Security
What Morrow can reach, how to check your download, and how to report a problem.
Morrow uses your existing course access.
Your Canvas or Moodle sign-in stays in Chrome, where it already was. Morrow can use only the courses and actions your signed-in account allows. Blackboard uses the account your administrator connected. Morrow holds no password of yours and creates no account of its own.
You control course changes.
Plan shows each proposed change before Morrow saves it. Edit access applies only to the courses and kinds of change you choose, and it expires. You approve changes on your own computer. When Morrow cannot confirm what the course saved, it tells you to check the item and does not send the change again.
What Morrow Bridge can do in Chrome.
The Bridge asks Chrome for eight abilities, and each one has a single job: activeTab and tabs to tell your course tabs apart; scripting to run Morrow’s reader and writer inside the course page you selected; webNavigation to know when that page has finished loading; webRequest to watch the result of an upload it started, so it can confirm what happened; storage to keep your settings and course choices on your computer; alarms to expire its own credentials on time; and offscreen for work that needs a page context without opening a window. The only address it may reach by default is http://127.0.0.1, which is the Morrow app on your own machine.
Course sites are opt in, one at a time.
The Bridge ships with no access to any course site. When you connect a course, Chrome asks you to allow that one exact address, and Morrow requests only that address. Removing it in Chrome takes the access away immediately. Morrow never asks for access to the rest of the web.
Check that your download is the one we published.
Every release lists a SHA-256 checksum beside its file. Compare it before you install. On a Mac, run shasum -a 256 followed by the file you downloaded. On Windows, run Get-FileHash followed by the file and -Algorithm SHA256. If the value does not match the one published with the release, delete the file and tell us.
Morrow is not signed by Apple or Microsoft.
Morrow is independent software and does not pay into either company’s developer programme, so macOS shows an unidentified developer prompt and Windows may show a SmartScreen notice on first run. The Download page has the exact steps to get past each one. The checksum above, not a signature, is how you confirm you have the file we published.
How Morrow updates.
The Morrow app checks for a new version, verifies the sealed payload it downloaded, and installs it only when that check passes. A failed check leaves your working copy alone. Morrow Bridge updates through Chrome once it is listed in the Chrome Web Store. Until then it runs as a temporary developer installation that the app replaces for you and that you reload once in Chrome.
How to remove Morrow completely.
In Chrome, open chrome://extensions and select Remove on Morrow Bridge. On a Mac, quit Morrow, move it from Applications to the Trash, then delete ~/Library/Application Support/Morrow and ~/Library/Caches/Morrow. On Windows, uninstall Morrow from Installed Apps, then delete %APPDATA%\Morrow and %LOCALAPPDATA%\Morrow. Nothing of yours is left on a server, because nothing of yours was sent to one.
Report a security concern.
Email hello@meetmorrow.app with a short description and the steps to reproduce it. Do not include student information, private course content, passwords, sign-in details, or revealing screenshots. We will tell you how to share sensitive detail safely.
What happens after you report it.
We acknowledge your report within three business days and give you a first assessment within ten. After that we update you at least every fourteen days until it is closed. When a fix ships we say so in the release, and we credit you by name if you would like that. Morrow is maintained by one person, so these are the times we can actually keep.
Give us time to respond.
Do not read, change, or copy information you do not own or have permission to test. Please let us investigate and ship a fix before you publish. We will not pursue anyone who reports a problem in good faith and follows this page.