Privacy Policy for Jupiterp

Last Updated: August 14, 2026

Introduction

Welcome to Jupiterp. We are committed to protecting your personal information and your right to privacy. This Privacy Policy governs your use of the Jupiterp website and explains how your data is collected, used, and protected when you use our authentication services, including Google Sign-In.

What Data We Collect

When you sign in using Google OAuth, we request access to the minimum requisite information necessary to implement our services. Specifically, we collect your email address, your basic profile information (such as your name), and any course schedules that you create while using our application.

Why We Request Your Data

We use your email address as a unique identifier to securely manage and maintain your account. The primary purpose of collecting this information is so we can save your created course schedules to your specific account, allowing you to reliably access and utilize your personalized schedules across multiple sessions or devices.

How Your Data is Used and Shared

Your data is strictly used for the core functionalities of Jupiterp—to authenticate your identity and store your schedules securely. We do not sell, rent, or distribute your email, profile information, or any user data to any third-party data brokers, advertising platforms, or information resellers. Furthermore, your data will not be accessed, aggregated, or analyzed for external sale or distribution to any party conducting surveillance.

Jupiterp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Professor Reviews

This section covers what happens when you submit a review of a professor. It applies only if you choose to write one; browsing Jupiterp requires none of it.

What we collect

  • Your email address, which we never store. On submission it is converted to an irreversible hash using a secret value held outside the database. We keep the hash and the domain (terpmail.umd.edu or umd.edu) and discard the address itself. We cannot recover it, we never display it, and the professor never sees it. The hash exists to check you are at UMD and to stop the same person reviewing the same course repeatedly.
  • The review itself: your rating, and whatever you write. This is published if it is approved.
  • Your IP address and browser user-agent, also stored only as hashes, and only to investigate abuse. These are deleted after 90 days, and immediately if you withdraw the review.

Your email address is held in plain text in one place and for one purpose: the queue that sends your confirmation message. It is erased from that queue as soon as the message is sent.

Automated classification

Reviews may be sent to Google's Gemini API to be classified against our review policy, so that the ones needing a closer look are identified. What is sent is the review text, the rating, and the course and instructor it concerns. No identifying information is sent: not your email address, not its hash, not your IP address.

We use Gemini's free tier. Google's terms for the free tier permit them to use content submitted through it to improve their products, including for human review. That is a meaningfully different arrangement from a paid tier, and you should know about it before you write anything: text you submit as a review may be read by people at Google and may be used to train their models. It is not linked to you, because we do not send anything that identifies you.

If you would rather this did not happen to something you have written, do not submit it as a review.

A classifier never makes the final call on its own where it matters. Reviews touching on allegations about a specific person are always read by a person.

Deleting a review

Use the management key you were given when you confirmed the review. Withdrawing it erases the text and the abuse hashes. A record that a review existed is kept so that the one-review-per-course rule continues to work; it contains no content and nothing that identifies you beyond the same irreversible hash.

Content already sent to Google for classification is outside our control once sent, which is another reason the paragraph above is worth reading before you write.

Other services involved

  • Brevo sends the confirmation email, and receives your address to do so.
  • Cloudflare Turnstile checks that submissions come from a person. It sets no cookie and collects no personal data.
  • Supabase hosts the database, in the United States.

Data Security

We take reasonable and appropriate steps to protect all applications and systems that make use of Google API Services to ensure that user data is secure in transit and at rest against unauthorized or unlawful access, use, destruction, loss, alteration, or disclosure.

Changes to This Policy

Jupiterp reserves the right to modify this Privacy Policy at any time. If we change the way your application uses Google user data, we will notify users and prompt them to consent to an updated privacy policy before making use of that data in a new way.

Contact Us

For any questions or concerns regarding these policies, please contact us at admin@jupiterp.com.