UGSearch Privacy Policy
Last updated: 7 October 2026. Applies to UGSearch 0.3 and later.
UGSearch is a free, unofficial product by Hellebuyck Adventures (Thibault Hellebuyck). It is not owned by or affiliated with Ghent University (UGent). UGSearch is an extension for your AI app (for example Claude Desktop) that lets the AI read your Ufora, Ghent University's learning environment. This policy explains which data UGSearch uses, where it is kept and who can see it.
Summary
- The extension runs on your own computer. Your Ufora sign-in, your password and your knowledge base stay there. There are no analytics and no tracking.
- With an account we only keep technical data about your linked computer, never content from Ufora (see "Your UGSearch account").
- Online use goes through our relay server, which stores and logs nothing (see "The online link").
- Your data goes only to Ufora (to fetch it) and to the AI app you use (to answer your question).
- UGSearch never sees your password. You sign in on Ghent University's real sign-in page.
- You can delete everything at any time (see "Deleting your data").
1. Data UGSearch uses
| Data | Purpose | Where it is stored |
|---|---|---|
| Ufora session cookies (after you sign in) | To read Ufora on your behalf | Encrypted (AES-256-GCM) in ~/.ugsearch/sessie.enc |
| Browser profile of the sign-in window (Ghent University sign-in cookies, so "stay signed in" works, and the normal browser cache) | To sign you in again silently when the Ufora session expires | ~/.ugsearch/browserprofiel/, managed by Chrome or Edge. UGSearch does not add encryption on top of what the browser itself does. |
| Knowledge base of your current courses: course names and codes, announcements, table of contents, assignments and quizzes (titles, deadlines, instructions), calendar, to-do items, forum topics, your groups (including group members' names), open group sign-ups, and the text of pages and documents (HTML, PDF, Word, PowerPoint, plain text) | To answer your questions instantly and completely | Encrypted (AES-256-GCM) in ~/.ugsearch/kennis/ |
| Grades, forum posts, your name | Only when you ask for them | Fetched live, not stored on disk |
| Setting "writing on/off" | Whether write actions are allowed | ~/.ugsearch/instellingen.json |
| Documents you choose to download | On your request (the "document downloaden" tool) | Downloads/Ufora/<course>/ |
~ is your home folder (macOS: /Users/<name>, Windows: C:\Users\<name>).
The encryption key is created on your computer. On macOS it is stored in the Keychain (item "ugsearch"). On Windows it is stored in the file ~/.ugsearch/.sleutel in your home folder. On Windows the encryption therefore mainly protects against copying individual data files, not against someone with access to your whole user account.
UGSearch reads nothing from your AI app: no chat history, no memory, no uploaded files.
2. What goes where
- Ufora (Ghent University),
https://ufora.ugent.be. UGSearch requests your Ufora data with your own session, the same way your browser does. The code only allows read requests to a fixed list of Ufora addresses, and never sends your session to any other website. Write actions (posting to a forum, submitting an assignment, joining or leaving a group, pinning a course) happen only after you click Allow ("Toestaan") in a macOS or Windows system dialog. The AI cannot click that button. During sign-in, the browser window talks directly to Ghent University's sign-in page. How Ghent University handles your data is described in the Ufora privacy statement. - GitHub,
api.github.com. To tell you when a new version exists, UGSearch asks GitHub for the latest release number at most once every 6 hours. The request is anonymous: it contains no Ufora data and nothing about you. Like any internet request, GitHub does see your IP address and the label "UGSearch". See GitHub's privacy statement. - Your AI app (for example Claude by Anthropic). When you ask a question, UGSearch passes the relevant Ufora information to your AI app so it can answer. What that app does with it (storage, processing, possibly training) is governed by that app's privacy policy, not by UGSearch's. Don't share anything through your AI that you don't want to share with that service.
UGSearch does not sell data, shows no ads and keeps no content from Ufora with its makers.
3. Retention
- Data stays on your computer until you delete it. While UGSearch runs, it refreshes the knowledge base with your current courses every 20 minutes. Document texts that were already read stay stored until you delete everything.
- Removing the extension from your AI app does not delete the
~/.ugsearchfolder. Delete it yourself (see below). - Downloaded documents in
Downloads/Uforaremain until you delete them.
4. Deleting your data
- Through your AI: ask your AI "wis alles van UGSearch" (delete everything from UGSearch) and confirm in the dialog. Or delete the
.ugsearchfolder in your home folder, as described below. - Manually (always possible, also when installed as an extension):
- Quit your AI app.
- Delete the
.ugsearchfolder in your home folder. On macOS: Finder โ Go โ Go to Folder โ~/.ugsearch. On Windows:%USERPROFILE%\.ugsearch. - On macOS: open Keychain Access and delete the item ugsearch.
- Optionally delete
Downloads/Ufora. - To end your Ufora session at Ghent University as well, sign out in Ufora itself.
5. Children
UGSearch is meant for Ghent University students and is not directed at children under 16.
6. Changes
If this policy changes, we update the date at the top and mention the change in the GitHub release notes.
7. Your UGSearch account (ugsearch.app/app)
If you create an account, we store in Supabase (EU, Frankfurt):
- your email address and the name you enter (or the one from your Microsoft profile if you sign in that way);
- for each linked computer, technical data only: a name (e.g. "Thibault's MacBook"), the operating system, the UGSearch version, whether UGSearch is connected to Ufora (yes/no) and with how many courses, whether the online link is active, the names of the AI apps you linked (e.g. "Claude", "ChatGPT"), your permanent link id, and when your computer last checked in.
We never store content from Ufora, your Ufora sign-in, your password, your questions to your AI or the answers.
- Your computer sends this data every 15 minutes, signed with a key that exists only on your computer. To turn this off, run
ugsearch account uit, or unlink your computer in the dashboard. - Deleting: "Account wissen" (delete account) in the dashboard immediately removes your account, your devices and your link codes.
- Legal basis: performance of the service you request (your account). Retention: as long as your account exists. A device that has not checked in for 12 months is deleted.
8. The online link (relay.ugsearch.app)
If you connect UGSearch online (Claude online, ChatGPT, Le Chat), your AI app's requests travel through our relay server to UGSearch on your computer.
- The relay server runs on Cloudflare. It does not store or log the content of requests and responses. It can technically see them while forwarding, because encryption ends at the server. A fully end-to-end encrypted version is planned.
- Your Ufora sign-in and your knowledge base stay on your computer.
- Cloudflare processes technical connection data, such as IP addresses, under its own privacy policy.
9. The website ugsearch.app
- Hosting. The website runs on Vercel. Like any web server, Vercel records technical data about your visit (IP address, browser, time) to run and secure the site. See Vercel's privacy policy.
- No tracking. The site uses no analytics and no ads. Fonts and images are served by the site itself. When you sign in, your browser keeps your session (local storage) so you stay signed in.
- Waiting list. Existing waiting-list sign-ups are kept until launch and deleted afterwards, at the latest 12 months after launch. You can have them deleted sooner.
- Downloads come from GitHub. When you download, GitHub sees your IP address.
10. Contact
-
Data controller: Hellebuyck Adventures, Thibault Hellebuyck.
-
Questions or problems: GitHub Issues on ugsearch-releases. Please don't post personal data there.
- Security issues or privacy complaints, confidentially: GitHub Security Advisories on ugsearch-releases.
- About your data in Ufora itself: Ghent University, via privacy@ugent.be.