Legal
Privacy Policy
Thank you for using intoola. This Privacy Policy explains how intoola ("we," "our," or "us") collects, uses, stores, and protects information when you install and use the intoola Chrome extension (the "Extension"). We have written this policy to be as plain and specific as possible, because we believe you deserve to understand exactly what happens to your data.
Please read this policy carefully before using the Extension. By installing or using intoola, you agree to the practices described in this policy. If you do not agree, please uninstall the Extension.
1. Who We Are
intoola is a Chrome browser extension developed to help students study more effectively by connecting to supported learning management systems, including Canvas, Brightspace, and Google Classroom, and using AI to generate flashcards, study notes, and practice questions from their course materials.
We are an independent software developer. If you have questions about this policy or our data practices, please contact us through our Chrome Web Store listing page. We do not have a separate customer support email address or phone number at this time.
2. Scope of This Policy
This policy applies to:
- The intoola Chrome Extension and all features and functionality it contains.
- All information processed in connection with your use of the Extension, including data retrieved from Canvas, Brightspace, or Google Classroom and data processed by AI services.
This policy does not apply to third-party services that intoola connects to on your behalf, such as Google's Gemini API or Stripe. Those services are governed by their own privacy policies, which we reference and link to in Section 8.
3. Information We Access
intoola reads data from supported LMS pages and services, including Canvas, Brightspace, and Google Classroom, using the connection method available for each platform. For browser-tab integrations, it works through your existing, already-authenticated session and does not collect your LMS password. Below is a complete and specific description of everything we access, why we access it, and what we do - and do not do - with it.
3.1 LMS Course Information
We read the names and course codes of your actively enrolled courses. This information is used solely to present you with a list of your courses inside the Extension so you can select which course to study. We do not store this information on any external server.
3.2 LMS Assignments
When connected to Canvas, Brightspace, or Google Classroom, we may read the following assignment data on a read-only basis:
- Assignment titles, descriptions, and due dates.
- Files attached to assignments (used when you select that assignment for study material generation).
This data is accessed exclusively to allow you to select assignments as source material for AI-powered study content. We do not write to, modify, delete, or otherwise alter data in your Canvas, Brightspace, or Google Classroom account unless a feature clearly asks for and receives separate authorization.
3.3 LMS Module and Course Content
We read module and module-item titles and the content linked within them, including:
- LMS page, module, lesson, topic, or class-post text.
- File names and file content attached as module items.
- Assignment details linked from modules.
We access only the content of modules within the course you have actively selected in the Extension.
3.4 LMS Course Files
We read the names and content of files attached to your courses (such as PDFs and images) when you select them for study material generation. We access only the specific files you have selected - we do not browse or access other files in your account.
3.5 Optional Additional Notes, Prompts, and Chat Messages
You may optionally type additional context or instructions in the "Additional Notes" field on the Generate screen, type prompts in chat, or ask follow-up questions in supported features. This text is included in the prompt sent to the Gemini API. intoola does not intentionally store the original prompt text as a separate source record after generation, but prompts and chat messages may be included in saved chat transcripts, generated materials, logs returned by third-party AI services, or generated outputs that you save or share.
3.6 Chrome Profile Email and First-Open Record
When you first open the Extension, intoola may read the email address and Chrome account identifier associated with your current Chrome profile using Chrome's identity API. We store a one-time first-open record containing your email address if available, Chrome account identifier if available, a locally generated install identifier, the Extension version, and the first-open timestamp. We use this record to understand first-time usage, support account-related troubleshooting, and prevent duplicate first-open records for the same browser profile.
intoola also uses your Chrome profile email address when you request AI generation through our Cloudflare Worker. This helps us reduce API abuse, enforce generation access controls, and associate AI generation requests with a signed-in Chrome profile. If Chrome does not provide a valid profile email address, the Extension may block AI generation until you sign in to Chrome with an email account.
intoola also stores lightweight product analytics connected to the same Chrome account or install identifier. These analytics include onboarding progress, onboarding pages viewed, the last onboarding question or screen reached, whether onboarding was completed, selected onboarding answers in summarized form, feature screens viewed, feature click counts, and a percentage distribution of feature clicks. We use this information to understand where users drop off and which features are used most often.
After a first-time paid subscription purchase, intoola may ask you to enter an optional referral code. If you submit a referral code, we store that code with your Chrome account or install identifier and subscription referral record. If you choose not to enter a code, we store that you skipped the referral prompt so we do not keep asking.
3.7 Saved, Shared, and Generated Materials
intoola may store generated materials that you create, save, sync, import, or share. These records may include the generated output text, material type, title, course name, creation and update timestamps, share code, access records, and the Chrome profile email associated with the saved or shared material. Chat sessions may be saved as generated materials and may include both your chat messages and intoola's responses.
