Privacy
Dibs data details. Updated Wednesday, September 30, 2026.
Optional audit contributions
Signed-in readers may separately opt in on each upload to contribute the PDF for authorized human investigation of DARS parsing errors and creation of test examples. This is not required to import an audit or use dibs. Existing uploads are not enrolled automatically. The contributed PDF can contain your name, UCLA ID, grades and academic history; it is not anonymous. It is stored encrypted in private storage with restricted operator access. We record the consent version, time, expiry, file size and review time with your account. We keep at most one copy per account; a new contribution replaces it.
The contributed copy is not used to train AI models or sent to AI services for accuracy review. Reviewers may create invented, non-identifying test examples from a verified error, but may not add your PDF or its identifiable contents to code, test fixtures or training datasets. This does not change the separately disclosed handling of your imported coursework when you use Ask dibs.
Review access ends 30 days after contribution. An hourly cleanup deletes expired files; service outages can delay physical cleanup, but expired files remain unavailable for review. In Settings you can delete the contributed copy and withdraw permission at any time without deleting your imported courses or requirements. Account deletion also removes the contribution. Already-created synthetic examples contain no link to your account and are not removed by withdrawal. Contribution PDFs are excluded from routine database backups; consent metadata may remain in restricted database backups until those backups expire.
The company privacy policy covers dibs. The details below explain how dibs handles your coursework, conversations, alerts and account information. For a privacy request, email dibs@smilingplug.org.
Research mode in Ask dibs
When separately enabled for your Planning pass, research mode asks you to confirm your interests, major or field, experience and weekly availability before using a research search. This confirmed brief, any included-refinement note, matching evidence, answers and starter templates are stored with your Ask conversation under the conversation rules below. Personalized email draft text is kept only in the temporary encrypted draft storage described below; the conversation keeps a preparation receipt instead. This differs from the standalone finder's optional saved brief: starting research mode does not create that separate saved copy. You can use Ask's conversation controls to delete the chat and its generated drafts, including one still being written. Separate accounting records retain the outcome, public group references and an opaque link to the request, without keeping the deleted conversation's readable text. Editing a draft box is not saved and dibs sends no messages.
Optional saved research results
The research finder has an operator preview and a separately enabled paid pilot. In the standalone research finder, without an explicit save choice, your brief and fit explanations are not retained, except for the temporary context used when you separately confirm a full email draft as described below; the accounting references described below still remain. If you explicitly choose Save, dibs stores your confirmed major or field, interests, experience and weekly availability encrypted with your account. Saving a refinement also stores its added focus or preference; saving the original search does not automatically opt you into saving a refinement. The saved copy also contains encrypted matching evidence, including relevant excerpts from your interests, source quotations, and the search coverage notes. Public group IDs and source revisions are stored separately. No draft edits are saved and no messages are sent.
A saved brief is available across your signed-in devices for at most 120 days, ending earlier when the associated purchase expires. The saved result shows its exact expiry. You can delete it from Manage saved research even when research access has ended or the pilot is disabled. Expired briefs cannot be opened; an hourly cleanup removes them, although outages can delay physical cleanup. Deleting an original saved brief also deletes its saved refinements. Deleting a refinement keeps the original brief. Account deletion removes saved briefs too. Restricted database backups may retain deleted copies until those backups expire.
Deleting a saved brief does not restore spent research allowance or start another search. Separate usage records retain an opaque request identifier, a keyed input digest and outcome for accounting. Execution records retain the selected public group IDs and source revisions after you delete the saved brief; these references can reflect which research you explored, but contain no brief, matching explanation or draft text. Account deletion removes the link from the purchase to your account. Reopening checks the stored source evidence and does not make another model call. If source evidence changed, dibs asks for a new search rather than inventing the old explanation. Paid research searches use model-backed matching, which sends the research-interests text, any added refinement note and public research summaries to the configured Ask provider. Major, experience and weekly availability are not included in that matching call. Operators can also choose model-backed matching in their preview. Keep unnecessary personal information out of your interests.
