Proxy keeps student names out of AI.
Proxy is Morrow's browser-local privacy layer. You can refer to a student by name, but the assistant sees a stable local code. When the answer returns, Proxy restores the name for you using a map the AI never receives.
How a request actually travels
Follow one line of course data on its way to the AI and back. Proxy swaps the name for a stable code before AI sees it, then renders the returned code as the real name only in your browser.
- What you see Canvas, with real names
You can ask naturally, the way instructors and designers already talk about a course.
- Proxy substitution Local map created in browser
Proxy assigns a stable local code, rewrites the outbound text, and keeps the code-to-name map out of the AI request.
- What AI sees Stable codes, not names
The assistant reasons and answers in stable codes. It never receives the local map that links Learner A1 to the learner on your screen.
Proxy keeps this map only in your browser. It is never sent to the AI, and it is what lets your screen show the student while the assistant only reasons about Learner A1.
Technical trace
The link is local. The AI only gets the code.
Proxy is useful because it keeps the relationship between real student identities and stable codes on the browser side of the boundary. The model can keep context across the task, but it does not get the lookup table.
- 1. Detect Proxy scans the AI-bound message for names, Canvas IDs, SIS IDs, emails, profile fields, and other direct student identifiers.
- 2. Link locally Each detected student identity is linked to a stable local code such as Learner A1. That lookup table is held in the browser, not sent with the request.
- 3. Send codes The rewritten message leaves the browser with useful course context plus stable codes, so the AI can reason across the task without seeing the roster.
- 4. Restore for you When the answer comes back, Proxy reads the stable codes and renders the matching real names in the authorized browser view.
Who sees what
Proxy makes the privacy boundary visible: what stays in the local Canvas session, what reaches the AI provider, and what Morrow cloud storage can back up for review.
Real names and the code map
The Canvas page, the student name, and the code-to-name map stay in the local browser layer. That is why your screen can read naturally while the outgoing request stays de-identified.
- Real Canvas context
- Student names
- Code-to-name map
De-identified text and stable codes
The model receives the course request after Proxy has stripped identifying details and replaced names with stable codes like Learner A1.
- Course task
- Stable student codes
- No local map
Account and subscription status only
Morrow's backend stores only your account email and subscription status. Reports and alignment evidence stay in your browser and are never sent to Morrow's servers.
- Account email
- Subscription status
If it could identify a student, Proxy strips it first
The layer is tuned for real course data, where names show up in rosters, gradebooks, SpeedGrader links, and free text. It looks for all of it.
- Names
- Student names, even when they are not labeled as such, across Latin, Cyrillic, and Han scripts.
- Contact
- Email addresses, phone numbers, and mailing addresses.
- Identifiers
- Student, SIS, and Canvas user IDs, login IDs, SpeedGrader IDs, and the ID baked into a grading link.
- Profile
- Sortable names, pronouns, avatar URLs, and other identity fields Canvas returns.
- Sensitive
- Social Security numbers and dates of birth.
- Grades, when tied to a person
- Scores and grades that arrive attached to a named student row.
Terms your reports depend on, like program names and quality standards, are deliberately kept, so the AI still has the context it needs to be useful.
Why Proxy uses stable codes, not blackouts
Proxy does more than black names out. Each student gets a stable local code, and the same student gets the same code every time.
That small detail is what makes the answers genuinely useful: the AI can reason about a person across a conversation without ever being told who that student is.
The map from code back to real name is built and held only in your browser. It is never part of what goes to the model. When an answer comes back, Proxy uses that local map to render the real names in front of you.
- Learner A1student name
- Learner A2student name
- Learner A3student name
Proxy is the only path to AI
Automatic, every message
Proxy checks every message bound for the AI, at the last step before the request leaves. There is no toggle to forget and no exception to opt into.
In your browser
It happens on your machine, not on a server Morrow runs. Morrow's backend never receives your roster, your chats, or your course content in the first place.
You bring the AI
Messages go to the ChatGPT account you connect, carrying only de-identified text and stable local codes. You approve every change Morrow proposes; it never finalizes anything on its own.
What this means for your program
The AI does not receive the roster or Proxy map
It receives de-identified text and stable codes. Proxy strips student names, IDs, emails, and other direct identifiers before the request reaches the model.
Morrow never receives your roster
You use your own AI account, and the only thing it receives is de-identified text. Morrow does not receive the raw roster, the local code map, or active course conversations.
The browser translates codes back for you
The local map renders real names in your browser view. You work with familiar names, while the AI only sees stable local codes.
Want the legal detail?
This page explains how Proxy works. The privacy policy is the complete terms: what Morrow reads, what it sends and where, the short list of what we store, and your rights.