Privacybelied foar Canvas Teacher Toolkit
Canvas Teacher Toolkit troch ND Studio
Last updated: August 22, 2026
Canvas Teacher Toolkit ("the extension") is a browser extension that adds teaching tools to the Canvas LMS interface. This policy explains what the extension does and does not do with your data.
The extension does not have a server. It does not collect, transmit, sell, or share your data with the developer or any third party. Everything it stores stays on your own computer, in your browser. Everything it reads or writes in Canvas happens directly between your browser and your school's Canvas site, using your existing login — exactly as if you had done it by hand.
The extension uses your browser's local extension storage (chrome.storage.local) to save your settings and content so they persist between sessions. This can include:
- Your preferences (dark mode on/off, which panel features are enabled).
- Your saved feedback-bank comments and badge-set definitions.
- Your class schedule, holiday dates, and grading-period labels.
- Student accommodation records you choose to enter (student name, class period, whether the student has a 504 plan and/or IEP, the accommodation details you type in, and any extended-time setting).
- Any custom Canvas web address you add in Settings.
This data is stored only on the device where you entered it. It is never uploaded anywhere by the extension. If you use the "Export all data" feature, the exported file is written to wherever you choose to save it, and you are responsible for keeping that file secure.
Accommodation information is sensitive and may be protected under laws such as FERPA and IDEA. The extension keeps this information local to your device and never transmits it to the developer. You control what you enter, where any exported backup file is saved, and who has access to your computer and browser profile. Treat exported backup files as confidential student records.
When you use its features, the extension acts on your behalf within Canvas using your current, already-authenticated Canvas session (the same cookies your browser already holds). Depending on the feature, it may:
- Read the page you are viewing (e.g. gradebook data, the assignment or student you have open) to display summaries or insert content.
- Read your course roster and files through Canvas's own API to match badge images and identify students for accommodations.
- Write changes you explicitly trigger — inserting content into the Rich Content Editor, setting a grade or comment, setting due dates and per-student overrides, or sending a Canvas message (Conversation).
These actions occur only when you click the corresponding button, and they go directly to your school's Canvas servers. The extension does not send this data to the developer or anyone else.
- Storage — to save your settings and content locally, as described above.
- Scripting — to load the toolkit on custom Canvas web addresses you choose to add.
- Alarms and Notifications — for the optional weekly accommodations-outreach reminder, if you turn it on.
- Host access to Canvas sites — the toolkit runs automatically on
*.instructure.com. Any other Canvas address is added only when you enter it in Settings and approve the permission prompt. You can remove it at any time.
The extension does not request access to your browsing history, other websites, your bookmarks, your camera, your microphone, or your location.
None. The developer receives no data from the extension. There are no analytics, no tracking, no advertising, and no third-party services.
You can view, edit, export, and delete all stored data from the extension's Settings page. "Clear all data" permanently erases everything the extension has stored on that device. Removing the extension from your browser also removes its local storage.
The extension is a tool for teachers. It is not directed to children and does not knowingly collect information from children. Any student information present is entered by the teacher and stored locally under the teacher's control.
If this policy changes, the "Last updated" date above will be revised and the updated policy will be distributed with the extension.
Questions about this policy can be directed to the extension's developer at the contact address listed on the extension's store page.