In the original personalized email editor, preparing a draft for a listed group makes one model call for that group and search. It sends your major or field, experience, interests, any added focus and the group's public research description to the configured Ask provider; dibs adds your weekly hours itself. The generated draft is stored encrypted, separate from any saved brief, so the same search can reopen it for 30 minutes without another model call. After that it can no longer be opened and a scheduled cleanup erases it, usually within minutes, although outages can delay physical cleanup. A record of that draft request stays after the text is erased, holding the public group ID, source revision, keyed identifiers, outcome and model usage counts but no brief or draft text, so the same search does not write it again; it is removed once the purchase has ended. Deleting a saved brief erases generated drafts for that search, including one still being written. Account deletion removes these records. Edits you make to a draft are never saved, and dibs sends no messages. Where drafting is not turned on, or does not complete, dibs offers a starter template with placeholders instead of a personalized draft.
The full-email editor has separate operator-preview and paid-research gates, both disabled by default. Paid access requires an existing completed research search owned by your account and an active eligible Planning pass. Preparing a listed lab uses no additional research search or planning request. Before generation, it asks which student facts may appear in the email, which attachments you intend to add yourself, and whether an optional writing sample may guide the style. It sends the approved facts, approved style sample, public lab evidence and application requirements to the configured Ask provider for drafting and review, with separate factual and editorial reviews, at most one repair, and fresh reviews of the repaired email (up to six calls per attempt). An optional details helper makes at most one separate call using only the original details you selected; you must confirm its proposed wording before drafting. The factual reviewer also receives those selected originals so qualifications are not lost. Unchecked student fields are excluded from that drafting input. The confirmed input is encrypted while waiting or processing and expires after at most 30 minutes; completion removes the approved fact and style text from that temporary input. The research-search profile and shortlist authorization context, before-send checklist and generated email can be reopened for up to 30 minutes after completion so the lab route can be rechecked. If generation fails or times out, no email is made available and the approved facts, style and material choices are cleared when the failure or timeout is recorded. For a service failure or a first draft withheld by factual or safety review, only the existing encrypted search and authorization context remains until its original 30-minute expiry; opening a page does not extend it. You may explicitly review the current route, re-enter and confirm fresh details, keeping truthful facts unchanged or correcting them, and explicitly request one recovery attempt for that lab and search without another research allowance debit. This uses up to six further drafting and review calls and does not run the details helper again. An expired session requires reopening an owned shortlist with current authorization; deleted, changed-source or access-revoked selections cannot recover. Service failure and review withholding share the same one recovery attempt for the lab and search. Recovery is never automatic, a draft may still be withheld, and the recovery attempt cannot itself be retried. Expired input and drafts cannot be opened; scheduled cleanup removes their encrypted copies, although outages can delay physical cleanup. Delete this draft removes the saved body and temporary input immediately and prevents later drafting stages or a completed in-flight response from restoring the email. It does not recall data already sent to the provider or unlock recovery. Deleting either attempt clears both attempts for that lab and search and prevents later responses from restoring them. Request identifiers, public group IDs and source revisions, model and prompt identifiers, and bounded usage counts remain for accounting and duplicate prevention, without the readable draft or approved input. Operator-preview records are eligible for cleanup after 30 days; paid-search records are eligible when the associated purchase has ended. Account deletion removes these records. You can delete a saved draft after drafting access or its release gate has ended. Page edits are not saved, attachments are not uploaded by this editor, and dibs does not send the email.
Optional SMS alerts
SMS is an optional Premium feature and is not available until the service is enabled. While unavailable, dibs does not collect a number through SMS settings. When you request setup, dibs stores your number in encrypted form, verification timing and attempts, and whether you agreed to recurring seat alerts. We record the consent wording version and time, your setting and opt-out status. We do not store verification codes.
Twilio receives your number to check that it is an eligible mobile number, verify control and deliver messages. Twilio also processes replies and delivery status. Seat-alert texts link to your watches and do not include your coursework or degree audit. Mobile numbers and SMS opt-in information are not sold or shared with third parties or affiliates for their marketing or promotional purposes. They may be shared with service providers as needed to operate the messaging service.
Delivery and verification records include timestamps, provider references and a keyed number identifier for abuse prevention and sending limits. These records are removed by a daily cleanup once older than 35 days. Account deletion removes the saved phone and subscription and unlinks remaining operational records from the account; those records remain until cleanup. A keyed identifier of a number that opted out is retained to prevent unwanted texts, including after account deletion. It is not used for marketing.
Turn SMS off in settings, reply STOP, or email dibs@smilingplug.org. Opt-out replies are processed for this purpose, not used as message content for analytics. The SMS alert terms explain frequency, carrier charges and service limitations. Twilio processes its own service records under its privacy terms.
