Legal

Privacy Policy

Last updated: 26 August 2026

This policy explains how Untitled Management Software (“UMS,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use our web and mobile apps and launch pages.

Operator, scope, and age

UMS is operated by Elijah Lopez, trading as Untitled Management Software, an unincorporated business. The service is presently offered in Ireland and the United States. UMS is intended for users who are at least 16 years old. We do not knowingly collect personal information from anyone under 16.

Information we collect

We collect account information you provide, including your name, email address, profile details, authentication data handled through Firebase, and verified primary or secondary account email addresses. For eligible UCD or Palomar promotional access, we store the qualifying email, verification source and time, the relevant ucd_autumn_2026 or palomar_autumn_2026 entitlement, and its active and read-only boundaries.

We store schoolwork and productivity information you add or approve, such as courses, assignments, class sessions, events, notes, course links, due dates, descriptions, locations, study plans, and the corrections and course associations you make during an import. Brightspace agenda PDFs and Canvas .ics calendar files are parsed in your browser; UMS does not upload or retain either raw file or its raw text. Only normalized items you select are sent to UMS for saving. If you connect Google Calendar, UMS can read the calendars you choose and stores the events you confirm through the normal calendar-sync feature.

If you use Google sign-in or optionally connect Google Calendar, we receive the Google account information and calendar permissions needed for the feature. Connection tokens are encrypted until you disconnect Calendar or delete your account. UMS does not request or store Canvas credentials or Canvas calendar-feed tokens. Payment card details are processed by Stripe and are not stored directly by UMS.

If you join a UCD incoming-student, Palomar incoming-student, or iOS waitlist, we collect your normalized email, the specific list you selected, list-specific consent, optional and separate general-marketing consent, confirmation and unsubscribe status, submission time, and limited attribution values such as campaign, ambassador, society, referral, and session codes. Each waitlist and its consent record are separate.

Consent records

When you give or withdraw a consent, we keep a separate, unaltered record of that choice: the date, which consent it was (waitlist list consent, general-marketing consent, or an unsubscribe), whether it was given or withdrawn, and the exact wording you were shown at the time. If you start a paid subscription while eligible for immediate access under a promotional launch offer, we record in the same way your acknowledgment that you are waiving the standard 14-day right to withdraw from an online purchase. We keep these consent records so we can show what you agreed to if a consent is ever disputed; we do not use them for marketing or profiling.

First-party product measurement

We collect limited first-party events needed to understand the UCD and Palomar launch funnels, including landing-page CTA clicks, AI-free explainer views, signup, school verification, onboarding milestones, reviewed and saved import counts, Calendar connection, study-plan use, PWA installation, waitlist confirmation, and account export. We preserve the first campaign attribution associated with an account and separately update its most recent attribution. Events may include the page, time, a random session-only launch identifier, and validated campaign or referral codes. They do not contain email or IP addresses, raw import text, schoolwork descriptions, notes, OAuth tokens, calendar credentials, advertising identifiers, or browser fingerprints. We use no advertising pixels or third-party analytics cookies on either campus journey.

AI-free operation

UMS does not send your schoolwork to generative-AI models or large-language-model services. It does not use an AI chatbot, generate or rewrite notes, or make opaque academic recommendations. Study plans use predictable rules based on dates, effort estimates, availability, and daily time selected by the student.

How we use information

We use information to provide and secure the app, authenticate accounts, verify eligibility, save schoolwork, import dates, produce rule-based study plans, sync calendars when requested, send account or consented waitlist email, manage subscriptions, schedule reminders, troubleshoot errors, measure the launch funnel, and respond to support or privacy requests.

We do not sell personal information or use it for targeted advertising.

How we share information

We share information only with providers needed to operate UMS, including Firebase and Google services for authentication and optional Calendar sync, Stripe for billing, SendGrid for email, DigitalOcean for application and database infrastructure, and Cloudflare for delivery and security. Cloudflare may process technical request information and set a strictly necessary security cookie. UMS adds no analytics or advertising cookies to the UCD journey. Providers may process information in Ireland, the United States, or other locations where they operate, subject to their safeguards. We may also disclose information when required by law or needed to protect users and the service.

Your choices

You can edit your information, disconnect Google Calendar, change notification preferences, manage a subscription, move or delete imported and planned items, unsubscribe from either waitlist, withdraw marketing consent, and delete your account. You can revoke Google access from Google Account settings. The account page also provides a portable ZIP export containing courses, assignments, events, classes, and plans as CSV, plus sanitized notes as HTML. The export excludes credentials, tokens, telemetry, and internal identifiers.

Retention and deletion

Account content is retained until you delete it. First-party product events and campaign attribution are retained for up to 13 months or until account deletion. Import and sync diagnostic logs are retained for 30 days. Waitlist records are retained until 31 March 2027 unless you withdraw sooner. Encrypted Calendar connection tokens are retained until disconnect or account deletion. After confirmed account deletion, live account data is deleted immediately. Backup copies expire within 30 days, and deletion tombstones are reapplied if a backup is restored. Consent records, described above, are kept separately for up to 3 years as evidence of what you agreed to, and are not deleted early just because the waitlist entry, account, or subscription they relate to is deleted or unsubscribed sooner.

We use authenticated access and encrypted storage for sensitive connection tokens. No transmission or storage method is completely secure.

Independent service

Independent student app. Not affiliated with or endorsed by UCD, Palomar College, D2L, Brightspace, Instructure, or Canvas.

Changes and contact

We may update this policy as the app or our practices change and will revise the date above. For support, privacy questions, access or deletion requests, or waitlist consent questions, email [email protected].