Canvas+ Privacy Policy
隐私说明
- Your Canvas name, login, grades and submissions are never sent to us or anyone else.
- A Canvas+ account is optional and stores only your e-mail address. No password.
- No tracking, no analytics, no ads. Nothing is sold or shared, or used for anything other than the features you see.
What Canvas+ reads, and why
Canvas+ only runs on Canvas sites: every *.instructure.com site, plus any other Canvas site you turn it on for yourself from the toolbar button. On those sites it reads, using the Canvas login you already have in your browser:
| Information | Used for |
|---|---|
| Your courses, terms and course colours | Course list, short course names, colours |
| Your To Do / planner items (titles, due dates, submission status) | The deadline list, countdowns and reminders |
| Assignment groups, weights, points and your scores | “% of final grade” tags and the final-exam calculator |
| The course grading scheme | Letter-grade cut-offs in the calculator |
| The course syllabus / home page text (only for courses with no weights set in Canvas) | Finding the grade breakdown (e.g. “Homework 20%”) for the calculator |
| Your current score in each course, and your final scores and terms from past courses | The score next to each course, the cumulative / term GPA dashboard and the GPA projection |
| Work Canvas marks as missing, and the course’s late policy (when Canvas shares it) | The missing-work alert and what a late submission would cost |
| Course modules and the course’s Files (names, folders, and the files you choose) | Downloading course files as a .zip, and picking slides for an exam review pack |
Canvas+ never asks for your password and cannot see it. It reads this data directly from Canvas in your browser; it is not copied anywhere else.
Canvas+ AI assignment summary (optional)
Only when you click “AI summary” on an assignment, quiz or discussion (signed in to a free Canvas+ account, and after you agree the first time), Canvas+ sends that assignment’s own text — its title, instructions, rubric, due date and points — to the Canvas+ server at ai.baowenliu.com. The server asks a third-party AI provider to write the summary and sends it back. If the assignment links to files (PDF, Word, text), other Canvas pages, or outside web pages, the text of up to 4 of those files/pages (read in your browser with your own Canvas login) and the addresses of up to 3 outside links are sent too; the server then downloads those public web pages itself to read them. Nothing else from your Canvas account is sent.
AI syllabus summary: when you click “AI syllabus summary” for a course, the same rules apply to that course’s syllabus: Canvas+ sends the text of the course’s Syllabus page (and the course home page if the syllabus is short), plus up to 4 syllabus files or pages it links to (or a file named “syllabus” in the course files), so Canvas+ AI can list exam dates, the grade breakdown and the course policies. Your grades are never sent. “Add to calendar” creates the .ics file in your browser; nothing about it is sent anywhere. If the syllabus’s grade breakdown doesn’t add up to 100%, Canvas+ fills in the rest from the assignment-group weights on the course’s Grades page — read in your browser only and never sent.
AI e-mail drafts: when you click “Write an e-mail” (to ask for an extension, ask about the rubric, book office hours, and so on), Canvas+ sends the assignment’s title, due date, points and part of its instructions, plus what you type in the form (for example the reason you choose to give), to the Canvas+ server, which returns a draft. Your name and your instructor’s or TA’s name are not sent: they are read from Canvas and filled into the draft in your browser. Drafts are not stored on the server. Canvas+ never sends e-mails for you — you copy the draft or open it in your own mail app.
AI course Q&A: when you ask a question about a course, Canvas+ reads that course’s syllabus (and the syllabus file it links to), modules (their outline, and the course pages and files in them that match your question), assignments, announcements and the course’s grade setup (assignment groups and their weights — not your scores) in your browser with your own Canvas login, picks the parts most related to your question, and sends them with your question (and your previous two questions and answers in that conversation) to the Canvas+ server, which answers only from that material. Your grades, submissions and name are not sent. Questions and answers are not stored on the server.
New grade and announcement notifications: every 15 minutes (and when you open Canvas), Canvas+ asks Canvas — with your own login, from your browser — for recently graded work and new announcements in your current courses, and shows a notification on your computer. Only which items it has already told you about is remembered, in your browser. Nothing is sent to the Canvas+ server. Scores are hidden in notifications unless you turn that on; each kind of notification can be turned off in the reminder settings.
