Privacy Policy
Last updated: July 2026
This policy explains what Ozyplan collects, how it is used, and the choices you have. It describes the product as actually built — including Ozyplan Canvas Sync, the browser extension that imports coursework from your school's Canvas.
Information we collect
- Account information — your email address and name, used to sign you in and personalize the app.
- Academic profile — optional details you choose to add (grade/year, school, weekly study hours, time zone, academic goal) used to tailor planning.
- Coursework you provide — courses you create, files you upload (such as syllabi, slides, project briefs and images of handouts) and the text extracted from them.
- Coursework imported from your school — where you connect Canvas or an ICS calendar feed: course names, teacher and term details, assignments and quizzes, due dates, point values, rubrics, project instructions, pages, announcements, the syllabus, and course files. We also keep a record of where each item came from and when it last changed, so the same material is not imported or re-read twice.
- AI results — analyses, briefings, forecasts, Study Packs, Worked Examples and plans generated for you and saved to your account.
- Usage & billing records — logs of AI operations (feature, model, token counts, estimated cost) and your subscription status. Payments are handled by Stripe; we do not store your full card number.
- Product analytics — event records (such as "account created" or "briefing generated") with small, non-sensitive properties. These never contain your coursework content or AI prompts.
Ozyplan Canvas Sync (browser extension)
Canvas Sync is an optional Chrome extension. If you install it and connect it, it reads coursework from your school's Canvas using the session already signed in on your own computer, and sends it to your Ozyplan account. Everything below describes what it does and does not do.
- What it reads — the courses you are enrolled in, and the assignments, quizzes, rubrics, due dates, pages, announcements, syllabus and course files that your own Canvas account can already open. It reads only the one Canvas site you approve.
- Which courses it imports — this school year's, and only courses that behave like academic classes. Before importing anything, it asks Canvas a few structural questions about each enrolment — how many assignments it has, whether they carry marks, when they were due, whether it publishes a syllabus, how many modules it has — and sends Ozyplan those counts and dates, not the content. Clubs, information pages and past courses are not imported, and you can see what was set aside, and why, on your Canvas page.
- What it never asks for or stores — your Canvas password, your school sign-in details, and any multi-factor codes. It never signs in as you, and it never transmits your Canvas login session anywhere.
- What it cannot reach — locked or unpublished material, quiz questions, teacher-only content, other students' submissions or grades. It has no more access to Canvas than your own account does.
- What it never does — submit, post, edit or delete anything in Canvas, or download your grades. It is read-only.
- How it identifies your account — the extension creates its own random key and gives Ozyplan only a one-way hash of it, so the key itself is never stored on our servers. You can disconnect at any time from the extension or from your Ozyplan account, which revokes it immediately.
- Analytics from the extension — counts and error categories used to see where setup goes wrong (for example "first sync completed"). These never include your coursework, file names, Canvas web addresses, or your school's identity.
Browser permissions, and why each one exists
These are the permissions the published extension requests. Chrome shows them to you at install, and this list is the same one submitted to the Chrome Web Store.
- storage — remembers which Ozyplan account this browser is connected to and which courses to keep in sync, so you are not asked twice.
- alarms — runs the background refresh on a schedule. Chrome shuts the extension down when idle, so a scheduled alarm is the only way to wake it.
- scripting — runs a small script inside the Canvas tab you are looking at, to recognise the site as Canvas and to fetch your course files within your own session.
- activeTab — lets your click on the toolbar icon grant access to that one tab, rather than the extension holding standing access to everything.
- Access to https://*.instructure.com — the standard Canvas web address, so the common case works without a second prompt.
- Access to ozyplan.com — Ozyplan itself, where your coursework is sent and where the connection to your account is made.
- Optional access to other sites — some schools host Canvas on their own web address. The extension declares the ability to ask for other sites, but nothing is granted at install: when you are on a school-hosted Canvas, it asks Chrome for that one address at the moment it is needed, and Chrome shows you exactly which site it is asking for. You can decline, and you can revoke it later from Chrome's extension settings.
The extension does not request access to your cookies, your browsing history, your downloads, or your other tabs, and it contains no remotely-loaded code. It is designed to work on the Canvas site you approve and on Ozyplan, not to observe your general browsing.
Automatic analysis of your coursework
Some analysis happens without you pressing anything. When coursework is first imported, Ozyplan reads the material it judges most useful so your plan is not empty when you arrive. On paid plans, it also continues in the background afterwards — working through the synced coursework worth reading, a small amount at a time, so more of your course context is ready when you need it. This is bounded: it only ever considers coursework already imported into your own account, it skips material that has not changed, and it stops when there is nothing worthwhile left.
Automatically analyzed coursework is handled exactly like coursework you analyze yourself, and is covered by every other section of this policy. If you would rather nothing were read automatically, disconnecting Canvas stops it.
Service providers who process your data
To operate the service, your data is processed by:
- Supabase — database, authentication, and file storage that hosts your account and content.
- OpenAI — generates AI analyses and plans. To do this, the relevant coursework text is sent to OpenAI for processing.
- Stripe — processes subscription payments and stores billing details.
- Vercel — hosts and serves the application.
We do not sell your personal information, and we do not use your coursework to train AI models. We share your data only with the processors above to run the service, or where required by law.
How long we keep it
We retain your data while your account is active. When you delete your account, your profile, courses, documents, imported coursework, AI results, plans, usage records, and subscription record are deleted, and your stored files are removed. Analytics records are de-identified.
Disconnecting Canvas, and deleting what was imported
These are two separate actions, and it matters which one you want.
- Disconnecting — from the extension or from your Ozyplan account — revokes the connection and stops all future syncing and automatic analysis. It does not delete the coursework already imported, which stays in your account so your existing plans and study material keep working.
- Deleting — removing a course, a document, or your whole account deletes the imported material itself. Removing the extension from Chrome stops syncing but, on its own, deletes nothing from your Ozyplan account.
Your choices and rights
- Export — download a JSON copy of your data from Account → Privacy & Data.
- Delete — permanently delete your account and associated data from the same screen.
- Manage sources — remove uploaded files and courses, and disconnect Canvas or a calendar feed, at any time.
Security
Access to your data is enforced by row-level security so you can only reach your own records. Files are stored in a private bucket served through short-lived signed links, credentials for connected school accounts are encrypted at rest, and traffic is served over HTTPS. No system is perfectly secure, and we do not claim otherwise.
Children
The service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us so we can remove it. We do not claim any certification or formal compliance audit (including FERPA, COPPA or GDPR); if your school requires one, please contact us before using Ozyplan with school-provided accounts.
Changes
We may update this policy as the product changes; the "Last updated" date above reflects the current version.
Contact
Questions about privacy? Email vidyasetu.support@gmail.com.