Privacy Policy
Last updated: February 17, 2026
Introduction
This Privacy Policy describes how DormWay, Inc. ("DormWay," "we," "our," or "us") collects, uses, stores, and shares information when you use the DormWay web application and related services (collectively, the "Services"). This policy applies to DormWay, which provides comprehensive academic management, syllabus analysis, and productivity features for college students.
By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, do not use our Services.
Information We Collect
Google User Data
When you authenticate using Google OAuth, we collect:
- Your name (as provided by Google)
- Your email address (as provided by Google)
- Your Google profile picture URL (if available)
- Basic profile information from your Google account
- Google OAuth tokens for authentication purposes only
Information You Provide
We collect information that you directly provide to us, including:
- Course syllabi and academic documents you upload (these may be processed by third-party AI services for analysis and summarization — see “Third-Party AI Services” below)
- Academic schedules and calendar information, including LMS calendar feeds (Canvas, Moodle, Blackboard, etc.)
- Assignment deadlines and exam dates you input
- Messages and queries you send to the Ace AI assistant or BrainGains Q&A features (these are sent to third-party AI services to generate responses)
- Grade calculations and academic goals you set
- Study preferences and time management settings
- Feedback and communications you send to us
Automatically Collected Information
- Usage data (features used, frequency of use, interaction patterns)
- Device information (device type, operating system, browser type)
- Log data (IP address, access times, pages viewed)
- Analytics data through Amplitude and similar services
- Performance metrics to improve service quality
How We Use Google User Data
We use Google user data obtained through OAuth strictly for the following purposes:
- Authentication and Account Creation: To create and maintain your DormWay account and authenticate your identity
- Service Provision: To provide you access to our syllabus analysis and academic management features
- User Identification: To display your name and profile picture within the application interface
- Communication: To send you service-related emails using your Google email address (with your consent)
- Account Security: To protect your account and prevent unauthorized access
We do NOT use Google user data for:
- Targeted advertising or behavioral advertising
- Selling to third parties or data brokers
- Creating user profiles for advertising purposes
- Training third-party AI models (our AI providers process data via API only and do not use it for training)
- Any purpose other than providing and improving the DormWay service
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Services
- Process and analyze your syllabi using AI to generate academic insights, including assignment timelines, workload predictions, and policy summaries (see “Third-Party AI Services” below)
- Power the Ace AI assistant, which uses your course data and chat messages to provide personalized academic help via third-party AI models
- Generate document summaries and enable knowledge-base search across your uploaded materials using AI-powered document processing
- Create personalized day plans, workload predictions, and time management recommendations
- Send you notifications about important deadlines and academic milestones
- Respond to your comments, questions, and requests
- Send you technical notices, updates, security alerts, and support messages
- Monitor and analyze trends, usage, and activities in connection with our Services
- Detect, investigate, and prevent fraudulent transactions and other illegal activities
- Personalize and improve the Services and provide features that match your interests
- Comply with legal obligations and enforce our terms and policies
Third-Party AI Services
DormWay uses third-party artificial intelligence (AI) services to power core features of the application. This section describes what data is sent to these services, who receives it, and how it is used.
AI Service Providers
We use the following third-party AI providers to process your data:
- OpenAI (OpenAI, L.L.C.) — Powers the Ace AI assistant chat, syllabus analysis, schedule extraction, day plan generation, and academic intelligence features
- Anthropic (Anthropic, PBC) — Powers certain AI assistant responses and document analysis
- Ragie (Ragie, Inc.) — Powers document storage, indexing, retrieval, and AI-generated document summaries for the BrainGains knowledge base
- Perplexity (Perplexity AI, Inc.) — Used for campus and city information enrichment (not directly linked to individual user data)
What Data Is Sent to AI Services
Depending on the features you use, the following types of data may be sent to the AI services listed above:
- Chat messages: Text you type in the Ace AI assistant or BrainGains Q&A features
- Uploaded documents: Syllabi, lecture notes, assignments, and other academic documents you upload for analysis or summarization
- Course and schedule data: Course names, assignment deadlines, exam dates, and class schedules used to generate personalized academic insights and day plans
- Contextual data (if you enable it): Location (campus detection), calendar events, and time-of-day context used to personalize AI responses
No Third-Party AI Training
Your data is never used to train AI models. DormWay accesses all AI providers exclusively through their commercial API services, which are contractually prohibited from using API-submitted data for model training, fine-tuning, or any form of machine learning improvement.
- API-only access: We interact with all AI providers (OpenAI, Anthropic, Ragie, Perplexity) solely through their commercial API endpoints. Under each provider’s API terms of service, data submitted via API is not used for training, fine-tuning, or improving their models.
- No data retention by AI providers: Per the API terms of service of our providers, data submitted through API calls is processed in real-time to generate a response and is not retained by the provider for any secondary purpose. OpenAI’s API data retention policy, for example, retains API inputs for up to 30 days solely for abuse monitoring, after which it is deleted. Anthropic’s API does not use inputs or outputs for training.
- Your data stays yours: We do not permit any AI provider to retain, share, sell, or use your data for any purpose beyond generating the specific response you requested.
- Encryption in transit: All data transmitted to AI services is encrypted using TLS 1.2 or higher.
How Your Data Reaches AI Services
- No direct connection: The DormWay app on your device communicates only with DormWay’s own backend servers (api.dormway.app). Your device never connects directly to any third-party AI provider.
- Server-side processing: Our backend server receives your request, selects the appropriate AI provider, sends only the data necessary to fulfill the request, and returns the AI-generated response to your device.
