Privacy Policy
Morrow is a Chrome extension that helps instructors run their Canvas courses through a chat interface. This policy explains what data Morrow reads, what it sends and where, and the short list of what we keep.
Your active courses stay local
Active courses, chat edits, and finished alignment reports all live in your browser’s extension storage. Nothing about your courses or reports is synced to Morrow’s servers.
Student details become stable codes
Before any message reaches your AI provider, Proxy checks the outbound text and swaps student-identifying details for stable codes inside your browser.
Backend stores only your account
Morrow’s backend handles sign-in and licensing only. It stores your account email and subscription status, never your reports, course content, rosters, or student credentials.
What Morrow is
Morrow is a Chrome extension that helps instructors manage Canvas course work through a chat interface. The extension itself runs entirely inside your browser, beside your Canvas course.
It uses the ChatGPT account you connect for AI: you bring the AI account, and Morrow does not provide one.
Morrow has one small backend for account sign-in and subscription status. It is operated with Supabase for authentication and account records.
Billing, when applicable, is handled by a payment processor.
The important boundary: Morrow's backend never stores your course content, chats, or generated reports. Active course content, credentials, student roster identities, and your finished reports never touch Morrow’s servers — they stay in your browser.
Raw Canvas content and the local Proxy code map stay out of Morrow's backend.
What data Morrow reads
While you use Morrow, the extension reads:
- Your Canvas session cookies (from Chrome’s cookie store), only to send authenticated requests to Canvas on your behalf, exactly as your browser does when you click around Canvas yourself. Your cookies are never copied anywhere, stored on disk, or transmitted to any server other than Canvas.
- Your Canvas quiz authentication token, read from the Canvas quiz page so Morrow can make Canvas quiz requests as you. It is never transmitted off your device.
- Course content visible in your browser: when you ask Morrow about a specific course, module, assignment, or page, it fetches that content through the Canvas API (as you) so it can answer your question. It only fetches what you ask about.
- The URL of the tab you’re on, so it knows whether you’re currently on Canvas or somewhere else. The URL is used for context display only; no browsing history is kept.
- Your ChatGPT sign-in, or your OpenAI API key, whichever you provided during setup. Used only to call your own AI account on your behalf.
- Your account email, if you create a Morrow account. Used only to sign you in and check your plan.
Morrow does not read:
- Other websites’ cookies or content.
- Your browsing history beyond the current tab’s URL.
- Files on your computer outside of ones you explicitly attach to a project.
- Your password, PIN, or any non-cookie credential. Your Morrow account password is handled by Supabase Auth and is never seen by the extension.
- Your payment card details. If your account includes a paid subscription, payment is handled by our payment processor; card details never reach Morrow or pass through the extension.
What data Morrow sends, and where
- Your chat messages → your AI provider
(
api.openai.com, orchatgpt.comif you signed in with ChatGPT). Sent using the account or API key you provided, which is your own AI account. Before any message leaves your browser, Proxy checks outbound text and swaps student-identifying details for stable codes before the text reaches AI. - Canvas API requests → Canvas
(
*.instructure.comand its quiz variants), authenticated as you, using your existing Canvas session. - Sign-in redirects → OpenAI / ChatGPT
(
auth.openai.com,chatgpt.com), only if you chose “Sign in with ChatGPT.” - Account sign-in and subscription check → Morrow’s backend
(
*.supabase.co). When you sign in, your email and an authentication token are sent to verify your account and return your subscription status. Nothing about your courses, chats, or generated reports is sent to Morrow’s backend — those stay in your browser. - Billing → our payment processor (if your account includes a paid subscription). Payment is handled by our payment processor; card details never reach Morrow, and Morrow receives back only the resulting subscription status.
Morrow sends no analytics, no telemetry, no crash reports, and no usage pings to anyone. There is no tracking pipeline.
Morrow's backend stores only your account details and subscription status. It cannot track your browser activity, search history, active editing sessions, or the reports you generate.
What Morrow stores
On your device, in your browser’s extension storage:
- Your chat conversations.
- Your projects, with their custom instructions and any files you attached.
- Settings and preferences, such as which AI model you’re using and your UI preferences.
- Your ChatGPT sign-in or OpenAI API key, and, if you signed in, your Morrow account session token.
- A cached copy of your subscription status, so the UI works offline.
On Morrow’s backend (Supabase), if you create an account:
- Your account email and authentication record.
- Your subscription status (mirrored from Stripe).
That is the complete list of what leaves your machine for Morrow’s own servers. Student-identifying roster details, cookies, raw course content, and your generated reports never leave your device for Morrow's servers.
Active course operations and finished reports both remain local, in your browser. Nothing about them is synced to Morrow's account-backed storage.
Student data and AI training
Before any message reaches AI, Proxy checks and swaps student-identifying details for stable codes inside your browser. Morrow sends no analytics, no telemetry, and no usage pings to anyone.
