Canvas+ Privacy Policy
- Your Canvas name, login, grades and submissions are never sent to us or anyone else.
- Using Canvas+ requires a free Canvas+ account. It stores only your e-mail address. No password.
- No ads, no tracking across websites, no analytics tools. The only usage counts are which days your account opened Canvas+ and which Canvas+ features it used on those days (dates and feature names only, see below). Nothing is sold or shared, or used for anything other than the features you see.
What Canvas+ reads, and why
Canvas+ only runs on Canvas sites: every *.instructure.com site, plus any other Canvas site you turn it on for yourself from the toolbar button. On those sites it reads, using the Canvas login you already have in your browser:
| Information | Used for |
|---|---|
| Your courses, terms and course colours | Course list, short course names, colours |
| Your To Do / planner items (titles, due dates, submission status) | The deadline list, countdowns and reminders |
| Assignment groups, weights, points and your scores | “% of final grade” tags and the final-exam calculator |
| The course grading scheme | Letter-grade cut-offs in the calculator |
| The course syllabus / home page text (only for courses with no weights set in Canvas) | Finding the grade breakdown (e.g. “Homework 20%”) for the calculator |
| Your current score in each course, and your final scores and terms from past courses | The score next to each course, the cumulative / term GPA dashboard and the GPA projection |
| Work Canvas marks as missing, and the course’s late policy (when Canvas shares it) | The missing-work alert and what a late submission would cost |
| Course modules and the course’s Files (names, folders, and the files you choose) | Downloading course files as a .zip, and picking slides for an exam review pack |
Canvas+ never asks for your password and cannot see it. It reads this data directly from Canvas in your browser; it is not copied anywhere else.
Canvas+ AI assignment summary (optional)
Only when you click “AI summary” on an assignment, quiz or discussion (signed in to a free Canvas+ account, and after you agree the first time), Canvas+ sends that assignment’s own text — its title, instructions, rubric, due date and points — to the Canvas+ server at ai.baowenliu.com. The server asks a third-party AI provider to write the summary and sends it back. If the assignment links to files (PDF, Word, text), other Canvas pages, or outside web pages, the text of up to 4 of those files/pages (read in your browser with your own Canvas login) and the addresses of up to 3 outside links are sent too; the server then downloads those public web pages itself to read them. Nothing else from your Canvas account is sent.
AI syllabus summary: when you click “AI syllabus summary” for a course, the same rules apply to that course’s syllabus: Canvas+ sends the text of the course’s Syllabus page (and the course home page if the syllabus is short), plus up to 4 syllabus files or pages it links to (or a file named “syllabus” in the course files), so Canvas+ AI can list exam dates, the grade breakdown and the course policies. Your grades are never sent. “Add to calendar” creates the .ics file in your browser; nothing about it is sent anywhere. If the syllabus’s grade breakdown doesn’t add up to 100%, Canvas+ fills in the rest from the assignment-group weights on the course’s Grades page — read in your browser only and never sent.
AI e-mail drafts: when you click “Write an e-mail” (to ask for an extension, ask about the rubric, book office hours, and so on), Canvas+ sends the assignment’s title, due date, points and part of its instructions, plus what you type in the form (for example the reason you choose to give), to the Canvas+ server, which returns a draft. Your name and your instructor’s or TA’s name are not sent: they are read from Canvas and filled into the draft in your browser. Drafts are not stored on the server. Canvas+ never sends e-mails for you — you copy the draft or open it in your own mail app.
Simple Syllabus: some schools keep syllabi on Simple Syllabus (school.simplesyllabus.com) instead of Canvas’s Syllabus page. Only if you allow that site (Chrome asks you once, in a small window), Canvas+ opens that course’s own “Simple Syllabus” link from the course menu (in a hidden frame, the same way Canvas opens it, with your own sign-in), notes which syllabus it shows, and reads that one syllabus from your browser. Nothing is searched or guessed; the syllabus found is remembered for that course in your browser. Its text is then used exactly like a Syllabus page above (the AI syllabus summary, and the calculator’s grade breakdown). Canvas+ never changes anything on Simple Syllabus, and nothing else is sent to it. You can remove the permission any time in chrome://extensions.
Zoom recordings (lecture notes): only if you allow Canvas+ on zoom.us (Chrome asks you once, from the AI Course tab), Canvas+ adds a “Lecture notes” button to Zoom cloud-recording pages. When you click “Make lecture notes”, it reads that recording’s transcript (the captions Zoom made from the audio, with their times — the same text as Zoom’s “Audio transcript” panel; speaker names are removed) and sends only that text and the recording’s title to the Canvas+ server, which asks the AI to write chapters with timestamps, key points and anything said about exams or deadlines. The video, the recording link and your name are not sent. Nothing is stored on the server: neither the transcript nor the notes. The notes are saved only in your browser. Nothing happens on Zoom until you click the button. You can turn this off any time in chrome://extensions.
