Last updated August 29, 2026
Privacy
You hand Sorted your syllabus, which means you hand it your semester. This page says exactly what happens to it, who else touches it, and how to make all of it disappear.
What this covers
This describes Sorted, the web app and the browser extension that pairs with it. It does not cover your school, your school’s learning management system, or anything else you reach from a link here.
Sorted is not a school and is not part of one. It receives nothing from your registrar. Everything it holds arrived because you uploaded it or because you connected an account and told it to.
What you give us
- Your account. Email address and the name you enter. If you sign in with Google, Google also sends your name and profile picture.
- Your syllabi. The files you upload, kept as you sent them, plus the text pulled out of them so extracted dates can be checked against the document.
- Your semester. Courses, assignments, exams, due dates, grade weights, meeting times, and whatever you mark done.
- Connected accounts. If you connect Canvas or pair the browser extension, we store the access tokens that make the connection work and the coursework it syncs back.
- Payment, if you subscribe. Your card details go to Stripe and never to us — we cannot see them and do not store them. What we keep is Stripe’s id for you, which plan you are on, and when the period ends.
What we collect without asking
A session cookie, so you stay signed in. Two values in your browser’s own local storage: whether you chose light or dark, and your recent conversation with the assistant so it is still there after a reload. That conversation is held by your browser and is never sent to us or stored on our servers — clearing it is the “new chat” button in the assistant panel, or clearing site data. Ordinary server logs, which include IP addresses and are kept short.
No analytics, no advertising trackers, no third-party scripts. There is nothing on this site measuring you for anyone else’s benefit.
Who else touches it
- Supabase hosts the database, the file storage, and sign-in. Your data lives on their infrastructure in the United States.
- OpenAI reads your syllabus, and answers your questions. Two separate things happen there, and both should be said plainly.
- Uploading. The file is sent to OpenAI so a model can extract the coursework from it. The uploaded copy is deleted from OpenAI as soon as the extraction finishes, successfully or not.
- Asking. Every question you put to the assistant is sent to OpenAI together with a summary of your semester, so it can answer from your real deadlines instead of guessing: your course codes and titles, your coursework titles and due dates, and your grade weights. Whatever you type into it goes too.
- Stripe only if you subscribe. Stripe takes the payment and holds the card; we send it your email address so it can send you receipts, and an identifier for your account so a payment can be matched to it. Stripe is the payment processor, not an advertiser, and what it does with payment data is governed by its own privacy policy.
- Google only if you choose Google sign-in, and only to confirm it is you.
- Your school’s LMS only if you connect one, and only to read your own coursework. Sorted never writes anything back to it.
Nothing is sold, rented, or handed to advertisers. There is no arrangement under which anyone pays for access to what you upload.
Who can read your semester
You. Every table is protected by row-level security keyed to your account, and your uploaded files live in a private bucket where the path itself has to start with your user id. Another student cannot read your coursework even by guessing a URL.
People operating Sorted can reach the database, because someone has to be able to fix it. That access is used to keep the service running and to investigate problems you report, not to browse.
How long we keep it
Until you delete it. There is no scheduled purge and no archive you cannot reach.
Deleting a course deletes its coursework. Deleting your account, from your profile, removes your uploaded files from storage and then deletes the account itself, which cascades every row attached to it: courses, assignments, syllabi, extraction records, connected portals, and paired browsers. It happens immediately, it is not reversible, and there is no backup copy held for you afterwards.
What you can do
- Change your name and time zone from your profile.
- Disconnect a school portal or revoke a paired browser at any time.
- Delete your account yourself, without asking anyone.
- Ask for a copy of what we hold, or for a correction, by writing to wrkt.yt@gmail.com. There is no one-click export yet; we will assemble it by hand.
Security, stated plainly
Traffic is encrypted in transit. Data is encrypted at rest by our hosting provider. Authorization is enforced in the database itself rather than only in application code, so a bug in a query cannot hand one student another student’s semester. Tokens for connected portals are never readable by the browser.
No system is proof against everything, and claiming otherwise would be the first dishonest sentence on this page. If something goes wrong that affects you, you will hear it from us.
Age
Sorted is built for university students and is not intended for anyone under 13. If we learn that an account belongs to someone under 13, we delete it.
Changes
If this policy changes in a way that affects what happens to your data, the date at the top changes and we tell account holders by email. Editing a sentence for clarity does not get an email; changing where your syllabus goes does.
Contact
Write to wrkt.yt@gmail.com. A real person reads it.