Privacy Policy

Courses can contain names, grades, messages, submissions, and other private information. Morrow, the app for Mac and Windows, replaces known student identifiers with course labels before it sends course records to your assistant. Morrow uses course-specific labels for known identifiers in Canvas records. The sections below explain each connection and its limits.

Effective September 6, 2026Updated September 25, 2026Contact hello@meetmorrow.app

Morrow

Understand your courses while protecting student identity.

Morrow replaces known student names, email addresses, usernames, and school or course IDs in supported records with course labels before they reach your assistant.

How Morrow creates student labels

Morrow first confirms the course and reads the roster needed for the records it will handle. When the course provides them, the roster includes current, former, and deleted enrollments. Morrow keeps the roster, with each student’s names, email address, username, and school or course account IDs, on your computer. Before course information reaches your assistant, it replaces a student’s full name in its usual orders, any other name the course lists for the student, the email address, the username, and the school or course account IDs with a label such as Student A1. A first or last name used alone is replaced where it is written with a capital letter. If Morrow cannot read the needed roster or protect those listed details, it stops the request.

Where label protection has limits

This protection applies to known student identifiers in the course records that pass through Morrow. It covers fields and text in discussions, messages, comments, submissions, pages, and other course records. It does not cover identifiers that Morrow does not know. A nickname, middle name, or misspelling that the course does not list on its own, and the name of someone who is not a student in the course, such as a parent, can reach your assistant as written. A name written with a grammatical ending that changes the word, such as Annas for Anna in German or Марии for Мария in Russian, can reach your assistant as written. Morrow may leave a first or last name used alone as written where it is in small letters, such as jane, because in small letters it is usually an ordinary word, such as will or long. A course account ID shorter than five digits, written in plain text in a post or a page, can reach your assistant as written, because short numbers are usually counts or scores. A name part that two students share becomes [learner], because Morrow cannot tell which student it names. Your assistant receives labels such as Student A1 with the protected course facts needed for your request. For an approved course action, Morrow matches a label back to the exact student only on this computer and in the selected course. Inside these edges, every known identifier stays a label.

Use a real name inside Morrow Private Chat.

Ask your assistant to start Morrow Private Chat. Choose the course in Morrow Bridge. List every student name or ID used in your message, then type the message in the local drawer. Morrow checks each listed identity against a fresh, complete course roster. It replaces known identity text with labels such as Student A1 before it sends the message to your assistant. If a listed identity is missing, unclear, or outside the selected course, Morrow does not send the message.

For example, you can type “Review Michaela Adams’s missing work, recent scores, and submission history” inside Private Chat and list Michaela Adams. Your assistant receives “Review Student A1’s missing work, recent scores, and submission history.” You can also compare that learner’s participation with the course pattern, draft a message for you to review, or prepare an approved course action. You can close Private Chat at any time to clear the local conversation.

Three requests, and what your assistant receives.

Each request below is typed in Private Chat, with Michaela Adams listed as the identity. Each one does real work on one student, and none of them sends her name to your assistant.

Missing work: you type “Michaela Adams has not submitted the lab report. Draft her a short note with one next step.” Your assistant receives “Student A1 has not submitted the lab report. Draft a short note with one next step.” It writes the note. You read it and send it to Michaela.

A comparison: you type “Compare Michaela Adams’s discussion posts with the rest of the section this month.” Your assistant receives that question with Student A1 in place of her name, together with the course facts it needs to answer it. Other details in the posts may still identify her.

A message: you type “Send Michaela Adams a message about the lab report.” Your assistant receives “Send Student A1 a message about the lab report.” It drafts the message for your review. You read it and send it to Michaela yourself.

Roster names use the same course label.

Morrow uses the course roster to match Michaela Adams written as “Adams, Michaela”, as her email address, as her username, or as the ID number her school or course platform gives her. Her first name alone also becomes Student A1 when no other student shares it. A first name shared by two students becomes [learner], because Morrow cannot tell which student you mean.

In Morrow, the replacement also reaches the words students wrote. If a classmate posts “I agree with Michaela,” your assistant reads “I agree with Student A1.” A name inside a discussion post, message, comment, or submission is replaced the same way as a name in a roster field.

Use the protected label Morrow returned.

Ask your assistant to use Morrow to read the selected course. When that result calls a learner Student A1, keep using Student A1 in the same course. The real identity stays on your computer.

Student A1 stays bound to one course.

Your assistant gets the protected label and the course facts needed for the request. The roster names, email addresses, IDs, usernames, and aliases that Morrow matches stay on your computer. Unlisted names and other details can still reach your assistant. Morrow resolves Student A1 to the exact person only for an approved course action on this computer and in that selected course. The same label in another course does not identify the same person.

In Morrow, your course sign-in stays in Chrome.

