Privacy Policy

Last updated: October 5, 2026

Collegium (“we,” “us”) is an AI study assistant that connects to your own Canvas account to help you keep track of and work on your coursework. This page explains, plainly, what we collect, how we store it, how we use it, and how you control it.

What we collect

  • Account information. Your email address and authentication credentials, used to sign you in.
  • If you sign in with Google. Google shares your name, email address, and profile picture with us. We use them only to create your Collegium account and sign you in. We never get your Google password, and we can’t see your Gmail, Drive, Calendar, or anything else in your Google account. We don’t sell this information or use it for ads, and deleting your Collegium account deletes it.
  • Course data from your own Canvas session. After you explicitly consent in-product, our browser extension reads data visible in your own logged-in Canvas session — courses, assignments and due dates, rubrics, syllabus files, pages, and files (extracted as text) — and sends it to our servers. We never ask for or store your Canvas password; the extension only reads what your own browser session can already see.
  • More of your Canvas, only if you say yes. Collegium can also read your to-do list, the announcements and calendar events for your classes, the modules (units) in each class, your grades and how each class weights them, and your own submitted work with the comments and rubric scores on it. That is only your own work and what your teachers wrote about it, never classmates’ posts. We ask you separately before reading any of it, and none of it is read or stored until you say yes. Like the rest of your course data, it is used only to answer your own questions; see “How we use it” below.
  • Files you upload. When you add a file to your Library or attach one in chat, we keep the original file in private storage scoped to your account, with the text we read from it. When a page or slide is mostly a picture (a scan, a diagram, a photo), an AI model reads the picture and writes out what it says and shows, so Collegium can search it.
  • Profile memory you provide. Anything you tell Collegium about your voice, learning style, or preferences, so it can better tailor its help to you.
  • Usage and billing records. Basic product-usage metadata (e.g. which features you use) and subscription/billing status. Payments are handled by a PCI-compliant third-party payment processor — we never see or store your card number.

How it’s stored

Your data lives in a managed cloud database (hosted Postgres), encrypted at rest, and isolated per user with row-level security (RLS) — meaning the database itself enforces that your data is only ever readable in the context of your own account. Course documents are stored as extracted text and as searchable embeddings (numeric representations used for search). Files you upload are also kept as the original file in private storage. All of it is scoped to your account only.

To be precise about what we are not claiming: this is not client-side-only storage (your data is stored on our servers, not only in your browser), and it is not end-to-end encrypted (we can access it server-side to power the product, and to provide support if you ask us to). We do not claim to be “FERPA-compliant” as a certification — we take FERPA’s spirit seriously in how we handle educational records (consent gates, encryption, deletion), but that is a design commitment, not a formal compliance claim.

How we use it

Your course data and profile memory exist for one purpose: to power your own assistant — retrieving the right context and feeding it to an AI model so it can actually help with your specific courses, deadlines, and materials, instead of generic answers.

  • When you chat or generate work, relevant pieces of your course data are sent to our AI providers: the language models that write the response, and a separate provider for the embeddings that power search. Our main language model provider may train on requests: its terms allow it, and we have no opt-out with them. Our embeddings provider does not train on your data, and our backup language model route only uses services that do not. Pages of uploaded files that are mostly pictures are sent to our main language model provider so it can read them. When a class syncs, its syllabus is sent once to our main language model provider to write that class’s one-line topic.
  • We do not sell your data. We do not show ads inside Collegium. We do advertise Collegium elsewhere (TikTok), and on our public marketing pages only — the home page, pricing, the guides, the extension page, never inside the product — an ad-measurement pixel and a first-party cookie record whether one of those ads brought you here. See “Advertising measurement” below. None of your course data is ever sent to it.

Your control

  • Consent first. We never scrape or store your Canvas data before you explicitly consent in-product.
  • Revocable anytime. You can revoke consent at any time, which stops future syncs. Previously stored data is not automatically deleted by revoking consent alone — use full deletion (below) to remove it.
  • The extra Canvas data is its own choice. If you agree to it, you can take that back in Settings: turning it off deletes it at once. Your classes, files and due dates stay, because you agreed to those separately.
  • Full deletion, anytime. From Settings, you can permanently and immediately delete your account and all associated data. This cascades to your course data, uploaded files, embeddings, chats, and profile memory — it is not a soft delete.

Third parties we use

Collegium runs on a small number of established service providers. We describe them by what they do for you, rather than naming each one here:

  • Cloud infrastructure providers — the managed database, authentication, file storage, and application hosting that run the product.
  • Payment processing partners — subscription billing and card handling. Your card details go to the processor directly; they never touch our servers.
  • AI service providers — the language models that generate chat replies and written work, and the embeddings service that powers search over your course materials. They receive your data to answer your own request; see “How we use it” above for what each may do with it.
  • Product analytics — on our website and inside the product, we record how you use Collegium: pages, clicks, errors, and screen recordings. Recordings can show what is on your screen, including your course material. Text you are typing into a field is masked; once you send a message, it appears on screen and a recording can show it. Once you sign in, these records are linked to your account’s ID number (never your name or email), so we can see how one person uses Collegium across devices. Only we use them, and only to improve Collegium.
  • Advertising measurement (TikTok) — on our public marketing pages only, a TikTok pixel and a first-party cookie (ch_adclick) remember which ad brought you to the site, so we can tell whether our ads work. If you sign up after arriving from an ad, TikTok receives the ad click id and a one-way hash of your email address to match the sign-up to the ad. It never receives your Canvas data, your questions, or anything from inside the product, and it is not loaded on any signed-in page.

If you want the specific providers we use — for example to check them against your school’s policy — email us at the address below and we will tell you.

Changes to this policy

If we make material changes to this policy, we will update the “Last updated” date above and, where appropriate, notify you in-product.

Contact

Questions about this policy or your data? Email operations.team.co@gmail.com (interim contact).