Privacy Policy
Last updated August 31, 2026
This policy explains how Assignly collects, uses, stores, and shares information when you use the desktop app, tryassignly.com, and related services. Assignly is responsible for the processing described here. Contact us at [email protected].
Age and global availability
Assignly is available globally to people age 13 or older. If the law where you live requires permission from a parent or guardian to use an online service or allow its processing, you may use Assignly only after that permission is given. We do not knowingly collect personal data from anyone under 13. Contact us if you believe a child under 13 has used the service.
Your Canvas connection
Assignly opens your school's Canvas login page in a native window, so we never receive or store your school password. Canvas cookies stay in your operating system keychain. Routine Canvas reads, downloads, and submissions you explicitly confirm run from your computer.
Cookies reach our API only when the app requests a signed device session. The API uses them to call your school's Canvas profile endpoint, confirm the Canvas school and user id, then discards them. We do not store Canvas cookies on our servers. The resulting token contains the Canvas host, stable Canvas user id, a random session id, and a two-week expiry. Disconnecting revokes that session id and clears the keychain entry.
We compare Canvas hostnames with Instructure's public school directory and a manually maintained allowlist. During the current beta this check runs in monitoring mode: an unmatched public host is logged and may still connect while we identify legitimate school vanity domains. The lookup sends a hostname only, never cookies or coursework.
Information we process
- Canvas school and user identifiers used for sessions, metering, plans, referrals, and course invites.
- Course, assignment, calendar, rubric, feedback, file, and grade data displayed or processed on your device.
- Assignment text, selected course material, and—when visual quiz help is enabled—a processed screenshot of the visible Canvas or publisher page needed for an AI request.
- Generated drafts and job status stored so you can reopen completed work.
- Local workspace information, such as saved plans, writing preferences, and Study Packs, which normally stays on your device.
- Account data from Google or Discord, including name, email, profile image, provider id, OAuth tokens, and Assignly session data.
- Subscription, entitlement, metering, referral, and Stripe customer/subscription identifiers.
- Optional feedback, notes, diagnostics, and any Sage response you expressly choose to attach.
- Security and operational records such as request ids, session revocations, known Canvas hosts, IP address, and user agent.
AI providers
When you request visual quiz help, Assignly may send the visible Canvas or publisher viewport through OpenRouter to Google Gemini after covering editable controls the page exposes to the app. Embedded third-party content may remain visible. Assignly does not store these screenshots; the request requires OpenRouter endpoints with data collection denied and Zero Data Retention. Other Sage, draft, or syllabus requests send the text needed for that request to Cerebras. Groq may receive the same type of data when it is used for failover. Assignly does not use your inputs or outputs to train models. Cerebras states that it does not retain inference inputs and outputs. Groq states that ordinary inference data is not retained by default, but may be retained for up to 30 days to investigate abuse or reliability problems unless Zero Data Retention is enabled. Provider practices can change; their current policies govern their processing.
Product and website analytics
Assignly uses PostHog Cloud in the United States. The desktop app sends content-free product events with a random install id and, after Canvas connects, a server-generated pseudonymous person id. Events may include app version, platform, fixed feature choices, numeric usage counts, and your Canvas school hostname. The desktop does not load session replay or record your screen, assignments, drafts, grades, names, email, or Canvas user id.
The public website runs cookieless, anonymous analytics: page views, clicks, and performance measurements with no cookies, no identifiers stored on your device, and no session replay or heatmaps. Share and utility pages with private link fragments additionally strip the fragment and mask text before analytics.
Accounts and payments
An Assignly account is optional for Canvas browsing and the trial. Google or Discord sign-in is required for paid checkout. We store the account, its sessions, and its verified link to your Canvas identity. Signing out of Assignly does not disconnect Canvas on the device.
Stripe processes Checkout and Customer Portal. Stripe receives account and transaction data, the plan selected, device/network information used for fraud prevention, and the payment details entered on Stripe's pages. We store subscription status and Stripe customer/subscription ids. Stripe does not receive Canvas cookies or assignment content from Assignly.
Feedback, invites, and sharing
Beta feedback is stored with your pseudonymous Canvas user key. A feedback note and limited diagnostics may also be sent to our private Discord feedback channel. An attached Sage response is stored in our database and may also be included in that private Discord report so we can see the response your feedback refers to.
Course-invite links can reveal a course label and aggregate participant count to someone with the link. Semester Scan cards contain aggregate counts and date ranges, not names, schools, course names, assignment titles, grades, Canvas ids, or Canvas links. Study Pack content is encoded in the URL fragment selected by you; browsers do not send that fragment to our website.
We previously collected waitlist signups through Tally. Tally may still hold the information submitted, usually an email address. Contact us to request deletion.
Service providers and international processing
We use Cloudflare for the website and release files, Railway for the API, Supabase for Postgres, PostHog for analytics, Stripe for billing, Google and Discord for sign-in, OpenRouter, Google Gemini, Cerebras, and Groq for inference, Discord for feedback delivery, and Tally for the historical waitlist. These providers process data where they operate, including the United States. Data-protection laws in those locations may differ from those where you live.
Why we process information
Where privacy law requires a legal basis, we process information to provide the service and perform our agreement with you; for legitimate interests such as security, fraud prevention, support, reliability, anonymous cookieless website analytics, and improving content-free product flows; and to meet legal, tax, accounting, and payment obligations.
Retention
- Canvas cookies remain on your device until you disconnect or replace the connection.
- Signed Canvas sessions expire after two weeks; revocation records are removed after the related session expires.
- Account, entitlement, metering, referral, invite, job, and draft records remain while needed to provide the service or until a valid deletion request, subject to the exceptions below.
- Billing, fraud-prevention, security, dispute, and tax records may be kept as long as reasonably necessary or legally required.
- Feedback is kept through the beta and afterward while it remains useful for support and product decisions, unless deletion is requested.
- PostHog and other processors retain data under their configured retention periods and legal obligations.
Deletion from active systems may not immediately remove limited copies from backups, provider systems, fraud-prevention records, or records we must retain by law. We will isolate or delete those copies when the applicable retention period ends.
Your choices and rights
Depending on where you live, you may have rights to access, receive, correct, delete, restrict, or object to processing of personal data, withdraw consent, and complain to a local privacy authority. We do not sell personal data or share it for cross-context behavioral advertising. We do not discriminate against anyone for making a privacy request.
Email [email protected] to make a request. Include enough information for us to verify the relevant Assignly account or Canvas connection without sending your Canvas password or cookies. You can also disconnect Canvas in the app, sign out, cancel a subscription in Customer Portal, and change website analytics through “Privacy choices.”
Security
We use encrypted transport, OS keychain storage for Canvas cookies, signed expiring sessions, least-privilege desktop permissions, access controls, and bounded data handling. No system is completely secure. Contact us promptly if you believe your account or data has been compromised.
Changes
We may update this policy as the product or law changes. The revision date will change, and we will provide additional notice in the app, website, or account email when a change materially affects how personal data is used.
Contact
Privacy questions and requests: [email protected].