Weekly digest: on your first Canvas visit each week, Canvas+ puts together — in your browser — the past week’s new assignments, new grades and announcements and the next 7 days’ deadlines, and keeps it (plus a snapshot of your course totals, to show the change from last week) in your browser’s extension storage only. Grades never leave your computer. If you use “This week’s focus”, Canvas+ sends only the announcements and the assignment names and due dates to the Canvas+ server, which returns a short list of priorities; it is not stored on the server. The Monday reminder is a local Chrome notification and can be turned off in the reminder settings.
Exam review packs: when you make a review pack for an exam, you pick which course files (slides, notes, PDFs, Word files, course pages) it should use. Canvas+ reads those files in your browser with your own Canvas login and sends their names and text, with the course name and the exam’s name, date and scope, to the Canvas+ server, which asks the AI provider to write a study outline, practice questions and flashcards. Course materials are the same for everyone in a course, so the finished pack is cached on the server under a one-way fingerprint (hash) of the materials: a classmate who picks the same files for the same exam gets the same pack without another AI request. The material text itself is not stored, and packs are not linked to who made them. Your packs, and your answers to their practice questions, are saved only in your browser.
All my exams: the exam list, and the exam dates under each course, come from that course’s syllabus read by the AI syllabus summary above (a syllabus already read costs nothing). The dates are then kept in your browser only.
- Never sent: your name, Canvas login, grades, submissions, messages or any other personal information.
- Sent along: a random install ID created by the extension. Using the AI requires a free Canvas+ account (see below); the daily limit shown in the panel is counted per account.
- Kept on the server: the summary and a one-way fingerprint (hash) of the assignment text, so the same assignment isn’t summarised twice; daily usage counts per account and per a hashed IP address (raw IP addresses are not stored). The assignment text itself is not stored by Canvas+, and summaries are not linked to who asked for them.
- The AI provider (currently DeepSeek, with OpenAI as a backup when DeepSeek is unavailable) processes the text only to write the answer, under its own terms and privacy policy.
- If you never use an AI feature, nothing is ever sent.
Features that stay in your browser
These use only data Canvas+ reads in your browser, and send nothing to the Canvas+ server:
- GPA dashboard and projection: your past course scores and letters, the credits, letters and grading scale you enter, and the “what-if” letters. Your own settings are saved with Chrome’s
storage.sync(see below). - Mistake book: multiple-choice questions you answer wrong in a review pack, how often you missed them and whether you have mastered them. Saved only in your browser; “Export to Anki” creates a file on your computer.
- Missing-work alert: read from Canvas when you open the panel, shown only there.
- Deadline changes, course-total changes and exam reminders: every 15 minutes Canvas+ asks Canvas, with your own login, for your courses (with your current course totals) and upcoming items, and compares them with what it saw last time. When a total changes, a deadline moves, or an exam is 3 days or 1 day away, it shows a notification on your computer (with the course’s mistake-book count). The last totals, deadline times and which reminders were sent are kept in your browser only. Each kind of notification can be turned off in the reminder settings.
- Course file downloads: the .zip file is built in your browser.
- Background picture: the picture you upload is kept in your browser’s local storage only.
Feedback and bug reports
When you use “Feedback / report a problem” in the panel (signed in to your Canvas+ account), Canvas+ sends to the Canvas+ server: the type you pick and the message you write, plus the Canvas+ version, your browser and operating system (for example “Chrome 131 · macOS”), the path of the Canvas page you were on (for example /courses/123/grades — never the rest of the address), and the panel language, so bugs can be reproduced. It is stored with your account e-mail, so the developer can reply, and a one-way fingerprint (hash) of the account that limits how many messages can be sent per day. Only the developer can read it, on a password-protected page, and uses it only to answer you and improve Canvas+. Nothing is sent unless you press “Send”; no grades or course content are included unless you type them. To have your feedback deleted, e-mail me@baowenliu.com.
Canvas+ account (optional)
A free Canvas+ account is needed to use the AI features (so the free daily limit can’t be dodged), to send feedback (so the developer can reply), and for the Pro membership, which then works on any computer. There is no password. You can sign in:
- With Google: Chrome opens Google’s own sign-in window. Canvas+ asks only for your verified e-mail address (scopes “openid email”) — not your name, contacts, Drive or anything else — and never sees your Google password.
