Privacy, in plain English
Your Canvas login stays in Canvas.
Canvas Pilot organizes a read-only copy of coursework you can already access. This policy explains what the website, Canvas Pilot Connector, and optional ChatGPT connection handle—and what they deliberately leave alone.
Last updated September 23, 2026
The short version
- The connector never reads or transmits your Canvas password, browser cookies, CSRF values, or Canvas session tokens.
- A sync happens only after you choose Pair & sync Canvas or Sync Canvas.
- Canvas Pilot uses the normalized coursework snapshot only to provide the study hub, synchronization, support, and connections you request.
- Canvas Pilot does not sell coursework or account data, use it for advertising, or run advertising trackers.
Information Canvas Pilot handles
Account information
When you create a Canvas Pilot account, the authentication provider processes your display name, email address, account identifier, verification state, and secure sign-in records.
Normalized Canvas coursework
When you start a sync, the connector may read and upload your Canvas profile identifier and display name; course and term details; modules and module items; assignments; due dates; grades; submission, completion, and planner state; syllabus and referenced page text; discussion-topic and announcement text; quiz metadata; file metadata; and calendar or planner entries, including a location name or address when Canvas provides one. A Simple Syllabus document is included only after you open that document and explicitly import its visible text.
Connector and service records
The connector stores its configuration, normalized snapshot, sync status, and a revocable device credential in Chrome local extension storage. The cloud service stores the matching device identifier, a one-way credential digest, sync revision, timestamps, and the current normalized snapshot for your account. Service providers may process basic request metadata needed to deliver and secure the service.
Support reports
If you submit the in-app support form, Canvas Pilot stores the category, summary, description, current page, account reference, and submission time. Coursework, screenshots, console logs, cookies, and credentials are not attached automatically.
How the information is used
- Build your private coursework dashboard and keep it available after the collecting computer is off.
- Show courses, modules, readings, deadlines, grades, status, search results, and freshness information.
- Synchronize a new snapshot when you request it and protect access by tenant and device.
- Give an AI connection read-only access to your stored snapshot only after you authorize that connection.
- Diagnose a report you submit, prevent abuse, and operate the service securely.
Canvas Pilot does not use this information to submit coursework, start assessments, change grades, modify Canvas, determine creditworthiness, or build advertising profiles.
Where information goes
Normalized coursework and account records are processed by Canvas Pilot's contracted hosting providers: Appwrite for account and application data, and Railway for the synchronization and MCP API. Canvas receives read-only requests from your already signed-in browser. ChatGPT or another supported MCP client receives coursework only after you separately authorize that connection.
Canvas Pilot does not transfer user data to data brokers or advertising networks. Information may be disclosed when required by law, to protect users or the service, or during a business transfer with equivalent privacy obligations.
Storage, retention, and your choices
- A newer successful sync replaces the current cloud snapshot for your account; Canvas Pilot is not a permanent archive of every historical Canvas response.
- The connector's local data remains in that Chrome profile until you clear the extension's data or uninstall it.
- Cloud account and coursework data remain while your account is active or until a deletion request is completed. Security, support, and backup records may remain for a limited period where operational or legal obligations require it.
- You can revoke ChatGPT access from ChatGPT's connected-app controls and remove the connector from Chrome at any time.
- Until self-service export and deletion controls are available, submit an Account request in Canvas Pilot under Settings → Help & feedback to request access to or deletion of your cloud data.
Chrome Web Store Limited Use
Canvas Pilot Connector's use and transfer of information received from Google Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the connector's prominent, user-facing coursework synchronization purpose.
Security and scope
Data is sent over HTTPS. The connector constructs a new allowlisted snapshot, strips URL query strings, rejects credential-like fields, and makes read-only Canvas requests. No system is perfectly secure, so keep your browser and connector current and report unexpected behavior promptly.
Canvas Pilot is independent and is not affiliated with Instructure or Canvas. You remain responsible for following your school’s policies when using the service.
Questions or requests
Use the private Help & feedback form inside Canvas Pilot for account or data requests. For public, non-sensitive product issues, use the support page below. Do not post coursework, grades, account identifiers, or credentials in a public issue.