Privacy Policy

Last updated September 9, 2026

Rested ("Rested," "we," "us") is a study-scheduling tool for students. This page explains what data we collect, why, and how you can control it. Questions go to maurokolomi@gmail.com.

What we collect

  • Account: your name, email, and profile photo from Google when you sign in.
  • Calendar access: with Google sign-in, we request calendar.events (to check upcoming events and create or update the study blocks you accept) and calendar.freebusy (to see when you're busy, without reading event details). We never read, edit, or delete events we didn't create ourselves.
  • Calendar feeds: any Canvas, Blackboard, Moodle, or .ics feed URL you add, and the assignment or class data pulled from it.
  • Gmail (optional, Pro only): a separate opt-in grants read-only Gmail access (gmail.readonly) to scan for deadline mentions. We never send email from your account, and this can be revoked independently of Calendar access at any time.
  • Uploaded syllabi (optional, Pro only): PDF or Word files you upload are parsed for dates and deadlines; the extracted text is stored so you can review it later.
  • Billing: subscriptions and payments are handled directly by Stripe. We store your Stripe customer and subscription IDs only — we never see or store your card number.
  • AI processing: when you use scheduling suggestions or the chat assistant, the relevant parts of your schedule and your messages are sent to Anthropic's Claude API to generate a response.

How we use it

Solely to run the product: syncing your calendars, proposing and placing study blocks around your classes and sleep window, extracting deadlines, answering questions in the assistant, sending the weekly digest email if you opt in, and processing your subscription. We do not sell your data, and we do not use your calendar or Gmail content for advertising.

Who we share it with

Only the vendors needed to run the service: Google (sign-in and Calendar/Gmail APIs), Anthropic (AI features), Stripe (billing), Resend (transactional email), and Supabase (database hosting). Each receives only the data needed for its function.

Security

OAuth refresh tokens are encrypted at rest. Access to your data is limited to what the app needs to function.

Your controls

  • Revoke Calendar or Gmail access anytime from your Google Account permissions page — this immediately stops our access.
  • Turn off the weekly digest anytime in Settings.
  • To delete your account and associated data, email maurokolomi@gmail.com — we'll confirm and remove it. There's no self-serve delete yet, so this is handled manually today.

Children

Rested isn't directed at children under 13, and we don't knowingly collect data from them.

Changes

If this policy changes meaningfully, we'll update the date above and note material changes on this page.