PRIVACY POLICY
Last Updated: August 31, 2026
This Service is an independent, non-commercial project created by University of Minnesota students and is not a registered business entity.
Welcome to our Study Buddy platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website.
Please read this Privacy Policy carefully. By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
1. Information We Collect
A. Sign-In via Google
The only way to sign in is “Sign in with Google,” using your University of Minnesota Twin Cities Google Workspace account (the one ending in @umn.edu). There is no separate username or password, and we never see, receive, or store your Google password. When you sign in, we receive from Google only:
- Your name.
- Your @umn.edu email address.
- Your Google account ID (used to link your session).
We do not request or access your Google Calendar, Google Drive, Gmail content, or any other Google service beyond basic sign-in identification. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can review or revoke this Service’s access to your Google Account at any time at Google Account Permissions — this is independent of deleting your account on our platform (see Section 6).
How access is restricted. After Google returns your identity, our server checks that your email address ends in “@umn.edu” and refuses the sign-up otherwise. Any “choose a umn.edu account” prompt you see from Google is only a convenience hint, not the control. An @umn.edu Google account is issued by the University to students, faculty, staff, and other affiliates; this Service does not verify your enrollment status, role, or age, and does not connect to, or exchange data with, any University system. We are not affiliated with, sponsored by, or endorsed by the University of Minnesota.
B. User Profile & Platform Data
Once authenticated, you may choose or be required to provide additional information to facilitate matchings, including:
- Academic Information: Major, current courses, and academic interests.
- Meetup & Schedule Data: Availability, study preferences, and proposed meetup locations or times.
- Communication Content: The text of real-time chat messages and direct messages you exchange with other users. The Service has no image or file uploads.
C. Automatically Collected Technical Data
Our infrastructure relies on third-party services to host and power the platform. We collect technical logs automatically via:
- Vercel (Hosting & Metrics): IP addresses, browser types, operating systems, access times, and pages viewed directly before and after accessing the Service.
- Supabase (Database & Authentication Backend): Secure authentication tokens, user IDs, query timestamps, and structural operational logs.
2. Dynamic Data Visibility and Peer Sharing
A. Broad Internal Visibility (Important Disclosure)
Unlike traditional social networks, this platform is designed as an open campus directory to maximize student connection. By creating an account, you explicitly acknowledge and agree that your profile is visible to any other user signed in with a University of Minnesota Twin Cities Google account (@umn.edu). This visibility is limited to your name and any profile fields you choose to complete (most of which can be hidden individually in your settings) — it does not include your password or Google authentication tokens, which we never possess. Your email address is never displayed to other members, though a member who already knows your @umn.edu address can use it to find your profile through the people search.
B. Purpose of Sharing
This visibility is intended solely to allow other members to recognize classmates, coordinate schedules, and arrange academic meetups. We do not independently verify anyone’s identity or student status.
C. User Responsibility
You are responsible for the information you choose to post in your public profile. Because any signed-in member can view your profile, we strongly advise against posting highly sensitive personal details (such as your physical home address or phone number) in open text areas.
D. Anti-Scraping and Bulk Harvesting Controls
Access to the member directory is limited to accounts that sign in with an @umn.edu Google account. We also apply the following measures to reduce the risk of data harvesting:
- Message sending is rate-limited on our server to slow automated abuse.
- Signed-in areas of the site (including profiles and the people search) are excluded from search-engine indexing.
- Mass copying, automated scraping, bulk export, or programmatic harvesting of other members’ profile data is strictly prohibited by our Terms of Service and will result in immediate and permanent account termination.
3. How We Use Your Information
We use the information we collect to:
- Restrict platform access to accounts that sign in with a University of Minnesota Twin Cities Google account (@umn.edu).
- Operate, maintain, and improve the matching and chat functionalities of the platform. Facilitate peer-to-peer communication and meetup scheduling.
- Facilitate peer-to-peer communication and meetup scheduling.
- Monitor and analyze usage trends to optimize database performance via Supabase and Vercel.
- Maintain user safety, investigate harassment or platform abuse, and enforce our Terms of Service.
4. User Safety, Moderation, and Administrative Review
We prioritize a safe environment for student collaboration. To ensure platform safety, we implement the following protocols:
- User Controls: You can block or report another member directly within the application interface at any time.
- Automated language filter. Chat messages and some text fields are passed through an automated profanity filter that masks certain words before the message is stored. Whenever the filter changes a message, we automatically keep a moderation record containing both the masked version everyone saw and the original text you typed. This happens for every filtered message, not only reported ones — it is how we detect deliberate attempts to evade the filter. These records are readable by platform administrators and are retained no longer than the limit in Section 6.
- Administrative Chat Review: Chats are private between participants during normal use, but they are not anonymous or guaranteed confidential. To investigate a report of a Terms of Service violation (harassment, threats, scams, safety concerns), or to comply with a legal request, platform administrators may access and review the relevant messages and account activity.
5. How We Share Your Information
Aside from the intentional peer-to-peer visibility detailed in Section 2, we do not sell, rent, or trade your personal data, and we do not use it for targeted advertising or for profiling that produces legal or similarly significant effects. We share your information only with the service providers we need to run the platform:
- Vercel (hosting) and Supabase (database and authentication) process and store your data on our behalf.
- Resend (email delivery) sends the notification and meetup emails you have not turned off, and — if configured — an internal alert to our team when a report is filed. To send an email, Resend receives the recipient’s email address and display name and the contents of that message (a meetup email includes the meetup time and location and the names of members who have RSVP’d; a report alert includes the reason selected and any description the reporter wrote). If email is not configured, no email is sent and Resend receives nothing.
