Privacy notice.

This notice explains how CourseMCP collects, uses, shares, retains, and deletes personal information when you use our website, extension, API, and MCP service.

Effective 7 September 2026.

Scope and independence

CourseMCP is an independent service. It is not affiliated with, endorsed by, or approved by Instructure, Canvas, or your educational institution. Your institution and services you connect to CourseMCP have their own privacy practices.

CourseMCP is responsible for the processing described in this notice. Questions and privacy requests may be sent to privacy@coursemcp.com.

Information we handle

Account and subscription data. We receive your account identifier, email address, and available profile details from WorkOS. We receive subscription status and transaction references from Polar, but CourseMCP and its extension do not receive your full payment-card details.

Material you direct us to import. We process the course name, files, text, source URLs and identifiers, observed timestamps, content hashes, and provenance needed to create and maintain your private library. For a Canvas-connected import, a one-way fingerprint derived from the Canvas origin and your Canvas user identifier binds the library to one Canvas identity; we do not store the underlying Canvas user identifier.

Usage, device, and support data. We process sign-in and security logs, IP address and user-agent information received by our servers, timestamps, coarse event names, source and plan categories, bounded counts, error diagnostics, and information you send when requesting support.

After an import, the extension reports counts by failure stage and a fixed error category, such as a denied download or an unsupported file type. We retain these with the course's import history and send the categories, counts, and overall outcome to PostHog for troubleshooting. Diagnostic reports exclude filenames, source URLs, document content, authentication tokens, and raw error messages.

Website analytics. Our production website uses PostHog to count visits to page categories and selected setup, sign-in, download, and copy-button actions. These actions indicate interest, not a completed installation or import. A random browser identifier is stored in local storage; after sign-in we associate it with your CourseMCP account identifier, without sending your email or name. Website analytics excludes page URLs, query strings, referrers, page text, form values, and course content. Session recording and automatic interaction capture are disabled. We honour browser Do Not Track and Global Privacy Control signals, which prevent this website tracking from loading.

Extension installation counts. From version 0.1.2, release builds automatically send a randomly generated installation identifier, extension version, and whether the installation is new or an existing copy first seen after an update. Our API records the first report time to measure adoption; failed reports are retried. These reports contain no account identity, authentication token, Canvas data, or browsing history, and are not sent to PostHog. We separately record the first successful extension sign-in on your account, without linking it to the installation identifier.

Information we exclude

CourseMCP does not ask for or transmit your Canvas password, session cookie, or bearer token. Canvas-connected import is designed to exclude grades, submissions, messages, rosters, and other students' data. Do not manually import material you are not authorised to process, including unnecessary sensitive information about another person.

How and why we use it

We use information to authenticate you; provide, secure, troubleshoot, and improve the service; store and index the material you select; return cited passages at your request; administer subscriptions; respond to support; prevent abuse; and comply with law.

Where applicable law requires a legal basis, we rely on performance of our contract with you, your direction or consent for optional processing, our legitimate interests in operating and securing the service, and compliance with legal obligations. You may withdraw consent for future processing where consent is the basis, without affecting earlier lawful processing.

Extension permissions

The extension reads an active Canvas course only after you choose import and grant access to that exact HTTPS Canvas origin. It uses your existing authenticated browser session, does not automate login, does not monitor unrelated browsing, and does not import course material in the background. You may also select local files for manual import.

Chrome local storage holds a CourseMCP access token, your versioned data-use acknowledgement, import checkpoints and status, and up to 20 course resync reminders. Disconnecting removes that local data and any granted Canvas origin permissions.

A separate random installation identifier and delivery acknowledgement remain in local storage after disconnecting to avoid counting sign-ins as new installations. Removing the extension clears its local installation state; reinstalling may generate another identifier.

AI and connected agents

Extracted text chunks are sent to OpenAI's API to create numeric search embeddings. CourseMCP does not use course material to train AI models, and our OpenAI API configuration is subject to OpenAI's business-data commitments. When you connect a separate AI agent, CourseMCP sends it retrieved passages only in response to authenticated requests; that agent is a separate service with its own terms and privacy practices. Always review source material before relying on an AI-generated answer.

Service providers

We disclose information to providers only as needed to operate CourseMCP: WorkOS for authentication; Fly.io for application and database hosting; Cloudflare R2 for private object storage; OpenAI for search embeddings; Polar for checkout and subscription administration; PostHog for allowlisted product analytics; and Sentry for redacted error diagnostics. Which optional analytics and error services are active depends on the deployment configuration.

Analytics and error metadata are designed to exclude course titles, filenames, source URLs, and document text. We may also disclose information at your direction, to protect users and the service, in connection with a business reorganisation subject to appropriate safeguards, or when required by law.

No sale or advertising

We do not sell course content or personal information, use it for targeted advertising or creditworthiness decisions, or transfer it for an unrelated purpose. CourseMCP personnel do not read course content except with your permission for specific support, when reasonably necessary to investigate security or abuse, or when legally required. Our extension-data practices are intended to comply with the Chrome Web Store User Data Policy and Limited Use requirements.

Retention and deletion

We retain imported content while the relevant course or account remains active. Deleting a course or account removes its live database records, search indexes, derived text, and version history and queues private stored objects for retryable deletion. Encrypted backups may retain deleted records until their scheduled expiry; backups are isolated from ordinary use and are restored only for disaster recovery.

We retain limited security, billing, and legal records for as long as reasonably necessary for fraud prevention, accounting, disputes, and legal obligations. Retention depends on the data type, account status, operational need, contractual commitments, and applicable law.

Installation records are retained for cumulative adoption counts and retry deduplication. They are not linked to an account, so account deletion does not remove them. You can request removal by providing the installation identifier from the extension's local storage to privacy@coursemcp.com. The account's extension sign-in timestamp is deleted with the account.

Security and transfers

We use access controls, tenant-scoped records, encryption in transit, private object storage, short-lived upload URLs, file validation, and restricted operational logging. No system is completely secure. Our providers may process information outside your country; where required, we rely on contractual and other lawful transfer safeguards.

Your choices and rights

You can disconnect the extension, delete a course, or delete your account. Depending on where you live, you may also request access, correction, portability, restriction, objection, or deletion, and may complain to your local privacy regulator. We may need to verify your identity and may retain information where an exception applies.

Send requests to privacy@coursemcp.com. We do not discriminate against users for exercising applicable privacy rights.

Age limits

CourseMCP is intended for people who are at least 18 or the age of legal majority where they live. We do not knowingly provide individual accounts to children. An institution wishing to make CourseMCP available to younger students must first enter an appropriate written arrangement with us and obtain any required school or parental authorisations.

Changes and contact

We may update this notice as the service or law changes. We will post the new effective date and provide additional notice when a change materially affects your rights or how we use information. Contact privacy@coursemcp.com with privacy questions.