Teach with AI support you can explain

Instructors and reviewers deserve straight answers. Here is exactly what Morrow does with your course and your students' data: where the work happens, what reaches AI, and the short list of what we keep.

Proxy strips student details before anything is sent to AI Changes are logged, with undo where possible Active course work stays in your browser session

Three places, and only three

Morrow is designed around clear boundaries. Active course operations, chats, and reports all stay in your browser, Canvas, and your AI account. Nothing about them reaches Morrow's servers.

In Your Browser

The work happens on your session

Morrow is a Chrome extension that runs beside your Canvas course. It reads and updates courses through your own signed-in Canvas session. Your reports and course work stay in your browser.

To Your AI

Your ChatGPT account answers

Morrow uses the ChatGPT account you bring. Before any message reaches AI, Proxy swaps student names, emails, and IDs for stable codes inside your browser.

To Morrow

Account state only

Morrow’s backend never receives your reports or course content. It stores only your account email and subscription status.

What is public, what is evidence, what is a brief

Artifacts are labeled by status: available, current evidence, readiness packet, public overview, response brief, or on request. Public documents are linked, and restricted packets route through review.

The table is worded, never a row of logos. Each artifact reads as one of the plain states below, with review metadata attached.

  • Available The document exists now and is linked here for you to read or attach.
  • Current Evidence A published evidence packet exists now, with final attestations handled only when they are actually earned.
  • Readiness Packet A readiness document exists now, but it is not a completed audit badge or final attestation.
  • Public Overview / Response Brief A public overview or response brief is linked, while signed terms, workbook exports, or institution-specific materials are handled through review.
Compliance and trust artifacts, current status
Artifact Status Version Last reviewed Access Action
Privacy Policy Public policy statement, not a legal attestation Evidence Proxy boundary walkthroughStorage boundarySubprocessor summary Available 2026.06 Jun 23, 2026 Next review Sep 23, 2026 Public
Security Overview Control overview, not an independent audit report Evidence Browser permission postureCSP and security headersNo analytics or telemetryAI governance boundaryAdmin and deployment controlsStatus and availability postureSecurity reporting route Available 2026.06 Jun 23, 2026 Next review Sep 23, 2026 Public
Proxy / Student Data Student-data filtering explanation, not a legal attestation Evidence Local Proxy code mapAI-bound redaction pathReports stay local Available 2026.06 Jun 23, 2026 Next review Sep 23, 2026 Public
Accessibility Statement Accessibility posture and known testing scope, not final third-party conformance Evidence Keyboard and focus checksSemantic HTML practicesGenerated accessibility gate Available 2026.06 Jun 23, 2026 Next review Sep 23, 2026 Public
Terms of Use Public terms for review, not a signed institutional agreement Evidence Approval-first boundaryCustomer account boundary Available 2026.06 Jun 23, 2026 Next review Sep 23, 2026 Public
VPAT / ACR Evidence Accessibility Conformance Report evidence, not VPAT certification Evidence WCAG review scopeKnown accessibility workAssistive-technology evidence scope Current Evidence VPAT 2.5Rev WCAG evidence Jun 23, 2026 Next review Aug 23, 2026 Public evidence
SOC 2 Type II Readiness Readiness packet only, not a SOC 2 report or completed audit Evidence Trust Services Criteria mapControl posture matrixReadiness status Readiness Packet Readiness 2026.06 Jun 23, 2026 Next review Aug 23, 2026 Public readiness summary NDA usually required
DPA Overview Public DPA overview, not a signed DPA Evidence Subprocessor listController and processor rolesRights and deletion path Public Overview 2026.06 Jun 23, 2026 Next review Sep 23, 2026 Public overview; signed packet on request
HECVAT Response Brief Response brief, not a completed institution-specific workbook Evidence HECVAT version trackedSecurity, privacy, and accessibility coverageWorkbook-specific details Response Brief HECVAT 4.1.6 brief Jun 23, 2026 Next review Aug 23, 2026 Public brief; workbook on request NDA usually required

Follow the data

Your course data is processed locally between Chrome, Canvas, and your ChatGPT account. Reports and evidence stay in your browser; Morrow's backend never receives them.

Chrome + Morrow runs beside your course Proxy map Learner A1 ↔ the student browser only Canvas (your LMS) current Canvas course data ChatGPT (your AI account) stable codes, no map Morrow cloud account + subscription only
Your active course data, chats, and generated reports all stay in your browser session. Proxy keeps the code-to-name map local and sends stable codes to your AI account. Morrow's backend stores only your account email and subscription status — it never receives your course content or reports.

Data flow: Morrow runs in Chrome, reads Canvas through your session, Proxy keeps the local code map in the browser, and sends de-identified requests to your AI account. Morrow's backend only ever sees your account email and subscription status, never your course content or reports.

  • Canvas stays the source of current course data. Morrow reads it through your browser session.
  • Proxy links real students to stable local codes in the browser and strips student-identifying details before a request reaches your AI account.
  • The AI provider receives stable codes, not the local code-to-name map.
  • Morrow's backend stores only your account email and subscription status. It never receives your course content, chats, or reports.

Proxy, student-data filtering, and no model training

The same boundary, stated as policy. Here is what that means for student data and for whether anyone learns from your course.

Proxy checks and strips student-identifying details before any message reaches AI. The AI answers on the account you bring, so the limits of your own provider apply.

Morrow's backend stores only your account details and subscription status, never your reports, alignment evidence, raw course content, or student-identifying records.

The three claims on the right are the policy form of that boundary. Each is a line your security reviewer can quote, not a promise we cannot keep.

  • Proxy before AI AI-bound text is checked in the browser. Student names become stable codes, while direct identifiers such as emails and IDs are stripped before any message reaches AI.
  • No analytics, no telemetry Morrow sends no usage pings, no analytics, and no telemetry to anyone, including us.
  • Not used for training For pay-as-you-go OpenAI API accounts, OpenAI’s default is to not use your data to train models.

Drawn from how Proxy works.

AI governance, stated plainly

Morrow treats AI as a governed course-operations tool: customer-controlled account, Proxy before the model, and human approval before writes.

Morrow does not train on course data

Morrow does not operate a model, fine-tune models, or use customer course data to train AI systems.

The connected AI account controls provider terms

AI requests run through the ChatGPT or OpenAI account the user connects, under that account’s data controls.

Proxy limits what the provider receives

Before AI sees a request, Proxy strips direct student identifiers and sends stable local codes instead of the roster map.

AI proposes; people approve

Morrow shows proposed course changes for review. Writes to Canvas happen only after approval, with extra confirmation for high-risk actions.

For OpenAI business and API services, OpenAI states that inputs and outputs are not used to train models by default unless the organization opts in. The governing terms still follow the AI account you connect.

You approve every change

Morrow defaults to Plan mode: it checks the course you have open and proposes changes, and nothing writes to Canvas until you say yes. Deletes and high-risk actions always ask again.

Plan Mode Is the Default Deletes Need Explicit Confirmation Changes Are Logged, with Undo When Possible

Plan mode proposes; you review an itemized list and decide. Once you approve, Morrow applies the changes and reads the result back. Every change is recorded, so you can show what happened.

Have a security questionnaire?

Read the security overview for the architecture, Chrome permissions, and data handling, or contact us for a HECVAT, DPA, or a security review.