Privacy policy
Prepello is a free browser extension that reads your own university course site (Canvas) while you are logged into it, along with the lecture recording service your courses link to, and hands the material back to you as an organised folder you can open, keep, or give to an AI tool. This policy explains what it does with your data, and just as importantly, what it never does.
The short version
- There is no account. No sign-up, no password, no email address, nothing to log into. We do not know who you are.
- It reads three sites, and all of them are your university's. Your Canvas course site, and the two lecture recording services your courses put their lectures in, Echo360 and Canvas Studio. Nowhere else, ever.
- Your course content never reaches us. The scan and the export both run in your own browser, on your own computer. There is no server holding your files, so there is nothing for us to read, pool, sell, or train on.
- The one thing Prepello sends us is counts. Anonymous numbers about how the extension is being used, so we can see what works and what is broken. Every field is listed in full below.
- One switch turns that off, in Settings, and then nothing is sent at all.
- Your export is yours. It downloads to your computer. Where it goes after that is your decision, and nobody else's.
- No ads, no trackers, nothing to buy.
What happens on your computer
When you start a scan, Prepello reads your course site using the session you are already signed into, the same pages you can open yourself in a browser tab. It reads only. It never posts, submits, uploads, or changes anything on your course site.
What it reads is stored on your own machine, in your browser's local storage: the structure of your courses, the pages, the files, recent announcements, and the lecture transcripts described next. This never leaves your computer except in the two ways described below. Uninstalling the extension removes it.
Lecture recordings and their transcripts
Courses put their lecture recordings in a separate service, and Griffith uses two: Echo360 and Canvas Studio. An Echo360 recording is either linked from a tab inside the course or embedded directly in a course page; a Studio recording is embedded in a course page. Both services generate an automatic text transcript of each recording. During a scan, Prepello reads those transcripts and keeps the text with the rest of the course, so the words of a lecture are searchable and can be handed to an AI tool alongside the slides.
These are the second and third websites Prepello is permitted to read from, and they are the whole list. Both are services your university has already enrolled you in, and reading either is subject to that service's own terms and privacy policy, the same as when you watch a lecture in your browser.
Echo360
Three things about it are worth stating plainly.
- Prepello signs you in to Echo360 the way your course does, and you will not be asked for anything. Echo360 only accepts a request once your course site has handed it a session. Prepello obtains one the same way clicking the Echo360 tab in Canvas does: it briefly opens that link in a background tab and closes it again. There is no extra login, no password, and no separate account, because your university's single sign-on already covers it. You may see a tab appear and disappear for a moment while a scan runs. That is this, and nothing else.
- Prepello cannot read the credential it uses. The sign-in cookies Echo360 sets are marked HttpOnly, so your browser sends them on a request but never hands their contents to a script on the page. Reading them at all would take a separate cookie permission, and Prepello does not ask for one. The whole list of permissions Prepello asks for is set out further down this page, and a cookie permission is not on it. That list is not just our word for it: every permission the extension declares is copied from its own manifest file, which ships inside the extension and can be read by anyone who opens it. The one item on that list you will not find in the manifest is the folder for folder sync, because your browser asks you for that one directly, at the moment you pick the folder. So Prepello can prove you are you to Echo360, and can never see, store, copy, or transmit the thing that proves it.
- It reads only, and this is everything it reads. To find your recordings, Prepello asks Echo360 which lecture sections your university has enrolled you in and what recordings each one holds. For a lecture embedded directly in one of your course pages, it also reads that recording's own Echo360 page, which is where the recording's title and its identifier live. That section list is Echo360's own, so it can include courses from earlier terms that have already left your Canvas dashboard. Prepello never asks Echo360 who you are: it makes no request to Echo360's account or profile endpoints, and nothing it reads from Echo360 is stored or sent anywhere except the recordings and transcripts described here. Prepello then reads the transcript of each recording in the courses you are scanning, and keeps the transcript and the recording's title with the rest of that course. It does not download the video or the audio, does not post to Echo360, does not change a recording, and does not touch anything about your viewing history, your quiz answers, or your participation.
