WBUindependent student platform

Privacy Policy

Last updated 11 September 2026

Who we are

The controller of your personal data is ShePlaysPro OÜ, registry code 17201843, Allveelaeva tn 4-158, 10415 Tallinn, Estonia. You can reach us at support@wbu.name.

The short version

We collect what the platform needs to work and nothing for advertising. We do not sell your data, and there are no advertising or tracking scripts. The one measurement we do run — Vercel Analytics — sets no cookie and cannot identify you. The unofficial transcript file you upload is read once and thrown away; only the course rows we extract from it are kept.

What we collect

  • Account — your email address and name. If you sign in with Google we receive your email address, name and profile picture from Google; we never see your Google password.
  • Profile — the photo, major and starting term you enter during onboarding, and anything else you later add to your profile.
  • Studies — the courses you enrol in here, and the courses, grades and credits extracted from a transcript you choose to import.
  • Degree-plan preferences — the specialization track and study-plan version you choose in Settings, which profile suggestions you have dismissed, and when you last opened the Updates page.
  • AI advisor conversations — the messages you send and the replies you get, so the conversation is still there when you come back. The advisor can propose adding or removing courses in your plan; nothing changes until you confirm it in the chat.
  • Advisor notes — with your permission (on by default, switchable off in Settings), the advisor keeps a short list of durable notes about you — goals, hard constraints, interests, answer preferences — so it can pick up where you left off between conversations. It is told to leave out health, family, finances, religion, politics and your grades. You can read, edit, add to, or clear these notes, or turn the whole thing off, under Profile → Settings → What the advisor remembers, and they are included when you download your data.
  • Security — your IP address is used as a short-lived counter to limit how many requests can be made per minute. It is not stored against your account and expires within minutes.
  • Days you use the platform — the dates you open the platform while signed in, so we can see how many people use it and how regularly. This one is tied to your account, which is why it sits apart from the anonymous measurement below: it is a date and nothing more — no time of day, no page, and no record of what you did that day.
  • Usage, anonymously — which pages get visited, where visitors arrived from, the country, and the kind of device and browser, together with how quickly pages load. This is measured by Vercel Analytics and Speed Insights. There is no cookie, no identifier that follows you between days, and nothing that ties a visit to your account — we can see that a page was viewed, not who viewed it.

Your unofficial transcript is not kept

When you upload a transcript, the file is parsed in memory and discarded in the same request. It is never written to disk or to storage. What we save is the structured result: course code, title, grade, credits and term. An academic transcript is sensitive, and an extra copy of one is a liability rather than a feature. The rows we do save are kept until you delete them in Settings or close your account.

External transcripts (IB, AP, A-Levels, or transcripts from another university) are handled the same way — the file is read and discarded, and only the subjects, grades and credits are saved — except that an AI model is used to read them (Anthropic, already listed below among the processors).

For each previous-education upload we keep a short technical log — the document type you selected, the outcome, the number of courses read, and the processing cost — without the document itself or any of its content. We use it to monitor extraction quality.

Degree progress. To show your degree progress we compare the courses on your transcript and your enrolments against the published study plan and regulations for your program and cohort. This comparison is calculated when you open the page and is not stored. We may also point out when your profile settings (first term, major) do not match what your transcript shows; you can accept or dismiss the suggestion.

What the assistants keep, and what they don't

Files you attach to a chat are not kept. A photo, PDF, spreadsheet or document you attach to a message is read by the model to answer that one message and is not stored — what we save is the text of the conversation, not the file.

Study guides the tutor turns into PDFs. When Tutor 1.0 makes a downloadable PDF from a worked solution or revision guide, the file is kept in private storage only you can open, with a link left in the chat. Each one is deleted automatically 30 days after it is made, is included when you download your data, and is removed when you close your account.

Which assistant a conversation belonged to. A conversation is either Advisor 1.0's or Tutor 1.0's; that is stored with it so it reopens with the right one, and it travels with the conversation when you download your data.

Who else processes it

  • Supabase — authentication and the database, hosted in the EU.
  • Vercel — hosting, in the Frankfurt region, and the anonymous usage and performance measurement described above.
  • Anthropic — when you use the AI advisor, your message and the study context it needs (your courses, grades and the catalogue) are sent to Anthropic's Claude model to generate a reply.
  • Google — only if you choose to sign in with Google.
  • Upstash — Redis; rate-limiting and usage counters; USA/EU regions.
  • Resend — transactional email; USA.
  • Cloudflare — Turnstile bot protection; processes IP address and browser signals; USA/EU.

These are processors acting on our instructions. We share data only with the processors listed above, strictly to operate the service, and there is no advertising network involved. People inside WBU are a separate question, and the next section answers it.

When you dictate to the AI advisor, speech recognition runs in your browser (Apple or Google, depending on your device); WBU never receives or stores any audio — only the text you keep and send.

