CoursePilot is an independent Chrome extension that helps college students organize coursework and study from their own materials. It is not a product of Instructure, Canvas, Gradescope, or Piazza. This policy describes what the extension reads, what stays on your device, and what leaves it. If these practices change, the extension will show the disclosure again before continuing.
CoursePilot is for college students 18 and older only. It is not designed for children and is not intended for K–12. Do not install or use it if you are under 18.
After you choose courses, CoursePilot indexes those courses in this browser (IndexedDB and extension storage). That can include course names, assignments, files, pages, syllabi, grades, discussion text, Piazza and Gradescope material you connect, chats, drafts, and study decks.
The extension reads your signed-in Canvas, Gradescope, and Piazza session cookies and CSRF tokens so it can call those sites as you — you do not paste a password or access token. Cookie values are used only to make those requests from your browser. CoursePilot does not upload cookie values to CoursePilot servers or to analytics.
Hosted AI (default). When you use Cloud relay, the extension sends the model prompt — for example assignment text, attached PDFs, chat messages, and retrieved course snippets — plus your Canvas hostname and Canvas user id to CoursePilot’s relay at canvasgoon-relay.canvasgoon.workers.dev (Cloudflare). The relay forwards the prompt to OpenRouter, which sends it to the selected model provider (default: Google Gemini). The hostname and user id are used only to enforce per-account usage caps. They are stored as a hash on the relay, not as a student roster.
Your own API key or Ollama. Prompts go to that provider or stay on your machine. They do not use the CoursePilot relay.
Product analytics (off unless you opt in). If you turn analytics on, CoursePilot sends an anonymous install id, your Canvas hostname, extension version, AI provider name, course count, and product events (for example sync, generate, settings saved) to PostHog. Event properties are allow-listed. Course text, cookie values, names, and email are not sent.
Bug reports. If you email support, you choose what to include in that message.
Only to provide CoursePilot’s disclosed purpose: organizing your coursework, retrieving your materials, and generating study aids or drafts you asked for. We do not sell your data, use it for advertising, or use it to train CoursePilot’s own models.
Local course data remains until you use Settings → Clear all data or uninstall the extension. Relay usage meters expire after the billing month (about 40 days). OpenRouter and model providers retain prompts under their own policies. PostHog retains opted-in analytics under PostHog’s policy.
To delete local data: Settings → Clear all data, then uninstall. To request deletion of opted-in analytics or relay meters, email aicoursepilot@gmail.com from a message that includes your Canvas hostname.
Cookies and site access are used only to read your existing school session and course pages. Optional access to additional HTTPS sites is requested only when you add a school Canvas URL that is not on instructure.com or canvas.com. Localhost access is requested only if you choose Ollama.
AI output is a study aid you review. CoursePilot never submits work to Canvas, Gradescope, or Piazza. Turning a draft or chat answer in as your own work may violate your school’s honor code. You are responsible for what you submit.
CoursePilot is not affiliated with, endorsed by, or a product of Instructure, Canvas, Gradescope, or Piazza. Those names describe the sites you already use.
If collection or sharing changes, CoursePilot will show an updated in-product notice and require acceptance before you continue. The current policy will stay at this URL. Use of the product is also governed by the Terms of Use.