- With an e-mail code: we e-mail you a one-time 6-digit code. Only a hash of the code is kept, for 10 minutes. To stop abuse, the number of codes per network (hashed IP) and per day is limited.
Kept on the server: your e-mail address, when the account was created, and which browsers (random install IDs, at most 3) are signed in. Sign out from “My account” in the panel. To delete your account, e-mail me@baowenliu.com and it will be removed within 30 days.
Canvas+ AI Pro (optional paid membership)
Canvas+ AI Pro is a monthly subscription that raises the daily AI limit. Payment happens on Stripe’s own checkout page; your card details go only to Stripe and are never seen or stored by Canvas+.
- Kept on the server when you subscribe: your account e-mail, your Stripe customer and subscription IDs, the subscription’s status and renewal date, and a backup activation code (with the install IDs of the at most 3 browsers using it). We e-mail you once to confirm the membership.
- Stripe processes payments under its own privacy policy (stripe.com/privacy).
- You can cancel any time from “Manage or cancel” in the panel. To have your membership record deleted, e-mail me@baowenliu.com.
What Canvas+ changes in Canvas
Only one thing, and only when you ask: when you tick the circle next to an item, Canvas+ marks it as done (or not done) in your own Canvas To Do list. It never submits work, changes grades, or posts anything.
What is stored, and where
- Your settings (dark mode, colours, language, reminder options, which items are hidden) are saved with Chrome’s
storage.sync. If you use Chrome Sync, Google syncs these settings between your own browsers; Canvas+ itself receives nothing. - Temporary copies of your deadline list and grade weights are cached in Chrome’s local storage on your computer (for a few minutes to a few hours) so the panel opens quickly and reminders can be shown. They never leave your device.
- Kept in your browser until you delete them or uninstall: your review packs and practice answers, your mistake book, exam dates read from syllabi, the snapshots used for change notifications (course totals, deadline times, which reminders were sent), and your background picture. They never leave your device.
Permissions
| Permission | Why |
|---|---|
Access to *.instructure.com | Run on Canvas and read your Canvas data (see above) |
| Optional access to other sites | Only for a Canvas site you turn on yourself, one site at a time; you can remove it any time |
storage | Save your settings and the local caches |
scripting, activeTab | Start Canvas+ on a Canvas site you just turned on, and check whether a page is Canvas when you click the toolbar button |
alarms, notifications | Show deadline reminders (24 h / 2 h), new grades and announcements, course-total and deadline changes, exam reminders and the weekly digest at the right time |
identity | Open Google’s sign-in window when you choose “Sign in with Google” |
Deleting your data
Turn off anything in the panel at any time. Uninstalling Canvas+ removes all of its stored data from Chrome. You can also remove a site from the toolbar popup. To delete your Canvas+ account, membership record and feedback from the server, e-mail me@baowenliu.com (an active subscription is cancelled first).
Children
Canvas+ is a tool for university students and is not directed at children under 13. The optional account stores only an e-mail address (and any feedback sent with it); if you believe a child has created one, e-mail me@baowenliu.com and it will be deleted.
Chrome Web Store
The use of information by Canvas+ complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Not affiliated
Canvas+ is an unofficial, independent project. It is not affiliated with or endorsed by Instructure or any school. Canvas is a trademark of Instructure, Inc.
