Privacy
Your password, your data, and how to delete it
The short version: you type your passwords into the platforms' own sign-in pages, inside a browser we rent from Kernel and show you live. We never see or store a password. We keep an encrypted copy of the signed-in session so we can check your work for you, plus what we read from your courses. You can delete one platform or everything, at any time.
Where you type your password
When you press Connect, we start a real web browser on a server run by Kernel (onkernel.com) and stream it into our page, the “live view”. It opens the platform's own sign-in page: CUNY Login for Brightspace and BMCC email, Cengage for WebAssign, MyOpenMath's own page. What you type there, your password and your authenticator code included, goes to that remote browser and from it to the platform, the way it would from any browser. It never passes through our website's servers, and we never see or store it.
It never passes through our servers. We never see or store it.
The live view is allowed to use your clipboard, so you can paste a password from a password manager: what you paste goes to the remote browser, as if you had typed it. Our page cannot read what you type or paste there.
Once you are signed in, our worker notices by itself and shuts the remote browser down. Kernel keeps that browser's profile (its saved cookies, like any browser keeps you signed in); we keep only an id that points to it.
What we keep
- Your signed-in sessions, encrypted.For Brightspace, WebAssign and MyOpenMath, the session cookies from your sign-in; for BMCC email (Outlook), only a note that you connected. We never store, log or use a Microsoft cookie or token: when you sign in and during each sync, our worker reads the remote browser's cookies only to check that you are signed in, and keeps none of them. Each stored session is encrypted (AES-256-GCM) and locked to its own connection.
- Your courses and work.Course names and codes, instructors' names and email addresses when the platform shows them; assignments with their due dates, instructions, links and whether they were handed in; what your syllabi say about grade weights, late work and dates; and which homework platforms your courses use.
- Dates waiting in Review.When an instruction, a syllabus or a professor's email mentions a deadline, we keep a one-line summary and the few words the date came from; for an email also its sender, subject and sent time. We never store an email's body.
- Which emails were already read.So none is read twice: a fingerprint of each message's sender, subject and time. We also keep your BMCC mailbox address, read from your Outlook page, to show “Connected as”. And for each email sender we asked you about, or that you marked as your professor, their name and address and your answer.
- Copies of what we asked Claude.About assignment instructions, syllabi and WebAssign or MyOpenMath pages, with Claude's answers, so we can check and improve how pages are read. Course enrollment keys and anything after the “?” in a web address are removed first. Email text is never kept this way. These copies are kept until you delete your account (disconnecting a platform does not remove them).
- Sync records.When each sync ran, how long it took, counts and warnings (which can name a course or an assignment), and when your sign-in was last seen working.
- Your account.Your email address (you sign in with it) and your time zone.
- The sign-up list.The email address you left on the home page, the school you picked, when you signed up, the tag in the link you came from (such as “reddit”), your beta spot number if you got one (and whether it is still held for your first sign-in or confirmed by it), and when we last emailed you a sign-in link. It is how we decide who can use the site and how we tell you when more spots, or your school, open up. It is never sold or shared, and nothing about you is ever sent to our Discord: the Discord is a separate, public community you may join or not. To stop a flood of sign-ups, the server also counts sign-ups per network address for ten minutes, in memory only, under a scrambled key rather than the address itself; that count is never stored.
- Page recordings, for debugging only.The site's operator can have the pages a sync or a sign-in reads saved to the server's disk, to fix how pages are read. This works only for accounts whose ids the operator lists on the server, which is meant for the operator's own account; nobody else is ever recorded. A BMCC email (Outlook) recording keeps only each page's layout: every name, address, subject, preview and message text is masked in the browser before anything is saved. A WebAssign recording keeps the pages as they were. Recordings are never put in our database, and a platform's recordings are deleted when you disconnect it or delete your account. On this server recordings are switched off.
- Shared hints about the platforms' pages (not about you).When a sync learns which button or link leads where, it keeps the button's short text and the page it points to (never anything after the “?”), so later syncs, for every student, can go straight there. These name nobody and stay after you delete your account.
