Privacy Policy

Last updated: 2026-08-08

Operator and purpose

InstantGPA is an independently operated academic calculation and planning service. We collect the structured data below to calculate results, preserve approved records, provide paid tools, prevent abuse, and improve transcript parsing, grading coverage, course matching, and the university directory. We do not sell academic records or use grades for personalized advertising.

Free users

After confirmation, we store country, university, college or faculty, department or programme, grading system, directory-match status, policy version, timestamps, and approved structured transcript data: course names and codes, terms, credit hours, grades, attempts, statuses, and calculated summaries. Free records use a random browser installation key rather than an account email and synchronize pseudonymously to Cloudflare D1. Clearing browser data intentionally restarts the Free journey, but does not by itself delete a record already synchronized to D1.

Premium subscribers

Firebase Authentication and Firestore are the single subscriber-data store. Firestore holds the subscriber identity and account status, entitlement, PayPal references and lifecycle, usage and page limits, transactional-email delivery records, academic profile and transcript, Premium workspace, syllabus evidence, simulations, transfer comparisons, review results, adviser-report payloads, report-link security metadata, access counters, and administration events concerning the subscriber. Cloudflare D1 is not used for identifiable Premium subscriber records; it remains available for pseudonymous Free data, public directory contributions, and global configuration. Older identifiable Premium records, if found during sign-in, are copied to Firestore before their D1 copy is removed.

Files and OCR

Searchable XLSX, CSV, text, and PDF files are read locally first. The approved academic record does not retain the original file, file name, or raw transcript/OCR text. If local reading is insufficient, the service asks for consent before secure cloud OCR. The uploaded file is used to extract text and table structure; temporary provider storage, when used, is configured for short retention.

Accounts, payment, and email

There are two customer tiers: anonymous Free and paid Premium. Firebase sends identity-verification and password-reset messages. PayPal processes the subscription and may offer PayPal login or eligible debit/credit-card checkout; InstantGPA never receives full card or bank details. Resend sends transactional welcome, activation, cancellation, and account messages after the relevant event. Firestore stores limited provider references, status, dates, and delivery identifiers to reconcile access and avoid duplicate emails.

Regional pricing and connection data

Cloudflare derives an approximate country code at the network edge to choose an approved regional price. The application does not forward or store the visitor's raw IP address for pricing. Security controls may process connection metadata transiently to prevent abuse.

Analytics, cookies, and app cache

Optional analytics load only after consent and measure anonymous journey events such as setup started, transcript upload and review, pricing viewed, checkout started or completed, and the page where a session ended. They must not receive transcript files or text, course names or codes, grades, GPA values, student identifiers, email addresses, or passwords. Operational error reports are sanitized and do not include an account or installation identifier. Result feedback is submitted only when you explicitly choose Yes or No; optional written feedback must not contain personal or academic-record data. The installable app caches public interface files for reliable startup; API responses and private account data are not part of the public shell cache.

Retention, access, and deletion

Academic records are retained while the browser installation or Premium account remains in use, subject to payment-dispute, security, provider, and legal obligations. Pseudonymous journey events and result feedback are retained for up to 180 days; sanitized operational errors are retained for up to 90 days. The service periodically deletes older observability records. Access is limited to the user, authorized service operations, and infrastructure providers needed to operate InstantGPA. The Account page provides self-service JSON export and deletion for both Free and Premium data. Deleting Premium also cancels an active subscription before academic data is removed; PayPal may retain transaction records under its own legal obligations. If the self-service control fails, contact privacy@instantgpa.com.