Timetable Planner

Privacy, data policy & disclaimer

Last updated: August 7, 2026

Short version: Independent student-made tool — not affiliated with, endorsed by, or approved by City University of Hong Kong. No course catalog is hosted here. Courses come from Banweb pages you open (or ask the companion to re-read), stored encrypted only in your browser. Audits are .pdf only and stay on your device. Sign-ins are logged; Vercel Analytics records anonymous page views. Use of the site and companion is as is, at your own risk.

1. Who we are

Timetable Planner is a scheduling tool made by Haseeb. Course picking, conflict checks, and Degree Works parsing run in your browser. A small backend exists only to check allowlisted emails, store password hashes, and record successful sign-ins.

2. Disclaimer & limitation of liability

Not a University product. Timetable Planner and the optional Chrome companion are independent, student-made tools. They are not affiliated with, sponsored by, endorsed by, or explicitly approved by City University of Hong Kong (CityUHK), Central IT / CSC, or any CityUHK department. CityUHK names, systems (including Banweb / AIMS), and trademarks are mentioned only to describe interoperability; that does not imply official status.

No formal compliance determination. A review of publicly available CityUHK IT / information-security materials did not identify an explicit prohibition of the technical pattern used here (student-opened Banweb pages only; read-only local parse; on-device encrypted storage; no Banweb HTML upload; no CityUHK password capture). That finding is not University approval, legal advice, or a guarantee that use is permitted in every case. Policy text on third-party browser extensions and Banweb session use remains partly unsettled.

Your responsibility. By using this website and/or the companion extension, you accept that you alone are responsible for complying with CityUHK IT, acceptable-use, personal-data, and any Banweb / AIMS terms that apply to you. If any use is later found to violate University rules or law, you accept liability for your own use. The author does not indemnify users against University discipline, account sanctions, or other consequences.

All course and audit data is provided by you. Banweb pages you open (via the companion), Degree Works audit PDFs, CRNs, schedules, and any other information you enter are supplied by the user. Timetable Planner, its author (Haseeb), and the hosting operators do not verify the legality, accuracy, completeness, or ownership of user-supplied data.

To the fullest extent permitted by law, Haseeb and Timetable Planner accept no legal liability for user-uploaded or user-supplied content; for scheduling decisions or registration outcomes; for conflicts with university rules or third-party rights; or for any loss or damage arising from use of this tool. The website and companion extension are provided as is and as available, without warranties of any kind, and without any claim of University approval. Use is entirely at your own risk.

3. What we collect

For access control we store your allowlisted email and a hashed password you create on first visit (not the password itself in plain text). After sign-in, an HttpOnly session cookie remembers that you are allowed in (about 7 days).

We also keep a login access log: when you successfully sign in (or set your password for the first time), we record your email, the UTC timestamp, and whether it was a first-time setup. Failed login attempts are not logged. We do not collect course selections, Degree Works audits, schedules, CRNs, grades, advertising identifiers, or tracking pixels.

4. How course data is handled

This site does not host a course catalog. An optional Chrome companion extension may parse Banweb / AIMS pages that you open (or that you ask it to re-read while already open) and keep an AES-GCM encrypted copy in the extension’s local storage on your device. A decryption key is released only after you sign in to this planner and is held in Chrome session storage for that browser session (reloading the extension clears the key until you open the planner again). The companion also checks a public status endpoint on this site before capturing; if the site is unavailable or the companion is turned off server-side, capture stops. Parsed schedules and Banweb HTML are not uploaded to our servers. Allowed file upload on the site is limited to Degree Works audit PDFs (.pdf), read only in your browser.

5. Companion extension (permissions & data)

The companion is optional and runs only in your browser. It does not need your CityU password; it uses whatever Banweb session you already have in Chrome. It does not scrape Banweb in the background or fetch course pages on its own.

  • Runs only on: Banweb Master Class Schedule and individual course section pages (P_GetCrse / P_DispOneSection), plus this planner origin (and localhost when developing) so captured courses can sync into the planner UI. It does not inject into other Banweb pages (e.g. grades, personal info).
  • Reads: course/section HTML when those pages load, or when you use Capture open Banweb tabs in the extension popup to re-parse tabs that are already open (reads the current page content; does not reload Banweb for you).
  • Chrome permissions: storage (encrypted catalog + settings), tabs (find open Banweb course tabs for capture), and scripting (run the capture script in those tabs if needed after an extension reload). Host access is limited to Banweb and this planner’s origins.
  • Stores: an encrypted course catalog on your device. Courses expire after a retention window (default 30 days per course, configurable via server policy), or sooner if you clear the catalog or a remote storage-epoch wipe is applied on the next status check.
  • Contacts this site for: companion status (kill switch / retention / wipe policy) and, after you sign in here, a short-lived decryption key. Course schedule payloads are never uploaded.
  • Does not: sell data, show ads, send Banweb HTML to third parties, or keep a shared catalog on our servers.

Installing the companion is voluntary. You can remove it in Chrome’s extension settings at any time.

6. Where data lives (and dies)

Your cart / weekly timetable is stored on this device in AES-GCM encrypted localStorage (keyed to your signed-in email). A decryption key is released only after you sign in and is held in page memory for that session—not written to localStorage. Search filters and parsed audit data exist only in temporary browser memory for the current planner tab. Refreshing or returning later restores the encrypted timetable after sign-in. Captured Banweb courses may remain in the companion’s encrypted storage as described above until they expire, you clear them, or a remote wipe applies. The companion’s decryption key lives only in session storage for the current browser session. The access cookie is separate and only records that you signed in.

7. Printing

Print Schedule uses your browser’s built-in print function. No print job or schedule data is sent to us.

8. Third-party services

The page may load public libraries from content delivery networks (for example Tailwind CSS and PDF.js). Those CDN providers may see ordinary web-request metadata. Your Banweb captures, audit PDF, schedule selections, and login password are not sent to those CDNs.

Password hashes (not plain passwords), the login access log (email + timestamp), and related access data are stored with Upstash (a Redis database service) so sign-in can work on the hosted site. Upstash processes that storage on our behalf under their terms and privacy policy. Session cookies, allowlist checks, and Vercel Web Analytics (privacy-oriented page-view metrics; no advertising cookies) are handled by our app on Vercel (the hosting provider).

9. Children’s privacy

We do not knowingly collect information from children beyond the invite-only email used for access. The planner has no public accounts or profiles.

10. Your control

Use Sign out to clear the access cookie. To wipe planner UI state, close the tab or refresh the page. In the companion popup, use Clear captured catalog to remove stored Banweb course data, or uninstall the extension. Captured courses also age out automatically under the retention policy. To be removed from the allowlist, reset your password, or ask for your login-log entries to be cleared, contact Haseeb (password reset clears your hash so you can set a new one on next visit).

11. Changes

If this policy ever changes, the “Last updated” date above will be revised.

12. Contact

Questions about this policy: contact the author (Haseeb) through the channel where you obtained Timetable Planner, or via the contact form on smhaseeb.com. Install help: install.html.

University staff. If you are CityUHK staff and wish to request that this site or companion be taken down, ask how the technical design works, or discuss a formal integration path, please use the contact form on smhaseeb.com. Good-faith takedown or clarification requests will be taken seriously.