AURA Calendar — Privacy Policy

Last updated: 29 August 2026

AURA Calendar ("AURA", "the extension") is a Chrome extension that gathers your school assignments, tests and quizzes from Canvas LMS and shows them together in a single calendar and to-do list. This policy explains exactly what data the extension touches, where that data goes, and what it is used for.

The short version

AURA stores your data on your own device. It has no accounts, no analytics, no advertising, and no tracking. Nothing you do in AURA is sold, rented or shared with anyone. The developer cannot see your assignments.

1. Who runs AURA

AURA is built and maintained by an independent student developer. There is no company behind it and no server that holds user accounts. Questions, requests and complaints: aura.calendar.app@gmail.com.

2. What data AURA handles

Canvas LMS data

When you are on a Canvas site (any *.instructure.com address) and already signed in, AURA reads coursework from Canvas using your existing browser session — the same information Canvas already shows you when you click through the site:

AURA does not read your grades, your messages, other students' data, or anything outside the courses you are enrolled in. It does not send anything to Canvas and never modifies your Canvas account.

Data you type in yourself

To-do items, manually created events, quick links, background choices, language and theme preferences.

What AURA does not connect to

This version of AURA does not sign in to Google, does not connect to Google Calendar, and does not request access to any Google account. It has no email access of any kind.

3. