Candy Land College Assistant

What we keep, and how to delete it

Candy Land is an independent student project in beta. It is not affiliated with or endorsed by any college or university. This page says exactly what the service stores about you, why, for how long, and who can see it.

The short version. Assignment requests, submitted syllabi and optional project backups are kept until deliberately deleted; there is no automatic 30- or 180-day purge. The site's owner can read them. You can delete account-linked data from My account → Delete my data; some older backups created before account indexing may need separate deletion.

What is stored

WhatDetailsKept for
Your accountEmail address, the name you choose, a salted hash of your PIN (never the PIN itself; an account made with Google has none), your Google account's id and email if you sign in with Google, sign-in sessions, and a history of account events (signed in, assignment started or completed). If you continue with Google on an email that already has an account, Google has verified you own it, so that account's PIN is retired and its other sessions signed out.Until you delete it. Sessions last 30 days.
Assignment requests (the activity log)Your prompt, the text extracted from files you attach, the course and grader context the page sends, the finished draft, the time, your network address, approximate location (city/region/country) and browser. The original files stay in your browser.Until deliberately deleted.
Syllabus submissionsThe file (or photo), its extracted text, and the school, course, instructor and term you enter or the syllabus names. A syllabus you drop on the Assignment page is added to My classes the same way. New submissions are private to your account unless you choose to contribute. If you opt in, selected facts and public research may appear in public faculty profiles after review; your identity and the original file are never published. Earlier beta submissions may already have public profiles.Until deliberately deleted.
Your school calendarOnly if you connect one on My classes: the calendar feed link (kept encrypted, and never shown back to the page), which of your classes each of its courses is, and the due dates read from it (title, course, date, link and description of each graded item; meetings and personal events are left out). The link is read about every six hours to keep due dates current. When you switch to a different calendar, the one it replaced is kept for ten minutes so Undo can bring it back, then dropped. Nothing from it is published. It reaches a model only if you press Start it on one of its items, which puts that item's title and description in your prompt.Until you disconnect it or delete your data.
Google ClassroomOnly if you connect it on My classes, by signing in with Google: read-only access to your active classes and your own coursework and submissions. We keep a Google access token (encrypted, never shown to the page), which of your classes each Classroom class is, and the due dates read (title, class, date, link, description, and whether you turned it in). Nothing is ever posted to Classroom and nothing from it is published. It reaches a model only if you press Start it on one of its items, which puts that item's title and description in your prompt.Until you disconnect it (which also revokes the access at Google) or delete your data.
Optional project backupOnly if you turn on server backup: the extracted text and the current draft.Until deliberately deleted.
InvitesYour invite code, and which account joined with whose code, so both can be credited. A shared class page shows only the class's owner-approved syllabus facts — never who shared it.Until the account is deleted.
Page error reportsIf the page hits an error, the error's own message (emails and long numbers masked), which part of the app it was in, and the first lines of its technical trace. Never your prompt, files or drafts.Until deliberately deleted.
Usage and rate-limit countsDaily request, check and upload counters, including per-caller limiter keys. No prompt or finished draft in these counters.Until deliberately deleted.
Your browserYour work in progress stays in the tab that made it. Finished files are kept on your device only if you turn that on in Settings (7 days).Until the tab closes, unless you choose otherwise.

Who processes it

When you drop a syllabus, its school, course, teacher and term are read on your own device, and the text of its first pages (about the first 9,000 characters) is sent once to the model (Anthropic) for a second reading of those four details, so a class is never added on one reading alone. That text is not stored; only the cost of the read is recorded. Your syllabus's grading and scale are first read on your own device, by code. Only its course-specific sections are then read by the model (Anthropic) — the school's standard policy sections are left out — to pull out the school, course, grading, assignments, policies and required texts; each item must quote the syllabus to be kept. The web research that follows uses only what that read found — the school, course, instructor and course title — never your syllabus text or your identity. It builds a public profile of the instructor from public pages (their faculty page, public reviews including Rate My Professors, public course pages); each item in it must quote the page or syllabus it came from, and only those short quotes are shown.

Deleting your data

Open My account in the app and choose Delete my data, then confirm with your PIN. This permanently removes, straight away:

You can also remove a single class from My classes with its ×: its syllabus goes the same way (a copy another student submitted stays theirs). Disconnecting your calendar deletes its link.

Daily usage and rate-limit counters are not linked to an account and are not erased by account deletion. Cloudflare's own request logs follow its separate retention. Older backups created before account indexing may not be discoverable from your account; delete them from the device with the recovery key or contact the owner.

Information from Google

Candy Land's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google sign-in and Classroom data are used only to sign you in and to show your own due dates and coursework to you; they are never sold, used for advertising, or used to train AI models, and no person reads them except to keep the service running securely or where the law requires.

Your responsibility

Check your course's policy on AI tools before you use a generated draft. Don't put anything in a prompt or file that you wouldn't want the site's owner to read.

Questions or a deletion you can't do yourself: contact the person who invited you to the beta.

Terms of service · ← Back to Candy Land