Privacy Policy
Effective date: 2026-08-14
Semestree (the “Service”) is operated by NUHYLabs Inc.. This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It applies to semestree.com, our iOS app, and our support channels.
The Service is currently a beta (trial) version: automatic analysis and AI processing of your uploaded materials may be inaccurate, and data may be lost during the beta period. See the beta service clause in the Terms of Service for details.
1. Information we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account identifiers | Email address, first and last name, password (stored hashed). | You, at signup. |
| Social sign-in data | If you sign in with Google: your email address, first and last name, Google account identifier, and email-verified status. If you sign in with Apple: your email address, Apple account identifier, and email-verified status; your name is provided only at the first authorization. If you use Apple’s Hide My Email, we receive and store the relay address Apple generates instead of your real address. Your Google or Apple password is entered on their own screens and is never sent to or stored by the Service. | Google or Apple, only if you choose that sign-in. |
| Profile | School, expected graduation year (“Class of”), and major — these are required to finish setting up an account and use the Service. Student ID and referral code are optional. | You, on the account setup screen. |
| Study content | Syllabi and lecture files you upload, the text extracted from them, and the courses, schedules, to-dos and notes you create. | You. |
| Support inquiries | The message you write, the screenshots you attach, the contact email you give us, and which client and version you sent it from. Screenshots may show anything that was on your screen — see section 8. | You, when you contact support. |
| LMS notification email | If you turn on email forwarding (off by default): sender address, subject, received time, sender-authentication results, schedule-related excerpts, and the original mail file kept briefly. See section 5. | Your school's LMS, forwarded by you. |
| Payment records | Date, amount, plan, and order ID. Card numbers and expiry dates are handled by our payment processor and are never collected or stored by the Service. | You and our payment processor, only if you buy a plan. |
| Device and usage data | IP address, device and browser information, usage logs, and the address and title of pages you visit. | Collected automatically. |
| Advertising identifiers | Cookie and local-storage identifiers used to measure ads and build remarketing audiences. Only collected if you have not opted out — see section 10. | Collected automatically by Google tags. |
We do not ask for sensitive personal information such as government IDs, precise geolocation, biometrics, health records, or financial account numbers, and we have no feature that requires them. Be aware that free-text you write yourself — a to-do, a schedule note, or a support message — can contain whatever you put there. Please do not put health or other sensitive details in those fields.
2. How we use it
- Creating and managing your account, verifying it, and signing you in
- Providing the features: auto-sorting, summaries, quizzes, and the AI tutor for your materials
- If you use LMS email forwarding: detecting course-schedule changes and proposing them to you
- Answering your support inquiries
- Improving the Service, and detecting and responding to errors and abuse
- Processing payments and refunds, and keeping transaction records
- Measuring advertising performance and building remarketing audiences — unless you opt out
We do not use your uploaded study materials to train AI models, and we do not sell your personal information for money.
3. How long we keep it
| Category | Retention |
|---|---|
| Account, profile, study content, schedules, to-dos | Kept while your account is open. When you delete your account, access ends immediately and everything is permanently destroyed within 30 days. |
| Uploaded files and their extracted text | Deleted when you delete them, or with your account as above. Items in Trash are destroyed automatically once the trash retention period passes. |
| Support inquiries and attachments | Kept for 2 years after the inquiry is resolved, so we can recognize a recurring problem. The link to your account is removed when you delete your account. |
| Payment and refund records | Kept for 7 years to meet tax and accounting obligations, and to defend chargebacks. This is the one category that survives account deletion. |
| Administrator access logs | Kept for 2 years, then destroyed. See section 8. |
| Original LMS mail files | 72 hours after processing, or 14 days if processing failed. Destroyed immediately if sender verification fails. See section 5. |
| Advertising identifiers | Controlled by your browser — clear them at any time, and see section 10. |
4. Who we share it with
We do not sell your personal information, and we do not disclose it to third parties except to the service providers below, when you direct us to, or when the law requires it. Each provider may use the data only to perform the service we hired them for.
| Provider | What they do | What they receive |
|---|---|---|
| Amazon Web Services, Inc. (USA, us-east-1) | Servers, database, file storage; mail receiving and short-term storage of originals if you use LMS forwarding | Everything the Service stores, as its hosting provider |
| OpenAI (USA) | AI processing — summaries, quizzes, tutor; extracting schedule changes from forwarded mail | The study-material text needed for the feature you are using, and the subject and body excerpt of forwarded mail |
| DeepInfra (USA) | Speech-to-text for audio and lecture recordings you upload | The audio file being transcribed |
| PayPal, Inc. (USA) | Payment processing and refunds — only if you buy a plan | Amount, currency, plan name, our order number, plus your IP address and browser information |
| Google LLC (USA) | Advertising measurement and remarketing (only if you have not opted out); verifying the sign-in token if you use Google sign-in | See section 10 for the advertising items; for sign-in, the token Google issued plus your IP and browser information |
| Apple Inc. (USA) | Verifying the sign-in token — only if you use Apple sign-in | The token Apple issued, plus your IP and browser information |
All of these providers process data in the United States. If you are outside the US, using the Service means your information is processed there.
5. LMS notification-email forwarding (optional)
This feature finds course-schedule changes in announcement mail sent by learning management systems (Blackboard, Canvas, etc.). It is off by default and works only if you issue a dedicated forwarding address in settings and configure your school mail to forward to it. You can unlink it yourself at any time from the settings screen.
- What we collect: the sender address, subject, received time, sender-authentication results (SPF / DKIM / DMARC / spam verdict), schedule-related excerpts, and processing status. Full message bodies are not stored in your receiving history.
- Restricted to LMS senders: we process only mail sent from LMS domains (blackboard.com, instructure.com) or forwarded copies of such mail. Mail from any other sender fails verification, its original is destroyed immediately, and its subject is not shown as-is in the app.