Generated materials may contain information from the course materials, files, screenshots, transcript text, prompts, or other content you selected or typed if that information appears in the AI-generated output. intoola does not separately store the original submitted files as source files, but generated or saved materials can contain excerpts, summaries, names, or other details derived from what you submitted.
3.8 What We Do NOT Access
For the avoidance of doubt, intoola does not access:
- Your Canvas, Brightspace, or Google Classroom password or login credentials.
- Courses, assignments, or files you have not actively selected within the Extension, except for limited course-list information used to let you choose a course inside the Extension.
- Gmail, Google Drive, browser history, bookmarks, or other extensions.
- Any information from other Chrome extensions you may have installed.
4. How We Use Your Information
The information we access is used for one purpose: to generate study materials on your behalf. The specific data flow is as follows:
- When you select assignments, modules, or files within the Extension, the text and file content of those materials is transmitted through our Cloudflare Worker to Google's Gemini API for AI processing.
- When you request AI generation, your Chrome profile email address is sent to our Cloudflare Worker for API abuse prevention and generation access control.
- The Gemini API uses this content to generate flashcards, study notes, practice questions, explanations, chat responses, lecture notes, or other study materials, which are then returned to the Extension and displayed to you.
- The original source files and selected source materials are not intentionally stored by intoola as source files after generation. However, generated outputs, saved materials, shared materials, and saved chat transcripts may persist and may contain excerpts, summaries, course names, prompts, or other information derived from the submitted content.
We do not use your information for any of the following purposes:
- Advertising or marketing targeting.
- Building advertising profiles or selling behavioral profiles.
- Training AI models (note: Google's own terms for the Gemini API govern how Google handles data sent to their API - see Section 8).
- Selling or licensing to third parties.
- Any purpose not described in this policy.
5. Data Storage and Retention
intoola is designed with a minimal data footprint. Here is the complete picture of what data is stored and where:
5.1 On Your Device (Local Storage)
The Extension stores several pieces of data on your device using your browser's local storage:
- A free generation counter - a single integer recording the total number of free AI generations you have used. This counter is used to enforce the free-tier limit (2 generations) for users who have not subscribed to Pro.
- A daily token-usage counter - a date string (today's date) and a number of AI tokens consumed today, which may include prompt, context, cached-context, and output tokens as reported by the AI provider or measured by intoola's systems. This counter is used to enforce daily usage limits that apply to all users. It resets automatically based on intoola's server-side usage records.
- A first-open tracking flag and install identifier - values used to avoid creating duplicate first-open records for the same browser profile.
- Feature usage counters - local counts used to calculate feature click percentages.
- A referral prompt flag - a local value used to avoid showing the referral prompt more than once.
- Saved materials and chat sessions - generated materials, saved study outputs, shared/imported materials, and chat transcripts may be stored locally so you can view them again later.
These local values do not include original LMS source files stored as separate source files, but saved generated materials and chat transcripts may contain text derived from selected Canvas, Brightspace, or Google Classroom materials, prompts, screenshots, transcripts, or files.
5.2 On Our Servers: Identity, Usage, Billing, and Analytics
intoola stores one-time first-open records, lightweight product analytics, optional subscription referral records, subscription entitlement records, and AI generation requester records through a Cloudflare Worker, which writes those records to Firebase Realtime Database, Cloudflare KV, D1, Stripe, or another intoola-controlled datastore where appropriate. These records may include your Chrome profile email address if available, Chrome account identifier if available, a locally generated install identifier, the Extension version, the first-open timestamp, onboarding progress, onboarding pages viewed, onboarding completion status, summarized onboarding answers, feature screens viewed, feature click counts, feature click percentage distribution, selected course names used for analytics context, daily generation count by Chrome email, daily AI token usage by Chrome email, Stripe customer ID, subscription ID, subscription status, billing period metadata, and any referral code you choose to submit.
5.3 On Our Servers: Saved and Shared Materials
If you save, sync, share, import, or revisit generated materials, intoola may store those generated materials in Firebase Realtime Database or another intoola-controlled datastore. Saved or shared material records may include the generated output text, material type, title, course name, user email, share code, access records, roles such as creator or importer, created/updated timestamps, and saved chat transcript content.
intoola does not intentionally store your original submitted files, selected LMS source materials, screenshots, or raw prompt packages as separate source records after generation. But saved/generated materials may contain information from those inputs because AI outputs and chat transcripts can include excerpts, summaries, names, course details, or other derived content.
