Back to Schoolnight

PRIVACY NOTICE

Your family information stays yours.

Effective August 24, 2026. This notice covers the Schoolnight service, currently operated by Alex Ratner in New York. Questions, privacy requests, and deletion requests can be sent to support@getschoolnight.com.

Who Schoolnight is for

Schoolnight is a general-audience service for adult family owners. It is not directed to children. An adult controls each family account and any connection to Gmail or Google Calendar.

Information Schoolnight uses

Schoolnight stores account and family details you provide, such as parent contact information, children, schools, preferences, reminders, events, and actions. If live Gmail access is later enabled and an adult family owner chooses to connect it, Schoolnight will request only the read-only Gmail scope. That permission cannot send, draft, edit, or delete email.

Connected Gmail messages and attachments will be processed transiently to identify school-related communications and create visible family reminders, events, and actions. Original email bodies and attachment contents are not intended to be stored in the Schoolnight database. Schoolnight keeps validated structured facts and minimal source details—such as sender, subject, received time, and Gmail message and thread references—so the adult family owner can review the source in Gmail.

If the adult family owner chooses the separate, optional Google Calendar import, Schoolnight requests only calendar.calendarlist.readonly and calendar.events.readonly. That permission cannot create, edit, delete, invite, or manage calendars; it can only list calendars and read events from calendars the parent explicitly selects. Only the event information necessary for visible Schoolnight functionality is kept—such as title, start and end time, time zone, and a link to open the original event. Attendees, contact details, conferencing information, private extended properties, attachments, descriptions, and raw Google event payloads are not imported. Imported text is sanitized before display. The existing Schoolnight calendar permission (calendar.app.created) remains a separate, optional grant that only manages the secondary calendar Schoolnight creates.

How information is used and shared

Information is used only to provide, secure, support, and improve the user-facing Schoolnight service. Schoolnight does not sell Google user data, use it for advertising or credit decisions, or use it to train or improve a generalized or foundation AI model.

Schoolnight uses Cloudflare for application hosting and isolated processing, Supabase for authentication and database storage, Google for user-authorized Gmail access, and AWS KMS for credential protection. When the optional Gmail extraction feature is enabled, selected message and attachment content may be transferred transiently to OpenAI solely to produce the user-facing family facts requested by the connected adult; Schoolnight configures the request for no model training and does not retain the raw provider request or response. Resend may deliver requested family notifications, and Stripe may process subscription billing; neither is permitted to receive Gmail OAuth credentials or original Gmail message bodies.

Schoolnight personnel do not routinely access Gmail content. Any exceptional access must be narrowly authorized for security, legal compliance, or message-specific support requested by the adult family owner, and must be audited.

Google Limited Use

Schoolnight's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Retention and deletion

OAuth connection transactions expire after about 10 minutes and are targeted for cleanup within 24 hours. Raw Gmail content is designed to exist only in memory for the current processing attempt. Calendar import uses bounded initial windows and incremental sync tokens; sync cursors advance only after the corresponding database update succeeds, and every operation is idempotent and retry-safe. Completed processing jobs are retained for up to 30 days, notification delivery records for up to 90 days, product analytics for up to 13 months, and security audit records for up to one year. Structured family facts and source references remain until the adult family owner deletes Gmail-derived data, removes a calendar, or deletes the account.

Disconnecting Gmail fences new work, stops the mailbox watch, attempts provider token revocation, and destroys the encrypted local credential. Disconnecting Calendar import fences new work, cancels pending calendar jobs, attempts provider token revocation, destroys the encrypted credential and sync tokens, and—at the parent's choice—leaves or deletes imported Calendar dates. Removing a calendar stops monitoring it without affecting other selected calendars. Confirmed account deletion removes active Schoolnight family data within 30 days. Encrypted database backups are targeted to expire within 35 days; deletion tombstones are designed to prevent deleted accounts from reappearing after a restore.

Your choices

The adult family owner can disconnect Gmail, disconnect Calendar import, pause or remap selected calendars, remove calendars, delete Gmail-derived or Calendar-derived data, remove family information, or request account deletion. Gmail, Calendar import, and the Schoolnight calendar permissions are separate grants and are never silently expanded. Schoolnight never signs forms, sends school replies, makes payments, or accepts legal or medical terms on a family's behalf.