Privacy

Privacy Policy

Last updated: 14 September 2026

The short version Canvas Downloader runs 100% on your own computer. It has no backend, no servers, no accounts, no analytics, and no telemetry. Your Canvas Access Token and your files never leave your device, except when the app talks directly to your own university's Canvas server to download your content. The developer never sees, receives, or stores any of your data.

Who this policy applies to

This policy covers the Canvas Downloader desktop application for Windows (including the version distributed through the Microsoft Store) and macOS, and the project website. Canvas Downloader is a free, open-source app built by a student. It is not affiliated with, endorsed by, or connected to Instructure, Inc. or Canvas LMS.

Information the app accesses

Canvas Downloader only handles the information it needs to download your own course materials. Specifically:

The app does not ask for your name, email, payment details, location, or contacts.

About your password. If you use an Access Token, your password is never involved at all. If you choose Sign in with Canvas, you type it into your own university's real sign-in page, shown in a window the app opens for it. The app does not read it, store it itself, or send it anywhere. Because that window is a browser, it can offer to remember the password for you, exactly as Microsoft Edge would: if you accept, Windows encrypts it for your account only and it stays on your computer. Signing out of the app deletes it again, along with your Canvas session.

How your information is used

Your information is used for one purpose only: to let the app authenticate to your university's Canvas server and download the content you ask for, onto your computer. There is no other processing, profiling, or secondary use.

Where your data is stored

Because everything is local, there is no developer-controlled database or cloud account that holds your data.

What we do not do

One exception, and it is the only one. If you choose Sign in with Canvas, the app asks Canvas to create an access key in your own name, called Canvas Downloader, so that you do not have to sign in again every day. That is the single thing the app ever writes to your Canvas account, it happens only on that sign-in route, and many universities switch it off for students, in which case nothing is created at all. You can see it and delete it yourself at any time under Account, Settings, Approved Integrations.

Third parties

The browser extension (optional)

There is a small companion extension, Canvas Downloader Connector, for people who would rather not sign in a second time. It is entirely optional: the app signs in perfectly well on its own, and nobody has to install anything. All it does is hand your existing Canvas sign-in from the browser tab you already have open to the app on the same computer.

This website

This policy says it covers the project website, so here is exactly what the website itself does. This site is a set of static pages hosted on GitHub Pages. It sets no cookies, runs no analytics, and has no tracking of any kind, and there is no script here that records who you are or what you clicked.

Your browser contacts GitHub, YouTube and Microsoft only for the reasons above. Nothing on this website is sent to the developer, because there is no developer server to send it to.

Data retention and deletion

You are always in full control of your data because it lives on your machine:

Children's privacy

Canvas Downloader is intended for students using their own university Canvas accounts. It is not directed at children and does not knowingly collect any information from anyone, regardless of age.

Open source

Canvas Downloader is fully open source. You don't have to take our word for any of the above, because the complete source code is publicly readable on GitHub.

Changes to this policy

If this policy changes, the updated version will be posted on this page with a new "last updated" date. Material changes will be noted in the project's release notes.

Contact

Questions about privacy? Open an issue on GitHub and we'll respond there.