Skip to main content
Canvas study support

YY Canvas Assistant

Privacy Policy

This policy explains what information YY handles, why it is needed, and which services help provide the app.

1. Scope

This policy applies when you visit YY's public pages, create or use a YY account, connect YY to Canvas, use AI study features, provide feedback, or use billing features when they become available.

2. Information YY handles

Account information
Account identifiers and profile information made available through Clerk, such as your email address, together with membership and account settings.
Canvas connection and course information
The Canvas site URL and access token you provide, plus course information requested for features you use. This may include courses, modules, assignments, pages, files, quizzes, questions, instructions, and dates.
Study content
Questions, prompts, selected course material, generated responses, quiz answers used in an active session, and documents you choose to upload.
Feedback
Ratings, helpfulness selections, comments, source feature, timestamp, and the account email supplied with feedback.
Billing and entitlement information
When billing is enabled, YY may receive Stripe customer, checkout, subscription, invoice, payment, and refund identifiers or status, along with the membership and credits recorded for your account.
Operational records
A pseudonymous account reference, route, request success or failure, duration, AI token totals, and credits reserved or charged. These records support reliability, cost measurement, billing controls, and troubleshooting.

3. How information is used

YY uses the information described above to:

  • Authenticate accounts and provide requested features.
  • Retrieve course information from Canvas on your behalf.
  • Generate, improve, and return study assistance you request.
  • Maintain memberships, credits, billing records, and payment status.
  • Store documents or preferences you ask YY to retain.
  • Review feedback, secure the service, diagnose faults, and prevent misuse.

4. Canvas credentials and course data

Your Canvas access token is held in the app's in-memory state while you use the page. It is sent to YY's server endpoints when needed so those endpoints can make the Canvas request you selected. The current application does not intentionally save the Canvas access token in YY's persistent application stores.

Your Canvas site URL is saved in your browser's local storage. For active Canvas quiz sessions, a Canvas validation token may also be stored locally so the session can be recovered; the app removes that stored token when the quiz is completed. Canvas handles information under your institution's Canvas configuration and applicable policies.

5. AI processing

Content needed to answer an AI request can be sent to DeepSeek. Depending on the feature, that content may include your prompt, assignment or quiz information, and selected extracts from course files or pages. DeepSeek returns generated output to YY for display to you.

YY's usage records contain AI token totals and internal request context, not the text of prompts, generated answers, Canvas credentials, or service secrets. Question-and-answer history shown in the app is stored in your browser as described below.

6. Services involved

YY currently uses these service-provider categories:

  • Clerk for account authentication and account metadata.
  • DeepSeek to process requested AI study features.
  • Stripe for checkout and billing when purchases are enabled.
  • Upstash for credits balances and billing-event safeguards.
  • Supabase for restricted billing, pseudonymous usage, and feedback records.
  • Vercel and Vercel Blob for app hosting and private document storage.
  • Canvas to return information requested using the credentials you provide.

These services process information under their own terms and privacy notices, and receive information in connection with the relevant feature.

7. Cookies, local storage, and analytics

Clerk may use cookies or similar browser storage required for authentication and session security. YY also uses browser local storage for the selected language, Canvas site URL, recent question-and-answer history, archived-item preferences, and temporary quiz-session recovery described above.

The current YY source does not include a dedicated advertising tracker or a dedicated product analytics service. If that changes, this policy must be updated before the new tracking is enabled.

8. Payment information

Paid checkout is not currently available from the public Pricing page. When purchasing is enabled, card details will be entered into Stripe's checkout, not collected or stored directly by YY. YY will receive the billing identifiers and status needed to provide the purchased membership or credits and to support billing records.

9. Storage and retention

A complete retention schedule is still to be confirmed before paid launch. The current implementation has these product-level behaviours:

  • Browser question history is limited to the most recent 20 entries per Canvas site.
  • Archived-item preferences are limited to 500 item identifiers per Canvas site.
  • Browser data remains until the app replaces or removes it, or you clear site data.
  • An uploaded base document remains in private storage until it is replaced or deleted.
  • Service providers may retain records according to their configuration and policies.

10. International processing

Some providers used by YY operate internationally. Information may therefore be processed outside Australia, depending on the provider, account configuration, and service location.

11. Security

YY uses authenticated routes for private app features, keeps uploaded base documents in private storage, and separates payment-card entry from YY through Stripe checkout. Canvas credentials are passed only when needed for selected requests and are not intentionally written to YY's persistent stores. No internet service can guarantee absolute security.

12. Your choices and requests

You can clear YY's local browser data using your browser controls. You may also request access to, correction of, or deletion of personal information held by YY. How a request is handled may depend on applicable legal requirements.

The direct channel for privacy requests is still to be confirmed. It will be published on the Contact page before paid checkout is enabled.

13. Changes to this policy

YY may update this policy when the product, providers, or legal requirements change. A confirmed effective or last-updated date will be displayed here before paid launch.