Skip to content
Privacy

What leaves your device, and when.

Scholarwire stores your Canvas data, notes and study history on this device: in this browser profile's storage and in the Scholarwire extension. Every account signs in once, with Google or an email link, and an encrypted copy then syncs to our server so the same semester opens on your other devices.

Signing in is required. Encryption happens on your device before anything leaves it. We hold the key.

On your device

Everything, by default.

Courses, assignments, due datesThis device
Grades and submission stateThis device
NotesThis device
Flashcards, decks, review historyThis device
Quizzes and attemptsThis device
Study plan and availabilityThis device

It is stored unencrypted on this device, like any website's local data. Anyone who can use this computer account can read it, so use a personal browser profile and turn on disk encryption if you share a machine. Delete all local data in Settings removes both copies on this device, the browser one and the extension one; it never touches a synced copy on the server, which has its own delete (below). Uninstalling the extension and clearing site data for this origin does the same local wipe by hand. An export contains everything, including grades, so treat the file the way you would treat a transcript.

Canvas

How the extension reads your school.

Scholarwire for Canvas installs with access to no websites. You grant it your school's Canvas address from the extension popup, and that grant covers that one address. It then calls the Canvas API with the session cookie your browser already holds, exactly as the page you are looking at does. We never see your Canvas password, we hold no Canvas token, and there is no integration for us or your school to revoke, because there is no integration.

What Canvas records is what it always records: that your account read your own assignments page. Your school does not receive a notice, a report, or a list of what you looked at in this app.

Exception one

AI features.

When you use an AI feature, only the text or file you chose is sent to the model provider and handled under that provider's API data retention policy. Nothing is sent automatically, nothing is sent in the background, and no AI feature runs unless you click it. If you switch AI off in Settings, every AI surface in the app disappears.

Where it runs

On our servers, through your account. Signing in is the whole setup, and a free account gets credits each month.

What we keep

A count of the credits you have spent this month, so the number in Settings is right. We do not keep the text you sent or the answer that came back.

Exception two

Signing in and sync.

Sign in, and every device you sign in on syncs automatically: your notes, decks, quizzes and study plan, not just your account. No separate step to turn it on.

Your notes and study material are encrypted before they leave your device, with a key kept with your account so any device you sign in on can open them. Keeping that key means we could open them. Nobody here does. Only the app itself can use the keys, and every use is written down.

Who can read it

What we store is encrypted. Opening it needs the key, and only the app itself can use the key, never a person reading a database.

Free pauses it

Sync is part of Pro and your 14-day trial. On Free it pauses: nothing is deleted, and every device keeps what it already has until you upgrade.

Exception three

Calendar sync.

Calendar sync is off until you turn it on. When it is on, only calendar fields (titles, dates, times, course names and locations) are published to a private link, and turning it off deletes them from the server.

It exists because Google Calendar, Apple Calendar and Outlook have to be able to fetch a file over the internet to subscribe to it. The secret in the URL is the only credential, so treat the link the way you would treat a password and turn sync off and on again to issue a new one if you ever share it by accident. It carries only the layers you ticked. It never carries grades, notes, submissions, flashcards or anything you wrote.

Exception four

Accounts and billing.

Every account signs in before using Scholarwire, with Google first or a link sent to your email. An account stores identity and subscription state: an email address, a sign-in credential, your plan, your AI credits, and whether the subscription is active. Signing in is also what starts sync (above); your Canvas data, notes and study material live on your device and, encrypted, in your account, never only on our server.

Card details go to the payment processor and never reach us. Deleting an account removes the identity and subscription record and the encrypted synced copy and its key. It does not touch the data already on your devices, because we cannot reach it.

Exception five

Claude and ChatGPT.

When you connect Scholarwire to Claude or ChatGPT, our server decrypts your synced records to answer that assistant's questions. It does this only while answering a request you made, only for the account that connected, and it logs the call.

What it can turn on

Courses, due dates, announcement excerpts, one note at a time by name, your synced syllabus and assignment readings, and, only if you turn it on per connection, your course-level grade standing. Never a Canvas link, a file's raw bytes, or a per-assignment score.

Turning it off

Settings, Connectors, Disconnect. That stops the connection immediately and does not touch anything already synced to your other devices.

Your syllabus and the readings and pages linked from an assignment are stored the same way as your notes: encrypted in the synced copy, and decrypted for the connector only to answer a request you made, like every other record here. Settings, Canvas has a switch for course material syncing. Turning it off stops new material from being read and deletes the text already stored; the rest of your semester is untouched.

If you use it

Google Drive.

Import one Drive file at a time. You choose the file in Google Drive, and this browser downloads it straight from Google. It never passes through our servers, and Google's permission covers only the files you chose: the rest of your Drive stays invisible to Scholarwire, and nothing is written back to it.

What lands in the note is stored the way every other note is: on your device, and encrypted in your synced copy. The permission itself is held in the tab for the length of the import and is never saved.

What we do not do

The short list.

Sell or share your dataNever
Advertising or ad trackersNone
Third-party analytics in the appOptional, no cookies
Train models on your workNever
Report anything to your schoolNever

We may measure how the marketing site and sign-up funnel are doing: page views, whether an extension install finished, and whether a checkout started or failed. This uses no cookies beyond a random id in your browser's own storage, not a tracking cookie a third party can read, and it never records what you study. Automated traffic (bots, scrapers) is filtered out before anything is counted. It runs only when we have configured it on the server. With nothing configured, no analytics script loads.

Your control

What you can do at any time.

Export

One file with everything, in a readable format, not gated behind a paid plan.

Delete

Delete all local data clears the browser copy and the extension copy in one action.

Disconnect

Revoke the site grant in Chrome and the extension can no longer read Canvas.

Children

Who this is for.

Scholarwire is built for college students and is not directed at children under 13. We do not knowingly create accounts for them.

How long

What we keep, and for how long.

Your email, sign-in credential and planWhile the account exists
The encrypted copy of your notes and study materialWhile the account exists
AI credit countsThe billing period they belong to
Calendar feed contentsUntil you turn the feed off
Sign-up and checkout measurements90 days, then deleted

Deleting your account removes the identity and subscription record, the encrypted synced copy and its key, and any calendar feed. Payment records are kept by the payment processor for as long as its own tax and accounting rules require, which is the one part of this we cannot shorten.

Reaching us

Questions, requests and reports.

For a question about this page, a copy of what we hold, or a deletion you cannot do yourself because you have lost access to the app, start at the support page. You can also write to support@scholarwire.app. Write from the email address the account signs in with. Everything else, including export and delete, is a button in Settings and needs no request.

Security problems go to the same place unless a separate address is published here.

Changes

If this page changes.

Any change that would move data off your device gets stated in the app, in one plain sentence, at the place where it happens, before it happens. That rule is in the product specification, not just here.

Last updated