- Legal Requirements: We may disclose your information if required to do so by law, court order, or a government request, or if we believe such action is necessary to protect member safety or investigate platform abuse.
6. Data Retention and Deletion Policy
We keep personal data only while we have a use for it. Most categories of stored data are subject to a single retention limit — currently 365 days — after which they are automatically and permanently purged by a scheduled job. The course catalog and the list of eligible email domains are kept indefinitely; they are not personal data.
- Deleting your account — what happens right away. When you delete your account we replace your name with “Deleted User” and erase your bio, academic details, links, and settings; we remove you from every group (transferring or disbanding groups you managed); we cancel every pending request involving you; and we delete your meetup RSVPs, poll votes, and notifications. Your Google sign-in link is destroyed at this point, which is why deletion cannot be undone — signing in again later creates a brand-new, separate account.
- Messages you already sent. Messages you sent stay visible to the people and groups you sent them to, shown as coming from “Deleted User.” Each message is deleted about 365 days after it was originally sent.
- What we keep for up to 365 days after deletion, then permanently purge. A minimal internal record that the account existed; your course list and your connection (friend, study-buddy, and block) records, with your identity already removed from them; and — in a separate, access-restricted store that is never shown in the app or the admin tools — your real email address. We retain the email address only to enforce account bans and prevent ban evasion, to act on abuse or safety reports filed shortly before or after a deletion, and to respond to a lawful preservation request or subpoena received during that period.
7. Children's Privacy and Age Considerations
A. Strict COPPA Compliance
Our Service is strictly intended for individuals who are 13 years of age or older. When you sign in, you must confirm that you are at least 13 years old. We do not knowingly collect, maintain, or solicit personal information from children under the age of 13.
If you are a parent or legal guardian and believe your child under 13 has created an account, please contact us immediately at the email listed at the bottom of this page. If we learn or suspect that we have inadvertently collected personal data from a child under 13, we will lock the profile and permanently delete all associated data from our Supabase backend infrastructure immediately.
B. University Affiliation and Age
This Service authenticates users through “Sign in with Google” using an @umn.edu account. Google does not confirm anyone’s age to us, and an @umn.edu account does not confirm current student status. As a result, some users of this Service — for example, students enrolled through PSEO or other dual-enrollment programs — may be under 18. Because members' names and profile information are visible to other signed-in members (see Section 2), and because chat features allow direct peer-to-peer communication, users under 18 and their parents or guardians should be aware of this visibility before creating a profile or engaging in chats. We do not have any mechanism to verify a user’s age or to restrict or flag underage accounts.
8. Family Educational Rights and Privacy Act (FERPA) Disclaimer
This platform is an independent student-to-student matching tool and is not officially sponsored, endorsed, or operated by your university or college administration.
No Access to Official Records: We do not pull, store, access, or modify official institutional academic records, grades, transcripts, GPA metrics, or official enrollment files protected under the Family Educational Rights and Privacy Act (FERPA).
Not a school official: The people who run this Service are not employees, agents, contractors, or “school officials” of the University of Minnesota, and the Service is not authorized by the University to act on its behalf or to receive information from any University system.
User-Generated Academic Data: Any academic information displayed on your profile (such as your major or current courses) is entirely self-reported and voluntarily provided by you. It does not constitute an official educational record. The University of Minnesota does not endorse, operate, sponsor, or have administrative access to this platform, and this platform does not report, share, or transmit any user data back to the University. Any reference to “University of Minnesota” on this site refers only to the community it serves, not to institutional affiliation or endorsement.
9. Your Privacy Rights
Regardless of where you live, you have the right to:
- Access the personal information we hold about you, and confirm whether we are processing it.
- Correct inaccurate profile or account information (most fields you can edit yourself under Edit profile).
- Delete your account and the data tied to it at any time (see Section 6).
- Obtain a copy of the profile and content data you provided, in a portable, machine-readable format.
We do not sell your personal data, use it for targeted advertising, or use it for profiling that produces legal or similarly significant effects, so there is nothing to opt out of in those categories.
How to make a request. Email us at the address at the bottom of this page from — or naming — the @umn.edu address on your account (this is how we verify the request is yours). We aim to respond within 45 days; if a request is complex we may take a reasonable extension and will tell you. There is no fee.
If we say no. If we decline a request, we will explain why. You may reply to appeal that decision and we will review it again. If you are still not satisfied, you may contact the Minnesota Attorney General’s Office.
10. Security of Your Data
Your data is stored and transmitted using the security controls of our service providers (Supabase, Vercel, and, for email, Resend), including encryption in transit and at rest. Access to member data on the administrative side is limited to the small team that runs the Service. No method of transmission or storage is 100% secure, and while we restrict entry to @umn.edu Google accounts, we cannot guarantee absolute security against unauthorized access or against another member misusing information you have made visible to them.
If we become aware of a data breach affecting your personal information, we will notify affected users without unreasonable delay, and we will notify the Minnesota Attorney General’s Office where and within the time required by Minnesota’s data-breach-notification law (Minn. Stat. § 325E.61).
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top always reflects the current version. For a material change, the next time you open the app you will be shown a notice and asked to review and accept the updated documents before continuing, and we record when and which version you accept. For a minor change (typos, clarifications), updating the date is the only notice. Contact us at the email below with any questions about a change.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us through our email:
goldysstudybuddies@gmail.com