Proxy is what makes AI usable on real course work. Names and other identifying details are swapped locally, in your browser, before text is sent to your AI provider.
The code-to-name map stays on your device, not on a server Morrow runs. For a plain-language walkthrough of how the de-identification round-trip works, see how Proxy works.
Model training. Your messages go to your own AI account, and that provider’s terms govern how they handle the data they receive.
For pay-as-you-go OpenAI API accounts, OpenAI’s default is to not use your API data to train its models.
Because you bring your own AI account, you control those settings directly with your provider.
You approve every change. Morrow defaults to a look-first mode: it checks the Canvas course you have open and proposes changes, and nothing is written to Canvas until you approve it.
Deletes and other high-risk actions always ask again. You review the proposed list and decide what gets applied; Morrow never finalizes a change on its own.
Who can see your data
- You, on your own machine.
- Your AI provider (OpenAI / ChatGPT), for the messages you send to the AI. Their retention and usage is governed by the OpenAI or ChatGPT terms you agreed to.
- Canvas (Instructure), for the API calls you authorize, governed by your Canvas or institutional terms.
- Morrow’s backend (Supabase / Stripe), for your account email and subscription status only.
- Nobody else. No analytics vendor, no ad network, no data broker. The extension developer cannot see your conversations, your courses, or your students.
Retention
Local data persists on your device until one of the following:
- You uninstall the extension, and Chrome removes extension storage automatically.
- You use Morrow’s built-in “clear conversation” or “delete project” actions.
-
You clear extension storage manually from
chrome://extensions.
Account data (your email and subscription record) is retained by Morrow’s backend for as long as you have an account.
You can request deletion at any time (see Contact).
Deleting your account does not delete your local data, and clearing your local data does not delete your account.
Stripe retains payment and transaction records under its own policy and applicable financial-record law.
Your rights
For data on your device:
- Access: open Morrow and look. Everything is there.
- Export: use Morrow’s export features, or your browser’s storage tools, to pull your data.
- Deletion: use any of the clearing methods above.
- Correction: edit or delete the message or project in the Morrow interface.
For your account data (email and subscription status) held by Morrow’s backend: contact us (below) and your record will be provided, corrected, or deleted.
Because the backend stores only account details and subscription records, it holds no student identifiers, course content, or reports at all.
Children
Morrow is intended for instructors, not students. It is not directed at children under 13, and the extension does not knowingly collect or store data from anyone under 13.
If an instructor’s Canvas course includes minors, that data is handled by Canvas under Canvas’s own policies.
Morrow is only the tool through which the instructor views or edits that course. Morrow’s backend never receives course rosters or student records.
Third-party services
Morrow connects you to a small set of services. Each has its own privacy policy, which governs what they do with the data they receive when you use Morrow:
OpenAI / ChatGPT · your AI provider
Your chat messages are sent to your own OpenAI or ChatGPT account so the AI can answer you. Proxy strips student-identifying details before the text leaves your browser. Governed by the OpenAI privacy policy.
Instructure (Canvas) · your LMS
Canvas API requests are made as you, using your existing Canvas session, to read and update the courses you authorize. Governed by the Instructure product privacy policy and your institution’s terms.
Supabase · account sign-in & subscription
Supabase stores your account email and verifies sign-in and subscription status. It never receives your reports, course content, student details, or the local Proxy map. Governed by the Supabase privacy policy.
Resend · contact and trust requests
Website request forms are sent through Resend so Morrow can reply. Messages may include your name, work email, institution, selected interest, requested trust artifact, and message text.
Cloudflare · website delivery and rate limits
The website runs on Cloudflare Pages. Contact submissions may use a short-lived hashed rate-limit key derived from request metadata and email address to reduce spam and abuse.
Payment processor · billing, if applicable
If your account includes a paid subscription, billing is handled by our payment processor. Card details go to the processor, not to Morrow. Governed by the payment processor’s privacy policy.
Morrow’s developer is not responsible for those services’ practices; you authorized the traffic to them when you chose to use Morrow as an interface to Canvas and your AI account.
The marketing website has no analytics vendor, no ad network, no tracking pixel, and no product-usage telemetry.
Contact and trust requests use only the server-side email and rate-limit workflow needed to reply and reduce abuse.
Changes to this policy
If Morrow’s data practices change, this policy will be updated and the “Last updated” date at the top will change.
Material changes will be announced in the extension’s update notes.
Continued use of the extension after a material change constitutes acceptance of the revised policy. If you disagree, you can uninstall the extension at any time.
Contact
If you have a question about this policy, or you want to access, correct, or delete your account data, reach us through the contact page. Tell us it’s a privacy request and we’ll handle it.
Questions about how Morrow handles data?
Read the security overview for the architecture and Chrome permissions, or contact us with a privacy or compliance question.