Signed-in activity
When you open a page while signed in, Dibs records your account ID and the calendar date in Los Angeles, at most once per account per day. We use these records to measure active accounts and return use, including visits where you remain signed in. This record contains no page URL, search text, coursework, IP address or device identifier. Operators can review activity totals. No additional analytics cookie is used and signed-out visits are not linked to an account. Daily activity records are kept for up to 90 days, removed by a daily cleanup, and deleted when you delete your account.
Ambassador codes
When you redeem an early-access invite, Dibs records your account, the invite, redemption date, and allowance. Operators can review this access record. It does not automatically share your DARS or conversations with the person who invited you. The invite is kept in an encrypted browser cookie for up to one hour while you sign in.
When you redeem an ambassador code, Dibs records the code, your account, the redemption date, and the access granted. Operators can review this record. Ambassadors can see whether their codes have been redeemed and the total redeemed, but this program does not show them your identity, coursework, DARS, conversations, or plans. A code is kept in an encrypted browser cookie for up to one hour while you sign in. Deleting your account removes its redemption record; a used code remains used.
Student discussions in Ask dibs
Ask dibs may use dated Reddit posts and comments as student perspectives. Relevant excerpts may be shared with our AI provider and retained with an answer's sources. They may contain personal information and are not verified course facts. Contact us to request review or removal of a source.
Bug reports and feedback
Feedback is private to dibs' operators. dibs stores the report you type, its category, submission time, and a local page path when supplied, without its search query or fragment. Contact email is optional and saved only when you choose to share it. Reports sent while signed in are linked to your account and deleted with that account, including operator notes. Guest reports are not linked to an account. Operators can keep private notes and change a report's status; this does not send an email. No academic records, uploads, session contents or IP address are attached to a report automatically. Please leave sensitive information out of the text you submit.
What dibs stores
If you sign in, dibs keeps your email address, your name as Google reports it, and an opaque Google account identifier. Then whatever you go on to tell it:
- The sections you watch, and a record of the alerts it sent, so it does not send the same one twice.
- The courses you say you have taken, with the letter grade where one came from a degree audit. The grade is kept because a prerequisite that demands a C has to be able to refuse a D. It also supports your private science GPA and medical-school coursework comparison.
- Your major and college, your year, your admit term and your enrollment appointment time, when you answer for them, plus the requirement list a degree audit produced. Never the audit PDF during an ordinary import. Optional contributed copies are described above.
- The target medical schools you save. These choices are private and are used to put each school's published requirements beside your recorded coursework.
- If an operator gives you complimentary premium access, dibs keeps the expiry or explicit no-expiry choice, your previous access expiry, the operator's account reference and a private reason for the grant. This is a support record, separate from a payment.
- Your public display name and contributions, if you write a student review or use class chat. A review publishes your display name, review text, rating, course, posting and editing times, and the term, instructor and workload counts if you supply them. Attendance is your statement, not checked against your academic records. Your email, audit and grades are not included in the public review.
- Reports you file, including their reason and optional note. For a reported review, dibs keeps a copy of the text and rating as reported, any supplied workload counts, plus moderation decisions and their reasons. Operators can read the case; the author is not shown who reported it. A shared public profile holds any mute or ban on contributing to reviews and class chat.
If you do not sign in, browsing needs no account and dibs keeps three things, all only if you choose to give them:
-
Courses you have already taken, in a cookie in your own browser
(
dibs_taken). Course ids and nothing else, expiring after 1 year. Clearing the list deletes it immediately. - If you upload a degree audit and confirm it, the requirements it lists and your major code and name, in a row on the server, for 180 days. Not the PDF, and nothing that identifies you: the row is reachable only from a token in a cookie in your browser. Deleting the audit removes the row and the cookie together, and signing in moves it onto your account and deletes it.
-
Which kind of student you said you are, if you explicitly save your standing on a
ranking page, in a cookie in your own browser
(
dibs_standing). One word, expiring after a year. Saving "Rather not say" deletes it immediately, and signing in copies it onto your account.
