Privacy notice
Who runs TrackUni
TrackUni is run by Mahimn Patel, a University of Toronto student, as an independent project. It is not a service of the University of Toronto, or of Instructure, which makes Quercus.
Questions, a request about your data, or a Quercus token you think has leaked: write to mahimn.patel.k@gmail.com, deeppatel.epc@gmail.com or lancedezhili@gmail.com.
What TrackUni keeps
- Your sign-in: your name, your UofT email, your Microsoft account's id, your signed-in sessions (each with the network address and browser it started from), and a record of account events such as connecting Quercus.
- Your Quercus connection: the access token you pasted, or the access Quercus sign-in gave, stored encrypted.
- Your own database: what TrackUni reads from your Quercus (your courses, assignments, quiz descriptions, announcements, modules, pages, files and their text, discussions, grades and feedback, your calendar and your Quercus inbox), what it works out from them, and your own notes, statuses, overrides and settings.
- A shared cache of the text taken out of course documents and of what the AI service found in them, kept by document rather than by student, so each document is read once for every classmate who has it. Nothing in it names you.
- Server logs of what the server did and of its errors. They refer to you only by a coded reference, and Quercus tokens are removed from them. Older logs are overwritten as new ones are written.
No other student sees your sign-in, your connection or your database. The operator's status page shows each student's email, whether their Quercus connection works, any error reading it, and their AI service spending; it shows no course content.
Where it is kept
On one Google Cloud server in Toronto, Canada (region northamerica-northeast2), on its own disk, with its backups and logs. TrackUni uses no other database or storage service. You sign in through UofT's Microsoft sign-in, and TrackUni reads Quercus as you.
The AI service
To build each course's plan (its deadlines, tests, weights and rules), TrackUni sends the text of your courses' syllabus, course pages, course files and video captions, the course websites and documents they link to, and pictures of scanned pages to Z.ai (Zhipu AI), which processes requests in Singapore. Your marks, messages, submissions and name are never sent. That service keeps what it is sent under its own policy. You can ask TrackUni not to send yours, on the connect page or in Settings.
Your Quercus token
A personal access token lets whoever holds it use Quercus as you. Paste only one you made for your own Quercus account, and never give it to anyone else. TrackUni stores it encrypted, opens it only on its server to read your courses, never shows it again and never writes it to a log. It only reads: it never posts, submits, replies or changes anything in Quercus.
Disconnecting, or deleting your account, removes TrackUni's copy. To end the token itself, delete it in Quercus under Account, Settings, Approved integrations. If you think it leaked, delete it there first, then write to an address above.
How long it is kept
Everything above is kept while your account is. Each night the server backs up your database and keeps the newest 14 copies, and backs up the sign-in records, the Quercus connections and the shared cache, keeping the newest 7.
Export and deletion
In Settings, under Your data, Export my data downloads your database as one SQLite file. Delete account removes your account, your Quercus connection, your calendar link, your database and its backups at once, and ends a Quercus sign-in at Quercus. The nightly backups of the sign-in records keep your name, email and encrypted connection for up to 7 days, then they are gone. The shared cache stays, since nothing in it names you, and so does a record that an account was deleted and when, which names no one.
Using TrackUni is also subject to its terms.