Purpose and status
This page is a public overview of Morrow's Data Processing Addendum posture. It is written for privacy, legal, procurement, and information security reviewers who need a clear starting point before contract exchange.
It is not a substitute for the signed DPA, order form, or institution-specific legal terms.
Plain status: Morrow can provide DPA terms for customer review. The public site should describe the posture accurately, while binding commitments are made in the signed agreement.
Roles
Morrow's role depends on the data and workflow. For institutional course review work, the customer controls the educational record and decides whether Morrow is authorized for the Canvas environment.
Morrow processes data only to provide the product and related support, security, backup, and account services.
| Party | Typical role | Responsibility |
|---|---|---|
| Customer institution | Controller for customer-controlled data. | Authorizes use, manages Canvas roles, controls institutional policy, and responds to student or faculty rights requests. |
| Morrow | Processor or service provider under the signed terms. | Processes data to deliver the product, runs Proxy before AI-bound text leaves the browser, applies storage controls, and supports audit/evidence workflows. |
| AI provider | Customer-controlled service when the customer uses its own ChatGPT/OpenAI account. | Receives redacted prompts through the account the customer or instructor provides, subject to that provider's terms and settings. |
Institution-specific student-data terms, if required by the institution, are handled in the signed customer agreement rather than assumed by this public overview.
Data categories
Morrow is designed to keep active course operation local and store only the data needed for account access, subscription checks, evidence continuity, support, and compliance review.
| Category | Examples | Morrow handling |
|---|---|---|
| Account data | User email, account identifiers, plan or subscription state. | Stored by the backend for sign-in, licensing, support, and account administration. |
| Course content | Canvas pages, modules, quizzes, assignments, rubrics, dates, and settings selected by the user. | Processed through the user's browser and Canvas session. Morrow stores de-identified reports and evidence, not live rosters. |
| Student-identifying data | Student names, IDs, emails, and roster identifiers that may appear in course context. | Filtered locally before AI use and before Morrow report/evidence storage. Not used for model training by Morrow. |
| Generated evidence | Alignment reports, audit history, change rationale, and evidence exports. | Stored as de-identified review records so customers can retrieve audit evidence across sessions and devices. |
Security measures
The DPA should attach or reference technical and organizational measures that match Morrow's product posture. The public summary includes the measures reviewers most often need to route a risk decision.
- Chrome Manifest V3 extension architecture with packaged code and documented permissions.
- Local redaction before AI requests and before cloud storage of generated evidence.
- Customer-controlled Canvas session; Morrow does not store Canvas passwords.
- Approval-gated writes for course-changing operations.
- Encrypted cloud services for account records and de-identified report/evidence backup.
- Limited access to production systems based on operational need.
- Incident response and customer notification commitments defined in the contract packet.
Subprocessors and adjacent services
Morrow distinguishes true subprocessors from customer-controlled services. The subprocessor list in a signed DPA should be the authoritative version, but the public posture is:
| Service | Purpose | Boundary |
|---|---|---|
| Supabase | Authentication, account records, and backend data services. | Morrow subprocessor for account and backend service operation. |
| Stripe or payment processor | Billing and subscription payment processing when applicable. | Payment details are handled by the payment processor and do not pass through the extension. |
| OpenAI / ChatGPT | AI response generation using the customer's or instructor's account. | Usually customer-controlled in Morrow's bring-your-own-AI model; redacted data is sent under the customer's AI account settings. |
| Canvas / Instructure | Customer LMS where course data originates. | Customer system of record, not a Morrow subprocessor. |
Rights, deletion, and return
Customer agreements should define how Morrow assists with access, correction, deletion, export, retention, and return of customer data.
Operationally, Morrow can separate account records from generated de-identified evidence.
That lets legal and security teams make retention decisions without touching live Canvas data.
- Customers can request deletion of account-linked records subject to legal, billing, security, and backup-retention limits.
- Generated evidence can be exported for institutional retention before account closure.
- Canvas remains the source of truth for live course content and student records.
- Student or data-subject requests should route through the institution, which controls the educational record.
International transfers
If a customer requires GDPR transfer terms, Morrow can address them in the signed packet. The European Commission publishes standard contractual clauses for controller-processor relationships under Article 28 GDPR.
Customer counsel should identify the required transfer module and supplementary terms for the deployment.