Privacy policy
What Ursa collects, who can see it, and how to get rid of it — in plain language, written against what the code actually does.
Effective September 8, 2026
The short version
Ursa is a study tool that answers questions about EBHS using the school's own published pages. To do that it stores your EBHS email, anything you choose to put in your profile, and the conversations you have with it.
Your conversations are not readable by counselors, teachers, or anyone at the school. They are not sold, not used for advertising, and not used to train anyone's AI models. If you ask us to delete your account, we delete it.
Two things are worth knowing before you start:
- Ursa is not affiliated with East Brunswick High School. It is an independent student project. The school has not reviewed, approved, or endorsed it, and the school does not receive your data.
- Nobody is watching your chats in real time. If you tell Ursa you are in crisis, it will show you crisis resources, but it does not alert a counselor, a parent, or emergency services. Please see the section on crisis messages below.
The rest of this page is the detail behind those statements.
1. Who runs Ursa
Ursa is built and operated by an individual student developer. It is a personal project, not a company and not a school program.
Ursa is independent of East Brunswick High School and the East Brunswick Public School District. Neither has sponsored, reviewed, approved, or endorsed it. Ursa reads the school's publicly published web pages the same way any visitor can, and it cites them so you can check the original. It has no access to school systems, no access to your grades or transcript, and no channel through which it sends your information to the school.
If that ever changes — if Ursa becomes an officially adopted school tool — this page will be updated before the change takes effect, and students will be told. A school partnership would bring FERPA and a district data-privacy agreement into scope, which would mean new commitments, not fewer.
For anything in this policy, contact alan.lei0409@gmail.com.
2. What Ursa collects
From your Google sign-in
Ursa uses Google Sign-In. When you sign in, Google gives Ursa:
- your email address
- your name, if your Google profile has one
- a unique account identifier that lets Ursa recognize you next time
Ursa does not receive and never asks for your Google password, your Gmail messages, your Drive files, your contacts, or your calendar. The only Google permissions Ursa requests are the basic ones needed to know who you are.
Your email address is used for exactly two things: confirming that you are allowed to use Ursa (an approved school address, or an address explicitly added for testing), and identifying your account so your history and plan come back when you return.
What you type in
- Your profile, if you fill it in: graduation year, classes you have taken, interests, intended major, and free-text goals. All of it is optional. Ursa works without any of it; it answers in a more tailored way with it.
- Your plan: the courses and activities on your four-year plan, their status, and any notes you add.
- Your conversations: the questions you ask and the answers Ursa gives, along with the sources it cited and any thumbs-up or thumbs-down you leave.
Conversations are saved so you can come back to them and so Ursa remembers context within a thread. Anonymous questions asked before you sign in are not saved to an account; if you sign in immediately afterward, that first exchange may be carried into your new account so the thread is not lost.
Usage data
Ursa records events about how it is being used, so it can be improved: that a conversation started, that a message was sent, that a plan was generated, that crisis resources were shown, that you signed in, and the broad topic of a conversation (classes, clubs, majors, graduation, other).
One of these events stores your words. When Ursa cannot answer a question from the school materials it has, it records the first 300 characters of that question so the gap can be filled later. That text is visible to whoever operates Ursa, in a list of unanswered questions. It is not linked to your name in that view, but it is stored alongside your account identifier in the database, so treat it as attributable. Do not put anything private in a question you would not want read.
Cookies
Ursa sets a small number of cookies. It does not use advertising cookies, tracking pixels, or third-party analytics services.
- Sign-in cookies (set by Supabase, our authentication provider) keep you logged in and refresh your session.
ursa_anon_qcounts the free questions you have asked before signing in. It ishttpOnly— page scripts cannot read it — and expires after 30 days.ursa_srcrecords which link brought you here (for example, an Instagram post) so we can tell which outreach actually reaches students. It holds a short campaign tag, never anything about you, and expires after 30 days.
Technical information
Your IP address is used, in memory and momentarily, to rate-limit anonymous requests so one visitor cannot run up costs or overwhelm the service. It is not written to Ursa's database. Once you are signed in, rate limiting keys off your account identifier rather than your IP.
Our hosting providers keep standard server request logs, which include IP addresses, as part of operating their platforms.
3. How Ursa uses Google user data
This section is stated separately because Google requires it, and because it should be easy to find.
The information Ursa receives from Google Sign-In — your email address, name, and account identifier — is used only to:
- verify that you are permitted to use Ursa,
- create and identify your account, and
- show your own name back to you in the interface.
Ursa's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Ursa does not sell Google user data, does not use it for advertising or to build advertising profiles, and does not use it to train AI models. It is not transferred to anyone except the infrastructure providers listed below, who process it on Ursa's behalf in order to run the service.