- AI processing: to extract schedule information we send the mail subject and a body excerpt (up to 8,000 characters) to OpenAI. Daily-digest mail and mail with no schedule-related content are not sent.
- Retention of originals: original mail files are destroyed automatically within 72 hours once processed, or within 14 days if processing failed or the mail was not classified (a daily job, with a storage lifecycle rule of at most 15 days as a backstop).
- Never applied automatically: detected schedule changes appear only as proposals and take effect after you approve them.
- How to stop: unlink at any time under Settings > Email sync. Unlinking revokes the forwarding address immediately. However, the forwarding rule in your school mail must be removed from your school account — if it stays, mail keeps arriving and is discarded immediately without being stored.
6. Your privacy rights
Depending on where you live, you have some or all of the rights below. We honor them for all users in the United States, not only residents of states that require it.
- Know and access — what we collect, why, who we share it with, and a copy of the information itself.
- Portability — a copy in a machine-readable format. Settings > Privacy > Download my data gives you a JSON file.
- Correct — fix inaccurate information. Settings > Account.
- Delete — Settings > Account > Delete account. Access ends immediately and everything is permanently destroyed within 30 days, except the payment records named in section 3.
- Opt out of targeted advertising — see section 10 and Do Not Sell or Share My Personal Information.
- No discrimination — we will not deny you service, charge you a different price, or give you a lower quality of service for exercising any of these rights.
How to make a request. Use the settings screens above, or email mj@nuhylabs.com. We will verify the request against the email address on your account, and respond within 45 days. If we need more time we will tell you why and take no more than 45 additional days. An authorized agent may submit a request on your behalf with written permission from you.
Appeals. If we deny your request, we will tell you why. You may appeal by replying to that decision or emailing mj@nuhylabs.com with “Appeal” in the subject line. We will respond to the appeal within 45 days with a written explanation of our reasoning, and tell you how to contact your state attorney general if you disagree.
7. Children
The Service is intended for college students and is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. If we learn that we have, we delete the account and its data without delay. A parent or legal guardian may email mj@nuhylabs.com to review, correct, or delete such a child’s information.
If you are between 13 and 18, you may use the Service only with the permission of a parent or guardian, as stated in the Terms of Service. We do not knowingly use the personal information of anyone under 16 for targeted advertising.
8. Security and internal access
- One-way password hashing; HTTPS encryption in transit; token-based access control
- Internal administrator access is limited by design, not just by policy. Administrators signed in with a company account through single sign-on can see account details (email, name, sign-up date, plan status) and usage statistics. The names and contents of uploaded files, the titles and contents of schedules and to-dos, and course names are not shown in the admin console and are not sent to administrators by the server — they are removed from the response itself, not hidden in the interface.
- Two exceptions, both about support inquiries. When you contact support, an administrator reads the message you wrote — that is the point of sending it. They can also open the screenshots you attached, which may show anything that was on your screen at the time, including the file names and schedule titles that are otherwise withheld. Opening an attachment is a separate, deliberate action and each one is recorded in the access log.
- Destructive actions are restricted further. Creating, deleting, or resetting an account, and changing a plan or issuing a refund, require a named owner account. Being on the company domain is not enough.
- Access logging — administrator access to member data (viewing, changes, deletion, and opening support attachments) is recorded with the account, timestamp, source IP, affected member, and the action performed. These logs are kept for 2 years.
No method of transmission or storage is completely secure. If a breach affects your personal information, we will notify you and the appropriate authorities as required by applicable state law.
9. Contact
Privacy contact: Minjun Kwon (NUHYLabs Inc.)
Email: mj@nuhylabs.com
Address: 729A, 2F, 47 Gangnam-daero 112-gil, Gangnam-gu, Seoul 06044, Republic of Korea
10. Cookies, advertising, and how to opt out
Unless you have opted out, we load two Google advertising tags on the web pages of the Service: the Google Ads tag (gtag.js) and the Google AdSense loader. They contact Google LLC (USA) and store or read identifiers in your browser, including a cookie (_gcl_au) and a local-storage value (_gcl_ls) on our own domain, plus AdSense’s own cookies.
- Purpose: measuring whether a visit that came from an ad click led to a signup (conversion measurement), building remarketing audiences from visit history, and serving ads.
- What is collected and sent: ad-click and cookie identifiers, IP address, browser and device information (including screen size), the address and title of the page you visit, and the address of the previous (referring) page. Account information such as your name and email, and the study materials you upload, are not sent by these tags.
- This counts as “sharing” or “targeted advertising” under California, Colorado, Connecticut, Texas, Virginia and other state privacy laws, even though no money changes hands. That is why the opt-out below exists.
How to opt out. Go to Do Not Sell or Share My Personal Information and turn advertising off. Your choice is stored in that browser, so set it on each browser you use. We also honor the Global Privacy Control signal — if your browser or an extension sends GPC, we do not load the advertising tags at all and you do not need to do anything. A choice you make on our page takes precedence over the signal, in both directions.
Opting out does not restrict your use of the Service — no feature is locked and signup is not blocked. Note that we keep you signed in using browser storage, so clearing this site’s data will also sign you out (you can simply sign in again). To turn off only personalized ads tied to your Google account, you can also opt out at adssettings.google.com.
Separately, only for visits that arrive through an ad or campaign link (an address carrying utm_ parameters), we create an anonymous browser-level identifier in browser storage and send it, together with the campaign information, the path visited, and the referring page address, to our own servers. This is first-party analytics: it is not shared with advertising partners and is removed when you clear your browser storage.
11. Changes
We will post the effective date and details of any changes on this page. If a change materially affects how we use information we already hold about you, we will notify you in the Service before it takes effect.