AI course Q&A: when you ask a question about a course, Canvas+ reads that course’s syllabus (and the syllabus file it links to), modules (their outline, and the course pages and files in them that match your question), assignments, announcements and the course’s grade setup (assignment groups and their weights — not your scores) in your browser with your own Canvas login, picks the parts most related to your question, and sends them with your question (and your previous two questions and answers in that conversation) to the Canvas+ server, which answers only from that material. Your grades, submissions and name are not sent. Questions and answers are not stored on the server.
New grade and announcement notifications: every 15 minutes (and when you open Canvas), Canvas+ asks Canvas — with your own login, from your browser — for recently graded work and new announcements in your current courses, and shows a notification on your computer. Only which items it has already told you about is remembered, in your browser. Nothing is sent to the Canvas+ server. Scores are hidden in notifications unless you turn that on; each kind of notification can be turned off in the reminder settings.
Weekly digest: on your first Canvas visit each week, Canvas+ puts together — in your browser — the past week’s new assignments, new grades and announcements and the next 7 days’ deadlines, and keeps it (plus a snapshot of your course totals, to show the change from last week) in your browser’s extension storage only. Grades never leave your computer. If you use “This week’s focus”, Canvas+ sends only the announcements and the assignment names and due dates to the Canvas+ server, which returns a short list of priorities; it is not stored on the server. The Monday reminder is a local Chrome notification and can be turned off in the reminder settings.
Exam review packs: when you make a review pack for an exam, you pick which course files (slides, notes, PDFs, Word files, course pages) it should use. Canvas+ reads those files in your browser with your own Canvas login and sends their names and text, with the course name and the exam’s name, date and scope, to the Canvas+ server, which asks the AI provider to write a study outline, practice questions and flashcards. Neither the material text nor the pack is stored on the server. Your packs, and your answers to their practice questions, are saved only in your browser.
All my exams: the exam list, and the exam dates under each course, come from two places. (1) Without any AI: every few hours Canvas+ reads your current courses’ assignment list from Canvas, with your own login, in your browser, and picks out the quizzes and assignments that are exams (named like “Midterm” or “Final Exam”, or in an exam group) with their due dates; nothing is sent to the Canvas+ server. (2) The course’s syllabus read by the AI syllabus summary above (a syllabus already read costs nothing). The dates are kept in your browser only, and also feed the calendar view and the exam reminders.
- Never sent: your name, Canvas login, grades, submissions, messages or any other personal information.
- Sent along: a random install ID created by the extension. Using the AI requires a free Canvas+ account (see below); the daily limit shown in the panel is counted per account.
- Kept on the server: only daily usage counts per account and per a hashed IP address (raw IP addresses are not stored), deleted after a week. Neither the assignment text nor the summary is stored on the server; your summaries are saved only in your browser.
- The third-party AI provider processes the text only to write the answer, under its own terms and privacy policy.
- If you never use an AI feature, nothing is ever sent.
Your course’s rules on AI come first. Every Canvas+ AI feature sends course material text (assignment instructions, syllabi, course files and pages you choose) to the Canvas+ server and on to the third-party AI provider above. Some courses don’t allow AI tools, or don’t allow course materials to be shared with them. Whether to use these features is your decision, following each course’s policy. Canvas+ AI is built to help you understand, plan and review — it explains the process and does not do your work for you.
Features that stay in your browser
These use only data Canvas+ reads in your browser, and send nothing to the Canvas+ server:
- Course cards and score trend: each course’s current score from Canvas, and a line of how your course grade changed, rebuilt from your graded work (the date each score was graded and the course’s weights). Worked out and drawn in your browser; the trend is cached there for up to 30 days so the cards open quickly.
- GPA dashboard and projection: your past course scores and letters, the credits, letters and grading scale you enter, and the “what-if” letters. Your own settings are saved with Chrome’s
storage.sync(see below). - Mistake book: multiple-choice questions you answer wrong in a review pack, how often you missed them and whether you have mastered them. Saved only in your browser; “Export to Anki” creates a file on your computer.
- Missing-work alert: read from Canvas when you open the panel, shown only there.
- Deadline changes, course-total changes and exam reminders: every 15 minutes Canvas+ asks Canvas, with your own login, for your courses (with your current course totals) and upcoming items, and compares them with what it saw last time. When a total changes, a deadline moves, or an exam is 3 days or 1 day away, it shows a notification on your computer (with the course’s mistake-book count). The last totals, deadline times and which reminders were sent are kept in your browser only. Each kind of notification can be turned off in the reminder settings.
- Course file downloads: the .zip file is built in your browser.
- Background picture: the picture you upload is kept in your browser’s local storage only.