5.4 In Transit
Data transmitted between your browser and third-party APIs (the Gemini API and Stripe) is transmitted using encrypted HTTPS connections. AI generation requests, Chrome profile email addresses used for generation access control, first-open records, product analytics, subscription entitlement checks, and optional referral records are transmitted to our Cloudflare Worker using encrypted HTTPS connections. The Worker forwards selected study content to Google's Gemini API for generation and writes analytics, billing entitlement, or abuse-prevention records to Firebase Realtime Database, Cloudflare KV, or another intoola-controlled datastore where appropriate.
5.5 Retention
First-open records, product analytics, optional referral records, subscription entitlement records, and generation requester records are retained unless you contact us to request deletion, unless we need to retain them for legal, billing, security, fraud-prevention, or operational reasons. Daily generation count and token-usage records may expire automatically based on Cloudflare KV retention settings. The local storage counters, install identifier, saved materials, saved chat sessions, and referral prompt flag on your device persist until you uninstall the Extension, delete the materials where the product allows it, or clear your browser's extension data. Saved or shared generated materials may remain in intoola-controlled storage until deleted through the product, replaced by sync, expired by future retention rules, or deleted in response to a valid request.
6. Data Sharing
We do not sell, rent, trade, or otherwise share your personal information with any third party for their own purposes. The only information we transmit to third parties is data that you explicitly direct us to send as part of using the Extension's core features, specifically:
- The text and file content of Canvas, Brightspace, or Google Classroom materials you select is sent through our Cloudflare Worker to Google's Gemini API (generativelanguage.googleapis.com) for AI-powered study content generation.
- Saved or shared generated materials may be stored in Firebase Realtime Database or another intoola-controlled datastore so you can access, sync, import, or share them.
- Your payment details are collected and processed by Stripe. intoola's Cloudflare Worker stores subscription entitlement metadata such as Stripe customer ID, subscription ID, subscription status, current billing period, and the Chrome profile or install identifier needed to verify Pro access. We do not store payment card numbers or bank-account details in the Extension.
- Chrome profile email addresses used for generation access control, first-open records, product analytics, subscription entitlement, saved/shared material ownership, and optional referral records are sent to our Cloudflare Worker and stored in Firebase Realtime Database, Cloudflare KV, D1, Stripe, or another datastore for account tracking, subscription verification, product improvement, saved-material sync, referral attribution, and API abuse-prevention purposes described in this policy.
Each of these third parties operates under its own privacy policy, which governs their handling of data they receive. See Section 8 for links to those policies.
We may disclose information if required to do so by law, court order, or valid legal process.
7. Chrome Extension Permissions
intoola requests the following Chrome permissions. Below is a complete list of each permission and why it is required:
- activeTab - Allows the Extension to access your currently active supported LMS tab so it can read selected course content through your existing authenticated session.
- scripting - Allows the Extension to use platform-specific relay scripts, such as
canvas_proxy.jsandbrightspace_proxy.js, on supported LMS pages to retrieve selected course content. - storage - Allows the Extension to store the free-tier generation counter, local usage records, settings, saved materials, saved chat sessions, and related local state in your browser.
- identity and identity.email - Allow the Extension to read the Chrome profile email address and Chrome account identifier used for first-open records, analytics identity, and AI generation access control.
- tabs - Allows the Extension to detect which browser window and tab are currently active, used solely to identify an open supported LMS tab.
- sidePanel - Allows the Extension to open as a Chrome side panel alongside your browser content rather than as a popup window.
- *https://\.instructure.com/\*** - Allows the Extension to access Canvas LMS pages and API endpoints on Instructure-hosted Canvas domains. Institutional Canvas domains (e.g., canvas.university.edu) are supported via the
activeTabpermission. - *https://\.brightspace.com/\, https://\.desire2learn.com/\, and supported institutional /d2l/* pages - Allow the Extension to access Brightspace pages and endpoints through your existing authenticated Brightspace session.
- https://generativelanguage.googleapis.com/\* - Allows the Extension to send selected course content to Google's Gemini API for AI generation.
- https://socrianstudyassistantshare-default-rtdb.firebaseio.com/\* - Allows the Extension to store, sync, and import saved or shared study-material records in Firebase Realtime Database.
- https://socrian.socrianstudyassistant.workers.dev/\* - Allows the Extension to send AI generation requests, first-open records, product analytics, billing requests, saved-material sync requests, share-access records, usage records, and optional referral records to intoola's Cloudflare Worker.
All permissions are scoped to the minimum necessary to provide the Extension's functionality.
Google Classroom data is not accessed through the Canvas or Brightspace host patterns listed above. If a Google Classroom connection requires an additional Chrome permission or Google authorization flow, the Extension will present that request before accessing Google Classroom data.
8. Third-Party Services and Their Privacy Policies
intoola integrates with the following third-party services. Each service has its own privacy policy that governs how they handle data. We encourage you to review these policies:
8.1 Google LLC (Gemini API)
The text and file content of Canvas, Brightspace, or Google Classroom materials you select is sent to Google's Gemini generative AI API. Your use of this service through intoola is subject to Google's Privacy Policy and Google's Generative AI Additional Terms of Service.
