What it reads, what it keeps, and what it sends: nothing about your students.
The short version. Rubric Auto-Filler runs in your browser, on Canvas SpeedGrader pages, and nowhere else. What it remembers, it keeps in your browser, on your Canvas site. It sends us nothing from your Canvas pages: no account, no sign-in, no tracking, no usage reports and no crash reports. We never see your students, your comments or your scores.
What it reads
On a SpeedGrader page it reads the rubric on screen (the criteria, their score boxes and their comment boxes), the Assignment Comments box, and the current student's first name. The name comes from the page itself. When the page doesn't carry it, the tool asks your own Canvas for the name the same way the page does, using the session you're already signed in to.
It runs only on pages whose address ends in instructure.com and contains SpeedGrader. It reads nothing on any other page. Chrome tells you at install that it can “read and change your data” on instructure.com sites. That's what running on a page means, and this page is everything it does with that.
What it keeps, and where
Everything is stored in your browser's own storage for your Canvas site, beside the storage Canvas uses, on the computer you're using:
- The grading you clicked Remember on, per course and assignment: your comment and score for each criterion, and your standard assignment comment.
- Students' first names it has learned, so it doesn't have to ask Canvas twice, and any “goes by” name you typed.
- Your settings: whether the name goes in, which score Fill writes, where the panel sits and whether it's folded.
- A short log of its own recent actions (lines like “Fill: 4 comments written”), for the diagnostic report. It never logs a student's name or the text of a comment.
- The date the extension first ran, which decides the free period for beta copies once billing opens.
- Once billing opens, and only if you paste a license key: the key, and what Lemon Squeezy last said about it.
Nothing is copied to another computer or synced anywhere. A different computer starts empty.
What it sends
- From aibypeak.com, it reads one short notice. When SpeedGrader opens, and about once an hour while it stays open, it reads a one-line text file from aibypeak.com. It's how we tell everyone at once that Canvas has changed something and we know. The request carries nothing from the page: no Canvas address, no names and no cookies. Like any visit to a web page, our web host sees the computer’s internet address and browser type. We don't use either one to count or identify anyone. The panel shows the text as plain words and never runs it. Usually the file is empty, and the panel shows nothing.
- To your Canvas: the name lookup above, which is the same request the SpeedGrader page makes itself, to the same place.
- To Lemon Squeezy, once billing opens and only if you have pasted a license key: the key itself, once when you paste it and about once a day after that, to check that the key is still good. Two other things go with it: a label made of the word Canvas and the date you pasted the key (so your computers can be told apart), and an identifier Lemon Squeezy gave back the first time. Lemon Squeezy is the company that sells the license, and the name that appears on your receipt and card statement. Its own privacy policy covers what it does with a key it's asked about. While the tool is in beta there are no keys, so this never happens.
Nothing else. No student information, no comment text, no page content and no Canvas address ever leaves your browser through this extension.
The diagnostic report
Copy diagnostic puts a plain-text report on your clipboard, only when you click it. It describes the shape of the page: which boxes the tool found and which it didn't, its version, your settings, its recent actions, and your Canvas address with the course and assignment numbers. The report says at the top that it carries no student names, no ID numbers and no comment text.
You decide whether to email it to us. If you do, we keep that email the way we keep any other, to fix the problem, and for nothing else.
What it never does
- Never submits an assessment and never posts a grade.
- Writes nothing to the page until you click Fill.
- Never reads or changes any page outside SpeedGrader.
- Never sends us anything from your Canvas pages, and never contacts anyone except as listed above.
Deleting what it kept
Removing the extension from Chrome stops it at once. What it remembered stays in your browser's storage for your Canvas site until you clear that site's data. In Chrome's settings, under Privacy and security, find the site data for your Canvas address and delete it. That also signs you out of Canvas in that browser, so do it at the end of a session, not the middle.
Your students and your school
Student names appear only inside your own browser, on a page you're already looking at as their instructor. We never receive them, and there's nowhere for them to go. If your school asks what this extension shares about students, the answer is nothing.
If you email us
Write to hello@aibypeak.com. We keep the email to answer it. No list. If you asked to be told when billing opens, you get one email when it opens and nothing else.
Changes
If what the tool keeps or sends ever changes, this page changes first, with a new date at the top, and the Chrome Web Store listing's privacy disclosures change with it.
Who we are
AI by Peak is a brand of Mercer & Mason LLC, an Indiana company. hello@aibypeak.com.
Not affiliated with or endorsed by Instructure. Canvas and SpeedGrader are trademarks of Instructure, Inc.
Back to Rubric Auto-Filler.