Privacy
Term has no account, no ads, no analytics and no tracking. Your timetable stays on your devices and in your own iCloud. The only time anything leaves them for Term's server is when you import a timetable from a file.
Your timetable
Your timetables, lessons, subjects and settings are stored on your device.
- iCloud. If iCloud sync is on, they are also kept in your private iCloud database, so your other devices can use them. The fields are end-to-end encrypted, with keys in your iCloud Keychain, so neither Apple nor the developer can read them. You can turn sync off on each device in Settings. Apple's handling of iCloud is covered by Apple's Privacy Policy.
- Apple Watch. Your iPhone sends your timetable directly to your paired Apple Watch.
- Widgets and reminders. These work on your device. Lesson reminders are scheduled locally, not sent from a server.
- Backups and exports. A backup, PDF, image or calendar file goes only where you choose to save or share it.
The developer never receives your timetable.
Importing from a photo, PDF or file
When you choose Import a timetable and pick a photo, screenshot, PDF or text file, Term sends that file to an AI model to read your lessons. Term asks before the first time, and nothing is sent unless you pick a file.
- What is sent: only the file you picked. A photo is sent as plain pixels, without its location or other metadata. No name, account or contact details are sent. The file itself may show whatever is printed on it, such as your name or school, so crop the picture first if you'd rather those weren't included.
- Where it goes: over an encrypted connection to Term's server (run on Cloudflare), which passes it through Vercel's AI Gateway to a model from OpenAI. The lessons it reads come back to your device, where you check them before anything is added.
- What is kept: Term's server does not store your file or the lessons read from it, and its logs record only error codes. Vercel does not keep the request. OpenAI never uses it for training, and keeps it for up to 30 days to check for misuse, then deletes it.
Keeping the server fair
To stop the server being misused, each reading is checked and counted:
- App Attest. On most devices, Term creates a key with Apple's App Attest the first time you import, and the server keeps that key's public half. It proves a request comes from Term on a real Apple device. It is a random key, not a device or Apple ID identifier, and it can't be used to identify you.
- Daily limits. The server counts how many files each key reads each day. The counts are deleted every night.
- Devices without App Attest. For these, the server uses your IP address for a moment to limit how many readings can be requested per minute. It is not stored.
Like any website, Cloudflare handles your IP address in order to deliver requests to Term's server.
Children
Term is made for students of any age. It has no account and doesn't ask for personal information. The only thing it ever sends to a server is a timetable you choose to import.
For people in the UK and EU
Marco, the developer of Term, is responsible for the data described here. A file you import is processed to provide the reading you asked for. Cloudflare, Vercel and OpenAI process it on the developer's behalf, and this may happen in the United States. Because Term doesn't keep your file or know who you are, there is usually nothing held about you to access or delete. You can still ask about your data, or complain to your local data protection authority (in the UK, the ICO).
Changes and contact
If this policy changes, the new version will be posted here with a new date. Questions? Email term@marcoo.me.
Last updated 26 September 2026.