GapTracker Privacy Policy
Last updated: August 20, 2026
GapTracker ("the app") helps students track knowledge gaps, study readiness, grades, exam
pacing, and assignments. This policy explains what data the app handles and how.
The short version: almost everything stays on your device. Data leaves your
device only in cases you choose: the text of a syllabus you import for automated parsing, the
direct connection to your school's Moodle or Canvas when you set one up, and — if you turn it
on — sync to your own iCloud account. GapTracker has no user accounts and no server that stores
your personal study data.
Data stored on your device
The following is stored locally on your device (using Apple's SwiftData) and is
not transmitted to us:
- Courses, exam dates, academic credits, target grades, and color labels
- Knowledge gaps / study topics, their severity, and status
- Assignments, their due dates, grade weights, subtasks, and submitted status
- Study sessions, timers, streaks, and statistics
- Grade components, the scores you enter, GPA, and past-semester courses
- Courses, assignments, due dates, and calendar events imported from Moodle or Canvas
- Any photos or voice notes you attach to a topic
This data is removed when you delete the item or uninstall the app.
Connecting Moodle or Canvas
You can optionally connect your school's Moodle or Canvas to import your courses,
assignments, due dates, and calendar events. These connections are direct between your
device and your institution — there is no GapTracker server in between, and we never
see your school data.
- Sign-in. For Moodle you sign in on your institution's own web page
(single sign-on) or paste an access token; for Canvas you paste your personal calendar-feed
link. GapTracker never sees or stores your password.
- Credentials stay on your device. The access token or feed link is kept in
the iOS Keychain on your device and is used only to fetch your data directly
from your institution over an encrypted (HTTPS) connection.
- What is imported (courses, assignments, due dates, and events) is stored
on your device like the rest of your data, and syncs to iCloud only if you turn iCloud sync
on (below).
- With your permission, the app may refresh this data in the background so your deadlines
stay current. You can disconnect a platform at any time in Settings, which removes its stored
credential.
- Your use of Moodle or Canvas is also governed by your institution's own privacy policy.
Syllabus parsing (data that leaves your device)
When you import a syllabus — a file you pick, or a photo you scan — the app extracts its text
and sends that text over an encrypted (HTTPS) connection to our parsing service. That service
forwards the text to Anthropic
PBC's Claude API, which returns a structured list of study topics, the grading breakdown, and
credit hours for you to review before anything is added.
- Our parsing service (hosted on Cloudflare Workers) processes the text transiently to make
the request and does not store your syllabus text. To prevent abuse it keeps
a short-lived, per-day request count by network address; this is not linked to your identity
or your syllabus content.
- Anthropic does not use data submitted through its API to train its models,
and retains it only as needed to operate the service and enforce its policies. See
Anthropic's Privacy Policy.
- Cloudflare carries the request as our hosting/transport provider. See
Cloudflare's Privacy Policy.
- If you import while offline or the service is unavailable, parsing falls back to an
on-device parser and no text leaves your device. Reading text from a scanned
photo is done on your device.
iCloud sync (optional)
Syncing is off by default. If you turn on "Sync with iCloud" in Settings,
your study data is synced across your own devices using Apple's iCloud (CloudKit) in your
private iCloud account. In that case Apple processes the data as your iCloud provider under
Apple's Privacy Policy;
we have no access to it and receive nothing. Turn the setting off to keep your
data on-device only.
Device permissions
The app may ask for these permissions; each is used only for the stated feature, on your
device, and is not collected by us:
- Notifications — local study reminders and exam countdowns.
- Calendar (write only) — to add study blocks you create.
- Camera & Photos — to scan or attach a syllabus or note.
- Microphone — to record voice notes you attach to a topic.
- Background App Refresh — to refresh your Moodle/Canvas deadlines when
connected, so they stay current.
What we do not do
- No analytics, tracking, or advertising SDKs.
- No advertising identifiers; we do not track you across apps or websites.
- No GapTracker user account, and no GapTracker server that stores your personal study data.
- We do not sell or rent your data.
Children
GapTracker is not directed to children under 13, and we do not knowingly collect personal
information from them.
Security
All network connections use encryption in transit (HTTPS). Learning-platform credentials are
stored in the device Keychain and are never included in the app or shared with us; for Moodle
single sign-on you authenticate on your institution's own page and your password is never seen
by the app. Syllabus-parsing API credentials are held only on the server side and are never
included in the app.
Changes
We may update this policy; the "Last updated" date above will change accordingly.
Contact
Questions? Email ehabmarrid1@gmail.com.