Legal
Last updated September 2026
CanvasCal is a Chrome extension and companion feed service, built by broken_boness, that reads your Canvas assignments and publishes them as a private calendar feed. This page explains what the extension and the feed service do and don't collect. CanvasCal is not affiliated with, endorsed by, or operated by Instructure (the makers of Canvas) or your school.
To read your assignments, CanvasCal asks for your Canvas URL and a personal access token. That token is stored only in chrome.storage.local, a storage area private to your browser on your device. The extension uses it exclusively to talk directly to your Canvas instance, browser to Canvas. It is never sent to our servers, never placed in a URL, and never written to any log.
When you sync, the extension sends only the assignment fields needed to build your calendar feed: the assignment title and due date, plus an optional description and a link back to the assignment in Canvas depending on your settings. Your course list, your Canvas token, and your login credentials are never part of that payload.
CanvasCal doesn't have user accounts, and we don't collect your name, email address, or any other personal identifier. The only thing identifying your calendar feed is a randomly generated, unguessable link (a UUID) created the first time you sync. Anyone who has that link can view the feed, which is why it's worth treating it like a password and not posting it publicly.
Synced assignment data is stored securely on our servers, accessed only by code we control. No service we use to run CanvasCal ever receives your Canvas token or credentials. They only ever receive the sanitized assignment fields described above.
The CanvasCal website and extension don't use cookies, analytics scripts, or any third-party tracking. Fonts used on this site are bundled at build time rather than loaded from a third-party server at runtime.
The extension gives you direct control over the data associated with your feed:
CanvasCal is intended for students using Canvas, typically at the high school level or above. We don't knowingly collect personal information from children, and as noted above, we don't collect personal identifiers from anyone.
If this policy changes in a meaningful way, we'll update the date at the top of this page. Continued use of CanvasCal after a change means you accept the updated policy.
Questions about this policy can be sent through broken_boness.