Morrow Bridge works through the Canvas or Moodle tab where you are signed in. Your password and cookies stay in Chrome. The Morrow app and your assistant do not receive them. For Canvas Item Bank work, Morrow Bridge briefly reads the Canvas Item Banks sign-in inside Chrome. It keeps that sign-in in memory and does not pass it to the app or your assistant. Read how the Bridge handles it.

Blackboard support is in development.

Blackboard does not use Chrome. When Blackboard support is ready, your Blackboard administrator will connect Morrow to your school, and you will add that approved connection on your computer.

You choose what to share.

In Morrow, when you ask the ChatGPT desktop app, Claude Desktop, Claude Code, or Gemini CLI to use Morrow, the course information needed for your request goes to that assistant. Morrow first replaces known student identifiers in records that pass through it. Other course information can still be confidential, so follow your school’s rules. Your assistant has its own privacy terms and settings.

What if I type a real name or upload a named file directly to my assistant?

That name or file reaches your assistant. It bypasses Morrow, so Morrow cannot replace the identity inside it. Use Morrow Private Chat or a protected label from a Morrow course result when you want this protection. Do not type a real student name or upload a named student file directly to ChatGPT, Claude, or another assistant and expect Morrow to filter it.

Morrow keeps work records on your computer.

Morrow keeps plans and change records on your computer so you can return to them. Treat the Morrow folder like any other folder that contains course information.

You control access to course files.

In Morrow, course files need a separate Chrome permission, Course file access, that you can remove. Because Canvas can keep course files at other web addresses, that permission lets Morrow Bridge reach all HTTPS sites, and Morrow uses it only for files in your selected Canvas courses. Morrow keeps a temporary copy only while it prepares a file change.

You can remove access.

In Morrow, you can disconnect a course, remove Edit access, remove course file access, and clear Morrow’s records from your computer. This stops new requests. It cannot remove information already sent to your assistant or undo a course change.

Morrow keeps your sign-in on your Muse Secure VM.

Muse runs on a Muse Secure VM, a computer that Meta provides for you. For Canvas, you sign in on your school’s page inside Muse. Moodle uses an existing Muse connection; this download does not set up a new Moodle sign-in. Morrow does not store your school password. Anyone with access to the VM’s browser or active session may be able to act through your school account.

For Canvas, the Muse Secure VM stores Morrow’s change records, Plan/Edit settings, and the private mapping between course labels and learners. The Moodle connection does not use student labels: individual student records reach Muse with names as written, so keep them out of Muse.

What Morrow sends to Muse.

For Canvas, Morrow replaces known learner identifiers with course-specific labels before it sends supported course records to Muse. This covers roster details and supported content such as pages, assignment descriptions, and quiz questions. If Morrow cannot read the course roster for a task that needs it, it stops. The Moodle connection does not use student labels. Use it for course materials and planning, since individual Moodle student records reach Muse with names as written.

For Canvas, the names you type reach Muse because you typed them, and Muse matches them to labels. Morrow records each Canvas name lookup on your Muse Secure VM: the course, the conversation, and whether it matched, but never the name. Some details are not hidden: a name Canvas does not list for the student, such as a nickname; a name written with a grammatical ending that changes the word, such as Annas for Anna in German or Марии for Мария in Russian; a first or last name used alone and written in small letters, such as “jane” in a page’s web address, because in small letters it is usually an ordinary word; the name of someone who was never a student in that course; an ID number written as plain text, such as “Canvas ID 912345” in a page; and other details written about a student, such as a birth date. A full name in a web address or a file name is hidden. A course named for its student, such as an independent study, shows the student’s label. To check who a label is, tell Muse the name of the student you have in mind. Muse looks it up and tells you whether it is the same label.

Meta’s terms cover what reaches Muse. By default, Meta uses eligible Muse conversations to train its models, and that can include what you type about your courses. Muse’s settings have an opt-out for this data sharing.

Some Muse Secure VMs can read their own network traffic.

On some Muse Secure VMs, the network that carries traffic out of the computer can read that traffic, including your Canvas or Moodle session and the course pages you load. Morrow cannot prevent that. If your school has rules about where course content may go, check them before you connect.

Disconnect Canvas or remove Morrow.

To disconnect Canvas, ask Muse to disconnect Morrow from Canvas. Muse asks you to confirm, then stops the Canvas helper, deletes its private browser and Canvas sign-in, and checks each step. This does not end a separate Moodle sign-in. Your Canvas settings, change records, and learner labels stay, so you can reconnect later. To remove the package and its local data, ask Muse to uninstall Morrow. After you confirm, Morrow removes its files, settings, and records. Your school may keep the old Canvas sign-in valid until it expires. To end it sooner, use your school account’s security settings or contact your administrator.

This website does not track you.

This site has no tracking cookies, account sign-in, or contact form. Cloudflare delivers the pages. Email to hello@meetmorrow.app goes through Cloudflare Email Routing to a Morrow Gmail mailbox and stays there until it is deleted. Do not email student records, passwords, sign-in details, or screenshots that show student information.

Chrome Web Store Limited Use.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.