Privacy Policy
Last updated: 14 September 2026
Who this policy applies to
This policy covers the Canvas Downloader desktop application for Windows (including the version distributed through the Microsoft Store) and macOS, and the project website. Canvas Downloader is a free, open-source app built by a student. It is not affiliated with, endorsed by, or connected to Instructure, Inc. or Canvas LMS.
Information the app accesses
Canvas Downloader only handles the information it needs to download your own course materials. Specifically:
- Your Canvas Access Token. You generate this yourself in your Canvas account settings and paste it into the app. It is used solely to authenticate to your university's Canvas server on your behalf.
- An access token the app creates for you (only if you sign in with Canvas). A Canvas sign-in normally lasts about a day, which would mean signing in again almost every time you open the app. So straight after you sign in, the app asks Canvas for a long-lived access token of your own, named Canvas Downloader, and uses that instead. Two things worth knowing: it is created in your Canvas account, so you can see it and delete it at any time under Account, Settings, Approved Integrations; and many universities switch this off for students, in which case nothing is created and the app simply keeps using your sign-in. The token is stored on your computer exactly like a token you paste in yourself, and it is never sent to the developer.
- Your own Canvas course data. When you start a download or sync, the app requests the courses, files, assignments, announcements, and similar content that your account already has access to.
- Your course's Panopto lecture recordings (optional). If you enable lecture recording downloads, the app follows the Panopto links in your Canvas courses and downloads the recordings your account can already watch, directly from your university's Panopto server. Transcription of those recordings happens entirely on your own computer, and audio is never uploaded anywhere.
- The files you choose to download. These are saved to the folder you select on your own computer.
- Local app settings. Your preferences, saved sync folders, and download history are stored locally so the app remembers your setup between sessions.
The app does not ask for your name, email, payment details, location, or contacts.
About your password. If you use an Access Token, your password is never involved at all. If you choose Sign in with Canvas, you type it into your own university's real sign-in page, shown in a window the app opens for it. The app does not read it, store it itself, or send it anywhere. Because that window is a browser, it can offer to remember the password for you, exactly as Microsoft Edge would: if you accept, Windows encrypts it for your account only and it stays on your computer. Signing out of the app deletes it again, along with your Canvas session.
How your information is used
Your information is used for one purpose only: to let the app authenticate to your university's Canvas server and download the content you ask for, onto your computer. There is no other processing, profiling, or secondary use.
Where your data is stored
- Canvas Access Token: stored securely in your operating system's credential vault, which is Windows Credential Manager on Windows and the Keychain on macOS. It is never written to a plain text file and never transmitted to the developer.
- Canvas sign-in (if you sign in instead of using a token): the app keeps the session your browser window created, so it can talk to Canvas as you. It is stored in the same place as an access token: Windows Credential Manager on Windows, the Keychain on macOS. Only the single session cookie is kept, not everything your sign-in window collected. If your operating system's vault refuses it, the app falls back to a file in its own settings folder that Windows encrypts for your account only. Either way it stays on your computer, is never written as plain text and is never sent to the developer. Signing out deletes it and clears the sign-in window.
- A password you asked the sign-in window to remember: kept in that window's own storage on your computer, encrypted by Windows for your account only, in the same way Microsoft Edge keeps a saved password. It is only there if you said yes when asked. Signing out of the app removes it, so a shared computer does not leave it for the next person.
- Downloaded files & settings: stored only on your local disk, in the locations you choose (for files) and in your user profile (for app settings).
Because everything is local, there is no developer-controlled database or cloud account that holds your data.
What we do not do
- We do not collect, receive, or store any of your data on any server. The app has no backend.
- We do not use analytics, tracking, advertising, or telemetry of any kind.
- We do not sell, rent, or share your information with anyone.
- We do not upload your files, submit assignments, post messages, or change anything in your courses.
One exception, and it is the only one. If you choose Sign in with Canvas, the app asks Canvas to create an access key in your own name, called Canvas Downloader, so that you do not have to sign in again every day. That is the single thing the app ever writes to your Canvas account, it happens only on that sign-in route, and many universities switch it off for students, in which case nothing is created at all. You can see it and delete it yourself at any time under Account, Settings, Approved Integrations.
Third parties
- Your university's Canvas (Instructure). The app connects directly to the Canvas server your token belongs to in order to download your content. Your use of Canvas is governed by your institution's and Instructure's own privacy policies.
- Your university's Panopto server (optional). Only if you enable lecture recording downloads: the app connects to the Panopto instance your university links from Canvas, authenticated through your own Canvas session, to download recordings you already have access to. Your use of Panopto is governed by your institution's and Panopto's own privacy policies.
