FixCanvas Privacy Policy
Effective date: October 9, 2026
Last updated: October 9, 2026
FixCanvas ("FixCanvas", "we", "us") is a Chrome extension that gives students a simpler view of their Canvas LMS courses, plus an AI assistant ("Ask") that answers questions about those courses. FixCanvas is run by Shifted, LLC, a Rhode Island company.
This policy covers the FixCanvas extension, the FixCanvas server (canvas-clean-proxy.bodhiabecker.workers.dev, "the Server"), and the FixCanvas website at fixcanvas.com. It explains what we collect, why, who we share it with, and the choices you have.
In short:
- Your Canvas data stays in your browser. It leaves only when you ask the AI a question, and you can see exactly what was sent.
- We don't ask for your name, email or Canvas login. Your plan is tied to a random install ID.
- We don't save your questions, the AI's answers or your course data on our Server.
- No ads, no analytics, no tracking, and we never sell your data.
FixCanvas is an independent project. It is not affiliated with, endorsed by or sponsored by Instructure, Inc., the maker of Canvas, or by your school.
1. Information FixCanvas handles in your browser
FixCanvas runs on Canvas pages (*.instructure.com, plus any school Canvas domain you choose to enable it on). It uses the Canvas session you are already logged in with to read, through Canvas's own API:
- your courses, course names and codes
- assignments, due dates, instructions, rubrics, submissions, grades and teacher comments
- announcements, discussions, modules, pages, syllabi and files (including text extracted from PDFs, Word, PowerPoint and text files so the AI can cite them)
- calendar events and planner items
- your first name, for the "Hi [name]" greeting
This data is cached in your browser's extension storage on your device. It is not sent to our Server except as described in section 2.
When you use FixCanvas to submit an assignment, post a reply, comment or mark a module item as done, that action goes straight from your browser to Canvas, using Canvas's API and your session. It does not pass through our Server.
FixCanvas never stores your Canvas password or any Canvas access token. It never runs on, reads or requests quiz or exam pages, questions, attempts or submissions. It only reads the course quiz list (title, due date, time limit and status).
2. Information sent when you ask the AI a question
When you send a question in Ask, the extension sends the following to our Server:
- your question and the earlier turns of that conversation (up to 8)
- the course data relevant to your question, such as due dates, assignment instructions, announcement text, file names and document excerpts, and (if you leave the toggle on) grades
- your install ID and signed token (section 3)
Before you send anything, "What gets sent with each question" shows the exact text that will go out and its size, and lets you turn off grades, announcement text, assignment instructions and file names. Each answered question has a link to what was sent with it.
The Server checks your limits and forwards your question and that course data to OpenAI, which writes the answer. The Server sends the answer back to you and does not save your question, the answer or the course data. We ask OpenAI not to store the request (store: false). OpenAI may still keep API data for up to 30 days to monitor for abuse, under its own API data policies, and it does not use API data to train its models by default. See OpenAI's API data usage policies.
Some questions (for example, asking for quiz or exam answers) are refused inside the extension, and nothing is sent.
Please don't put sensitive personal information in questions (health information, government ID numbers, passwords, other people's private information). The AI doesn't need it to answer.
3. Information the Server keeps
To run free limits, plans, invites and purchases, the Server keeps the following for each install:
| What | Why |
|---|---|
| A random install ID and a signed token, with no name or email attached | To identify your install without an account |
| How many questions you've asked and when, your trial start and end, and your remaining free, bonus and pack questions | To apply limits and plans |
| Your plan (free, trial, Pro, packs) and, if you've bought something, Stripe's customer and subscription IDs | To know what you've paid for |
| Your summer-pause setting | To pause and restart Pro billing over the summer if you turned it on |
| Your 6-character invite code, the install that invited you (if any), and how many friends you've invited | For invite credits |
| A restore code, if you've bought something | So you can move a purchase to another install |
| A keyed one-way hash (HMAC) of your network (IP) address, with daily counts | For per-network rate limits. We never store the IP address itself. |
| A random device ID linked to your install (see below) | So a reinstall gets the same plan |
| The extension version | To tell you when an update is required |
Device ID. So that reinstalling FixCanvas picks up the same plan (including a used free trial, invite credits and Pro), the Server's /device page keeps a random ID in that site's own storage in your browser. The extension reads it through a hidden frame on Canvas pages and the Server records which install it belongs to. The ID doesn't identify you, and clearing your browsing data deletes it. If your school's Canvas blocks the frame, nothing is linked.
Chrome sync. Your install ID is also saved in Chrome sync (chrome.storage.sync), so your other Chrome devices signed in to the same Google account share your plan. Google handles Chrome sync data under Google's Privacy Policy.
Operational logs. Our hosting provider, Cloudflare, records basic request logs (such as time, path, status and errors) that we use to keep the Server working and to stop abuse. These logs may include your IP address and are kept for a short period (up to 7 days) before they are deleted automatically. Our own logs don't include your questions, answers or course data.