Feedback and bug reports
When you use “Feedback / report a problem” in the panel (signed in to your Canvas+ account), Canvas+ sends to the Canvas+ server: the type you pick and the message you write, plus the Canvas+ version, your browser and operating system (for example “Chrome 131 · macOS”), the path of the Canvas page you were on (for example /courses/123/grades — never the rest of the address), and the panel language, so bugs can be reproduced. It is stored with your account e-mail, so the developer can reply, and a one-way fingerprint (hash) of the account that limits how many messages can be sent per day. Only the developer can read it, on a password-protected page, and uses it only to answer you and improve Canvas+. Nothing is sent unless you press “Send”; no grades or course content are included unless you type them. To have your feedback deleted, e-mail me@baowenliu.com.
Canvas+ account (required)
You sign in once with a free Canvas+ account before using Canvas+. The account keeps the free AI daily limit fair, lets the developer reply to your feedback, and carries a paid membership to any computer. Signing in sends only your e-mail address; nothing from Canvas is attached to your account. There is no password. You can sign in:
- With Google: Chrome opens Google’s own sign-in window. Canvas+ asks only for your verified e-mail address (scopes “openid email”) — not your name, contacts, Drive or anything else — and never sees your Google password.
- With an e-mail code: we e-mail you a one-time 6-digit code. Only a hash of the code is kept, for 10 minutes. To stop abuse, the number of codes per network (hashed IP) and per day is limited.
Kept on the server: your e-mail address, when the account was created, which browsers (random install IDs, at most 3) are signed in, and which days the account opened Canvas+ (the date only, at most once a day, kept 180 days) with the last time it did, and which Canvas+ features the account used each day (feature names only, such as “calendar”, “final grade calculator” or “syllabus summary”; at most once per feature per day; kept 180 days) — used only to count how many students use Canvas+ and which features they use most. Nothing about which pages, courses or assignments you looked at, or what you typed, is recorded. Sign out from “My account” in the panel. To delete your account, e-mail me@baowenliu.com and it will be removed within 30 days.
Canvas+ AI Pro (optional paid membership)
Canvas+ AI Pro is a monthly subscription that raises the daily AI limit. Payment happens on Stripe’s own checkout page; your card details go only to Stripe and are never seen or stored by Canvas+.
- Kept on the server when you subscribe: your account e-mail, your Stripe customer and subscription IDs, the subscription’s status and renewal date, and a backup activation code (with the install IDs of the at most 3 browsers using it). We e-mail you once to confirm the membership.
- Stripe processes payments under its own privacy policy (stripe.com/privacy).
- You can cancel any time from “Manage or cancel” in the panel. To have your membership record deleted, e-mail me@baowenliu.com.
What Canvas+ changes in Canvas
Only one thing, and only when you ask: when you tick the circle next to an item, Canvas+ marks it as done (or not done) in your own Canvas To Do list. It never submits work, changes grades, or posts anything.
What is stored, and where
- Your settings (dark mode, colours, language, reminder options, which items are hidden) are saved with Chrome’s
storage.sync. If you use Chrome Sync, Google syncs these settings between your own browsers; Canvas+ itself receives nothing. - Temporary copies of your deadline list and grade weights are cached in Chrome’s local storage on your computer (for a few minutes to a few hours) so the panel opens quickly and reminders can be shown. They never leave your device.
- Kept in your browser until you delete them or uninstall: your review packs and practice answers, your mistake book, exam dates read from syllabi, the snapshots used for change notifications (course totals, deadline times, which reminders were sent), and your background picture. They never leave your device.
Permissions
| Permission | Why |
|---|---|
Access to *.instructure.com | Run on Canvas and read your Canvas data (see above) |
| Optional access to other sites | Only for a Canvas site you turn on yourself, one site at a time; you can remove it any time |
storage | Save your settings and the local caches |
scripting, activeTab | Start Canvas+ on a Canvas site you just turned on, and check whether a page is Canvas when you click the toolbar button |
alarms, notifications | Show deadline reminders (24 h / 2 h), new grades and announcements, course-total and deadline changes, exam reminders and the weekly digest at the right time |
identity | Open Google’s sign-in window when you choose “Sign in with Google” |
Deleting your data
Turn off anything in the panel at any time. Uninstalling Canvas+ removes all of its stored data from Chrome. You can also remove a site from the toolbar popup. To delete your Canvas+ account, membership record and feedback from the server, e-mail me@baowenliu.com (an active subscription is cancelled first).
Children
Canvas+ is a tool for university students and is not directed at children under 13. The account stores only an e-mail address (and any feedback sent with it); if you believe a child has created one, e-mail me@baowenliu.com and it will be deleted.
Chrome Web Store
The use of information by Canvas+ complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Not affiliated
Canvas+ is an unofficial, independent project. It is not affiliated with or endorsed by Instructure or any school. Canvas is a trademark of Instructure, Inc.
Changes and contact
If this policy changes, the new version and its date will be posted here. Questions: me@baowenliu.com