HowdyPlan is a Chrome extension that helps Texas A&M students build class schedules. This policy explains exactly what it collects, where that data lives, and how to get it deleted.

Who we are

HowdyPlan is built and operated by Enoch Poon, a Texas A&M student, as an individual project. It is free and has no ads or analytics SDKs.

  • Contact: enochpoon11@gmail.com
  • Not affiliated with Texas A&M University.
  • Developer: Enoch Poon, an individual—not a company.

What we collect

HowdyPlan stores only the information needed to restore your profile and build schedules:

  • Your email address, major, campus, major status, Honors eligibility, completed courses, and self-reported grades.
  • Your schedule preferences, including preferred times, days off, blocked times, transit buffer, and professor preferences.
  • An anonymous client ID used for fair rate limits and an aggregate planner count.
  • Errors and warnings sent to the debug endpoint only when something breaks.

We do not collect your TAMU password, Google password, SSO credentials, browsing history, or pages you visit outside CollegeScheduler.

Google account data

Google Sign-In is optional. When you use it, Google gives HowdyPlan a short-lived access token that confirms your email address. The server verifies the token and refuses profile changes made with a different identity.

HowdyPlan uses Google account data only to authenticate your profile. It does not request access to Gmail, Drive, Calendar, contacts, or your Google password. Plain Google access tokens are never written to disk and can be revoked from Google Account third-party access.

Where data is stored

  • Primary database: PostgreSQL on a developer-operated server in Houston, Texas.
  • Transport: encrypted HTTPS through a Cloudflare Tunnel.
  • Backups: nightly snapshots retained for 14 days on the server and 30 days on a private laptop.

How data is used

Your profile and preferences are used to operate the schedule planner. The developer may also use profile data in aggregate for personal machine-learning research. Nothing is sold, shared with advertisers, or published in a way that identifies you.

Third parties

  • CollegeScheduler.com provides the registration-planning interface that HowdyPlan enhances.
  • Cloudflare routes encrypted traffic to the HowdyPlan API.
  • Google OAuth verifies your identity only if you choose Google Sign-In.

Retention and deletion

Profile data is kept until you delete it. Google access tokens are not stored on disk. Bug reports are kept for 90 days and request logs for 30 days.

Use Delete my data at the bottom of the HowdyPlan side panel to remove your profile, completed courses, preferences, watch entries, and related bug reports from the live database. Backups containing the data expire within 30 days. If deletion fails, email the contact address and the request will be handled within one week.

Your choices

You may ask to see, correct, or delete the information HowdyPlan holds about you. Update profile details in the extension or email enochpoon11@gmail.com.

Children's privacy

HowdyPlan is intended for college students. We do not knowingly collect personal information from children under 13.

Changes and contact

If this policy changes materially, the effective date will be updated and the extension will prompt users to review it. Questions or deletion requests can be sent to enochpoon11@gmail.com.