Privacy Policy

Last Updated: October 1, 2026

Overview

Stanford Root ("We", "us", or "the Service") is a free course search and schedule planning website for Stanford University students, run at stanfordroot.com. It lets anyone browse Stanford's course catalog and build a weekly schedule, and lets signed-in Stanford students read published student course evaluations and sync their schedule across devices. Stanford Root is an independent project and is not operated by or affiliated with Stanford University.

This policy explains what data we collect, why we collect it, who it is shared with, how long we keep it, and how you can delete it.

Information We Collect

When you sign in with your Stanford Google account, we receive:

  • Email address — used to verify you are a Stanford student (@stanford.edu).
  • Name — Google sends it with your sign-in. It is not displayed anywhere in the app; it is passed to our analytics provider so your sessions can be linked to one person (see "Usage Analytics" below).
  • Profile photo — shown in the app interface.

We do not request access to your Google Drive, Gmail, Calendar, or any other Google services beyond basic profile information.

Feedback you send through the in-app feedback form is stored as the message text and its category and nothing else, even when you are signed in: your account, name, and email are deliberately not attached to it. Your IP address is used for a moment to rate-limit submissions and is not stored with the feedback.

How We Use Your Information

  • To authenticate your identity and restrict access to Stanford students.
  • To associate your course schedule and preferences with your account.
  • To gate published Stanford course evaluations to the Stanford community, as Stanford requires.
  • To reply to you if you email us.

We do not use your information for advertising, we do not build advertising profiles, and we do not use it to train machine learning or AI models.

Google User Data

Signing in is handled by Google OAuth through Supabase Auth. We request only the basic sign-in scopes — openid, email, and profile — which give us your email address, your name, and your profile photo URL. We never receive your Google password.

We use that data for exactly one thing: creating and identifying your Stanford Root account so your schedule follows you between devices and so evaluations can be shown to Stanford students. We do not request, read, or store data from Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google service.

Stanford Root's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not transfer it to third parties except to the service providers listed below that operate the Service on our behalf, and we do not use it for advertising.

Data Storage

Your data is stored securely using Supabase, a hosted database platform with row-level security policies, on servers in the United States. Traffic to the Service is encrypted in transit with HTTPS. Your schedule selections are also stored locally in your browser via localStorage.

Data Retention

We keep your account record and saved schedule for as long as your account exists, so that your schedule is there the next time you sign in. Usage analytics events are kept only for as long as they are useful for understanding and improving the Service, and are deleted when they no longer are. When you ask us to delete your account, we delete your account record, your saved schedules, and your analytics events, as described under "Your Rights and Deleting Your Data". Data you have stored only in your own browser is cleared when you clear your browser storage.

Data Sharing

We do not sell or rent your personal information, and we do not share it with advertisers. We share data only with the service providers that run the Service on our behalf:

  • Supabase — authentication and database hosting.
  • Vercel — website hosting and request logs.
  • Human Behavior — product analytics (see "Usage Analytics" below).
  • Resend — delivers the notification email we get when someone submits feedback.

If you connect an app to your account, such as the Stanford Root MCP server for Claude, it gets access only after you approve it on our consent screen. It can then see your email address, see and change your saved schedule, and read evaluations as you.

We may also disclose information if we are legally required to do so.

Cookies & Local Storage

We use browser localStorage to persist your course schedule across sessions. Authentication tokens are managed by Supabase and stored as secure cookies. We do not use advertising cookies or sell your data. We do use a third-party product analytics provider (Human Behavior) to understand usage, as described under "Usage Analytics" below.

Usage Analytics

To understand how the Service is used and improve it, we collect usage analytics through two channels. First, we store first-party events in our own database (Supabase) — high-level actions such as page views, searches, adding a course to a schedule, and signing in, along with a randomly generated device identifier kept in your browser's localStorage. Second, we use Human Behavior, a third-party product analytics provider, which records how users interact with the Service (such as clicks, navigation, and session activity) and sends this data to Human Behavior's servers on our behalf. When you are signed in, we also send Human Behavior your email address, the name on your Google account, and your Stanford Root account ID, so that sessions from the same person are recognised as one person rather than a series of strangers. We do not use advertising trackers, and we never sell this data. This information is used only to measure engagement and improve the Service.

Your Rights and Deleting Your Data

You can browse the catalog and build a schedule without an account at all, and you may sign out at any time to end your session. You may also ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete it.

To delete your account and everything associated with it, email adhanaesaw@gmail.com from your Stanford address with the subject "Delete my account". We delete your account record, saved schedules, and analytics events within 30 days and confirm by email when it is done. You can also revoke Stanford Root's access to your Google account at any time from your Google account permissions page.

Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date.

Contact

If you have questions about this Privacy Policy, please reach out to us at adhanaesaw@gmail.com.