- Data minimization: We send only the minimum data required for each AI request. For example, an Ace chat message includes your question and relevant course context — not your full account profile or unrelated data.
- Optional AI features: You can choose not to use AI-powered features (such as the Ace assistant or document summarization). Core scheduling and course management features function without any AI processing.
Data Sharing, Transfer, and Disclosure
We do not sell, rent, or trade your personal information or Google user data to third parties. We may share your information only in the following circumstances:
- With Your Consent: We may share information when you explicitly consent to such sharing
- Third-Party AI Services: As described in the “Third-Party AI Services” section above, we share certain data with AI providers (OpenAI, Anthropic, Ragie, Perplexity) to power AI-driven features. This data is used solely to generate responses and insights for you and is not used to train AI models.
- Service Providers: We may share information with third-party service providers who perform services on our behalf, such as:
- Cloud hosting providers (AWS, Vercel) for data storage and processing
- Analytics providers (Amplitude) to understand usage patterns
- Customer support tools to assist with user inquiries
- Email service providers (Customer.io) for transactional communications
- Error monitoring (Sentry) for application stability
- Real-time messaging (Ably) for live updates
- Legal Requirements: We may disclose information if required to do so by law or in response to valid requests by public authorities
- Protection of Rights: We may disclose information when we believe it is necessary to protect our rights, property, or safety, or that of our users or the public
- Business Transfers: In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business
All service providers, including AI providers, are contractually obligated to keep your information confidential and use it only for the purposes we specify. Each third-party AI provider we use provides data protection standards equal to or exceeding our own.
Data Protection and Security
We implement comprehensive security measures to protect your personal information and Google user data:
- Encryption: All data transmitted between your device and our servers is encrypted using TLS/SSL protocols
- Secure Storage: Personal information is stored in encrypted databases with restricted access
- Access Controls: We implement strict access controls and authentication mechanisms for our systems
- Regular Security Audits: We conduct regular security assessments and vulnerability testing
- Employee Training: Our team members are trained on data protection and privacy best practices
- Incident Response: We have procedures in place to detect, respond to, and report data breaches
- Secure Development: We follow secure coding practices and conduct code reviews
While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to maintaining the highest standards of data protection.
Data Retention and Deletion
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
- Active Account Data: We retain your account information and associated data while your account remains active
- Academic Data: Syllabus data and academic information are retained for the duration of the academic term plus one year for reference
- Google User Data: Authentication tokens are refreshed as needed and deleted upon account deletion or revocation of access
- Analytics Data: Anonymized usage data may be retained for up to 2 years for service improvement
- Legal Compliance: We may retain certain information longer if required by law or legitimate business purposes
Data Deletion: You may request deletion of your personal data at any time by:
- Contacting us at privacy@dormway.app
- Using the account deletion feature in your account settings
- Revoking Google OAuth access through your Google Account settings
Upon receiving a valid deletion request, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes.
Your Rights and Choices
You have the following rights regarding your personal information:
- Access: Request access to your personal information and receive a copy of the data we hold about you
- Correction: Request correction of any inaccurate or incomplete personal information
- Deletion: Request deletion of your personal information, subject to certain exceptions
- Data Portability: Request your data in a structured, commonly used, and machine-readable format
- Withdraw Consent: Withdraw consent for processing where we rely on consent as the legal basis
- Object to Processing: Object to our processing of your personal information in certain circumstances
- Restrict Processing: Request that we restrict processing of your personal information in certain circumstances
- Opt-Out: Opt-out of marketing communications at any time using the unsubscribe link in emails
- Google Permissions: Manage or revoke our access to your Google data through your Google Account settings
To exercise any of these rights, please contact us at privacy@dormway.app. We will respond to your request within 30 days.
International Data Transfers
Our Services are operated in the United States. If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including personal information, to the United States and process it there. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
We ensure appropriate safeguards are in place for international data transfers in compliance with applicable data protection laws.
Children's Privacy
Our Services are intended for college students aged 18 and above. We do not knowingly collect personal information from children under 13 years of age. If we become aware that we have collected personal information from a child under 13, we will take immediate steps to delete such information from our servers. If you believe we might have any information from or about a child under 13, please contact us at privacy@dormway.app.
Third-Party Links and Services
Our Services may contain links to third-party websites or services that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. We encourage you to review the privacy policies of any third-party sites you visit.
California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete your personal information, the right to opt-out of the sale of personal information (though we do not sell personal information), and the right not to be discriminated against for exercising your privacy rights.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page with an updated "Last updated" date
- Sending an email notification to registered users (if the changes are material)
- Displaying a prominent notice within the application
Your continued use of our Services after any changes indicates your acceptance of the updated Privacy Policy. If you do not agree with the revised policy, you should discontinue use of our Services.
Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
DormWay, Inc.
Email: privacy@dormway.app
Address: 1800 Century Park East, 10th Floor
Los Angeles, CA 90067
United States
Data Protection Officer: privacy@dormway.app
For Google OAuth and data access concerns, you can also manage your permissions directly through your Google Account settings at https://myaccount.google.com/permissions
Legal Basis for Processing (for EEA Users)
If you are located in the European Economic Area (EEA), we process your personal information under the following legal bases:
- Contract: Processing necessary for the performance of our Services
- Consent: Where you have given explicit consent for specific processing activities
- Legitimate Interests: Processing necessary for our legitimate interests, such as improving our Services, provided these interests are not overridden by your rights
- Legal Obligations: Processing necessary to comply with our legal obligations