← Back to the website

Privacy Policy for Canvas Tab Shield

Last updated: October 8, 2026

Canvas Tab Shield applies its Canvas privacy features locally in your browser. When paid access is enabled, the extension also connects to the configured billing service to purchase and verify a license.

Canvas data

The billing integration does not send Canvas credentials, browsing history, assignment content, or academic records to the billing server or Stripe. License requests contain a license credential and the selected plan rather than page content or browsing URLs.

Local storage

The extension stores its enabled setting, account session credential, any existing unlinked license key, subscription status, and a signed access certificate in Chrome's local extension storage. The billing credential is available to trusted extension pages and its service worker. Content scripts receive only the settings needed to run on Canvas.

The website stores an account session credential in sessionStorage for the current tab. Clearing extension data, closing the website tab, or signing out removes the local credential. Verified-email customers can sign in again to restore their membership. Existing license-key customers must link their purchase to an email account before discarding the key.

Billing service

The billing service stores the verified account email address, an account identifier, hashed session credentials and sign-in-code digests, sign-in expiry and attempt counts, a license identifier, a hash of the license key, Stripe customer and subscription identifiers, Checkout and purchase identifiers, payment timestamps, access state, and processed webhook IDs. It uses this information to verify purchases, renew or expire access, prevent duplicate fulfillment, and handle refunds or disputes.

The service uses connection IP addresses in memory to limit abusive requests. A hosting provider may retain access logs, including connection and request information, according to its configuration. License credentials are sent in authorization headers, not URL parameters.

Email sign-in

Sign-in uses a one-time email code instead of a password. Codes expire after 10 minutes and allow up to five verification attempts. Account sessions expire after 30 days and can be revoked by signing out. Expired session and code records are pruned during sign-in activity.

When Resend is configured, the service sends the email address and sign-in message to Resend for delivery. See Resend's Privacy Policy. Production cannot use the local development code preview. Possession of an existing license key is required to link its purchase to an email account; linking revokes the old key.

Stripe

Checkout and subscription management open on Stripe-hosted pages. Stripe collects the payment and billing details required to process the purchase, which can include name, email address, billing address, and card details. The extension and this billing backend do not collect or store full card numbers.

Stripe's processing is described in Stripe's Privacy Policy. The project operator can access customer and billing information in their Stripe account for payment administration and support.

Retention and requests

Billing records remain in the operator's Stripe account and server database while needed for access, payment administration, support, and applicable recordkeeping obligations. Contact the developer through the Chrome Web Store support channel for access, correction, deletion, or billing questions. Uninstalling the extension does not cancel a monthly subscription; use Manage access in the popup or Manage billing in the website account area.

Policy updates

Material changes to billing or data handling will be reflected in this policy and the Chrome Web Store listing. This document describes the provided implementation; the operator must confirm the production hosting, retention, and support details before launch.