Security
What Morrow can reach, how to check your download, and how to report a problem.
Morrow uses your existing course access.
In Morrow, the app for Mac and Windows, your Canvas or Moodle sign-in stays in Chrome, where it already was. Blackboard support is in development. In Morrow, Canvas signs in through your school’s page on your Muse Secure VM. Moodle uses an existing, separate connection in Muse. In Canvas and Moodle, Morrow can use only the courses and actions your signed-in account allows. Morrow holds no password of yours and creates no account of its own.
You control course changes.
Morrow starts each course in Plan. Canvas in Morrow also starts in Plan. Both show each proposed change before Morrow saves it, and Edit stays on until you turn it off. In Morrow, Edit applies only to the courses and kinds of change you choose, and you approve changes on your own computer. For Canvas in Morrow, Edit applies to your whole account or to one conversation, and you approve changes in your Muse conversation. After a supported Desktop change or a Canvas change in Muse, Morrow checks the saved item. If it cannot confirm the result, it tells you to check the item and does not send the change again.
What Morrow Bridge can do in Chrome.
The Bridge asks Chrome for eight abilities: activeTab and tabs to tell your course tabs apart; scripting to run Morrow’s reader and writer inside the course page you selected; webNavigation to know when that page has finished loading; webRequest to watch the result of an upload it started, so it can confirm what happened, and to read the sign-in that Canvas’s own Item Banks page sends; storage to keep your settings and course choices on your computer; alarms to check for the Morrow app every minute, so the Bridge reconnects after either one restarts, and to keep its toolbar badge current; and offscreen for work that needs a page context without opening a window. The only address it may reach by default is http://127.0.0.1, which is the Morrow app on your own machine.
Canvas signs each Item Banks request with a sign-in of its own. For Item Bank work you ask for, the Bridge opens the selected course’s Item Banks page in a background tab and reads that sign-in from the first request Canvas’s page sends. The Bridge keeps it in memory only, uses it only for that Item Bank work, never uses it for more than ten minutes, and clears it when the work is done. It never saves it or passes it to the Morrow app or your assistant.
Course sites are opt in.
The Bridge ships with no access to any course site. When you connect a course, Chrome asks you to allow that course site. If you connect from a Canvas Item Banks page, Chrome also asks for the two New Quizzes addresses Canvas uses for Item Banks. Removing a site in Chrome takes the access away immediately.
Course file access is separate, and it stays off until you turn it on in Plan and Edit settings. Canvas can keep course files at other web addresses, so Chrome then asks you to let Morrow Bridge reach all HTTPS sites. Morrow uses that access only for files it confirms belong to your selected Canvas courses and for the image of a Hot Spot question you approved. You can turn it off at any time in Plan and Edit settings.
Check that your download is the one we published.
Every release lists a SHA-256 checksum beside its file. Compare it before you install. On a Mac, run shasum -a 256 followed by the file you downloaded. On Windows, run Get-FileHash followed by the file and -Algorithm SHA256. If the value does not match the one published with the release, delete the file and tell us.
Morrow is not signed by Apple or Microsoft.
Morrow is independent software and does not pay into either company’s developer program, so macOS shows an unidentified developer prompt and Windows may show a SmartScreen notice on first run. The Download page has the exact steps to get past each one. The checksum above, not a signature, is how you confirm you have the file we published.
How Morrow updates.
Morrow does not update itself yet. To update, download the new version from the Download page and install it over the old one. Your settings stay. For now, Morrow Bridge updates through the app: the app replaces the Bridge folder for you, and you reload Morrow Bridge once on Chrome’s Manage Extensions page. Once it is listed in the Chrome Web Store, Chrome will update it. To update Morrow, ask Muse to set it up again from the Morrow for Muse page. Your Canvas sign-in and settings stay.
How to remove Morrow completely.
Start in Morrow while it is still installed. In What stays on this computer, select Remove Morrow’s data and confirm. Morrow first takes its own entry out of each assistant settings file it changed. It then removes its setup record and journal, the Bridge folder, your Materials folder if it is in the default place, the earlier default Materials folder if you later chose another one, and lists what it removed. Copy anything you want to keep out of those Materials folders first. Then quit Morrow. If you set up Claude Desktop, also remove Morrow in Claude Desktop under Settings, Extensions. Claude Desktop keeps its own copy of the Morrow extension.
Next, remove the app and Morrow Bridge. On a Mac, move Morrow from Applications to the Trash. On Windows, open Settings and select Apps. On Windows 11, select Installed apps, find Morrow, select More, and select Uninstall. On Windows 10, select Apps & features, select Morrow, and select Uninstall. In Chrome, open chrome://extensions and select Remove on Morrow Bridge.
Last, delete the folder that stays. On a Mac, delete ~/Library/Application Support/morrow-installer. You can also delete ~/Library/Preferences/app.meetmorrow.installer.plist, a small settings file macOS keeps for the app. On Windows, delete %APPDATA%\morrow-installer. This folder keeps Assistant settings backups, copies of your assistant settings from before Morrow changed them, so save them first if you want them.
If you removed the app before you selected Remove Morrow’s data, remove Morrow from each assistant’s settings yourself. If you set up Claude Desktop, remove Morrow in Claude Desktop under Settings, Extensions. If you connected Blackboard, also delete the .morrow folder in your home folder: ~/.morrow on a Mac, or %USERPROFILE%\.morrow on Windows. It holds your Blackboard site, key, and application secret.
Morrow runs no server of its own, so no Morrow server holds anything of yours. What you sent to your assistant is covered by that assistant’s own settings.
How to disconnect or remove Morrow.
Your Canvas sign-in for Morrow runs on your Muse Secure VM. An existing Moodle connection in Muse is separate. Anyone with access to either active session could act through your school account. To disconnect Canvas, ask Muse to disconnect Morrow from Canvas. Muse asks you to confirm, removes the Canvas sign-in, and checks each step. This does not end your separate Moodle sign-in.
To remove Morrow, ask Muse to uninstall it. After you confirm, it removes the package and Morrow’s local settings and records. Your school may keep the old Canvas sign-in active until it expires. To end it sooner, use your school account’s security settings or contact your administrator.
Report a security concern.
Email hello@meetmorrow.app with a short description and the steps to reproduce it. Do not include student information, private course content, passwords, sign-in details, or revealing screenshots. We will tell you how to share sensitive detail safely.
What happens after you report it.
We acknowledge your report within three business days and give you a first assessment within ten. After that we update you at least every fourteen days until it is closed. When a fix ships we say so in the release, and we credit you by name if you would like that. Morrow is maintained by one person, so these are the times we can actually keep.
Give us time to respond.
Do not read, change, or copy information you do not own or have permission to test. Please let us investigate and ship a fix before you publish. We will not pursue anyone who reports a problem in good faith and follows this page.