Legal
Privacy Policy
Thank you for using Socrian. This Privacy Policy explains how Socrian ("we," "our," or "us") collects, uses, stores, and protects information when you install and use the Socrian Chrome extension (the "Extension"). We have written this policy to be as plain and specific as possible, because we believe you deserve to understand exactly what happens to your data.
Please read this policy carefully before using the Extension. By installing or using Socrian, you agree to the practices described in this policy. If you do not agree, please uninstall the Extension.
1. Who We Are
Socrian is a Chrome browser extension developed to help students study more effectively by connecting to their Canvas LMS or Brightspace LMS account and using AI to generate flashcards, study notes, and practice questions from their course materials.
We are an independent software developer. If you have questions about this policy or our data practices, please contact us at justin@socrian.com.
2. Scope of This Policy
This policy applies to:
- The Socrian Chrome Extension and all features and functionality it contains.
- All information processed in connection with your use of the Extension, including data retrieved from Canvas LMS or Brightspace LMS and data processed by AI services.
This policy does not apply to third-party services that Socrian connects to on your behalf, such as Google's Gemini API or ExtensionPay. Those services are governed by their own privacy policies, which we reference in Section 8.
3. Information We Access
Socrian reads data directly from your open Canvas LMS or Brightspace LMS browser tab using a content script. It does not use OAuth or any login flow of its own — it works through your existing, already-authenticated LMS session.
3.1 Canvas and Brightspace Course Information
We read the names and course codes of your actively enrolled courses solely to present you with a list of your courses inside the Extension. We do not store this information on any external server.
3.2 Canvas and Brightspace Assignments
We read assignment titles, descriptions, due dates, and attached files on a read-only basis, exclusively to allow you to select assignments as source material for AI-powered study content. We do not write to, modify, delete, or otherwise alter any data in your Canvas or Brightspace account.
3.3 Canvas and Brightspace Module Content
We read module and module-item titles and the content linked within them, including LMS page text, file names and content, and assignment details — only for the course you have actively selected in the Extension.
3.4 Canvas and Brightspace Course Files
We read the names and content of files you specifically select for study material generation. We do not browse or access other files in your account.
3.5 Optional Additional Notes
You may optionally type additional context in the "Additional Notes" field. This text is included in the prompt sent to the Gemini API and is not stored beyond the current session.
3.6 Chrome Profile Email and Analytics
When you first open the Extension, Socrian may read your Chrome profile email address and account identifier to create a one-time first-open record. This record contains your email address if available, a locally generated install identifier, the Extension version, and the first-open timestamp. We use this to understand first-time usage and prevent duplicate records.
Socrian also stores lightweight product analytics tied to the same identifier, including onboarding progress, feature screens viewed, and feature click counts. We use this to understand where users drop off and which features are used most.
3.7 What We Do NOT Access
- Your Canvas or Brightspace login credentials, password, or authentication tokens.
- Courses, assignments, or files you have not actively selected.
- Gmail, Google Drive, browser history, bookmarks, or other extensions.
4. How We Use Your Information
The information we access is used for one purpose: to generate study materials on your behalf.
- Selected Canvas or Brightspace content is transmitted through our Cloudflare Worker to Google's Gemini API for AI processing.
- Your Chrome profile email is sent to our Cloudflare Worker for API abuse prevention and generation access control.
- Once AI-generated content is returned and displayed, the source content is not retained by us in any form.
We do not use your information for advertising, behavioral profiling, AI model training, or any purpose not described in this policy.
5. Data Storage and Retention
On Your Device
The Extension stores a free generation counter, daily token-usage counter, first-open tracking flag, feature usage counters, and a referral prompt flag in your browser's local storage. None of these include Canvas or Brightspace material content.
On Our Servers
First-open records, lightweight product analytics, optional referral records, and AI generation requester records are stored via a Cloudflare Worker in Firebase Realtime Database or Cloudflare KV. We do not store your Canvas or Brightspace course materials or AI-generated study content in this database.
Retention
Server-side records are retained unless you contact us to request deletion at justin@socrian.com. Local storage data persists until you uninstall the Extension or clear your browser's extension data.
6. Data Sharing
We do not sell, rent, or share your personal information with any third party for their own purposes. The only data we transmit to third parties is what you explicitly direct us to send:
- Selected Canvas or Brightspace content is sent to Google's Gemini API for study content generation.
- Payment and subscription status is managed by ExtensionPay. We do not process or store payment information ourselves.
- Chrome profile emails and analytics records are sent to our Cloudflare Worker for the abuse-prevention and product-improvement purposes described above.
We may disclose information if required by law, court order, or valid legal process.
7. Chrome Extension Permissions
- activeTab — Accesses your active Canvas or Brightspace tab through your existing authenticated session.
- scripting — Injects a small relay script into your Canvas or Brightspace tab to forward API requests.
- storage — Stores the free-tier generation counter locally.
- identity / identity.email — Reads your Chrome profile email for first-open records and generation access control.
- tabs — Detects which tab is your open Canvas or Brightspace tab.
- sidePanel — Opens Socrian as a Chrome side panel.
- *.instructure.com — Accesses Canvas LMS pages and API endpoints.
- Brightspace domains — Accesses Brightspace LMS pages and API endpoints through your institution's Brightspace domain.
- generativelanguage.googleapis.com — Sends selected content to Google's Gemini API.
- extensionpay.com — Verifies your subscription status.
- Firebase / Cloudflare Worker — Stores shared study materials, first-open records, and analytics.
8. Third-Party Services
Google LLC (Gemini API)
Canvas or Brightspace content you select is sent to Google's Gemini API. Your use is subject to Google's Privacy Policy and Google's Generative AI Terms.
ExtensionPay (Campfire Technology Inc.)
Subscription payments are managed by ExtensionPay. We do not receive or store your payment card details. Their privacy practices are available at extensionpay.com/privacy.
9. Security
All communications between the Extension, our Cloudflare Worker, the Gemini API, and ExtensionPay are conducted over encrypted HTTPS connections. The Extension reads Canvas and Brightspace data only through your existing authenticated browser session — no credentials or tokens are ever extracted or transmitted by us.
No method of transmission over the internet is completely secure. While we use commercially reasonable means to protect your data, we cannot guarantee absolute security.
10. Children's Privacy
Socrian is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has used Socrian, please contact us at justin@socrian.com and we will promptly investigate and delete any such information.
11. Your Rights and Choices
You may contact us to request access to or deletion of records associated with your Chrome profile email or install identifier. For data held by Canvas, Brightspace, or ExtensionPay, contact those services directly.
You can disconnect Socrian from Canvas or Brightspace at any time via the settings icon in the Extension. You can remove all local data by uninstalling the Extension via chrome://extensions/.
If you are located in the EEA, UK, or Switzerland, you may have rights under GDPR including access, correction, deletion, restriction, and portability. California residents may have rights under CCPA. Contact us at justin@socrian.com with any such requests.
12. Changes to This Policy
We may update this Privacy Policy as Socrian evolves or as legal requirements change. When we make material changes, we will update the "Last Updated" date at the top of this page and, where feasible, provide notice through the Chrome Web Store listing or within the Extension itself.
13. Contact Us
If you have any questions, concerns, or requests related to this Privacy Policy or Socrian's data practices, please email us at justin@socrian.com. We are committed to addressing privacy-related inquiries seriously and transparently.