How we handle your information
Last updated September 2026 · applies to paced.school and the paced web and mobile application
This page explains, in plain terms, what paced collects, why, where it lives, and the choices you have — including over your Google Calendar connection. A longer, formally-reviewed Privacy and Data Security Policy is being finalized with our institutional partners; this page will be kept in step with it and is the accurate, current answer in the meantime.
The short version
- We do not sell your information, and there is no advertising or analytics tracking anywhere in paced.
- Your daily check-ins and reflection journal stay on your own device — they are never sent to our servers.
- We never notify your school, an instructor, or anyone else about you, for any reason.
- Google Calendar access is optional, and you can disconnect it at any time — from within paced or directly from your Google account.
- You can delete your account and everything tied to it whenever you want.
Information we collect
The table below covers the categories of personal information paced holds today.
| Information | Where it's stored | Who can see it |
|---|---|---|
| Name, email address, password | Our servers | You. Our team only where strictly necessary for support or security. |
| Your schedule — courses, class times, assignment titles and due dates, plus the study and wellbeing blocks paced adds | Our servers and your device | You only. |
| Learning preferences — focus times, energy patterns, semester goals | Our servers and your device | You only. |
| Your language setting (English or French) | Our servers and your device | You only. |
| Your Google Calendar connection, including the token that lets paced read (and, if you enable it, update) your calendar | Our servers | You only. |
| Daily check-ins, "something happened today" entries, and your reflection journal | Your device only | You only — never transmitted to us. |
| Assignment sheets you upload | Read in your browser; not stored by us | Sent to OpenAI to build your plan — see below. |
We do not collect your student number, grades, transcript, date of birth, or payment card details, and we do not request access to your learning management system account.
Google Calendar access
If you choose to connect Google Calendar, paced uses Google's OAuth sign-in to request one of two scopes, depending on the feature you use:
- Read-only access (
calendar.readonly) — to show your existing classes and events inside paced and build a plan around them. - Calendar-editing access (
calendar.events) — requested only where you explicitly enable syncing changes back to Google Calendar, for example moving a study block paced created. This does not grant paced access to any calendar other than your primary one, and paced does not read or modify events it did not import.
Your Google access token is stored on our servers so the connection survives you switching devices, and is never exposed to any third party. paced does not use your Google Calendar data for advertising, does not share it with anyone else, and does not use it to train any AI model.
You are in control of this connection at all times:
- Disconnect it from your paced profile settings whenever you like.
- Independently revoke paced's access from your Google account permissions page — this works even if you don't come back to paced first.
- Deleting your paced account (below) also removes the stored connection and token.
How we use artificial intelligence
paced uses OpenAI to turn an assignment sheet into a step-by-step plan, break a step down further, draft an email to a professor, and summarize your own check-in patterns back to you. These requests are routed through our own server, which requires you to be signed in — no browser ever talks to OpenAI directly, and no OpenAI key is ever exposed to your device.
Depending on the feature, what's sent may include an assignment's title and dates, the text or images of a sheet you uploaded, your saved learning preferences, and — for the "noticed lately" insight only — a summary of your recent check-ins. Your name, email address, password, and the raw text of your reflection journal are never sent. OpenAI's API terms state that data submitted through their API is not used to train their models by default. No decision that affects your academic standing or access to any service is ever made automatically — every AI output is a suggestion you can edit, ignore, or delete.
What we never do
- We do not sell or share your personal information for money.
- We run no advertising, analytics, or tracking scripts of any kind.
- We never notify your institution, an instructor, or anyone else about your check-ins, journal entries, or wellbeing information — paced is not a monitoring or crisis-alert tool. If you tell us something happened, it adjusts your plan and can point you to real support resources; it does not contact anyone on your behalf.
- Your institution, where one sponsors your access to paced, cannot see your individual data. There is no instructor, advisor, or administrator view of any student's account.
Where your information is processed
| Provider | Purpose | Region |
|---|---|---|
| Google (Firebase) | Sign-in, database, web hosting | United States |
| OpenAI | Generating plans, breakdowns, drafts, and insights | United States |
| Cloudflare | Proxies AI requests; delivers in-browser document-reading libraries | Global edge network |
| Google Fonts | Interface typefaces; receives your IP address on page load | Global |
| Stripe | Payment processing for Premium subscriptions, where applicable | United States |
paced's database is currently hosted in the United States. We know that matters for some of our institutional partners, and we're evaluating options here — this section will be updated if that changes.
Your choices
- Clear your schedule — removes your imported calendar from your device and our servers. You can re-import at any time.
- Disconnect Google Calendar — from your profile, or from your Google account directly, at any time.
- Delete your account — permanently removes your account record from our servers, including your schedule, preferences, and Google Calendar connection, clears what's stored in your browser, and removes your sign-in credentials.
- Request a copy, correction, or deletion of your information — write to hello@paced.school and we'll respond as promptly as we can.
How we secure your information
- Each account can only read and write its own data — our database rules deny every other request by default.
- Keys for Google and AI services live only on our servers, never in your browser.
- All connections use HTTPS/TLS in transit, and data is encrypted at rest by our hosting provider.
In the spirit of telling you the truth rather than what sounds reassuring: we have not yet commissioned an independent third-party security assessment. It's on our roadmap ahead of a full institutional rollout, and we'll update this page honestly once it's done.
Changes to this policy
If we change how we handle your information in a way that matters, we'll update the date at the top of this page. If you have any question, concern, or request about your data, we want to hear it.
Email us at hello@paced.school — we read every message and answer honestly.