explain the reason for a denial or limitation.

12.3 Account deletion

Account deletion is separate from subscription cancellation.

A verified deletion request may involve:

  • preserving a responsive access copy where requested;
  • stopping recurring billing or confirming billing status;
  • removing the authentication identity;
  • invalidating refresh access and allowing existing access tokens to expire;
  • deleting temporary objects and application records;
  • addressing provider-held information separately; and
  • retaining a minimal restricted record of the request where necessary.

Deleting your SemCal account will not automatically delete:

  • calendars or events already copied to Google Calendar;
  • files you downloaded;
  • information stored in your own browser outside SemCal’s active control;
  • payment or transaction records Stripe must retain; or
  • information subject to a valid legal, complaint, security, or dispute-related retention requirement.

12.4 Correcting your information

You can correct proposed calendar events in the review interface before export.

For account or server-held information that cannot be corrected through the Service, contact privacy@semcal.app.

12.5 Google choices

You may revoke SemCal’s Google access through your Google Account settings.

Revoking access may prevent future exports but does not necessarily delete calendars or events that were already created in Google Calendar.

You can delete those calendars or events directly in Google Calendar.

12.6 Complaints and appeals

Contact privacy@semcal.app first so we can investigate and respond.

If you disagree with our response, you may reply and ask us to reconsider the decision.

Canadian users may also have the right to complain to the Office of the Privacy Commissioner of Canada or an applicable provincial privacy regulator.

Users in the United States may contact an applicable state attorney general, consumer-protection agency, or privacy regulator where state law provides that option.

13. SECURITY

SemCal uses administrative, technical, and organizational safeguards designed to protect personal information.

These safeguards include, where appropriate:

  • encrypted network connections;
  • authenticated access;
  • tenant and row-level database isolation;
  • least-privilege database roles and separate operational credentials;
  • restricted privacy-request storage;
  • two-step verification for administrative accounts;
  • bounded and validated file processing;
  • short-lived authorization and execution state;
  • content-minimized operational logging;
  • routine deletion of expired temporary Google export information;
  • security testing and automated verification; and
  • controlled procedures for access and deletion requests.

No internet service or storage system can be guaranteed to be completely secure. You are responsible for keeping your account credentials secure and for promptly notifying us if you believe your account has been compromised.

If a privacy or security incident creates a legal notification obligation, we will notify affected individuals and regulators as required by applicable law.

14. AGE REQUIREMENT

SemCal is intended only for people who are at least 16 years old.

You may not create or use a SemCal account if you are under 16.

SemCal is not directed to children under 16, and we do not knowingly collect personal information from children under 16.

If you believe that someone under 16 has provided personal information to SemCal, contact privacy@semcal.app. If we confirm that the person is under 16, we will take appropriate steps to close the account and delete the information, subject to any legal requirement to retain limited records.

15. THIRD-PARTY SERVICES AND LINKS

The Service may link or redirect you to third-party services, including Google Calendar, Google Account, Stripe, or other websites.

SemCal is not responsible for the privacy, security, availability, or content practices of an independent third-party service.

Review the third party’s policies before providing information directly to it.

16. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy to reflect:

  • changes to the Service;
  • changes to our providers or data practices;
  • new legal requirements;
  • security improvements; or
  • other operational changes.

The updated policy will show a new “Last updated” date.

If a change materially affects how we use or disclose personal information, we will provide additional notice where appropriate or required, such as through the Service or by email.

If Google user data would be used for a materially new purpose, we will update our disclosures and obtain any consent required before using it for that new purpose.

17. CONTACT US

Privacy questions, complaints, and requests:

SemCal
Attn: Privacy Officer
2150 Winston Park Drive, Unit 203
#1642
Oakville, ON L6H 5V1
Canada
privacy@semcal.app

General customer support:

support@semcal.app

Back to SemCal homepage