Canvas Studio
Studio is Instructure's own recording service, built into Canvas, and a
Studio lecture appears as a video embedded in a course page. Prepello reaches
it the same way it reaches Echo360 and for the same single reason, the
transcript. Each institution has its own Studio address, which is why the
permission is written as *.instructuremedia.com rather than one
fixed name.
Three things about it are worth stating plainly, and the second one is a real difference from Echo360 rather than a restatement.
- Prepello signs you in to Studio the way your course page does. A Studio video is opened by your course site handing Studio a signed launch. Prepello obtains one the same way loading the page does: it briefly opens that same launch link in a background tab and closes it again. There is no extra login and no separate account. Unlike Echo360, this happens once for each course being scanned rather than once for the whole scan, because Studio issues its permission per course, so you may see a tab appear and disappear once per course.
- Studio's sign-in step hands Prepello your name and your university email address, and Prepello throws them away. This is the one place the extension is told who you are. Studio will not answer a request about a recording without a short-lived access key, the only way to obtain that key is the sign-in step above, and the reply carrying the key also carries your name, your email address and your role on the course. Prepello takes the key out of that reply, uses it as a password on the requests described next, and keeps nothing else from it: none of it is written to your computer, none of it is included in an export, and none of it is sent to us or to anyone else. It is gone when the scan finishes. We would rather not receive it at all, as is the case with Echo360, but Studio offers no route to a transcript that does not include it, and describing it here is better than not mentioning it.
- It reads only, and this is everything it reads. For each Studio video embedded in the course pages you are scanning, Prepello asks Studio for that recording's own details, which is where its title, its length and whether it has a transcript live, and then reads the transcript itself when there is one. It reads no list of your other recordings, does not download the video or the audio, does not post to Studio, does not change a recording, and does not touch anything about your viewing history, your quiz answers, or your participation.
When there is no transcript
Not every recording has a transcript. Some are still processing, some are withheld by the course, and some simply never get one, most often workshops and other sessions without clean lecture audio. On Echo360 that is roughly one in twelve; on Studio it varies far more by course, and a course where most lectures have no transcript is a normal thing to meet. Prepello lists those honestly as gaps rather than guessing at the content, and a course with no recordings at all is a perfectly normal course.
If you turn on folder sync
Settings has an optional folder sync, off by default. If
you turn it on, Prepello asks you to pick a folder on your computer and then
writes a copy of your scanned course into it: a manifest.json
describing the course structure, plus the page text, the lecture transcripts,
and the files it has fetched. You choose the folder, and your browser asks your
permission before Prepello can write to it.
This is still only your own machine, and it is still never sent anywhere. But two things are worth knowing, because they are different from the browser-storage case above:
- Those files outlive the extension. They are ordinary files in an ordinary folder, so uninstalling Prepello does not remove them, and neither does turning folder sync off. Deleting them is up to you, and you can do it at any time without breaking anything.
- The folder copy is not the same thing as an export. It is a working mirror rather than a package built for sharing, so it keeps internal bookkeeping the export deliberately strips, including your Canvas user id. Treat the folder as yours, not as the thing you hand to someone else. The export is the thing built to be handed on.
What is in your export, and where it goes
An export is a zip file that your browser downloads to your computer. Prepello does not send it anywhere. It contains material from your own course: files, page text, the course structure, recent announcements from your course feed, and the text transcripts of your lecture recordings, each carrying the date it was captured.
Two parts of that are worth calling out, because they are the parts most likely to record other people.
- Announcements name teaching staff and sometimes other students. They are included because a change that matters, such as an assessment moving, often exists only in that feed, and an export that left it out would quietly be out of date. They are your own feed from your own enrolment, and they are labelled with an "as of" date so anything reading the export knows how current it is.
- Lecture transcripts are a written record of somebody speaking, normally your lecturer, and where a recording captured a question from the room, whoever asked it. The transcript is produced by the recording service's own automatic speech recognition, not by us, and it is the same text your university already shows you in the player. An Echo360 transcript labels voices only as "Speaker 0" and "Speaker 1" and a Studio transcript carries no voice labels at all, so neither attaches names, but the words are verbatim and a lecturer is usually identifiable from them. It is worth a thought before you upload a transcript somewhere, in a way that a slide deck does not need.
