Legal
Privacy Policy
Last updated: August 6, 2026
This policy explains what information Cherrypicker handles when you use its academic planning and scheduling tools, where that information goes, and the choices you have.
What Cherrypicker is
Cherrypicker is an independent academic planning tool for students, especially Foothill and De Anza students planning transfer pathways, degrees, certificates, coursework, and schedules. It is not a college service, enrollment system, or official academic record.
Information you provide
Depending on the features you use, you may provide:
- selected colleges, universities, majors, transfer goals, degree or certificate goals, and a primary goal;
- completed or in-progress courses, grades, units, quality points, terms, college, and transfer or other credit information;
- future-quarter plans, manually added courses, preferred schedules, tracked CRNs, registration priority group, availability, modality and campus preferences, and instructor preferences;
- free-text planning notes you type into the planner;
- instructor ratings, optional review text, course and term context;
- CSU articulation progress you enter manually, including course codes and an optional note;
- planning-group names, expiry dates, group goals, and the specific courses or redacted busy-time blocks you choose to share if you use Friend Mode;
- bug reports and the optional context you include; and
- messages you send to the scheduling assistant or to Ask.
Cherrypicker uses this information to run its core account functionality: academic planning, scheduling, progress and requirement tracking, the personalized Ask AI assistant, and the account features described throughout this policy.
Google sign-in information
Cherrypicker uses Google OAuth through Supabase Auth. Google and Supabase may provide Cherrypicker with your name, email address, profile image, and Google account identifier. Cherrypicker uses this information to authenticate you, create and manage your account, associate saved information with your account, and display account information such as your name, email, or initials.
Signing in with Google does not request your Google password or access to Google Drive, Gmail, Calendar, contacts, or school-portal credentials — sign-in asks only for basic identity information and no custom scopes. Google account information from sign-in is stored and processed through Supabase authentication and is not sold. It is shared only with service providers that operate the service, when required by law or safety needs, or as described under “When information may be shared.” Cherrypicker Premium separately offers an optional Google Calendar sync feature, described in the next section, that asks for a distinct, narrower Google authorization only if you choose to turn it on.
Google Calendar sync (optional, Cherrypicker Premium)
Cherrypicker Premium’s Scheduler can optionally add your planned class meetings to Google Calendar. This is a separate authorization from Google sign-in: nothing about it happens unless you press “Add to Calendar” and complete a distinct Google consent screen, and an account can be used fully without ever granting it.
That authorization requests exactly two Google scopes: free/busy status on your primary calendar (when you are busy, never event titles, guests, or locations), and access limited to a secondary calendar, “Cherrypicker Classes,” that Cherrypicker itself creates. Cherrypicker cannot read, modify, or delete events on your existing personal or work calendars. It only ever updates or deletes a calendar event it created, identified by an id it stored at creation time — never by searching your calendar for a course name.
If you connect Google Calendar sync, Cherrypicker stores an encrypted refresh token and a record of which calendar events it created for you, tied to your account, so it can keep your synced schedule current. Disconnecting revokes the authorization with Google and deletes the stored token and event records; your “Cherrypicker Classes” calendar and the events already on it are left in place, since disconnecting means Cherrypicker should stop acting on your behalf, not that your calendar entries should be removed. Deleting your Cherrypicker account deletes the stored token and event records along with your other account data.
Transcripts and academic records
You may upload an unofficial transcript PDF, up to 8 MB, for parsing. The PDF is sent through Cherrypicker’s server to a separate transcript-parsing function hosted on Vercel. That function temporarily writes the PDF while it parses it, deletes the temporary file afterward, returns structured course rows, and does not intentionally persist the PDF. Responses are marked not to be cached.
The parser first uses deterministic extraction. If it cannot confidently read particular lines, only those flagged lines—rather than the full PDF—may be sent to Anthropic’s API to recover structured course information. You review and can correct parsed results before confirming them. Confirmed structured rows may then be stored; the PDF itself is not stored in Cherrypicker’s database. Do not upload records you are not authorized to use.
Information stored with Supabase
For signed-in users, Supabase may store:
- authentication records and account metadata received through Google;
- a profile with display name, goals, primary goal, scheduling constraints, registration group, tracked CRNs, and last transcript-update quarter;
- confirmed structured transcript course rows;
- instructor reviews and their course or term context;
- manually reported CSU articulation progress;
- your Privacy & personalization settings;
- if you use Friend Mode: planning-group records, your membership and its sharing scope, and hashed (never plaintext) invite codes;
- if you connect Google Calendar sync: an encrypted Google refresh token and a record of the calendar events Cherrypicker created on your behalf, described under “Google Calendar sync”;
- anonymous product insights: see “Aggregated and deidentified information” below — that feature is not active yet, so no planning contributions are currently stored under it;
- subscription state for Cherrypicker Premium, such as status, plan, and period end;
- bug reports, rate-limit records, and account-related identifiers used to enforce ownership and abuse controls.
