FixCanvas
Legal

FixCanvas Privacy Policy

Effective date: October 9, 2026
Last updated: October 9, 2026

FixCanvas ("FixCanvas", "we", "us") is a Chrome extension that gives students a simpler view of their Canvas LMS courses, plus an AI assistant ("Ask") that answers questions about those courses. FixCanvas is run by Shifted, LLC, a Rhode Island company.

This policy covers the FixCanvas extension, the FixCanvas server (canvas-clean-proxy.bodhiabecker.workers.dev, "the Server"), and the FixCanvas website at fixcanvas.com. It explains what we collect, why, who we share it with, and the choices you have.

In short:

FixCanvas is an independent project. It is not affiliated with, endorsed by or sponsored by Instructure, Inc., the maker of Canvas, or by your school.


1. Information FixCanvas handles in your browser

FixCanvas runs on Canvas pages (*.instructure.com, plus any school Canvas domain you choose to enable it on). It uses the Canvas session you are already logged in with to read, through Canvas's own API:

This data is cached in your browser's extension storage on your device. It is not sent to our Server except as described in section 2.

When you use FixCanvas to submit an assignment, post a reply, comment or mark a module item as done, that action goes straight from your browser to Canvas, using Canvas's API and your session. It does not pass through our Server.

FixCanvas never stores your Canvas password or any Canvas access token. It never runs on, reads or requests quiz or exam pages, questions, attempts or submissions. It only reads the course quiz list (title, due date, time limit and status).

2. Information sent when you ask the AI a question

When you send a question in Ask, the extension sends the following to our Server:

Before you send anything, "What gets sent with each question" shows the exact text that will go out and its size, and lets you turn off grades, announcement text, assignment instructions and file names. Each answered question has a link to what was sent with it.

The Server checks your limits and forwards your question and that course data to OpenAI, which writes the answer. The Server sends the answer back to you and does not save your question, the answer or the course data. We ask OpenAI not to store the request (store: false). OpenAI may still keep API data for up to 30 days to monitor for abuse, under its own API data policies, and it does not use API data to train its models by default. See OpenAI's API data usage policies.

Some questions (for example, asking for quiz or exam answers) are refused inside the extension, and nothing is sent.

Please don't put sensitive personal information in questions (health information, government ID numbers, passwords, other people's private information). The AI doesn't need it to answer.

3. Information the Server keeps

To run free limits, plans, invites and purchases, the Server keeps the following for each install:

WhatWhy
A random install ID and a signed token, with no name or email attachedTo identify your install without an account
How many questions you've asked and when, your trial start and end, and your remaining free, bonus and pack questionsTo apply limits and plans
Your plan (free, trial, Pro, packs) and, if you've bought something, Stripe's customer and subscription IDsTo know what you've paid for
Your summer-pause settingTo pause and restart Pro billing over the summer if you turned it on
Your 6-character invite code, the install that invited you (if any), and how many friends you've invitedFor invite credits
A restore code, if you've bought somethingSo you can move a purchase to another install
A keyed one-way hash (HMAC) of your network (IP) address, with daily countsFor per-network rate limits. We never store the IP address itself.
A random device ID linked to your install (see below)So a reinstall gets the same plan
The extension versionTo tell you when an update is required

Device ID. So that reinstalling FixCanvas picks up the same plan (including a used free trial, invite credits and Pro), the Server's /device page keeps a random ID in that site's own storage in your browser. The extension reads it through a hidden frame on Canvas pages and the Server records which install it belongs to. The ID doesn't identify you, and clearing your browsing data deletes it. If your school's Canvas blocks the frame, nothing is linked.

Chrome sync. Your install ID is also saved in Chrome sync (chrome.storage.sync), so your other Chrome devices signed in to the same Google account share your plan. Google handles Chrome sync data under Google's Privacy Policy.

Operational logs. Our hosting provider, Cloudflare, records basic request logs (such as time, path, status and errors) that we use to keep the Server working and to stop abuse. These logs may include your IP address and are kept for a short period (up to 7 days) before they are deleted automatically. Our own logs don't include your questions, answers or course data.

4. Payments

Pro subscriptions and question packs are sold through Stripe. Stripe's checkout collects your email address and payment details (card, Google Pay or Link) directly; FixCanvas never sees or stores your card number. We receive and keep only Stripe's customer ID, subscription ID and the status of your purchase. Stripe handles your payment information under the Stripe Privacy Policy. You manage or cancel a subscription in Stripe's billing portal ("Manage subscription" on the Plan page).

5. How we use information

We use the information above only to:

We do not use your information for advertising, sell it, build profiles about you, use it to train AI models, or use it to determine creditworthiness or for lending.

Chrome Web Store Limited Use. FixCanvas's use of information received from Chrome APIs follows the Chrome Web Store User Data Policy, including the Limited Use requirements. We only use that data to provide and improve FixCanvas's single purpose; we don't transfer it except as needed for that purpose, to comply with the law, or as part of a merger or acquisition; and no human reads it except with your permission, for security, or as required by law.

6. Who we share information with

We share information only with the service providers that run FixCanvas, and only what each one needs:

ProviderWhat they receiveWhy
OpenAIYour question, conversation and the course data shown under "What gets sent"To write the AI's answer
CloudflareRequests to the Server, and the Server's stored recordsHosting
StripeYour email and payment details (collected by Stripe), and your install ID as purchase metadataPayments
GoogleYour install ID, through Chrome syncSharing your plan across your Chrome devices

We may also disclose information if the law requires it, to protect the rights, safety or property of FixCanvas, our users or others, or as part of a merger, acquisition or sale of assets (in which case this policy will continue to apply to the information transferred). We do not sell or rent personal information, and we do not "share" it for cross-context behavioral advertising.

7. Your school and FERPA

FixCanvas is a tool you choose to install for yourself. It is not provided by your school and is not a school official or school service provider. FixCanvas only reads what your own Canvas account can already see, using your own session. If your school restricts browser extensions or third-party AI tools, please follow its rules.

8. How long we keep information

9. Security

The Server uses HTTPS, accepts requests only from the extension with a signed token, keeps our OpenAI and Stripe keys as server-side secrets that never appear in the extension, and stores only hashes of IP addresses. Content shown in FixCanvas is sanitized, and the extension runs no remote code. No system is perfectly secure, but we work to protect your information and will notify you as required by law if a breach affects it.

10. Your choices and rights

Depending on where you live (for example, California, other US states, the EU/EEA or the UK), you may have the right to access, correct, delete or get a copy of your personal information, to object to or restrict certain processing, and to not be discriminated against for using these rights. Because we don't collect names or emails, we may need your invite or restore code to verify a request. You can also complain to your local data protection authority.

EU/EEA and UK users: we process your information to provide the service you asked for (contract), for our legitimate interests in preventing abuse and keeping the service running, and to comply with the law. Our Server and providers may process data in the United States and other countries; where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.

11. Children

FixCanvas is for students aged 13 and older. We do not knowingly collect personal information from children under 13. If you are under 18, please review this policy with a parent or guardian. If you believe a child under 13 has used FixCanvas, contact us and we'll delete the related records.

12. Changes to this policy

We'll update this policy when FixCanvas changes how it handles data, and change the "Last updated" date. For significant changes, we'll also tell you in the extension before the change takes effect.

13. Contact

Shifted, LLC
Email: support@fixcanvas.com
Or use the support tab of the FixCanvas Chrome Web Store listing.