Privacy Policy
BenchWork("we," "us," or "our") provides a web application designed to help college student-athletes organize their academic and athletic schedules, track coursework and grades, monitor eligibility-related information, and communicate with professors, coaches, and advisors.
This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. By creating an account or using the Service, you agree to the practices described in this policy.
Information We Collect
We collect the following categories of information:
Account information. Your email address and a password. Passwords are handled entirely by our authentication provider, Supabase Auth, and are stored only as one-way cryptographic hashes. BenchWork never receives, stores, or has any way to read your plain-text password.
Profile information. Your name and any other profile details you choose to provide.
Academic data.Information you input or upload, including course schedules and class times, class syllabi (uploaded as PDF or text files), grades and GPA, your school's minimum eligibility GPA threshold (if you choose to enter it), and academic tasks, assignments, and to-do items.
Athletic and calendar data. Practice times, games, travel schedules, exam dates, season start/end dates, and other calendar events you create or import.
Communications content. Draft emails generated by the Service for communicating with professors, coaches, or advisors, along with any context you provide to generate them.
Payment and subscription status. We know whether you have an active subscription, trial status, and plan type (monthly or annual). We do not collect or store your credit card number or other raw payment card data — all payment processing is handled directly by Stripe, our payment processor.
Notification token. If you turn on reminders in the iPhone app, we store the notification token Apple issues for that device so reminders can be delivered to it. The token identifies the installation, not you, and turning reminders off removes it.
Face ID.If you enable Face ID sign-in, the check happens on your device and your face data never leaves it — Apple does not share it with apps. All BenchWork stores is a sign-in token held in your device's Keychain, which is cleared when you log out or disable the feature.
Canvas connection. If you connect Canvas, we store the access token you provide and the coursework, assignments, and due dates we read with it. We never receive your Canvas password, and disconnecting or deleting your account removes the token.
Usage and technical data. Basic technical information such as log data, device/browser type, and general usage patterns, collected to keep the Service running reliably and securely.
We do not knowingly collect any information beyond what is described above, and we do not collect special categories of data (such as health, financial account numbers, or government ID numbers) unless you voluntarily include such information in free-text fields, which we discourage.
How We Use Your Information
We use the information we collect to:
- Create and maintain your account and authenticate your logins
- Provide the core features of the Service — organizing your schedule, tracking assignments and grades, calculating GPA-related eligibility indicators you configure, and displaying your calendar
- Parse and import schedules and syllabi you upload, so the information can be turned into structured calendar events and tasks
- Generate draft emails to professors, coaches, or advisors, based on the context you provide, for you to review and send yourself
- Process payments and manage your subscription (via Stripe)
- Communicate with you about your account, changes to the Service, or support requests
- Maintain the security, integrity, and reliability of the Service
- Improve and troubleshoot the Service
We do not use your data to serve ads, and we do not sell your personal information or academic data to data brokers or any other third party. We have no data broker relationships.
AI Processing Disclosure
BenchWork uses OpenAI's API (GPT-4o) to power two specific features, and this involves sending some of your content to OpenAI for processing:
1. Schedule and syllabus parsing.When you upload a syllabus or schedule to be automatically converted into calendar events, tasks, or assignments, the text content of that file is sent to OpenAI's API so it can extract dates, deadlines, and other structured information on your behalf.
2. Email draft generation.When you use the Service to generate a draft email to a professor, coach, or advisor, the context you provide is sent to OpenAI's API to generate a draft for your review.
What this means for you:
- Content you upload for these two features is transmitted to OpenAI as part of generating a response. It is not sent to OpenAI for any other feature of the Service.
- OpenAI processes this data under its own API data usage terms. As of this policy's effective date, OpenAI does not use data submitted through its API to train its models by default, but you should review OpenAI's API data usage policies for the most current information.
- AI-generated output is a starting point, not a finished product — see the "AI-Generated Content Disclaimer" in our Terms of Service. Always review AI-generated content before relying on it or sending it to anyone.
- We do not use your academic data to train our own models, and we do not have any model of our own.
If you do not want your syllabus or schedule content processed by OpenAI, you can enter your schedule manually. If you do not want to use AI-generated email drafts, you can write emails yourself outside the Service.
Third-Party Service Providers
We rely on a small number of trusted third-party service providers ("subprocessors") to operate BenchWork. We do not sell your data to these providers — they process it strictly on our behalf, to provide the Service to you:
- Supabase— Hosts our database and file storage. All account data, academic data, calendar data, and uploaded files are stored on Supabase's infrastructure.
- OpenAI — Processes syllabus/schedule content you upload and email context you provide, as described above.
- Stripe — Handles all payment processing, subscription billing, and the self-serve billing portal. Stripe collects and stores your payment card details directly — we never see or store your raw card number.
- Vercel — Hosts the BenchWork web application itself.
Each of these providers has its own privacy policy governing how they handle data on our behalf: Supabase, OpenAI, Stripe, Vercel.
We may add or change subprocessors over time as the Service evolves. If we make a material change to who processes your data, we will update this policy and, where appropriate, notify you.
Data Storage & Security
Your data is stored in the Supabase database and storage infrastructure associated with our account. We take reasonable, industry-standard measures to protect your information, including storing passwords only as salted cryptographic hashes, using encrypted connections (HTTPS/TLS) throughout, and limiting access to production data to what is necessary to operate and support the Service.
However, no method of electronic storage or transmission is 100% secure. While we work hard to protect your information, we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify you as required by applicable law.
As a small, solo-founder operation, our security program is appropriately scaled to our size — we do not currently maintain enterprise-grade certifications (such as SOC 2 or ISO 27001), and we are transparent about that so you can make an informed choice about the data you share with us.
Data Retention
We retain your account and academic data for as long as your account remains active. If you request deletion of your account, we will delete your personal information and associated academic data from our active systems within a reasonable period, except where we are required or permitted to retain certain information for legitimate purposes such as complying with legal obligations, resolving disputes, or maintaining accurate financial/billing records (which may be retained by Stripe independently).
Backup copies of data may persist for a limited additional period before being fully purged.
Your Rights & Choices
You have control over your data. Specifically, you can:
- Access your data at any time by logging into your account.
- Export your data by contacting us at hello@benchwork.app.
- Correct inaccurate information directly within the app or by contacting us.
- Delete your account and everything in it at any time from inside the app: open Settings, then Delete account. Deletion is immediate and permanent, and it cancels any subscription billed through our website. If you would rather we did it for you, email hello@benchwork.app.
- Manage your subscription — including canceling — at any time via the self-serve Stripe billing portal.
If you are a resident of a jurisdiction that provides additional statutory privacy rights, contact us and we will do our best to accommodate applicable requests.
Because grades, GPA, and course information are data you choose to input, you control what academic information exists in your BenchWork account.
Children's Privacy
BenchWork is intended for users who are 13 years of age or older, and our primary audience is college students who are 18 or older. The Service is not directed at or intended for children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly.
If you are between 13 and 18 years old, please be aware that BenchWork is a paid subscription product, and you should have a parent's or guardian's awareness and permission before subscribing.
Cookies
We keep our use of cookies minimal. BenchWork primarily uses a single authentication session cookie to keep you logged in securely between visits. We do not use advertising cookies, third-party tracking cookies, or cross-site behavioral tracking. Our payment provider, Stripe, may set its own cookies during checkout or when you access the billing portal.
Changes to This Policy
We may update this Privacy Policy from time to time as the Service evolves. If we make material changes, we will update the "Effective Date" above and, where appropriate, notify you directly. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at hello@benchwork.app.