The website (coursepilot.us)
Your CoursePilot account stores the information you give it to do its job: your username, contact details for alerts, the USC sections you watch, and — if you use the planner — the STARS report you upload and the planning choices you make. This data is used only to run seat alerts and degree planning for you. It is never sold, shared with third parties, or used for advertising.
Seat availability is read from USC's public class schedule. Alerts are delivered through the channels you configure (ntfy.sh or email).
The browser extension
The CoursePilot extension is local-first. On USC Brightspace it reads the courses, grades, assignments, and files your browser can already access, and stores that data only on your device, encrypted client-side in Chrome extension storage. Course data, grades, files, search indexes, preferences, and unwrapped encryption keys are never sent to the developer or to any external server. If Brightspace backup is enabled, the only data that leaves your device is a single wrapped encryption key saved to your own Brightspace storage.
On USC Web Registration, the extension reads only the course codes and section numbers visible on pages you open, so it can show a small watch button next to each section. When you click that button, it sends only the term code, course code, and section number to coursepilot.us using your existing signed-in session — never Brightspace data, grades, or files. The extension does not store your CoursePilot password or any long-lived token.
The extension requests access only to brightspace.usc.edu, webreg.usc.edu, and coursepilot.us. It does not collect school passwords, OAuth tokens, payment information, or government identifiers.
Your control
You can remove individual seat alerts at any time from your dashboard or the extension button. You can pause document indexing, turn local file search off, or clear the local search index from the extension settings. Uninstalling the extension or clearing its browser storage removes all locally cached data. To delete your website account data, contact the administrator.
Security
Website sessions use CSRF-protected, cookie-authenticated requests; the extension uses client-side encryption for cached course data and extracted search text. No system can be guaranteed perfectly secure, but CoursePilot is designed so the developer does not receive or hold your educational data.
Changes
This policy is updated when CoursePilot's features or data handling change; the effective date above changes with it.