4. Who your information is shared with
Ursa has no advertisers, no data brokers, and no analytics vendors. It relies on four providers to function, each of which processes data on Ursa's instructions:
- Google — handles sign-in. Receives nothing beyond the authentication exchange itself.
- Supabase — hosts the database and authentication. Holds your account, profile, conversations, plan, and usage events.
- Vercel — hosts the application. Sees web requests, including IP addresses in standard server logs.
- OpenAI — generates answers and runs the safety check. Receives the text of your messages, the excerpts of school material retrieved for your question, and any profile or plan context used to tailor the answer.
On OpenAI specifically: your messages are sent to OpenAI's API to produce an answer, and every message is also sent to a small OpenAI model that checks it for signs of distress. OpenAI states that data submitted through its API is not used to train its models by default.
Beyond those providers, Ursa shares personal information only if legally compelled to (a valid subpoena, court order, or equivalent legal process), or where disclosure is necessary to prevent imminent physical harm.
Ursa does not send your data to East Brunswick High School, to the district, or to your counselor.
5. Crisis messages are handled differently
If Ursa's safety check decides a message shows signs of distress or self-harm, two things happen:
- Ursa immediately replies with crisis resources — 988, the Crisis Text Line, 911, and how to reach a counselor at EBHS.
- That message is not saved. The crisis path returns before anything is written to the database. Ursa records only that crisis resources were shown and what triggered the check — never the content of what you wrote.
You should also know what does not happen, because it matters:
- No human is notified. Not a counselor, not a parent, not the school, not emergency services. Ursa is not a monitoring or reporting system, and nobody is reading messages as they arrive.
- Ursa cannot help in an emergency. If you are in danger, call or text 988, or call 911.
The message is still transmitted to OpenAI as part of the safety check before the decision to discard it is made.
6. Who can see what
- Your conversations: only you. There is no counselor dashboard, no transcript viewer, and no interface anywhere in Ursa through which another student, a teacher, or a counselor can read your chats.
- Your profile and plan: only you.
- Whoever operates Ursa can reach the underlying database, as the administrator of any service can. That access exists for maintenance, debugging, and honoring deletion requests — not for reading conversations, which is not done.
- The operations console shows counts and aggregates: how many conversations, which topics are common, how often answers were rated up or down, which links students arrived from. The one exception is the list of unanswered questions described in section 2, which shows question text verbatim.
7. How long information is kept
Your account, profile, plan, and conversations are kept for as long as your account exists, so that your history and your four-year plan are still there when you come back next semester.
There is no automatic expiry. If you want your data gone, ask — see the next section — and it will be deleted within 30 days.
Aggregate usage counts that contain nothing identifying (for example, "42 conversations about graduation requirements this month") may be kept after an account is deleted.
8. Your choices
- See and correct your information. Your profile and plan are editable in the app at any time.
- Delete your account and everything in it. Email alan.lei0409@gmail.com from the address you signed in with. Everything tied to your account — profile, conversations, messages, plan, and the usage events linked to you — will be deleted within 30 days. There is no self-serve delete button yet; this is a manual process, and it is honored.
- Get a copy of your information. Ask at the same address.
- Stop using Ursa. You can simply stop; nothing is collected when you are not using it. Deletion still requires an email.
Depending on where you live, you may have additional rights over your personal information. Ursa extends the choices above to everyone who asks, regardless of where they live, rather than trying to work out who qualifies.
9. Students under 13
Ursa is for high school students and is not directed at children under 13. Accounts may not be created by anyone under 13.
If we learn that an account belongs to someone under 13, it will be deleted along with its data. If you are a parent or guardian who believes a child under 13 has created an account, email alan.lei0409@gmail.com and it will be removed.
Parents and guardians may request access to, correction of, or deletion of their child's information at the same address.
10. Security
Ursa is built with reasonable protections: encrypted connections, database row-level security so an account can only reach its own rows, sign-in cookies that page scripts cannot read, rate limiting on every route that costs money or writes data, and administrative access restricted to the operator.
No service can promise perfect security, and this one is honest about being a student-built project rather than an enterprise platform. Please do not put information in Ursa that would be damaging if it were exposed — including anything about someone else.
11. Schools and FERPA
FERPA governs education records held by schools and by parties acting on a school's behalf. Ursa is neither: it is not operated by East Brunswick High School, has no agreement with the district, and receives no records from either. Nothing you type into Ursa becomes part of your education record, and nothing in your education record is available to Ursa.
If Ursa is ever formally adopted by the school, that changes, and this page will be rewritten before it does.
12. Changes to this policy
If this policy changes in a way that meaningfully affects what is collected or who sees it, the notice will appear in the app before the change takes effect, and the date below will be updated. Smaller clarifications will just update the date.
13. Contact
Questions, deletion requests, and anything else: alan.lei0409@gmail.com.
Effective September 8, 2026.