Changes and contact
If this policy changes, the new version and its date will be posted here. Questions: me@baowenliu.com
- 你在 Canvas 里的姓名、账号、成绩和提交的作业,永远不会发给我们或任何人。
- Canvas+ 账号是可选的,只保存你的邮箱,没有密码。
- 没有跟踪、统计分析和广告;不出售、不分享你的数据,也不会用于你看到的功能以外的任何用途。
Canvas+ 读取什么,为什么
Canvas+ 只在 Canvas 网站上运行:所有 *.instructure.com 网站,以及你自己在工具栏按钮里启用的其他 Canvas 网站。在这些网站上,它借用你浏览器里已经登录的 Canvas,读取:
| 信息 | 用途 |
|---|---|
| 你的课程、学期和课程颜色 | 课程列表、课程简称、配色 |
| 你的 To Do / 日程项目(标题、截止时间、提交状态) | 作业列表、倒计时和截止提醒 |
| 作业类别、权重、分值和你的分数 | "占总成绩"标签和期末计算器 |
| 课程的等级线设置 | 计算器里的等级分数线 |
| 课程 Syllabus / 主页的文字(仅限 Canvas 里没设置权重的课) | 找出成绩构成(比如“作业 20%”)填进计算器 |
| 你每门课的当前分数,以及往期课程的最终分数和学期 | 课程旁边的当前成绩、累计 / 学期 GPA 仪表盘和 GPA 预测 |
| Canvas 标记为漏交的作业,以及课程的迟交规则(如果 Canvas 公开) | 漏交作业提醒,以及现在补交会扣多少分 |
| 课程 Modules 和课程 Files(文件名、文件夹,以及你选中的文件) | 把课件打包成 .zip 下载,以及为考前复习包挑选课件 |
Canvas+ 从不索要、也看不到你的密码。这些数据在你的浏览器里直接从 Canvas 读取,不会被复制到任何其他地方。
Canvas+ AI 作业总结(可选)
只有当你在作业、测验或讨论上点击「AI 总结」时(需要登录免费的 Canvas+ 账号,第一次还需要你同意),Canvas+ 才会把这个作业本身的文字——标题、说明、评分标准、截止时间和分值——发送到 Canvas+ 的服务器 ai.baowenliu.com,由服务器请第三方 AI 服务商生成总结后返回。如果作业里附了文件(PDF、Word、文本)、其他 Canvas 页面或外部网页链接,还会一并发送最多 4 个文件/页面的文字(在你的浏览器里用你自己的 Canvas 登录读取),以及最多 3 个外部链接的网址,由服务器自行下载这些公开网页来阅读。不会发送你 Canvas 账号里的其他任何内容。
AI 总结 Syllabus:当你对某门课点击「AI 总结 Syllabus」时,规则相同:Canvas+ 会发送这门课 Syllabus 页面的文字(如果内容很少,也会加上课程首页),以及其中链接的最多 4 个 syllabus 文件或页面(或课程文件里名为 “syllabus” 的文件),让 Canvas+ AI 整理出考试时间、成绩构成和课程政策。你的成绩永远不会发送。「加到日历」生成的 .ics 文件在你的浏览器里完成,不会发送到任何地方。如果 syllabus 里的成绩构成加起来不是 100%,Canvas+ 会用这门课 Grades 页面的作业分类权重补全——只在你的浏览器里读取,不会发送。
AI 邮件草稿:当你点击「写邮件」(请求延期、询问 rubric、预约 office hour 等)时,Canvas+ 会把这项作业的标题、截止时间、分值和部分说明,以及你在表单里填写的内容(例如你愿意说明的原因)发送到 Canvas+ 的服务器生成草稿。你的名字和老师/助教的名字不会发送——它们从 Canvas 读取后只在你的浏览器里填进草稿。草稿不会保存在服务器上。Canvas+ 不会替你发送邮件,由你自己复制或用邮件 App 打开。
AI 课程问答:当你对某门课提问时,Canvas+ 会在你的浏览器里用你自己的 Canvas 登录读取这门课的 syllabus(及其中链接的 syllabus 文件)、Modules(目录,以及和问题相关的课程页面和文件)、作业、公告和成绩构成设置(作业分类和权重,不含你的分数),挑出和问题最相关的部分,连同你的问题(以及这次对话里前两个问答)一起发送到 Canvas+ 的服务器,服务器只根据这些资料回答。你的成绩、提交内容和名字不会发送。问题和回答不会保存在服务器上。
