← Back to Canvas Pilot

Privacy, in plain English

Your Canvas login stays in Canvas.

Canvas Pilot organizes a read-only copy of coursework you can already access. This policy explains what the website, Canvas Pilot Connector, and optional ChatGPT connection handle—and what they deliberately leave alone.

Last updated September 23, 2026

The short version

Information Canvas Pilot handles

Account information

When you create a Canvas Pilot account, the authentication provider processes your display name, email address, account identifier, verification state, and secure sign-in records.

Normalized Canvas coursework

When you start a sync, the connector may read and upload your Canvas profile identifier and display name; course and term details; modules and module items; assignments; due dates; grades; submission, completion, and planner state; syllabus and referenced page text; discussion-topic and announcement text; quiz metadata; file metadata; and calendar or planner entries, including a location name or address when Canvas provides one. A Simple Syllabus document is included only after you open that document and explicitly import its visible text.

Connector and service records

The connector stores its configuration, normalized snapshot, sync status, and a revocable device credential in Chrome local extension storage. The cloud service stores the matching device identifier, a one-way credential digest, sync revision, timestamps, and the current normalized snapshot for your account. Service providers may process basic request metadata needed to deliver and secure the service.

Support reports

If you submit the in-app support form, Canvas Pilot stores the category, summary, description, current page, account reference, and submission time. Coursework, screenshots, console logs, cookies, and credentials are not attached automatically.

How the information is used

Canvas Pilot does not use this information to submit coursework, start assessments, change grades, modify Canvas, determine creditworthiness, or build advertising profiles.

Where information goes

Normalized coursework and account records are processed by Canvas Pilot's contracted hosting providers: Appwrite for account and application data, and Railway for the synchronization and MCP API. Canvas receives read-only requests from your already signed-in browser. ChatGPT or another supported MCP client receives coursework only after you separately authorize that connection.

Canvas Pilot does not transfer user data to data brokers or advertising networks. Information may be disclosed when required by law, to protect users or the service, or during a business transfer with equivalent privacy obligations.

Storage, retention, and your choices

Chrome Web Store Limited Use

Canvas Pilot Connector's use and transfer of information received from Google Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the connector's prominent, user-facing coursework synchronization purpose.

Security and scope

Data is sent over HTTPS. The connector constructs a new allowlisted snapshot, strips URL query strings, rejects credential-like fields, and makes read-only Canvas requests. No system is perfectly secure, so keep your browser and connector current and report unexpected behavior promptly.

Canvas Pilot is independent and is not affiliated with Instructure or Canvas. You remain responsible for following your school’s policies when using the service.

Questions or requests

Use the private Help & feedback form inside Canvas Pilot for account or data requests. For public, non-sensitive product issues, use the support page below. Do not post coursework, grades, account identifiers, or credentials in a public issue.