Your email
Before anything is opened, each message is judged on its sender alone. We open messages from your professors: the addresses your courses and syllabi list, senders you told us are your professors, and senders of an email whose Review item you accepted (accepting it marks that sender as your professor). We also open mail from a CUNY college's own staff domain on our list (for BMCC, bmcc.cuny.edu).
Mail from a CUNY-wide address (cuny.edu or login.cuny.edu, which students have too) is not opened until you confirm the sender is your professor: Review asks you “Is this one of your professors?”. Until you answer, we keep only that sender's name and address, never the subject or any of the text. Yes means the next email sync reads their messages that are still in its window (at most the last 30 days); No means their mail is never opened. You can change either answer on Review.
We never open mail from a CUNY student address (such as stu.bmcc.cuny.edu or stu-mail.bmcc.cuny.edu, or another college's student domain), from any other cuny.edu address, from outside CUNY, or from no-reply and mailing-list senders, unless it is one of your professors as above. The text of a message that passes goes to Claude to find deadlines and is then dropped. For BMCC email, if opening a message makes Outlook mark it as read, the sync tries to mark it unread again when it was unread before, and notes it when it could not.
Who else handles your data
Kernel
Runs the remote browsers: your sign-ins, the syncs of WebAssign, MyOpenMath and BMCC email, and a Brightspace re-login when its session ends. It keeps each connection's browser profile until you disconnect.Supabase
Hosts our database (everything under “What we keep”) and the email sign-in to this site.Anthropic
Claude reads assignment instructions, syllabi, the professor emails that passed the sender check and, when needed, WebAssign and MyOpenMath pages, to find due dates. When a WebAssign, MyOpenMath or Outlook page is laid out in a way we do not know, Claude also picks the next button to press; on Outlook it sees only the page's buttons, never mail.PostHog
Product analytics and error reports, switched on on this server. When it is on it can receive page views (the page address without anything after the “?”, and your IP address and browser type, as any website visit does), a few named events about what you did and how it went, and error reports from our servers and your browser carrying an error's type and a message with addresses, links, tokens and quoted titles removed. The events are: a “Get early access” or “Join the Discord” button was pressed, and where on the page; the claim-a-spot form or the sign-in page answered, and how (a spot, the waitlist, welcome back, a mistake in the form, too many tries or an error), with the school picked from our list; a sign-in through the emailed link finished; a connection was started, succeeded or failed, with the platform's name and at which step; a sync was asked for; a day was picked on the agenda; an assignment was marked done. Each carries only labels from a fixed list like those, or a yes/no. To count a finished sign-in once, the link leaves a small cookie that says only that it worked; the next page reads and deletes it. Nobody is identified: PostHog keeps a random id in your browser so one browser's events can be followed from page to page, and it is never tied to your account, your name or your email. Never a recording of your screen, the text of a page, what you typed, your name, your email address or anything from your courses or mail.
The platforms themselves (CUNY's Brightspace and Microsoft 365, Cengage, MyOpenMath) see our syncs as your own signed-in browser, reading your pages.
How to delete it
- One platformOn Sources, press Disconnect. That deletes its stored session and its browser profile at Kernel (and, for email, the record of which messages were read, the questions about senders and your answers to them). Your courses and assignments stay, so a reconnect picks them straight back up.
- EverythingDelete my account, below. It first signs you out on every device, then deletes every connection with its browser profile at Kernel and any page recordings, your courses, assignments, Review items, email sender answers, syllabus facts, sync records and the copies of what we asked Claude, your account record in our database (it is created only when you sign in, so it stays deleted unless you sign in again), and your place on the sign-up list (a beta spot you held is given to the next person). Your sign-in record at Supabase is deleted too.
- Only on the list, never signed inThere is nothing else about you to delete, and we take your email off the list when you ask: send the site's owner a direct message on the Discord (invite link coming soon) (never post your address in a channel).
What we cannot reach: text already sent to Anthropic is handled under Anthropic's own terms for its API; Kernel and Supabase keep their own service logs. Our job queue keeps records that point at your connections by internal id (never your name, address or any content) for up to seven days after each job finishes, and the running server's log output can show internal ids and course or assignment names from sync warnings.
Sign in to delete your account.