International data transfers

Some of our processors are located in, or may process data in, the United States (Vercel, Supabase, Anthropic, Upstash, Resend, Cloudflare). Where personal data is transferred outside the EU/EEA, we rely on the EU–US Data Privacy Framework where the processor is certified, and otherwise on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). Where available, we select EU hosting regions (our database and application hosting are located in Frankfurt, Germany).

Who at WBU can see it

The section above is about companies. This one is about people. WBU has administrator accounts, and this is what they can and cannot reach.

They need it to work through the problems people report, to answer questions about access to an account, and to see that the platform is running as it should.

An administrator can see a list of every account, and can look a single account up by its full email address. For each account that shows: name, email address and whether it has been confirmed, student number, the date it was registered, the programme and which semester you are in, whether onboarding was finished, whether a transcript has been imported, when it last signed in, and its role. An administrator can change an account's role and switch an account off.

Whether a transcript has been imported is a yes or a no. The courses, grades and credits inside it are not shown. Neither are your conversations with the AI advisor, nor the rest of your profile — your recorded GPA and credits. This is not a promise about what an administrator chooses to look at. Those records sit behind rules the database enforces on its own: an administrator's session is refused them, and no screen in the admin portal asks for them.

Every time an administrator opens the list of accounts, and every time one looks up an email address, that is written to an internal log — who did it, when, and from which network address — whether or not the address matched anyone. Role changes and decisions on reports are logged the same way.

Where the portal shows figures rather than people — how many registered in a month, how many study each programme — the counting happens inside the database and only the counts come back. Any group smaller than five is shown as “under 5”, so a small programme cannot single out the person in it.

If you report a problem. An administrator reads the reason you picked and whatever you wrote in the box; your name is not shown next to it. If you reported an answer from the AI advisor, that answer is included only when you ticked the box to attach it. If you did not tick it, an administrator sees that an answer was reported and cannot read the answer or the conversation it came from.

Why we are allowed to

Under the GDPR we rely on the contract between us to run your account and show you your studies, on your consent for anything optional you switch on, and on our legitimate interest in keeping the service secure and available.

Age

WBU is for people aged 16 and over. If we learn that an account belongs to someone younger, we will delete it.

How long we keep it

For as long as your account exists. Deleting your account removes the profile, enrolments, imported course records, advisor conversations, the advisor's notes about you, profile photo and the record of the days you used it along with it. You can also delete an imported transcript on its own, without closing your account — your GPA and completed credits are reset with it.

A study guide the Tutor renders to a PDF is kept in private storage, readable only by you, for 30 days and then deleted automatically. Files you attach to a message (a slide, a problem, a photo) are read by the model to answer you and are not stored.

Course reviews and instructor ratings

WBU allows students to submit anonymous numeric ratings for courses in the Course Atlas. One of these ratings concerns the instructor teaching the course. We display instructor names as published in Webster University's official course listings, together with aggregated ratings submitted by students.

We process instructor names and aggregated ratings on the basis of our legitimate interest and the legitimate interest of students in sharing and accessing peer feedback on courses (Art. 6(1)(f) GDPR), balanced against instructors' interests as follows: ratings are anonymous and numeric only (no free-text comments); ratings are visible only to registered users of the platform; and we do not collect or display instructors' email addresses or any other contact or personal details beyond the name.

If you are an instructor and object to the processing of your name or the display of ratings relating to you, you may exercise your right to object under Art. 21 GDPR by writing to support@wbu.name. We will review your objection and, unless we can demonstrate compelling legitimate grounds that override your interests, will stop displaying instructor ratings for your courses. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, dsb.gv.at).

Sharing your schedule

The Schedule page lets you create a public link to your weekly timetable. Sharing your schedule creates a public link; anyone with it sees your courses and your first name — never your email, your grades or your GPA. The link carries a secret token, so only someone you send it to can open it, and you can revoke it any time from Schedule → Share, after which it stops working.

Your rights

Two of these you can exercise yourself, immediately, from Profile → Your data: download everything we hold about you as a JSON file, and delete your account or just the imported transcript. Individual advisor conversations can be exported from the advisor page, and the advisor's notes about you can be read, edited or cleared — or turned off entirely — under Settings → What the advisor remembers.

For anything else — correcting something, objecting to how we use it, or a question about any of the above — write to support@wbu.name and we will act within one month. If you think we have got it wrong, you can complain to your national data protection authority.

Cookies

The ones that keep you signed in, and one small functional cookie (wbu_seen) that holds today's date so the “days you use the platform” record above is written once a day rather than on every page you open. It is a functional session-activity marker: it stores that date and nothing else, and it does no tracking. Nothing here sets an advertising cookie, and the anonymous usage measurement stays cookieless.

Email notifications

We send email notifications about platform alerts to registered users; you can opt out in Settings or via the link in any email.

Changes

If this policy changes we will update the date at the top and, for anything significant, post a note in Updates.

Contact

support@wbu.name

About · Guide · Terms of Service · Privacy Policy · Impressum · support@wbu.name · Back to WBU

WBU is independent. We're not affiliated with Webster University or Webster Vienna Private University, and we can't register you for courses or confirm degree requirements — check those with your university.