Importantly, Google's policies govern how Google handles the content you send for AI processing, including any restrictions on Google's use of that content for model training purposes. We recommend reviewing Google's current API terms at ai.google.dev/gemini-api/terms for the most up-to-date information.
8.2 Stripe
Subscription payments are processed by Stripe. We use Stripe Checkout and the Stripe Customer Portal so payment-card details are entered on Stripe-hosted pages rather than inside the Extension. Stripe's privacy practices are governed by its own privacy policy, available at stripe.com/privacy.
8.3 Learning Management System Providers
Your use of Canvas, Brightspace, and Google Classroom remains subject to the privacy policies and terms of the applicable provider and your school or institution. intoola accesses only the course information and materials described in this policy when you use a supported connection.
9. Security
We take reasonable steps to protect the information processed by intoola, including:
- All communications between the Extension, intoola's Cloudflare Worker, the Gemini API, and Stripe are conducted over encrypted HTTPS connections.
- For browser-tab LMS integrations, the Extension reads selected Canvas, Brightspace, or Google Classroom data through your existing authenticated session; your LMS password is not extracted or transmitted by us.
- First-open records, usage records, and billing records are transmitted over encrypted HTTPS connections and stored separately from original LMS source files. Saved and shared generated materials are stored separately from analytics records, but may contain text derived from selected course content or prompts.
However, no method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. The security of your Canvas, Brightspace, or Google Classroom account is also governed by the applicable provider, your institution's security practices, and your own account security settings.
10. Children's Privacy
intoola is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use the Extension.
If you are a parent or guardian and believe that your child under the age of 13 has used intoola and provided personal information through it, please contact us through our Chrome Web Store listing page. We will take prompt steps to investigate and, where appropriate, delete any such information.
Users between the ages of 13 and 18 should use intoola only with the awareness and consent of a parent or guardian.
11. Your Rights and Choices
You may contact us to request access to or deletion of first-open records, product analytics, optional referral records, subscription entitlement records, generation requester records, and saved or shared generated materials associated with your Chrome profile email address or install identifier. For data held by Canvas, Brightspace, Google Classroom, Stripe, Google Gemini, or another third-party service, you should contact those services directly.
11.1 Disconnecting from an LMS
You can disconnect intoola from a Canvas, Brightspace, or Google Classroom session at any time by clicking the settings icon in the Extension popup and selecting "Sign Out / Disconnect." This clears all in-memory state maintained for the connected LMS session.
11.2 Uninstalling the Extension
You can uninstall the intoola Chrome Extension at any time through your browser's extension management settings (chrome://extensions/). Uninstalling the Extension will remove locally stored extension data from that browser profile, including local usage counters and locally stored saved materials. Uninstalling does not automatically delete server-side records such as subscription entitlement records, analytics records, or saved/shared materials already synced to intoola-controlled storage.
11.3 Clearing Local Storage
You can clear the Extension's local storage, including local usage counters and locally stored saved materials, by uninstalling the Extension or by clearing your browser's extension data. Clearing local storage does not automatically delete server-side records already synced to intoola-controlled storage.
11.4 Residents of the European Economic Area, UK, and Switzerland
If you are located in the EEA, UK, or Switzerland, you may have rights under applicable data protection laws (including the GDPR), including the right to access, correct, or delete personal data we hold about you, the right to restrict or object to processing, and the right to data portability. You may contact us about first-open records or any personal data held by our third-party service providers, and we will respond or direct your request appropriately.
11.5 California Residents
If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete personal information, and the right to opt out of the sale of personal information. intoola does not sell personal information, and we are committed to responding to valid requests.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time as intoola evolves or as legal requirements change. When we make material changes, we will update the "Last Updated" date at the top of this policy and, where feasible, provide notice through the Chrome Web Store listing or within the Extension itself.
We encourage you to review this policy periodically. Your continued use of the Extension after changes are posted constitutes your acceptance of the revised policy. If you do not agree to the changes, you should uninstall the Extension.
A history of prior versions of this policy is not currently maintained, but we are committed to providing clear, up-to-date disclosures about our data practices.
13. Contact Us
If you have any questions, concerns, or requests related to this Privacy Policy or intoola's data practices, please contact us through our Chrome Web Store listing page. We will do our best to respond to your inquiry in a timely manner.
We do not have a dedicated privacy officer or legal department at this time, but we are committed to addressing privacy-related inquiries seriously and transparently.
This policy was drafted for intoola (April 2026). It does not constitute legal advice. If you have specific legal questions about compliance with GDPR, CCPA, COPPA, or other applicable laws, please consult a qualified attorney.