Prepello

Privacy policy

Effective date: 19 August 2026

Prepello is a free browser extension that reads your own university course site (Canvas) while you are logged into it, along with the lecture recording service your courses link to, and hands the material back to you as an organised folder you can open, keep, or give to an AI tool. This policy explains what it does with your data, and just as importantly, what it never does.

The short version

What happens on your computer

When you start a scan, Prepello reads your course site using the session you are already signed into, the same pages you can open yourself in a browser tab. It reads only. It never posts, submits, uploads, or changes anything on your course site.

What it reads is stored on your own machine, in your browser's local storage: the structure of your courses, the pages, the files, recent announcements, and the lecture transcripts described next. This never leaves your computer except in the two ways described below. Uninstalling the extension removes it.

Lecture recordings and their transcripts

Courses put their lecture recordings in a separate service, and Griffith uses two: Echo360 and Canvas Studio. An Echo360 recording is either linked from a tab inside the course or embedded directly in a course page; a Studio recording is embedded in a course page. Both services generate an automatic text transcript of each recording. During a scan, Prepello reads those transcripts and keeps the text with the rest of the course, so the words of a lecture are searchable and can be handed to an AI tool alongside the slides.

These are the second and third websites Prepello is permitted to read from, and they are the whole list. Both are services your university has already enrolled you in, and reading either is subject to that service's own terms and privacy policy, the same as when you watch a lecture in your browser.

Echo360

Three things about it are worth stating plainly.

Canvas Studio

Studio is Instructure's own recording service, built into Canvas, and a Studio lecture appears as a video embedded in a course page. Prepello reaches it the same way it reaches Echo360 and for the same single reason, the transcript. Each institution has its own Studio address, which is why the permission is written as *.instructuremedia.com rather than one fixed name.

Three things about it are worth stating plainly, and the second one is a real difference from Echo360 rather than a restatement.

When there is no transcript

Not every recording has a transcript. Some are still processing, some are withheld by the course, and some simply never get one, most often workshops and other sessions without clean lecture audio. On Echo360 that is roughly one in twelve; on Studio it varies far more by course, and a course where most lectures have no transcript is a normal thing to meet. Prepello lists those honestly as gaps rather than guessing at the content, and a course with no recordings at all is a perfectly normal course.

If you turn on folder sync

Settings has an optional folder sync, off by default. If you turn it on, Prepello asks you to pick a folder on your computer and then writes a copy of your scanned course into it: a manifest.json describing the course structure, plus the page text, the lecture transcripts, and the files it has fetched. You choose the folder, and your browser asks your permission before Prepello can write to it.

This is still only your own machine, and it is still never sent anywhere. But two things are worth knowing, because they are different from the browser-storage case above:

What is in your export, and where it goes

An export is a zip file that your browser downloads to your computer. Prepello does not send it anywhere. It contains material from your own course: files, page text, the course structure, recent announcements from your course feed, and the text transcripts of your lecture recordings, each carrying the date it was captured.

Two parts of that are worth calling out, because they are the parts most likely to record other people.

If you then upload the export to an AI tool, share it, or put it in cloud storage, that content goes with it, including the announcements. That is your choice to make and Prepello is not involved in it: once the zip is on your computer, we have no part in where it travels and no way to see it. Whatever service you hand it to applies its own terms and its own privacy policy, so it is worth knowing what those say before you upload course material to it. Course material also usually belongs to your university or its publishers, and an export is for your own study.

What Prepello sends us: anonymous usage counts

Prepello sends small messages to a counting service we run, so we can see how much the extension is used, which parts are used, and where it fails. This is the only thing the extension ever transmits to us, and none of it is your course content.

That is not just a promise, it is how the thing is built. Every value listed below is a number, a true or false, one of a fixed set of words chosen from a list written into the code, the install number described in the next section, or the extension's own version number. There is no free-text field in any message, so a course name, a file name, a page of text or a link has nowhere to sit even by accident. A test in the codebase walks every message the extension can produce and fails if anything else appears.

Who the counts are attached to

One random identifier, created by your own browser when you install the extension, stored on your computer, and attached to every message so we can tell one install's activity apart from another's. It is a random number. It is not derived from you, your device, your Canvas account, your email, your university, or anything about you, and there is nothing we can do with it other than count. Uninstalling and reinstalling makes a new one, and the old one is not linked to it.

Sent with every message

No clock reading is sent from your computer. Our server records when the message arrived, and nothing more precise about you than that.

1. Opening Prepello open

Sent once when the dashboard is opened. It carries the four values above and nothing else.

2. Running a scan scan

Then one row per course, up to forty. The courses are numbered, not named. No course name, course code, subject or institution is ever sent, so these rows say "course 1, course 2" and nothing more. Each row is:

3. Making an export export

Sent once per export you start, including the ones that fail or that you back out of.

What is never sent

Turning it off

Open Prepello, go to Settings, and untick Send anonymous usage counts under Privacy. From that moment the extension sends nothing, and everything else keeps working exactly as before. You will also see a one-line notice about this the first time you open Prepello, before anything has been sent.

What we keep, and who else touches it

The counts land in a database run for us by Supabase, our hosting provider. The tables hold only the values listed above. Every column in them is a number, a true or false, an arrival time, an install number, the extension's version, or one of those fixed words, and the database itself refuses any word outside the published list. There is no column that could hold your course content, which is a property of how the database is built rather than a rule someone has to remember.

As with any web request, the server that receives the message can see the internet address it came from. We do not store it, we do not put it in the database, and it is never attached to your install identifier. Our hosting provider keeps ordinary server logs under its own terms, in the way every web host does.

We keep the counts for as long as they are useful for improving Prepello. Because nothing in them identifies you, there is no record of yours for us to find, hand over, or delete on request. If you would rather not be counted at all, the switch above is the whole answer.

What Prepello never does

The permissions it asks for, and why

Those three sites are the whole list. Prepello runs no code on any other website and reads no browsing history. It can see the address of a tab only when that tab is already on one of those three sites, which is the same permission that lets it read them at all, and the only tabs it opens itself are the brief Echo360 and Canvas Studio sign-ins described above. Every other tab you have open is invisible to it. Besides reading Canvas, Echo360 and Canvas Studio, the only network request it ever makes is the counting message described above, which goes to the counting endpoint and carries none of your content.

Changes to this policy

If what Prepello sends ever changes, this page changes first, with a new effective date, and the store listings link to it. The commitment underneath is the one worth holding us to: the list above is meant to be complete, so if it is ever out of date with the product, that is a bug and we want to hear about it.

Contact

Questions about any of this, or something that looks wrong: hello@prepello.app. It reaches a person.