Guide · Last verified September 1, 2026
Are Canvas extensions safe? What to check before you install one
On April 25, 2026, unauthorized actors got into Instructure's Canvas systems; Instructure disclosed the intrusion on May 1, and a second incident on May 7 came with a ransom message. It affected 8,809 institutions, the group responsible claimed data on roughly 275 million users, and a proposed class action was filed in federal court in California on May 13, 2026. None of that involved a browser extension. But it is the right moment to ask what an extension can see.
Permissions
What any Canvas extension can see
When you install an extension, Chrome asks you to grant it access to certain sites. On every site it has, the extension runs inside the pages you open: it can read what is on the page, change it, and make requests to that site as you, because your browser is already signed in. It does not need your password. Your logged-in session is the key, and the extension is inside the door.
Two things follow. First, reading and acting are the same permission. An extension that can read your assignments page can also press submit on it, and nothing in Chrome's prompt tells you which one it does. Only the code and the privacy policy can. Second, some permissions reach past the sites an extension runs on. “Read your browsing history,” which Chrome shows when an extension asks to see your tabs, means it can see the address and title of every tab you have open, whether or not it does anything there.
What an extension cannot do: see inside other extensions, read sites it was never granted, or reach data that never passes through your browser. And what it cannot undo: anything Instructure already stores.
Before you install
The checklist
- The permissions match the stated purpose. A search tool needs to run on your Canvas pages. It does not need your browsing history on every site. When the install prompt lists more than the job needs, ask why, and expect the publisher to have an answer.
- The privacy policy names every data type it collects. Not “we respect your privacy” but a list. If clipboard text, grades, or messages are collected, the policy should say so in those words, and say what happens to them.
- Where the index or data lives. On your device, on the publisher's servers, or both. “Local” should mean the search index stays in the browser; if there is also an account sync, the policy should say exactly what syncs.
- Whether it sends anything to a server, and to whom. Cloud AI, account sync, error reporting, and analytics all mean a server. The policy should name the kinds of provider that receive data, and the store listing's privacy disclosure should agree with it.
- Who the publisher is, and whether the site is verified. The Chrome Web Store shows a publisher's website and email, and marks a listing that was created by the owner of the listed website. A listing with no company, no site, and a throwaway address is a listing you cannot hold to anything.
- The last-updated date. An extension that has not shipped an update in a year is one nobody is watching, and you are about to give it your Canvas session.
- Recent reviews, not just the average. Sort by newest. A 4.8 built years ago says nothing about the version you are installing; complaints about new permissions or odd behavior show up in the newest reviews first.
- Open source or not. Public code is not a guarantee, but it lets someone check the claims. Closed code means you are trusting the policy alone.
- Whether it interacts with quizzes or grades on your behalf. Reading a grades page is one thing; submitting, answering, or hiding activity from Canvas is another. Anything that acts for you inside graded work is an academic-integrity problem before it is a privacy one.
Fine print
The honest limits of local-first
Local-first limits what an extension adds to your exposure. If the index stays in your browser, a breach of the publisher's servers cannot leak it, because it is not there. That is the whole benefit, and it is real. It is also narrow.
Local-first cannot protect anything Instructure already holds. Your name, email, enrollments, submissions, and messages live on Canvas's servers, and that is exactly what the 2026 breach reached. Nothing you install or uninstall changes the copy there.
It also stops at the feature boundary. The moment an extension offers account sync or cloud AI, some data leaves the device, and the honest question becomes which data, to whom, and whether you can decline. Scope for Canvas has both of those features. The table below says what each one sends.
Our own answer
Scope against its own checklist
Scope for Canvas is a free, local-first Chrome extension that searches everything in your Canvas and Brightspace courses and answers questions with citations to your own course materials.
Here is the checklist applied to version 11.0.5, read from its Chrome Web Store listing, its declared permissions, and the privacy policy on September 1, 2026. The policy is the controlling statement; where this table and the policy differ, the policy wins.
