Your coursework is personal.
This policy explains what Courseflow collects, why it needs that information, and the choices you have.
Effective September 3, 2026
About Courseflow
Courseflow is an independent student project that brings assignment deadlines from supported course sources into one dashboard and, when you choose, syncs those deadlines to your Google Calendar. Courseflow is not affiliated with or endorsed by the University of California, Berkeley.
Information Courseflow collects
Google account information
When you sign in with Google, Courseflow receives your Google account identifier, verified email address, and profile name. Courseflow uses this information to create and secure your account, display your name, and keep different users’ data separate.
Google Calendar information
If you separately connect Google Calendar, Courseflow requests the calendar.events permission and offline access. This permission can technically allow the app to view and edit events on calendars you can access. Courseflow uses it only on your primary calendar to find events marked as created by Courseflow and to create, update, or remove those Courseflow-managed assignment events. Courseflow does not use unrelated calendar events, attendees, or event content.
Course and assignment information
Courseflow stores the classes you select, assignment names and types, deadlines, source links, completion status, sync history, and notifications about changes. If you connect a personal bCourses calendar feed, Courseflow retrieves assignment information from that feed and stores the feed URL in encrypted form.
Gradescope browser extension information
If you choose to use the Courseflow browser extension, it reads supported Gradescope course and assignment pages you open and sends normalized course codes, assignment names, types, deadlines, and source links to your Courseflow account. The extension stores a connection key in your browser; Courseflow stores only a hash of that key on the server.
Technical information
Courseflow uses an HTTP-only session cookie to keep you signed in. Its hosting and database providers may process standard request information such as timestamps, IP addresses, browser details, and diagnostic logs for security and reliable operation.
How Courseflow uses information
- Provide the dashboard, imports, completion tracking, notifications, and calendar sync you request.
- Authenticate users, protect connections, prevent cross-account access, and diagnose failures.
- Maintain and improve Courseflow’s reliability and supported course integrations.
Courseflow does not sell personal information, serve targeted advertising, or use Google user data to train advertising models or generalized artificial-intelligence models.
How information is stored and shared
Account, coursework, and integration records are stored in Courseflow’s hosted database. Google refresh tokens and bCourses feed URLs are encrypted before storage, and browser-extension connection keys are stored as hashes. Information is disclosed only as needed to operate the service: to Google for sign-in and Calendar actions you request, and to infrastructure providers such as the application host and database provider acting on Courseflow’s behalf. Courseflow may also disclose information when required by law or to protect users and the service.
Courseflow does not transfer Google user data to data brokers, advertising platforms, or unrelated third parties.
Google API Services User Data Policy
Courseflow’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Retention, security, and your choices
Courseflow keeps account and coursework information while your account is in use or as needed to operate and secure the service. Backup and diagnostic records may remain for a limited period. No online system can guarantee absolute security, but Courseflow uses encryption, signed sessions, access controls, and account isolation to reduce risk.
- You can disconnect Google Calendar in Courseflow settings. This removes the stored Google refresh token and stops future calendar updates; events already placed on your calendar may remain.
- You can revoke Courseflow’s access at any time from your Google Account permissions.
- You can remove bCourses and browser-extension connections from Courseflow.
- For access or deletion requests, contact the Courseflow operator through the project repository. Do not post private account information in a public issue.
Children and international use
Courseflow is intended for college students and is not directed to children under 13. If local law requires permission from a parent, guardian, school, or other person before using the service, you must obtain that permission. Information may be processed in the United States where Courseflow’s providers operate.
Changes to this policy
Courseflow may update this policy as the service changes. The effective date above will be updated when material changes are published. If Courseflow materially changes how it uses Google user data, users will be notified and asked for consent when required.