Public catalog, section, requirement, articulation, link, seat-cache, and community data also live in or are designed to load into Supabase, but are not private student records. Instructor reviews are public. Manually reported CSU course lists and notes are currently readable as community data. Non-hidden bug reports are public, but the public bug-report interface and database permissions do not expose the reporter identifier.
Information kept on your device
Cherrypicker uses browser local storage for essential preferences and app state, including theme, onboarding status, goals, plans, manually added courses, chosen schedules, tracking, review prompts, and—in demo or signed-out mode—academic rows, reviews, constraints, and CSU manual entries. Some signed-in features also keep a local copy or device-only state. Clearing site data in your browser removes this device storage.
Supabase uses cookies or similar browser storage to maintain authentication sessions. Cherrypicker does not currently include advertising cookies or a separate analytics, advertising, or behavioral-tracking SDK.
AI features
Cherrypicker sends limited information to Anthropic, its AI service provider, so a model can return a response. This happens in four places:
- Ask. Cherrypicker has one AI assistant, reached from every “Ask” button in the app. A request contains the last few messages of your current conversation plus grounding data Cherrypicker assembles deterministically: public course, prerequisite, articulation, and current section information. When Personalized Ask is on—the default—it also includes the transfer goals you selected and the part of your saved plan the question is about: planned courses by quarter, your target transfer quarter, the planner’s own recorded reasoning, your planning notes, and the course codes your Past Coursework records as completed or in progress (codes only—never your grades, terms, or transcript text). Ask can also carry out a small, fixed set of Cherrypicker actions on your own plan—removing a class it can verify you already completed, moving or removing a class you asked it to, locking one in place, or opening a screen. Cherrypicker validates every one of those against your current plan before it happens, and never creates or edits coursework records.
- Plan generation. Cherrypicker’s deterministic planner builds, validates, scores, and chooses your plan; no model ranks or selects it. A model is used for one thing: if you typed new planning preferences, that text is sent on its own to be turned into structured preferences (for example “keep Spring light”) that the deterministic planner then enforces. With the preferences box empty or unchanged, Generate Plan sends nothing to any model.
- Schedule preferences. Cherrypicker reads common preferences (“nothing before 10”, “I work Tuesdays 4 to 6”) with a deterministic parser and sends nothing anywhere. Only when that parser cannot read what you typed is that one line—by itself, with no plan, schedule, or conversation—sent to be interpreted into the same preference chips. Schedules themselves are always generated by Cherrypicker’s deterministic solver.
- Transcript parsing. Only the individual lines the deterministic parser flags as low-confidence, as described above.
Turning Personalized Ask off removes your goals, plan snapshot, and planning notes from Ask requests; Ask keeps working from public course, prerequisite, articulation, and section-availability sources. Cherrypicker does not send your grades to any of these features, and its deterministic solver—not an AI model—generates schedules.
Anthropic acts as a service provider processing this information to return a response to Cherrypicker. Cherrypicker does not control Anthropic’s own handling of that information; Anthropic’s practices are governed by its own terms and privacy policy. Cherrypicker may change or add AI service providers, and will update this policy when it does.
Friend Mode
Friend Mode is optional sharing between people, not a public feature. Having Friend Mode enabled in your settings does not make your schedule visible to anyone. Information is shared only inside a planning group you intentionally join, and only after several separate steps: someone creates a group and gives you a single-use invite code directly, you redeem that code, and you then explicitly accept the membership. There is no way to find, request, or be added to another person’s group by searching for their name or email address.
Within a group, each member chooses what they share—by default, nothing. You pick which of your own course codes, and whether redacted busy-time blocks, a lunch preference, or a display label, the group’s schedule optimizer may use. Group scheduling results are computed in your browser from what members have chosen to publish.
Leaving a group, or the group expiring or being deleted by its creator, cuts off access immediately; rejoining requires a new invite. Turning Friend Mode off in your settings stops you from creating or joining groups going forward and does not delete your plan, schedule, or other academic data.
Aggregated and deidentified information
This feature is not active yet. Turning Anonymous product insights on does not currently send, store, or aggregate any planning data — the code that would collect and aggregate it exists in Cherrypicker’s codebase, but nothing in the running product calls it, and no automated job runs it on a schedule. No insights are published in the product today. The setting is on by default and can be changed at any time; your choice is recorded now and will apply from whenever, if ever, Cherrypicker turns this feature on.
If Cherrypicker activates this feature, it is designed to work as follows: with Anonymous product insights on, planning information such as the courses and terms in your plan would be stored under your account identifier — pseudonymous rather than anonymous at that stage — until aggregated; only the published aggregates would be deidentified. A published statistic would be computed only for groups of at least 10 students—smaller groups dropped entirely rather than published—and would report a size range instead of an exact count. The contributions would cover planned courses, terms, unit loads, planned transfer duration, and backup courses; grades, transcript rows, and contact details would not be among them.
