Legal
Privacy Policy
Last updated: July 19, 2026
This policy explains what information Cherrypicker handles when you use its academic planning and scheduling tools, where that information goes, and the choices you have.
What Cherrypicker is
Cherrypicker is an independent academic planning tool for students, especially Foothill and De Anza students planning transfer pathways, degrees, certificates, coursework, and schedules. It is not a college service, enrollment system, or official academic record.
Information you provide
Depending on the features you use, you may provide:
- selected colleges, universities, majors, transfer goals, degree or certificate goals, and a primary goal;
- completed or in-progress courses, grades, units, quality points, terms, college, and transfer or other credit information;
- future-quarter plans, manually added courses, preferred schedules, tracked CRNs, registration priority group, availability, modality and campus preferences, and instructor preferences;
- instructor ratings, optional review text, course and term context;
- CSU articulation progress you enter manually, including course codes and an optional note;
- bug reports and the optional context you include; and
- messages you send to the scheduling assistant.
Google sign-in information
Cherrypicker uses Google OAuth through Supabase Auth. Google and Supabase may provide Cherrypicker with your name, email address, profile image, and Google account identifier. Cherrypicker uses this information to authenticate you, create and manage your account, associate saved information with your account, and display account information such as your name, email, or initials.
Cherrypicker does not request your Google password or access to Google Drive, Gmail, Calendar, contacts, or school-portal credentials. Google account information is stored and processed through Supabase authentication and is not sold. It is shared only with service providers that operate the service, when required by law or safety needs, or as described under “When information may be shared.”
Transcripts and academic records
You may upload an unofficial transcript PDF, up to 8 MB, for parsing. The PDF is sent through Cherrypicker’s server to a separate transcript-parsing function hosted on Vercel. That function temporarily writes the PDF while it parses it, deletes the temporary file afterward, returns structured course rows, and does not intentionally persist the PDF. Responses are marked not to be cached.
The parser first uses deterministic extraction. If it cannot confidently read particular lines, only those flagged lines—rather than the full PDF—may be sent to Anthropic’s API to recover structured course information. You review and can correct parsed results before confirming them. Confirmed structured rows may then be stored; the PDF itself is not stored in Cherrypicker’s database. Do not upload records you are not authorized to use.
Information stored with Supabase
For signed-in users, Supabase may store:
- authentication records and account metadata received through Google;
- a profile with display name, goals, primary goal, scheduling constraints, registration group, tracked CRNs, and last transcript-update quarter;
- confirmed structured transcript course rows;
- instructor reviews and their course or term context;
- manually reported CSU articulation progress;
- bug reports, rate-limit records, and account-related identifiers used to enforce ownership and abuse controls.
Public catalog, section, requirement, articulation, link, seat-cache, and community data also live in or are designed to load into Supabase, but are not private student records. Instructor reviews are public. Manually reported CSU course lists and notes are currently readable as community data. Non-hidden bug reports are public, but the public bug-report interface and database permissions do not expose the reporter identifier.
Information kept on your device
Cherrypicker uses browser local storage for essential preferences and app state, including theme, onboarding status, goals, plans, manually added courses, chosen schedules, tracking, review prompts, and—in demo or signed-out mode—academic rows, reviews, constraints, and CSU manual entries. Some signed-in features also keep a local copy or device-only state. Clearing site data in your browser removes this device storage.
Supabase uses cookies or similar browser storage to maintain authentication sessions. Cherrypicker does not currently include advertising cookies or a separate analytics, advertising, or behavioral-tracking SDK.
AI services
Cherrypicker uses Anthropic in two limited places. The scheduling chat sends the messages in your current chat, your active constraint labels, and relevant course-section data to Anthropic so the model can translate scheduling requests into proposed constraints. It does not send your transcript through that chat route. Separately, flagged transcript lines may be sent to Anthropic as described above. Cherrypicker’s deterministic solver—not an AI model—generates schedules.
Service providers and external sources
Cherrypicker relies on Supabase for authentication and database services, Vercel for web hosting and transcript-function infrastructure, Anthropic for the limited AI processing described above, and Google for OAuth sign-in. Repository automation may run through GitHub Actions. The app also links to or uses public academic information from sources such as Foothill, De Anza, FHDA, ASSIST, UC, CSU, institution websites, and RateMyProfessors. Those third parties have their own privacy practices.
How information is used
Cherrypicker uses information to provide authentication, save and evaluate academic goals and coursework, generate plans and possible schedules, remember preferences, show account information, process transcripts, operate community reviews and bug reports, prevent abuse, troubleshoot the service, and improve academic data and features.
Cherrypicker does not sell personal information.
When information may be shared
Information may be disclosed:
- to the service providers identified above so they can operate Cherrypicker;
- when you intentionally submit information to a public feature, such as a review, CSU manual entry, or non-hidden bug report;
- to comply with law, legal process, or a valid government request;
- to investigate abuse, protect users, enforce terms, or protect rights and service security; or
- as part of a merger, financing, reorganization, acquisition, or transfer of the project, subject to this policy or notice of changed practices.
Retention and deletion
Account information is kept while your account is active and as needed to provide the service. Public community submissions may remain until deleted, withdrawn, moderated, or no longer needed. Operational records may be retained for a reasonable period where needed for security, legal obligations, backups, or dispute resolution.
A signed-in user can choose “Delete account” from the account menu or Account Settings. The current deletion endpoint deletes the Supabase Auth user; account-owned database rows that reference that user are configured to delete with the account. This includes the profile, transcript rows, reviews, rate-limit records, manual CSU entries, and bug reports. Device-local data is separate: clear Cherrypicker’s site data in your browser to remove it. If account deletion is unavailable or fails, email the contact below to request help with account and associated-data deletion.
Security
Cherrypicker uses access controls and server-side handling intended to limit unauthorized access, including database row-level rules for account-owned data. No online service can promise perfect security. Use care with sensitive information and do not put student IDs, passwords, full transcripts, or other private information into public reviews or bug reports.
Children’s privacy
Cherrypicker is intended for college planning and is not directed to children under 13. Cherrypicker does not knowingly collect personal information from children under 13. If you believe a child under 13 provided personal information, contact Cherrypicker so it can be reviewed and deleted.
Changes to this policy
This policy may change as Cherrypicker’s features and providers change. The updated policy will be posted here with a revised “Last updated” date. Material changes may also be communicated through the service when practical.
Questions?
Contact Cherrypicker at emamienzo@gmail.com.
CHERRYPICKER