Privacy Policy
1. Information We Collect
We collect information you provide directly and information generated through your use of the platform.
- Account information: username, email address, encrypted password, email verification status, and optional university/course selections.
- Contribution and activity data: your question responses (including timestamps and completion time), reactions, sessions, streaks, points, achievements, and related profile/gamification data.
- Guest usage data: a guest identifier stored in your browser and linked contribution data before account creation.
- Support submissions: form type, category, subject, message, optional contact email, follow-up preference, page URL, user agent, and submission context.
- Link tracking: when you use CourseMonkey short links (for example
/r/<slug>), we record redirect scan events. - Technical data: standard server/network logs such as IP address, request metadata, and timestamps for security and reliability.
2. How We Use Information
- Operate and maintain the platform and its core features.
- Generate and display aggregate course/professor insights and trends.
- Authenticate accounts, manage sessions, and verify email addresses.
- Support gamification, personalization, and continuity between guest and logged-in use.
- Respond to support, feedback, and volunteer submissions.
- Monitor abuse, enforce platform rules, and improve reliability/security.
3. How We Share Information
We do not sell personal information.
We may share limited information with:
- Service providers that help run the platform (for example hosting/infrastructure and email delivery providers such as Resend).
- Legal or safety recipients when required by law or reasonably necessary to protect rights, safety, or platform integrity.
- Successors in the context of a merger, acquisition, or asset transfer.
4. Cookies and Browser Storage
CourseMonkey uses browser storage (for example local storage) to keep you signed in, preserve guest/session state, store preferences, and queue unsent interactions when needed.
We may also load third-party assets (such as web fonts), and those providers may receive technical request data from your browser.
You can clear browser storage in your browser settings, but some features may stop working correctly.
5. Data Retention
- Account and contribution data are retained while your account is active and as needed to operate the service.
- Email verification tokens expire after 24 hours.
- Authentication tokens are short-lived access tokens plus refresh tokens with a configured lifetime.
- Support submissions are retained for triage, follow-up, abuse prevention, and record-keeping.
- Aggregated or de-identified analytics may be retained longer.
6. Your Choices and Rights
You may request access, correction, or deletion of your account data.
To request account/data deletion, use the Feedback form and include identifying account details (for example username/email) so we can verify the request.
7. Security and International Processing
We use reasonable technical and organizational safeguards, but no internet service is fully secure.
Your information may be processed in countries where our service providers operate, which may have different data protection laws than your jurisdiction.
8. Children
CourseMonkey is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
9. Changes and Contact
We may update this policy from time to time. When we do, we will revise the "Last updated" date above.
Questions about this Privacy Policy can be submitted through Feedback or Report an issue.