If you then upload the export to an AI tool, share it, or put it in cloud storage, that content goes with it, including the announcements. That is your choice to make and Prepello is not involved in it: once the zip is on your computer, we have no part in where it travels and no way to see it. Whatever service you hand it to applies its own terms and its own privacy policy, so it is worth knowing what those say before you upload course material to it. Course material also usually belongs to your university or its publishers, and an export is for your own study.
What Prepello sends us: anonymous usage counts
Prepello sends small messages to a counting service we run, so we can see how much the extension is used, which parts are used, and where it fails. This is the only thing the extension ever transmits to us, and none of it is your course content.
That is not just a promise, it is how the thing is built. Every value listed below is a number, a true or false, one of a fixed set of words chosen from a list written into the code, the install number described in the next section, or the extension's own version number. There is no free-text field in any message, so a course name, a file name, a page of text or a link has nowhere to sit even by accident. A test in the codebase walks every message the extension can produce and fails if anything else appears.
Who the counts are attached to
One random identifier, created by your own browser when you install the extension, stored on your computer, and attached to every message so we can tell one install's activity apart from another's. It is a random number. It is not derived from you, your device, your Canvas account, your email, your university, or anything about you, and there is nothing we can do with it other than count. Uninstalling and reinstalling makes a new one, and the old one is not linked to it.
Sent with every message
- That random install identifier
installId - Which of the three events it is
eventopen, scan, or export - The extension's version number
versionfor example 0.6.0 - Which browser
browseredge, chrome, or other
No clock reading is sent from your computer. Our server records when the message arrived, and nothing more precise about you than that.
1. Opening Prepello open
Sent once when the dashboard is opened. It carries the four values above and nothing else.
2. Running a scan scan
- Which kind of scan
kindinitial or deep - How it ended
outcomeok, partial, sessionExpired, or error - The category of a failure, if it failed
errorCategorynone, canvasApi4xx, canvasApi5xx, network, or other - How long it took, in milliseconds
durationMs - How many courses were in it
courseCount
Then one row per course, up to forty. The courses are numbered, not named. No course name, course code, subject or institution is ever sent, so these rows say "course 1, course 2" and nothing more. Each row is:
- Its number in the list
courseIndex - How many weeks, modules, pages, files, assignments and announcements were found counts only: weeks, modules, pages, files, assignments, announcements
- How many items could not be fetched
failedCount - How many were locked by the course
restrictedCount - How many modules could not be placed in a week
modulesUnmapped - How the course got sorted into weeks
weekMappingmappedByStructure, recovered, noScheduleFound, scheduleRowsUnmatched, notDeepScanned, or unknown
3. Making an export export
Sent once per export you start, including the ones that fail or that you back out of.
- Which format
formatsmart or plain - How much you exported
scopeKindweek, weeks, course, term, degree, or nothing yet - Which button started it
triggerhero or panel - How it ended
outcomesaved, failed, or cancelled - How the file was saved
sinkdownload, filePicker, or nothing yet - What you chose when asked about scanning first
scanChoicenone, scan, stored, or cancelled - Whether it scanned before exporting
autoScanRantrue or false - What kind of week it was
weekKindnone, current, break, afterTerm, beforeTerm, or noCalendar - How many items, how many bytes, how many gaps itemCount, byteCount, gapCount
- The gaps broken down by reason counts only: gapLinkOnly, gapRestricted, gapFailed, gapPending, gapSkipped, gapExcluded, gapMissing, gapUnconverted, gapUnscanned, gapIncomplete, gapOutOfScope
- How long it took, in milliseconds durationMs, fetchMs, packMs
- How old the scan was when you pressed export, in hours
manifestAgeHours
What is never sent
- No course content. No page text, no file contents, no part of any document.
- No names or titles of any kind. Not your courses, not your modules, not your files, not your pages.
- No course codes, and no university or campus.
- No links. No file address, no page address.
- Nothing identifying you. No email, no name, no student number, no Canvas user id, no login of any kind. Being signed in is what makes a scan possible, so the pages and responses the extension reads do carry your name, your Canvas user id, and in places your university email address. None of that can become a count, because a count has no field it could sit in, and none of it is ever sent to us.
- No clock reading from your computer.