出分和新公告提醒:每 15 分钟(以及你打开 Canvas 时),Canvas+ 会在你的浏览器里用你自己的 Canvas 登录,查看当前课程最近出分的作业和新公告,并在电脑上弹出通知。只会在浏览器里记住哪些已经提醒过,不会发送到 Canvas+ 服务器。通知里默认不显示分数,可以在提醒设置里打开;每种提醒都可以单独关闭。
本周简报:每周第一次打开 Canvas 时,Canvas+ 会在你的浏览器里汇总过去一周的新作业、新成绩、公告和接下来 7 天的截止时间,并把它(以及用于对比上周变化的课程总成绩快照)只保存在浏览器的扩展存储里。成绩不会离开你的电脑。使用「本周重点」时,Canvas+ 只会把公告内容和作业名称、截止时间发送到 Canvas+ 服务器,生成一份简短的优先事项,不会保存在服务器上。周一提醒是本地的 Chrome 通知,可以在提醒设置里关闭。
考前复习包:生成复习包时,由你选择要用哪些课程文件(slides、讲义、PDF、Word、课程页面)。Canvas+ 在你的浏览器里用你自己的 Canvas 登录读取这些文件,把它们的文件名和文字连同课程名、考试名称、日期和范围发送到 Canvas+ 服务器,由 AI 服务商生成复习提纲、练习题和抽认卡。同一门课的课件对所有同学都一样,所以生成好的复习包会以这些资料的单向指纹(哈希)为索引缓存在服务器上:同学为同一场考试选了同样的文件,会直接拿到同一份复习包,不再重复请求 AI。服务器不保存资料原文,复习包也不和生成它的人关联。你的复习包和练习题作答只保存在你的浏览器里。
所有考试:考试列表和每门课下面的考试时间,来自上面「AI 总结 Syllabus」读取的这门课的 syllabus(已经读过的 syllabus 不占次数),之后只保存在你的浏览器里。
- 不会发送:你的姓名、Canvas 账号、成绩、提交的作业、消息或其他任何个人信息。
- 一并发送:插件随机生成的安装 ID。使用 AI 需要先登录免费的 Canvas+ 账号(见下文),面板里显示的每日次数上限按账号统计。
- 服务器保存:总结结果和作业文字的单向指纹(哈希),这样同一个作业不用重复生成;以及按账号和经过哈希的 IP 统计的每日次数(不保存原始 IP)。Canvas+ 不保存作业原文,总结结果也不和提问的人关联。
- AI 服务商(目前是 DeepSeek,DeepSeek 不可用时由 OpenAI 备用)只用这些文字来生成回答,并按照它自己的条款和隐私政策处理。
- 如果你从不使用 AI 功能,就不会发送任何内容。
只在浏览器里运行的功能
下面这些功能只使用 Canvas+ 在你浏览器里读取的数据,不会向 Canvas+ 服务器发送任何内容:
- GPA 仪表盘和预测:往期课程的分数和等级、你填写的学分、等级和换算标准,以及「如果拿到」的假设等级。你自己的设置保存在 Chrome 的
storage.sync里(见下文)。 - 错题本:你在复习包里答错的选择题、错了几次、是否已掌握。只保存在你的浏览器里;「导出到 Anki」会在你的电脑上生成文件。
- 漏交作业提醒:打开面板时从 Canvas 读取,只显示在面板里。
- 截止时间变动、总分变化和考前提醒:每 15 分钟,Canvas+ 用你自己的 Canvas 登录读取你的课程(含当前总分)和即将截止的项目,和上次看到的对比。总分变化、截止时间变动,或者考试只剩 3 天 / 1 天时,会在你的电脑上弹出通知(附带这门课错题本的待复习数量)。上次的总分、截止时间和已发送过的提醒只保存在你的浏览器里。每种通知都可以在提醒设置里单独关闭。
- 下载课件:.zip 文件在你的浏览器里生成。
- 背景图片:你上传的图片只保存在浏览器的本地存储里。
反馈与问题报告
当你在面板里使用「反馈 / 报告问题」(需要登录 Canvas+ 账号)时,Canvas+ 会把你选择的类型和你写的内容发送到 Canvas+ 服务器,同时附带 Canvas+ 版本、你的浏览器和操作系统(例如“Chrome 131 · macOS”)、你当时所在 Canvas 页面的路径(例如 /courses/123/grades,不含网址的其他部分)和面板语言,方便复现问题。反馈会和你的账号邮箱一起保存,以便开发者回复你,另外保存账号的单向指纹(哈希)用于限制每天的发送次数。只有开发者能在有密码保护的页面上查看,并且只用于回复你和改进 Canvas+。只有你点「发送」才会发送;除非你自己写进去,否则不包含任何成绩或课程内容。如需删除你的反馈,请发邮件到 me@baowenliu.com。
Canvas+ 账号(可选)