4. Payments
Pro subscriptions and question packs are sold through Stripe. Stripe's checkout collects your email address and payment details (card, Google Pay or Link) directly; FixCanvas never sees or stores your card number. We receive and keep only Stripe's customer ID, subscription ID and the status of your purchase. Stripe handles your payment information under the Stripe Privacy Policy. You manage or cancel a subscription in Stripe's billing portal ("Manage subscription" on the Plan page).
5. How we use information
We use the information above only to:
- show you your Canvas courses in FixCanvas
- answer your AI questions
- apply free limits, trials, plans, invites and purchases
- prevent abuse, fraud and overuse
- keep the extension and Server working, secure and up to date
- respond to you if you contact us
- comply with the law
We do not use your information for advertising, sell it, build profiles about you, use it to train AI models, or use it to determine creditworthiness or for lending.
Chrome Web Store Limited Use. FixCanvas's use of information received from Chrome APIs follows the Chrome Web Store User Data Policy, including the Limited Use requirements. We only use that data to provide and improve FixCanvas's single purpose; we don't transfer it except as needed for that purpose, to comply with the law, or as part of a merger or acquisition; and no human reads it except with your permission, for security, or as required by law.
6. Who we share information with
We share information only with the service providers that run FixCanvas, and only what each one needs:
| Provider | What they receive | Why |
|---|---|---|
| OpenAI | Your question, conversation and the course data shown under "What gets sent" | To write the AI's answer |
| Cloudflare | Requests to the Server, and the Server's stored records | Hosting |
| Stripe | Your email and payment details (collected by Stripe), and your install ID as purchase metadata | Payments |
| Your install ID, through Chrome sync | Sharing your plan across your Chrome devices |
We may also disclose information if the law requires it, to protect the rights, safety or property of FixCanvas, our users or others, or as part of a merger, acquisition or sale of assets (in which case this policy will continue to apply to the information transferred). We do not sell or rent personal information, and we do not "share" it for cross-context behavioral advertising.
7. Your school and FERPA
FixCanvas is a tool you choose to install for yourself. It is not provided by your school and is not a school official or school service provider. FixCanvas only reads what your own Canvas account can already see, using your own session. If your school restricts browser extensions or third-party AI tools, please follow its rules.
8. How long we keep information
- In your browser: the extension's cache and settings stay until you uninstall FixCanvas or clear its data. The device ID stays until you clear your browsing data.
- AI questions: not kept on our Server. OpenAI may keep them for up to 30 days (section 2).
- Install records (section 3): kept while your install is in use, and deleted after 24 months of no activity or when you ask us to delete them.
- Purchase records: Stripe keeps payment records as required for tax and accounting. We keep Stripe IDs for as long as your purchase is active, and as needed for refunds, disputes and the law.
- Rate-limit hashes: kept only as long as the daily or per-minute limit they count.
- Operational logs: deleted automatically after a short period (section 3).
9. Security
The Server uses HTTPS, accepts requests only from the extension with a signed token, keeps our OpenAI and Stripe keys as server-side secrets that never appear in the extension, and stores only hashes of IP addresses. Content shown in FixCanvas is sanitized, and the extension runs no remote code. No system is perfectly secure, but we work to protect your information and will notify you as required by law if a breach affects it.
10. Your choices and rights
- Control what's sent: turn categories of course data off under "What gets sent with each question", or don't use Ask at all. The rest of FixCanvas works without the AI.
- Turn FixCanvas off: "Canvas view" switches back to regular Canvas at any time.
- Delete local data: uninstall FixCanvas. To also remove the device ID, clear your browsing data for
canvas-clean-proxy.bodhiabecker.workers.dev. - Access or delete Server records: contact us (section 13) with your invite code or restore code (shown on the Plan page) so we can find your install. We'll respond within 30 days. Deleting your records also removes your plan, credits and the link to any purchase, so cancel any subscription first.
Depending on where you live (for example, California, other US states, the EU/EEA or the UK), you may have the right to access, correct, delete or get a copy of your personal information, to object to or restrict certain processing, and to not be discriminated against for using these rights. Because we don't collect names or emails, we may need your invite or restore code to verify a request. You can also complain to your local data protection authority.
EU/EEA and UK users: we process your information to provide the service you asked for (contract), for our legitimate interests in preventing abuse and keeping the service running, and to comply with the law. Our Server and providers may process data in the United States and other countries; where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
11. Children
FixCanvas is for students aged 13 and older. We do not knowingly collect personal information from children under 13. If you are under 18, please review this policy with a parent or guardian. If you believe a child under 13 has used FixCanvas, contact us and we'll delete the related records.
12. Changes to this policy
We'll update this policy when FixCanvas changes how it handles data, and change the "Last updated" date. For significant changes, we'll also tell you in the extension before the change takes effect.
13. Contact
Shifted, LLC
Email: support@fixcanvas.com
Or use the support tab of the FixCanvas Chrome Web Store listing.