Coast privacy policy

Effective 2026-10-03. Coast is a service that reads a student's Canvas account and keeps their schoolwork organised: deadlines, a calendar, lecture notes, homework drafts and mock exams. This page says what Coast stores, what it shares, and how long it keeps it. It is written to be read.

What Coast stores about you

What is pooled with other students in your course

What describes a course rather than a student is kept per course and shared with every Coast student in that section: the syllabus and the policy read from it (dates, grade weights, drop rules, attendance and AI-use rules), meeting times, the instructor, the list of posted material and its text, and the chapter structure. A second student in the same section inherits these on day one. Consent for this pooling is part of signing up. Your own coursework, the token, your grades, your drafts and notes, your preferences and your calendar are private to you and are never pooled.

Google

Signing in with Google asks for your name, your email address and Google Drive's drive.file, which lets Coast create and update documents Coast itself made and nothing else in your Drive. You can decline Drive on Google's screen and still sign in. Coast reads back the documents it made so your edits become the current version.

One more is optional, asked for only if you choose it: Google Calendar's calendar.events, which lets Coast add and update the class blocks, deadlines and study blocks it creates and remove only those, and with which Coast also reads the events already in your primary calendar (their titles, times, locations and meeting links) to show your day beside your classes, kept only in the server's memory, never written to its database or disk, and fetched again after ten minutes. Coast does not ask for Gmail or Contacts, and it never changes a file it did not create.

To keep your Docs and calendar up to date while you are away, Coast keeps the refresh token Google issues, encrypted. Disconnect Google in Settings and Coast asks Google to revoke it and deletes its own copy either way; you can also remove Coast at myaccount.google.com, under Security, Third-party access.

Coast's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from Google is used only to provide the features described here, is never sold, never used for advertising, and never transferred to others except as needed to provide those features or as required by law. You can disconnect Google from Settings at any time, as described above.

Your Claude

The writing that needs a model is done by your own Claude account, which you connect to Coast as a remote connector. Coast sends your Claude the staged material and stores what it writes back. Coast does not send your data to any AI service on your behalf, with three exceptions: the syllabus of a course is read by Coast's own model account to extract the policy above, and that extract is the pooled course data (the sentence of a syllabus that states the course's rule on AI, and the lines around each grade weight, may be read again, as a check, by TypeSafe's Jev model; they are course material and carry nothing of yours); and, if you turn Careers on, your job leads are sorted, from each job's title, company and place and the search you describe (the opening lines of a job's posting go too, once you paste it or Coast finds it), by TypeSafe's Jev model, or by Coast's own model account with Anthropic when Jev is not in use. An account Coast has put on its agent-path test is the exception to these: its syllabi are read and its job leads sorted by its own agent, and no model of Coast's is sent them. Your resume is sent to no model of Coast's, and never to TypeSafe: your own agent is given it whole, and answers a short checklist about it, says how each job's full posting fits it (with whether you need sponsorship as one of three phrases, if you say), and writes the tailored resume and the answers to a posting. If you ask it to, your agent can fill an employer's application form in your own browser, from the resume tailored to that job and the answers you saved. It is told to stop before Submit, and Coast cannot make it: read the form before you send it. Coast itself never fills or sends a form. To find a job's full posting, Coast asks the public job boards of Greenhouse, Lever and Ashby by the company's name; nothing about you is sent.

Recordings of how the dashboard is used

To find where the page fails a student, Coast records sessions on the dashboard with PostHog, a product analytics service, which stores them on its servers in the United States. A recording is the page's layout and your clicks, scrolls and taps, tied to your Coast account number and never to your name or email. Before anything leaves your browser, every piece of text on the page is replaced with asterisks, except the names of the tabs, and everything you type is masked, so a recording does not contain your grades, notes, drafts, mail or course titles. It does contain the page's structure, which includes the course codes in its links (for example PHY-1021). The Settings tab and the setup pages are never recorded. Coast uses PostHog for these recordings only: no advertising, no tracking across other sites, and no cookie. PostHog keeps a recording for the period its plan sets, and you can ask for yours to be deleted at the address below.

Who can see your data

You. Coast's operator can see whether your nightly run succeeded and counts of what was staged, reads what you send through the "Something off?" form (a copy of which goes to Plane, the issue tracker Coast's operator uses, under your Coast account number and never your name or email) and the script errors your page reports, can watch the masked recordings above, and reads your coursework only with your consent recorded on your account. Coast's operator can also see your plan and payments, whether Canvas, Google and your agent are connected and when they last ran, when you last signed in, and who referred you. Access between students is enforced in the database itself and tested on every deployment.

How long Coast keeps it

While your account is active. When your term ends, your account is read-only for thirty days so you can download everything; then your private data is deleted: the token destroyed, Google asked to revoke access, your coursework, grades and preferences removed. You can ask for this at any time from Settings and you get an export first. Pooled course data is kept, because it describes the course, not you.

Security

Tokens and grants are encrypted at rest with a key held outside the database. Backups are encrypted. Every syllabus, assignment and page Coast reads is treated as untrusted text. Coast is small and run by one person; if something goes wrong that affects your data you will be told.

Contact

arielddiner7+coast@gmail.com