- Hugging Face (optional, one-time model download). Only if you set up local transcription: the app downloads the speech-recognition model you pick from Hugging Face's public model hub, the same way a browser downloads a file. No personal data, no account, and none of your content is sent, and after the download transcription runs fully offline.
- PyPI (optional, one-time library download). Only if you opt into GPU acceleration for transcription on a Windows PC with an NVIDIA card: the app downloads NVIDIA's official CUDA library packages from the Python Package Index. Again, a plain file download, with no account and nothing sent.
- GitHub (version check). When the app starts, it asks GitHub's public releases API whether a newer version has been published, so it can show you an update notice. The request carries nothing but the request itself: no token, no course data, no identifier of any kind. GitHub sees only what any website sees when you visit it. If it fails or you are offline, the app simply shows no notice. The Downloads & Releases page makes the same call in your browser.
- Microsoft Store (Windows). If you install the app from the Microsoft Store, Microsoft handles distribution and updates. Any data Microsoft collects as the store operator is governed by the Microsoft Privacy Statement. The app itself sends Microsoft nothing.
The browser extension (optional)
There is a small companion extension, Canvas Downloader Connector, for people who would rather not sign in a second time. It is entirely optional: the app signs in perfectly well on its own, and nobody has to install anything. All it does is hand your existing Canvas sign-in from the browser tab you already have open to the app on the same computer.
- What it reads, and when. Only when you click it, and only on the tab you clicked it on: the sign-in your browser is already holding for that Canvas site. Nothing else on the page, and nothing on any other page.
- It cannot see your browsing. It has no history permission and no script running on any page, and it holds no access to any site until you grant it for your own sign-in. The one thing it reads about a page is the address of the tab you open it on, at the moment you open it, so it can tell you whether you are on your Canvas before it offers to sign you in. Chrome does not tell it which other sites you visit, and nothing about any page is stored or sent anywhere.
- What it remembers. Until you close your browser, it remembers that a sign-in succeeded, so it can say so instead of walking you through the steps again. That is held in the browser's own session storage, is never written to disk, and goes when the browser closes.
- The toolbar mark. Once a minute it asks the app on your own computer one question - is
Canvas Downloader waiting for a sign-in - so the icon can show a dot when clicking it would do something.
That question goes to
127.0.0.1and nowhere else, and it is not a question about you. - Where it sends it. To
127.0.0.1, which is your own computer and nowhere else. The request cannot leave the machine. Nothing is sent to the developer, and there is no server involved. - The app only listens when you ask. The connection opens when you press Use the Canvas tab in my browser in the app, it accepts one sign-in and then closes, and it closes on its own after a few minutes if nothing arrives. It answers only a browser extension, never a web page and never another program on your computer, and it never sends anything back.
- You are shown whose account it is. The app checks the sign-in with Canvas and then puts the name on screen, so a sign-in that is not yours is visible rather than silent. A sign-in it cannot check with Canvas is not kept at all.
This website
This policy says it covers the project website, so here is exactly what the website itself does. This site is a set of static pages hosted on GitHub Pages. It sets no cookies, runs no analytics, and has no tracking of any kind, and there is no script here that records who you are or what you clicked.
- Fonts are served from this site, not from Google. They used to be loaded from Google Fonts, which meant your IP address reached Google before the page had even rendered. They are now part of the site.
- GitHub. The download buttons ask GitHub's public API which release is newest, so the links never point at a stale file. GitHub sees that request the same way it sees any visit.
- YouTube. Some pages embed a how-to video. When you play one, YouTube serves it and sees that request the same way it sees any visit.
- Microsoft. The "Get it from Microsoft" badge is an image served by Microsoft, and the button links to the Store listing.
Your browser contacts GitHub, YouTube and Microsoft only for the reasons above. Nothing on this website is sent to the developer, because there is no developer server to send it to.
Data retention and deletion
You are always in full control of your data because it lives on your machine:
- Remove your saved token at any time from within the app, or by deleting the "Canvas Downloader" entry in your OS credential vault.
- Delete downloaded files like any other files on your computer.
- Uninstalling the app removes its local settings. Files you already downloaded remain yours and are not touched.
Children's privacy
Canvas Downloader is intended for students using their own university Canvas accounts. It is not directed at children and does not knowingly collect any information from anyone, regardless of age.
Open source
Canvas Downloader is fully open source. You don't have to take our word for any of the above, because the complete source code is publicly readable on GitHub.
Changes to this policy
If this policy changes, the updated version will be posted on this page with a new "last updated" date. Material changes will be noted in the project's release notes.
Contact
Questions about privacy? Open an issue on GitHub and we'll respond there.