Canbeasy (“we”, “us”) is an independent app operated by a solo developer. We are the controller of the personal data described below. For privacy questions or requests, contact us at support@canbeasy.com.
Canbeasy is a tool you choose to use in your personal capacity with your own Canvas credentials. We are not a vendor or contractor of any school or district, we do not receive data from any school, and we are not “FERPA certified.” See §11.
| Category | Examples | Source |
|---|---|---|
| Canbeasy account info (optional unless you use AI or a paid plan) | Your email address, display name, account ID, profile picture if supplied by Google, and account creation/update dates | You, or Google when you choose Google sign-in |
| Plan and AI usage info | Your demo plan, AI-token balance, and the model-reported input, cached-input, output, and reasoning-token counts for AI features you run | Canbeasy and the AI provider response |
| Login and security info | A one-way password hash for email accounts; Google’s account identifier for Google accounts; active-session and anti-forgery values; Terms/age confirmation | You, your browser, or Google |
| Canvas account info | Your Canvas user ID and name; your school’s Canvas domain | Canvas, via your access token / session |
| Education records (sensitive) | Your courses, assignments, due dates, grades and submissions | Canvas, via your access token / session |
| Your Canvas access token | A credential that lets the app read your Canvas data on your behalf | You paste it, or it is created via the extension using your live Canvas session |
| Materials you add (“Vault”) | Uploaded files, document scans, photos, pasted text, and the text we extract from them | You |
| Audio recordings (sensitive) | Lecture/class audio you choose to record, and its transcript | You (microphone), only when you start a recording |
| School-linked documents | Google Docs/Drive files your class links to, fetched via your browser session (extension) | Google, via your live session |
| App settings | Language preference and setup progress | You / your device |
We do not collect advertising identifiers, location, contacts, or browsing history, and we do not run third-party analytics, advertising, or session-replay scripts.
HttpOnly session cookie, not in local storage. Your Canvas access token and language preference
live in your browser’s localStorage. Your class materials (“Vault”) are
cached in your browser’s IndexedDB. The extension keeps a small amount of
state in chrome.storage. This data stays on your device unless you sync it.Canbeasy’s coach and extraction features work by sending relevant content — your question, the relevant course materials, an uploaded file, an image, or recorded audio — to AI providers, which return a result. We send only what a given feature needs.
| Provider | Used for | Data sent | Location |
|---|---|---|---|
| Google Identity Services | Optional Google account sign-in | The minimum sign-in scopes (openid, email, and profile); Google returns your account identifier, verified email, name, and optional profile picture. We do not keep Google access or refresh tokens. | United States |
| Resend | Email verification, password recovery, and account-security notices | Your email address, display name, and the one-time account link | United States |
LMU AI (api.lmuai.com) — a third-party AI gateway that relays requests to large-language-model providers | The coach / tutoring text features | Your prompt + relevant course text | China (PRC) |
| xAI (Grok API) - only if Canbeasy enables Grok as its selected text-coach provider | Coach / tutoring text features | Your prompt + relevant course text | As specified for the selected xAI API region and in xAI's applicable terms |
| Google (Gemini API) | Reading images, audio, video, and PDFs you add | The file/photo/audio and a prompt | United States |
| DeepSeek | Condensing course material in the background; backup text processing when the main route is down | Text content | China (PRC) |
| Instructure (Canvas API) | Reading your Canvas data | Your access token / session | Per your school’s Canvas |
| Google Docs/Drive | Opening class-linked documents | Your live browser session (extension) | United States |
| Wikipedia; U.S. NCES school directory | Reference lookups; finding your school during setup | Search terms only (no personal data) | United States |
We do not sell your data and we do not allow these providers to use your content to show you ads. Two of these providers process or route data in China: LMU AI, the gateway that carries the text coach features, and DeepSeek, used for background and backup text processing. Content sent to them is course material and your questions about it — never your Canvas token. If you’d rather not send content to any AI provider, you can use Canbeasy’s dashboard, deadlines, and grades without the AI tools; those features only run when you use them.
For users in the EU/UK, our legal basis is your consent (which you can withdraw) and our legitimate interest in providing a service you asked for. Sensitive data (grades, audio) is processed only on your explicit instruction.
Depending on where you live (e.g., California, the EU/UK, and other U.S. states), you may have the right to access, correct, delete, or export your data, and to withdraw consent. To exercise any of these, use the in-app delete control (§8) or email support@canbeasy.com. We don’t discriminate against you for exercising a right, and you can complain to your local data-protection authority.
You can erase everything we hold at any time:
The in-app controls permanently delete your Canbeasy profile, login record, and encrypted server-side workspace, then clear the app’s on-device storage in one step.
This does not delete or change your Canvas or Google account. You should also revoke the Canvas access token in your Canvas account settings.
Canbeasy uses only strictly necessary cookies and on-device storage to function —
there are no advertising, analytics, or tracking cookies, so there is nothing to consent
to for tracking. The cookies are a signed HttpOnly account-session cookie and,
during Google sign-in only, a short-lived encrypted OAuth flow cookie. The other items we store are: your Canvas token and language
(localStorage), your Vault cache (IndexedDB), and extension state
(chrome.storage). We honor “Do Not Track”/Global Privacy Control signals by
not tracking anyone in the first place.
Canbeasy is intended for users who are 13 or older. Before connecting, you must confirm you’re at least 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has used Canbeasy, contact support@canbeasy.com and we will delete the data. Where required, users under the age of digital consent in their jurisdiction should have a parent/guardian agree on their behalf.
Canbeasy is an independent app. It is not affiliated with, endorsed by, sponsored by, or operated by any school or district, or by Instructure, Inc. “Canvas” is a trademark of Instructure, Inc., used here only to describe compatibility. Because you use Canbeasy in your personal capacity with your own credentials, Canbeasy is not a “school official” and is not covered by FERPA.
The recording feature captures audio only when you start it, and sends it to an AI provider for transcription (§4). You are responsible for the legality of recording: some U.S. states require the consent of everyone being recorded. Record only where you are allowed to, and see our Terms.
Canbeasy’s study help is generated by AI. It can be wrong or incomplete, is not reviewed by a human, and is meant as study support — not finished work or professional advice. Always check it against your course materials and your instructor.
We protect your data with encryption at rest for the server-side store, encrypted
connections, access scoped to your signed-in Canbeasy account, password hashing with
scrypt, signed HttpOnly/Secure/SameSite
session cookies, anti-forgery checks, and rate limits on sign-in attempts. Google sign-in
uses state, nonce, and PKCE checks, and we discard Google access and refresh tokens after
confirming your identity. No system is perfectly
secure, but if a breach affecting your data occurs, we will notify you and any authorities
as required by law.
Canbeasy is operated from the United States. Processing happens in the United States and, for the text-AI providers listed in §4 (LMU AI and DeepSeek), in China. If you use Canbeasy from outside those countries, your data is transferred there. Canbeasy is built for U.S. Canvas students; for EU/UK users, we rely on your consent and, where our providers offer them, contractual safeguards such as Standard Contractual Clauses for international transfers.
We may update this policy. Material changes will be posted here with a new “Last updated” date and, where appropriate, surfaced in the app. Changes are forward-looking.