| What it is for | Optional? | Where the data goes | |
|---|---|---|---|
| Canvas and Brightspace pages | Reads the course pages you open to build the search index, and adds the search bar and the Send to iPad button to them. Scope also runs on Gradescope, Kaltura lecture-video pages, and Berkeley’s course scheduler. It stays off login, logout, and single-sign-on pages. | Needed for search. | The index stays in browser-local storage on your device. |
| All websites | Version 11.0.5 declares access to every website and to local files, so Chrome’s install prompt warns that it can read and change your data on all sites. The page features above are declared only for the sites named there. We would rather you read that here than meet it in the prompt. | Granted at install. Chrome lets you narrow any extension’s site access afterwards, under the extension’s Details. | — |
| Open tabs | Lets the extension see the address and title of your open tabs and when pages finish loading. Chrome describes this as reading your browsing history, and the store listing discloses web history and user activity among the data it handles. | Granted at install. | The privacy policy, not this table, is the statement of what is kept. |
| Browser-local storage | Holds the search index, your settings, and the clipboard entries described below. | Needed. | Your device. |
| Google sign-in | Your Google ID, email, name, and profile picture, to create your account and keep synced records — course snapshots, documents, Course Brain artifacts, Student Profile facts — scoped to you. | Optional. Only account-linked features ask for it. | Scope’s servers, under your account. |
| Google Calendar | Writes selected course dates to your Google Calendar when you run the syllabus or planner sync. Scope keeps the access token so later writes work until you disconnect or it expires. | Optional, and asked for only when you use that feature. | Your Google Calendar; the token is held by Scope. |
| Clipboard, for the Student Profile | When you copy, cut, or paste on Canvas, Brightspace, or other sites, or when a page loads, Scope may capture the text in your clipboard, up to 4,000 characters per entry. In the policy's words, it keeps the actual text because what you copy is the clearest signal of what you are working on. The text is stored in browser-local storage, synced to Scope's database under the same path as your grades, notes, and tasks, and processed on your device into a content-light engagement summary that never contains the raw text. Read the clipboard section of the policy before you install. | Comes with the extension. | Your device and Scope’s servers, under your account. |
| AI answers | Answers come from the materials your instructors posted, each linked to its source. Scope tries Chrome’s on-device model first; when it is unavailable, or a whole-course question needs a larger model, the retrieved passages are sent through Scope’s servers to a cloud model from a named provider, disclosed in the privacy policy, only to produce that answer. Not used to train models. | The cloud fallback is optional and clearly marked. | Your device first; the disclosed provider sees only what is sent for that answer. |
| What it does not do | Act on your behalf inside graded work; the Academic integrity section below spells that out. Sell your data, use it for advertising, or hand it to data brokers. | — | — |
The rest of the checklist
- Publisher. Scope Inc. The listing links to canvascope.org, is marked as created by the owner of that website, and showed a publisher record with no history of violations on September 1, 2026.
- Last updated. August 30, 2026, version 11.0.5, as shown on the Chrome Web Store on September 1, 2026.
- Reviews. 5.0 from 6 ratings and 94 users on the Chrome Web Store on September 1, 2026. Six ratings is not a track record; read them, then read the policy. Counting Lectra Notes on iPad, 104 people were using Scope when we last counted by hand, on August 27, 2026 (how we count).
- Open source. Not today. You are trusting the policy and this page.
- Quizzes and grades. It reads the pages you open, including the grades page if you open it. It does not act on your behalf inside graded work; the next section says exactly what that rules out.
Academic integrity
What Scope will not do for you
Scope answers questions from the materials your instructors posted and links every answer to its source. It does not take quizzes, write submissions, or interact with Canvas quiz logs.
Extensions that answer quiz questions for you, or that block Canvas's activity log, are a different category, and we leave them out of our round-ups on purpose: they exist to act on your behalf inside graded work, which is the one thing a study tool should never do.
Questions
Can Canvas see which extensions I use?
Not as a list. Extensions run inside your browser, and Chrome keeps an extension's code separate from the page's own code, so a site cannot simply ask which extensions are installed. What a page can see is the page: if an extension adds a button or restyles the dashboard, that change is in the page, and a site that goes looking for it can in principle notice. Scope adds a search bar and a Send to iPad button to course pages, so the change is there to find. It reads course material through the same signed-in session your browser already uses; whether Instructure looks for extension activity in its own logs is a question only Instructure can answer.
Can an extension see my grades?
If it runs on your Canvas pages, yes. It sees whatever you open, and the grades page is a page; Chrome has no permission that carves grades out of the rest of Canvas. The questions that matter are whether it stores them and whether it sends them anywhere.
For Scope: search runs on the pages you open and keeps its index in browser-local storage. If you sign in, the privacy policy describes an account sync path that carries your grades, notes, and tasks, and clipboard entries travel the same path. Account-linked features need sign-in; the local index does not.
Is BetterCampus safe?
We have not audited it, and a competitor's page is the wrong place to take anyone's word on it. Run the checklist: open its Chrome Web Store listing, read the permissions and the privacy-practices disclosure, find the privacy policy and check that it names every data type, look at the last-updated date and the newest reviews, and decide whether what it asks for matches what it does. It restyles Canvas, so it has to run on your Canvas pages; that part is expected. Our comparison with BetterCampus covers what it does. Whether it is safe is your call, after the checklist.
What happened in the 2026 Canvas breach?
On April 25, 2026, unauthorized actors accessed Instructure's Canvas systems. Instructure detected the intrusion four days later and disclosed it on its status page on May 1. On May 7, Canvas was hit again, this time with a ransom message from the group ShinyHunters, which threatened to publish the data unless it was paid by May 12. The breach affected 8,809 universities, education ministries, and other institutions; ShinyHunters claimed 3.65 terabytes of data covering roughly 275 million users.
The exposed data included names, email addresses, student ID numbers, and messages between users. Instructure said it found no evidence that passwords, birth dates, government IDs, or financial information were involved. On May 13, 2026, a proposed class action was filed against Instructure in the United States District Court for the Southern District of California. No browser extension was involved. Source: Wikipedia's entry on the breach, read September 1, 2026.
Last verified September 1, 2026 against the Chrome Web Store listing (version 11.0.5, updated August 30, 2026), the extension's declared permissions, the privacy policy dated July 28, 2026, and Wikipedia's entry on the 2026 Canvas data breach.
Read the policy first, then decide.
The privacy policy is the full statement, clipboard collection included. If it reads right to you, Scope for Canvas is on the Chrome Web Store, free, version 11.0.5. If it does not, skip it; the checklist works on whatever you pick instead.