- Nothing at all when you switch it off. There is no "this person opted out" message. Off means silent.
Turning it off
Open Prepello, go to Settings, and untick Send anonymous usage counts under Privacy. From that moment the extension sends nothing, and everything else keeps working exactly as before. You will also see a one-line notice about this the first time you open Prepello, before anything has been sent.
What we keep, and who else touches it
The counts land in a database run for us by Supabase, our hosting provider. The tables hold only the values listed above. Every column in them is a number, a true or false, an arrival time, an install number, the extension's version, or one of those fixed words, and the database itself refuses any word outside the published list. There is no column that could hold your course content, which is a property of how the database is built rather than a rule someone has to remember.
As with any web request, the server that receives the message can see the internet address it came from. We do not store it, we do not put it in the database, and it is never attached to your install identifier. Our hosting provider keeps ordinary server logs under its own terms, in the way every web host does.
We keep the counts for as long as they are useful for improving Prepello. Because nothing in them identifies you, there is no record of yours for us to find, hand over, or delete on request. If you would rather not be counted at all, the switch above is the whole answer.
What Prepello never does
- Never writes to your course site, or to your recordings. Read-only on both, always. It never posts, submits, or changes anything, and it does nothing to work you hand in.
- Never asks for an account. There is no sign-in, no password, and no email capture anywhere in the product or on this site, and the Echo360 and Canvas Studio sessions it uses are ones your university's single sign-on already grants you.
- Never keeps a login credential. Your browser holds your Canvas, Echo360 and Canvas Studio sign-ins and sends them on Prepello's behalf; Prepello cannot see inside any of them. The one credential it does handle is the short-lived Studio access key described above, which it holds only in memory for the length of a scan and never writes down, exports, or sends anywhere.
- Never uploads your course content. Not to us, not to an AI provider, not to anyone. There is no server that holds it.
- Never pools or shares your material with other students.
- Never touches your course site, Echo360 or Canvas Studio unless you start a scan. Between scans it makes no requests to any of them.
- Never sells your data, and never hands it to an advertiser or a data broker. There is nothing to sell.
- No advertising, and no third-party trackers, in the extension or on this website.
The permissions it asks for, and why
- Access to your university's Canvas site
(
lms.griffith.edu.au), so it can read your course pages and files during a scan you start. Downloading a file follows wherever Canvas itself sends that download, which is its own file storage. - Access to the Echo360 lecture recording service
(
echo360.net.au), so it can find and read the transcripts of your own lectures, as described above. Prepello asks for this second site for one reason only, the transcripts, and to find them it reads which lecture sections you are enrolled in and which recordings each one holds. It never reads the video or the audio itself, and never your viewing history, your quiz answers, or your participation. - Access to the Canvas Studio recording service
(
*.instructuremedia.com), for the same single reason, the transcripts of your own lectures. The address is written with a*because each university has its own Studio subdomain and Prepello has to work at whichever one your course uses. It reads only the recordings your own course pages embed, and as with Echo360 it never reads the video or the audio itself, and never your viewing history, your quiz answers, or your participation. - Storage, and extra storage space, because a course scan includes lecture files and needs more room than a browser gives an extension by default. This is space on your own computer.
- Access to one folder you choose, and only if you turn on folder sync. Your browser prompts you to pick the folder and to grant permission to write to it, and Prepello can reach nothing outside it. If you never turn folder sync on, this is never asked for.
Those three sites are the whole list. Prepello runs no code on any other website and reads no browsing history. It can see the address of a tab only when that tab is already on one of those three sites, which is the same permission that lets it read them at all, and the only tabs it opens itself are the brief Echo360 and Canvas Studio sign-ins described above. Every other tab you have open is invisible to it. Besides reading Canvas, Echo360 and Canvas Studio, the only network request it ever makes is the counting message described above, which goes to the counting endpoint and carries none of your content.
Changes to this policy
If what Prepello sends ever changes, this page changes first, with a new effective date, and the store listings link to it. The commitment underneath is the one worth holding us to: the list above is meant to be complete, so if it is ever out of date with the product, that is a bug and we want to hear about it.
Contact
Questions about any of this, or something that looks wrong: hello@prepello.app. It reaches a person.