Skip to content
NorthQuad Labs
Home About Contact Account Log in

Legal

Privacy Policy

Effective date: August 3, 2026

SyllaSync is built and operated by NorthQuad Labs LLC ("we", "us"). This policy explains what data the SyllaSync browser extension and its backend service collect, why, where it goes, and how you can export or delete it. Questions: [email protected].

SyllaSync is offered only in the United States and is not directed to persons in the European Economic Area, the United Kingdom, or Switzerland.

What we collect

  • Account data. Your email address and a password. The password is stored only as a salted Argon2id hash, which we cannot read.
  • Blackboard account identifier. A one-way SHA-256 hash of your Blackboard user ID, used to detect when the extension is signed into a different Blackboard account than the one linked to your SyllaSync account. The raw ID is not stored and the hash cannot be reversed into it.
  • Course due-date data. Assignment, quiz, and exam entries the extension reads from Blackboard's calendar API: course name, item title, due date, and item type. Uploads may include additional fields present in Blackboard's calendar data. We keep these snapshots for up to 90 days so we can detect changes between syncs, and they are deleted sooner if you delete your account.
  • Calendar connection tokens. When you connect a calendar (Google), we store the OAuth tokens needed to write events on your behalf. Tokens are stored encrypted and are revoked with the provider when you disconnect or delete your account.
  • Sync records. A log of sync runs (status, timestamps, errors) and of the calendar events SyllaSync has created or updated, so syncs are repeatable and reversible.
  • Billing status. Payments are handled by Stripe. We store only your Stripe customer/subscription IDs and subscription status. Your card number and payment details live with Stripe, never on our servers.
  • Technical logs. Our servers record standard request logs (IP address, browser user agent, timestamps) for security and troubleshooting. These logs are kept only as long as needed for operations and security.

What we do not collect

  • Your Blackboard password. The extension reads due dates through Blackboard's calendar API using the Blackboard session already signed in inside your browser. Your Blackboard credentials are never read, stored, or transmitted by SyllaSync.
  • Existing calendar contents. Connecting Google Calendar requires access that covers your whole calendar, and we read the list of your calendars so you can choose which one to sync to. Beyond that we only create, update, or remove the events SyllaSync itself writes; we do not read the contents of events we did not create.
  • Analytics or tracking. The extension and website contain no third-party analytics, advertising, or tracking scripts.

How we use data

For one purpose: syncing your Blackboard due dates to the calendar you choose. We do not sell, rent, or share your data with third parties for marketing. Data leaves our servers only to the services listed below.

SyllaSync is an independent tool you choose to use. It is not affiliated with, endorsed by, or operating on behalf of your university or the North Dakota University System, and it accesses only data you can already see in your own Blackboard account.

Third parties

  • Google Calendar receives the due-date events you asked us to create, using the access you granted via Google's consent screen.
  • Stripe processes payments and receives your email so it can associate your checkout with your subscription.
  • Hetzner Online GmbH hosts our servers and databases.
  • Cloudflare serves our website and provides network security; it processes visitor IP addresses in transit.
  • Resend delivers account emails (verification, password reset, billing notices) to your email address.

SyllaSync's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymized.

Storage and security

Our servers are operated by Hetzner Online GmbH and located in Germany; by using SyllaSync you understand your data is stored on servers in Germany. Data is stored on servers with disk-level encryption at rest. Calendar tokens are additionally encrypted at the application layer. Passwords are hashed with Argon2id. All traffic between the extension, our servers, and third parties uses HTTPS. The extension stores your SyllaSync session tokens and sync settings locally in your browser's extension storage.

If a security breach affects your personal data, we will notify you by email as required by law.

Retention and deletion

  • Session and refresh tokens expire and are deleted automatically.
  • Due-date snapshots are kept for up to 90 days; sync records are kept while your account is active. Both are deleted when you delete your account.
  • Deleting your account (available in the extension's settings) starts an immediate purge: calendar connections and their tokens (revoked with the provider), due-date data, sync records, the hashed Blackboard identifier, and active sessions are permanently deleted; your password hash is deleted; and your email address is removed from our records. Records of past payments are retained by us and by Stripe as required for tax and financial-audit purposes; these no longer reference your account. Stripe retains transaction records under its own privacy policy.
  • You can export your data first: the extension's settings provide a full export (account info, due dates, connections, sync history) as JSON.

Your choices

Regardless of where you live, you can access (export) and delete your data as described above, and we do not sell or share your personal information for advertising.

Browser extension permissions

  • storage keeps you signed in and remembers sync settings.
  • alarms schedules background sync checks.
  • Access to blackboard.ndus.edu reads due dates from your Blackboard calendar via Blackboard's calendar API.
  • Access to syllasync-api.northquadlabs.com communicates with our backend.

Children

SyllaSync is intended for university students and is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, contact us and we will delete it.

Changes

If this policy changes materially, we will update this page, revise the effective date above, and notify you by email or in the extension at least 14 days before the change takes effect.

Contact

NorthQuad Labs LLC
1132 16th St N, Apt 03
Fargo, ND 58102, USA
[email protected]

NorthQuad Labs

Tools that make college life simpler, so students can spend their energy on what actually matters.

SyllaSync
Check it out Extension (coming soon)
Company
About Team Contact
Resources
Privacy Terms
© 2026 NorthQuad Labs LLC. All rights reserved.