Turning this setting off ensures nothing of yours is ever contributed once the feature is active, and deletes anything already stored for your account under it. This policy will be updated, with a revised “Last updated” date, before Cherrypicker turns this feature on.
Your privacy choices
Account Settings → Privacy & personalization holds the choices described above: Personalized Ask, Anonymous product insights, and Friend Mode, each on by default because they are part of how the account works, plus Opportunity personalization when that feature is available. Each is independent, each can be changed at any time, and a change applies going forward. Cherrypicker does not overwrite a setting you have changed. You can also sign out or delete your account as described under “Retention and deletion.”
Service providers and external sources
Cherrypicker relies on Supabase for authentication and database services, Vercel for web hosting and transcript-function infrastructure, Anthropic for the AI processing described above, Google for OAuth sign-in and, if you connect it, Calendar sync, and Stripe for Cherrypicker Premium payments and subscription management. Stripe receives the billing information you give it and an identifier linking the subscription to your account; no transcripts, coursework, grades, goals, or other academic data are sent to Stripe. Repository automation may run through GitHub Actions. The app also links to or uses public academic information from sources such as Foothill, De Anza, FHDA, ASSIST, UC, CSU, institution websites, and RateMyProfessors. Those third parties have their own privacy practices.
How information is used
Cherrypicker uses information to provide authentication, save and evaluate academic goals and coursework, generate plans and possible schedules, remember preferences, show account information, process transcripts, operate community reviews and bug reports, prevent abuse, troubleshoot the service, and improve academic data and features. Cherrypicker also uses aggregated and deidentified information for product improvement, usage analysis, service analytics, and understanding academic planning patterns, as described above.
Cherrypicker does not sell personal information.
When information may be shared
Two different things are worth keeping apart. Service-provider processing is Anthropic, Supabase, Vercel, Google, and Stripe handling information so they can perform a function Cherrypicker asked them to perform. User-directed sharing is you choosing to show something to another person, through Friend Mode or a public community feature. Friend Mode existing does not mean Cherrypicker sells or discloses schedules; nothing is shared with another user unless you connect with them and choose what they see.
Information may be disclosed:
- to the service providers identified above so they can operate Cherrypicker;
- to the members of a planning group you intentionally join, limited to what you choose to share with that group;
- when you intentionally submit information to a public feature, such as a review, CSU manual entry, or non-hidden bug report;
- to comply with law, legal process, or a valid government request;
- to investigate abuse, protect users, enforce terms, or protect rights and service security; or
- as part of a merger, financing, reorganization, acquisition, or transfer of the project, subject to this policy or notice of changed practices.
Retention and deletion
Account information is kept while your account is active and as needed to provide the service. Public community submissions may remain until deleted, withdrawn, moderated, or no longer needed. Operational records may be retained for a reasonable period where needed for security, legal obligations, backups, or dispute resolution.
Some records end sooner. Planning groups carry a required expiry date, after which member access ends; a group’s creator can delete it, and leaving a group ends your access immediately while keeping the minimal record that you were a member. Turning off anonymous product insights deletes the contributions stored for your account right away.
A signed-in user can choose “Delete account” from the account menu or Account Settings. The current deletion endpoint deletes the Supabase Auth user; every account-owned database table is configured to delete its rows for that user when the account is deleted. This includes every category of Supabase-stored account information described earlier in this policy — your profile, transcript rows, reviews, manually reported CSU progress, Privacy & personalization settings, Friend Mode group membership, subscription and entitlement records, rate-limit records, bug reports, and, if connected, your Google Calendar sync credentials and synced-event records. Deleting your account does not, by itself, cancel or refund an active Stripe subscription; contact the email below to manage or cancel billing separately. Device-local data is separate: clear Cherrypicker’s site data in your browser to remove it. If account deletion is unavailable or fails, email the contact below to request help with account and associated-data deletion.
Security
Cherrypicker uses access controls and server-side handling intended to limit unauthorized access, including database row-level rules for account-owned data. No online service can promise perfect security. Use care with sensitive information and do not put student IDs, passwords, full transcripts, or other private information into public reviews or bug reports.
Children’s privacy
Cherrypicker is intended for college planning and is not directed to children under 13. Cherrypicker does not knowingly collect personal information from children under 13. If you believe a child under 13 provided personal information, contact Cherrypicker so it can be reviewed and deleted.
Changes to this policy
This policy may change as Cherrypicker’s features and providers change. The updated policy will be posted here with a revised “Last updated” date. Material changes may also be communicated through the service when practical.
Questions?
Contact Cherrypicker at admin@cherrypickerapp.net.