What it does not store
No passwords: there is no password to store. No UCLA credentials, ever: dibs cannot and will not enroll you in anything, it only links out to the registrar. No card numbers: paying goes through Stripe on a page Stripe hosts, so your card never reaches dibs. No advertising trackers and no third-party analytics: no script on this site reports you to anybody, and nothing about your visit leaves this server.
dibs does count how often each page is asked for, on its own server, so it can tell whether anybody is finding it. A count keeps four things: which page, the site you came from if you followed a link, the campaign tag on that link if it carried one, and the time. It keeps no cookie, no address, nothing derived from an address, and no account, not even when you are signed in. These page-request counts are not linked to your account. The separate signed-in activity record described above measures return use by date. Browser-measured page usage, described below, adds approximate active time and a per-page identifier without linking visits to an account.
Who else sees it
Four, and only these four:
- Google, when you sign in with it, and only then.
- Resend, which sends the alert emails and therefore handles your address and the name of the class you are watching.
- Anthropic, when you use Ask dibs or submit a class-chat message or student review for automated screening. A question sends that question plus whatever dibs looks up to answer it, which can include your year, your major, the courses you have listed as taken and the outstanding blocks from your degree audit. Anthropic does not train on it. Community screening sends the submitted text, any supplied review workload counts and, for chat, up to three short preceding public messages for context. It does not attach account emails, display names, profiles, degree audits or grades. Text you type can itself contain personal information; do not post another person's private details. Automated verdicts and operator decisions are retained with the contribution; account deletion removes these screening records. Rejected submission counters keep the reason, count and date against your account, without the rejected text or IP address. Deleting your account erases these counters.
- Stripe, if you pay. They take the card on their own page and tell dibs only that an account paid. dibs sends them your email address so the receipt reaches you.
Nobody else receives private account or academic data through this page's listed services. Public reviews and class-chat contributions are visible as described above; study-space visibility is described below. Your data is not sold or used to train anything.
Study-space suggestions
Study-space suggestions store your account, proposed location, description and usual talking policy. Suggestions and corrections remain private until owner review. Approved directory entries do not show your email address. Review decisions and notes are stored with the suggestion. Deleting your account removes your suggestions; approved directory locations remain without your account reference.
General space comments remain private until owner approval and then show your chosen public display name. Comment reports are private to the owner. Deleting your account removes your comments and reports; review decisions about other people retain no actor account reference. This version does not accept photos, current noise or activity reports, or device location. Historical conditions reporting endpoints are retired. Stored reports, comments and flags remain until account deletion; deleting a report also deletes its comments and related moderation records. Decisions about other people's historical content retain no reviewer account reference after account deletion.
Deleting it
Your settings has a delete button. It removes the account and its personal records: the sign-in identities, the sessions, the watches, the record of alerts sent, the courses you listed with their grades, the requirements from any audit, your saved target schools, and complimentary grants received by you, including their private reasons. There is no soft delete and no recovery window.
If you are an operator, grants you issued to other people remain with your account reference removed. Their access and grant records belong to them.
Your reviews, their report copies and moderation cases, and reports you filed are also deleted with your account.
Deleting just a review is different from deleting your account. Its text and rating leave the course page and its workload counts are erased, but existing reports, their copies of the review and moderation decisions remain available to operators. A moderator restoring a review does not republish text its author deleted. Community guidelines describe moderation and appeals.
Where the course data comes from
Enrollment figures are read from the public Schedule of Classes. Grade distributions come from California Public Records Act responses covering Fall 2021 to Fall 2025: the same public records the other UCLA grade sites use.
dibs is not affiliated with or endorsed by UCLA.
Page usage and continuing your work
We measure which types of pages are used and approximate active time to improve dibs. A random identifier connects time updates for one page only. We store the page category, referral website hostname and campaign source where supplied, whether the visit is signed in, its start time and active seconds. We do not include account IDs, exact URLs, search terms, message text or degree-audit contents in these measurements. Records are deleted after 90 days.
Time measurement pauses when the page is hidden or unfocused, or after 60 seconds without interaction. We honor Global Privacy Control and Do Not Track for these browser usage measurements. Your measurement preference is stored in a cookie for one year. The control below applies to this browser; the separate server request counters and account activity-day records described above still operate.
When you are signed in, the homepage can link to your latest saved conversation or week. Conversation content stays collapsed until you expand it. Opening it does not send anything to a model. Unsent Ask dibs text is stored in this browser tab, separately for each account and conversation. It can be restored for up to one day. Expired drafts are removed when that conversation is opened again; tab storage otherwise lasts until the tab closes. A successful submission clears its draft. Saved conversations and plans belong to your account and can be opened from other devices.