使用 AI 功能需要一个免费的 Canvas+ 账号(这样免费的每日次数不会被绕过);发送反馈也需要登录(方便开发者回复你);Pro 会员也绑定在账号上,换电脑也能用。没有密码,可以这样登录:
- Google 账号:Chrome 会打开 Google 自己的登录窗口。Canvas+ 只获取你已验证的邮箱地址(权限范围为“openid email”),不会获取你的姓名、联系人、云端硬盘等其他任何信息,也看不到你的 Google 密码。
- 邮箱验证码:我们给你的邮箱发一个一次性的 6 位验证码,服务器只保存它的哈希值 10 分钟。为了防止滥用,每个网络(经过哈希的 IP)和每天能发送的验证码数量有上限。
服务器保存:你的邮箱、注册时间,以及哪些浏览器(随机安装 ID,最多 3 个)登录了这个账号。可以在面板的「我的账号」里退出登录。如需删除账号,请发邮件到 me@baowenliu.com,我们会在 30 天内删除。
Canvas+ AI Pro(可选的付费会员)
Canvas+ AI Pro 是按月订阅的会员,用来提高每天的 AI 使用次数。付款在 Stripe 自己的付款页面完成,银行卡信息只交给 Stripe,Canvas+ 看不到也不保存。
- 订阅后服务器保存:你的账号邮箱、Stripe 的客户和订阅编号、订阅状态和续费日期,以及一个备用激活码(和使用它的最多 3 个浏览器的安装 ID)。开通时我们会发一封确认邮件。
- Stripe 按照它自己的隐私政策(stripe.com/privacy)处理付款。
- 你可以随时在面板里点「管理 / 取消订阅」取消。如需删除会员记录,请发邮件到 me@baowenliu.com。
Canvas+ 会修改 Canvas 里的什么
只有一件事,而且只在你主动操作时:你点作业左边的圆圈时,Canvas+ 会在你自己的 Canvas To Do 列表里把它标记为完成(或取消完成)。它不会提交作业、修改成绩,也不会发布任何内容。
存储了什么,存在哪里
- 你的设置(暗色模式、配色、语言、提醒选项、隐藏哪些板块)保存在 Chrome 的
storage.sync里。如果你开启了 Chrome 同步,Google 会在你自己的几个浏览器之间同步这些设置;Canvas+ 本身收不到任何东西。 - 临时缓存:作业列表和成绩权重会在你电脑上 Chrome 的本地存储里缓存几分钟到几小时,用来让面板打开更快、按时发出提醒。它们不会离开你的电脑。
- 保存在浏览器里、直到你删除或卸载:你的复习包和练习题作答、错题本、从 syllabus 读到的考试时间、用于变化提醒的快照(课程总分、截止时间、已发送的提醒)以及背景图片。它们不会离开你的电脑。
权限说明
| 权限 | 用途 |
|---|---|
访问 *.instructure.com | 在 Canvas 上运行,读取你的 Canvas 数据(见上文) |
| 可选:访问其他网站 | 只用于你自己启用的 Canvas 网站,一次一个,随时可以移除 |
storage | 保存设置和本地缓存 |
scripting、activeTab | 在你刚启用的 Canvas 网站上启动插件;你点工具栏按钮时,判断当前页面是不是 Canvas |
alarms、notifications | 按时弹出截止提醒(24 小时 / 2 小时)、出分和新公告、总分和截止时间变动、考前提醒和每周简报 |
identity | 你选择「使用 Google 账号登录」时,打开 Google 的登录窗口 |
删除数据
面板里的任何功能都可以随时关闭。卸载 Canvas+ 会从 Chrome 中删除它保存的全部数据。你也可以在工具栏弹窗里移除已启用的网站。如需从服务器删除你的 Canvas+ 账号、会员记录和反馈,请发邮件到 me@baowenliu.com(如有订阅会先帮你取消)。
未成年人
Canvas+ 是给大学生用的工具,不面向 13 岁以下的儿童。可选的账号只保存一个邮箱(以及用它发送的反馈);如果你发现有儿童注册了账号,请发邮件到 me@baowenliu.com,我们会删除。
Chrome 应用商店
Canvas+ 对信息的使用遵守 Chrome 应用商店用户数据政策,包括"有限使用"(Limited Use)要求。
非官方
Canvas+ 是一个非官方的独立项目,与 Instructure 和任何学校都没有关联,也未获得其认可。Canvas 是 Instructure, Inc. 的商标。
更新与联系方式
如果本说明有变动,新版本和生效日期会发布在这里。有问题请联系:me@baowenliu.com