Privacy Policy
Terrier Tracker is a free tool built and run by one BU student. It is not affiliated with Boston University. This page describes exactly what it stores and what it does with it, in plain language.
The short version: your data is used to show you your own requirement progress. It is never sold, never rented, and never shared with advertisers. There is no advertising in this app and no third-party analytics or tracking pixels.
What is stored
- Account: your name, email address, and Google account ID, received from Google when you sign in. Optionally your school and expected graduation year if you enter them.
- Course data: the courses you mark as enrolled, completed, in progress or planned; bookmarks; custom courses you add by hand; transfer/AP/IB credits; your semester roadmap; your selected major; and, if you choose to type one into Course settings, the grade you received in a course. Grades are optional, are never required by any feature, and are never read from Boston University — they exist only if you enter them yourself.
- Things you post: forum questions and answers, course reviews and ratings, votes, and feedback you submit.
- Uploaded transcripts and course lists: if you import a transcript PDF, it is written to a temporary file on the server, read to extract course codes, and then deleted before the request finishes. A MyBU course-list CSV is read in memory and never touches disk. Neither file is saved to the database and neither is retained after the import. Only what they produced is kept, and only once you save it: course codes, and from the CSV also each course's term, status and grade.
- Operational records: sign-in and page-level usage events, and error reports, used to keep the app working and to see which features are actually used.
Most accounts sign in with Google, in which case no password exists here at all. Accounts created with an email and password store only a bcrypt hash of that password — never the password itself, and it cannot be reversed back into one. No payment information is collected, because nothing is for sale.
Who can see it
- You — all of it.
- Other signed-in users — only what you deliberately post: forum questions and answers, and course reviews. You can post anonymously; anonymous posts hide your name from other users, though they remain linked to your account in the database until you delete your account.
- An advisor you share with — if and only if you opt in to sharing. An advisor can be invited to your account, but they see nothing at all until you accept in Settings, and you can revoke access there at any time. While a link is active they see your tracked courses and requirement progress, plus any notes they write about you. Those notes are shown to you too, in the same place, and revoking deletes them along with the link.
- The maintainer — has database access, as the operator of any app does, and looks at individual data only when debugging a specific reported problem.
Service providers
The app runs on infrastructure operated by others, who process data only to provide their service: Google (sign-in), Railway and Vercel (hosting and database), Sentry (error reports), and Voyage AI (search embeddings). Email notifications are currently switched off, so no email provider receives anything. No data is sold or given to anyone else.
The only one of those that receives anything you wrote is Voyage, and only the free-text career interest you type into the course recommender, so it can be matched against course descriptions. It is not sent your name, your email, or your course history. Course recommendations are otherwise computed on our own server, and no course data is sent to any external AI model.
Deleting your account
Go to Settings and use “Delete account.” It takes effect immediately and is not reversible. Concretely, it:
- deletes your account record, all of your course data and roadmap, your course reviews, your votes, your notification preferences, your shared-roadmap links, and any advisor link;
- anonymizes your forum questions and answers — the text stays so that threads other students rely on don't break, but it is permanently unlinked from you and marked anonymous;
- immediately invalidates your current session token.
If you want your forum posts removed as well rather than anonymized, say so via Feedback before deleting and they can be taken down.
Aggregate operational records (counts of sign-ins, error reports) may persist in a form that is no longer linked to you. Encrypted infrastructure backups may retain data for a short period before they age out.
Roadmap share links
If you create a share link for your roadmap, anyone holding that link can view it without signing in — that is the point of it, and it is why the link should be treated like a key. The link contains a long random token and is not guessable or listed anywhere. You can delete a share link at any time from Settings, which stops it working immediately, and deleting your account deletes every link you made.
Exporting your data
Settings has an export for your roadmap as CSV or as a calendar (.ics) file. If you want a full copy of everything stored about you, ask via Feedback.
Not an official student record
Nothing here is an official BU record, and this tool makes no FERPA claim of any kind. Your official academic record lives with the University; what you enter here is your own copy of it, entered by you.
Questions
Use the Feedback button in the app. It reaches the maintainer directly. If this policy changes, the date at the top of this page changes with it.