Candy Land College Assistant
What we keep, and how to delete it
Candy Land is an independent student project in beta. It is not affiliated with or endorsed by any college or university. This page says exactly what the service stores about you, why, for how long, and who can see it.
What is stored
| What | Details | Kept for |
|---|---|---|
| Your account | Email address, the name you choose, a salted hash of your PIN (never the PIN itself; an account made with Google has none), your Google account's id and email if you sign in with Google, sign-in sessions, and a history of account events (signed in, assignment started or completed). If you continue with Google on an email that already has an account, Google has verified you own it, so that account's PIN is retired and its other sessions signed out. | Until you delete it. Sessions last 30 days. |
| Assignment requests (the activity log) | Your prompt, the text extracted from files you attach, the course and grader context the page sends, the finished draft, the time, your network address, approximate location (city/region/country) and browser. The original files stay in your browser. | Until deliberately deleted. |
| Syllabus submissions | The file (or photo), its extracted text, and the school, course, instructor and term you enter or the syllabus names. A syllabus you drop on the Assignment page is added to My classes the same way. New submissions are private to your account unless you choose to contribute. If you opt in, selected facts and public research may appear in public faculty profiles after review; your identity and the original file are never published. Earlier beta submissions may already have public profiles. | Until deliberately deleted. |
| Your school calendar | Only if you connect one on My classes: the calendar feed link (kept encrypted, and never shown back to the page), which of your classes each of its courses is, and the due dates read from it (title, course, date, link and description of each graded item; meetings and personal events are left out). The link is read about every six hours to keep due dates current. When you switch to a different calendar, the one it replaced is kept for ten minutes so Undo can bring it back, then dropped. Nothing from it is published. It reaches a model only if you press Start it on one of its items, which puts that item's title and description in your prompt. | Until you disconnect it or delete your data. |
| Google Classroom | Only if you connect it on My classes, by signing in with Google: read-only access to your active classes and your own coursework and submissions. We keep a Google access token (encrypted, never shown to the page), which of your classes each Classroom class is, and the due dates read (title, class, date, link, description, and whether you turned it in). Nothing is ever posted to Classroom and nothing from it is published. It reaches a model only if you press Start it on one of its items, which puts that item's title and description in your prompt. | Until you disconnect it (which also revokes the access at Google) or delete your data. |
| Optional project backup | Only if you turn on server backup: the extracted text and the current draft. | Until deliberately deleted. |
| Invites | Your invite code, and which account joined with whose code, so both can be credited. A shared class page shows only the class's owner-approved syllabus facts — never who shared it. | Until the account is deleted. |
| Page error reports | If the page hits an error, the error's own message (emails and long numbers masked), which part of the app it was in, and the first lines of its technical trace. Never your prompt, files or drafts. | Until deliberately deleted. |
| Usage and rate-limit counts | Daily request, check and upload counters, including per-caller limiter keys. No prompt or finished draft in these counters. | Until deliberately deleted. |
| Your browser | Your work in progress stays in the tab that made it. Finished files are kept on your device only if you turn that on in Settings (7 days). | Until the tab closes, unless you choose otherwise. |
Who processes it
- Anthropic (the Claude API) writes the draft. Your prompt, file text and course context are sent to it for each request.
- Winston AI runs the originality check. The finished text is sent to it when a check runs.
- Google, only if you use Continue with Google or connect Google Classroom: you sign in on Google's own page. For sign-in, Google tells Candy Land your Google account's id, your email, whether Google has verified it, and your name; we keep the id and email to recognise you next time. For Classroom, Candy Land reads your classes and coursework with the read-only access you grant.
- Cloudflare hosts the service and stores the records above. Its own request logs sample a fraction of requests for a few days.
- The site's owner can read the activity log, account list and syllabus submissions to run and improve the service. Nothing is sold or shared for advertising.
When you drop a syllabus, its school, course, teacher and term are read on your own device, and the text of its first pages (about the first 9,000 characters) is sent once to the model (Anthropic) for a second reading of those four details, so a class is never added on one reading alone. That text is not stored; only the cost of the read is recorded. Your syllabus's grading and scale are first read on your own device, by code. Only its course-specific sections are then read by the model (Anthropic) — the school's standard policy sections are left out — to pull out the school, course, grading, assignments, policies and required texts; each item must quote the syllabus to be kept. The web research that follows uses only what that read found — the school, course, instructor and course title — never your syllabus text or your identity. It builds a public profile of the instructor from public pages (their faculty page, public reviews including Rate My Professors, public course pages); each item in it must quote the page or syllabus it came from, and only those short quotes are shown.
Deleting your data
Open My account in the app and choose Delete my data, then confirm with your PIN. This permanently removes, straight away:
- your account, its sessions and its event history;
- every activity-log entry your account made;
- your link to every syllabus you submitted; a public section remains if another student submitted the identical file;
- your connected calendar, its link and the due dates read from it;
- your Google Classroom connection and what was read from it, with the access revoked at Google;
- account-linked project backups, including the backup of the device you delete from.
You can also remove a single class from My classes with its ×: its syllabus goes the same way (a copy another student submitted stays theirs). Disconnecting your calendar deletes its link.
Daily usage and rate-limit counters are not linked to an account and are not erased by account deletion. Cloudflare's own request logs follow its separate retention. Older backups created before account indexing may not be discoverable from your account; delete them from the device with the recovery key or contact the owner.
Information from Google
Candy Land's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google sign-in and Classroom data are used only to sign you in and to show your own due dates and coursework to you; they are never sold, used for advertising, or used to train AI models, and no person reads them except to keep the service running securely or where the law requires.
Your responsibility
Check your course's policy on AI tools before you use a generated draft. Don't put anything in a prompt or file that you wouldn't want the site's owner to read.
Questions or a deletion you can't do yourself: contact the person who invited you to the beta.