← SFU Companion

Privacy policy

SFU Companion Privacy Policy

Last updated: August 17, 2026

Overview

SFU Companion is an independent student project. It is not affiliated with or endorsed by Simon Fraser University (SFU). The app does not operate its own server, display advertising, sell personal information, or use analytics or tracking software.

The app connects directly to SFU and the third-party services described below. Some information is stored on your device so the app can work and remain useful when a network connection is unavailable.

Information the app processes

Depending on the features you use, the app may process:

  • Your SFU Computing ID and password during sign-in.
  • An SFU OAuth access token and your SFU username.
  • Your name, SFU ID, and barcode returned by SFU.
  • Your enrolled courses, schedule, instructors, assignments, and due dates.
  • Courses you add from the public course catalog.
  • Calendar items you create, including titles, locations, dates, and times.

Sign-in information

Your SFU Computing ID and password are sent directly to SFU to request an OAuth access token. SFU Companion does not save your password. The access token and session details are stored using the device's secure credential storage, such as iOS Keychain or Android Keystore.

Information stored on your device

Account and academic information may be cached in the app's private local storage. This can include your profile, classes, instructors, schedule, assignments, and related course information. Manually created calendar items and locally selected courses are also stored on the device.

Cached academic data is refreshed or replaced as you use the app. Your secure session remains until you sign out, it expires, or the app removes it. Manually created calendar items and other local-only information may remain after sign-out. Removing the app deletes information in the app's local storage, subject to the device operating system and any device backup.

Calendar access

Calendar permission is requested only when you choose to export an event. The app uses that permission to find a writable calendar and create the selected event. An event exported to your device calendar is controlled by your calendar provider and is not automatically removed when you sign out of or uninstall SFU Companion.

Services the app connects to

  • Simon Fraser University: authentication, profile, courses, schedules, assignments, course outlines, contacts, and other campus information.
  • SFU Courses: public course catalog search when you add a course manually.
  • Open-Meteo: weather for fixed campus coordinates; the app does not send your device location.
  • Mapbox and Carto: map rendering, map data, and map tiles used by the room finder. Mapbox telemetry is disabled in the app.
  • Google Maps: an embedded and externally linked map of automated external defibrillator locations on the Emergency screen.
  • Your calendar provider: receives event information only when you choose to export an event to a device calendar.

These services may receive ordinary connection information such as your IP address, device or browser information, and request metadata. Their handling of that information is governed by their own privacy policies.

What the developer does not receive

SFU Companion does not send your account or academic information to a server operated by the developer. The app does not include advertising, first-party analytics, or first-party crash reporting, and the developer does not sell your information.

Deleting information and withdrawing permission

You can sign out in Settings to remove the saved SFU session and the account caches cleared by the app. You can remove locally added courses and calendar items within the app. You can withdraw calendar permission in your device settings. To remove all information held in the app's local storage, uninstall the app. Events already exported to a device calendar must be managed in that calendar.

Children's privacy

The app is intended for people who use SFU services. It is not directed to children under 13, and the developer does not knowingly collect personal information from children through a developer-operated server.

Changes to this policy

This policy may be updated when the app's features, data handling, or service providers change. The date at the top identifies the latest version.

Contact

For privacy questions or requests, contact the developer through tcombinator.dev or the SFU Companion source repository.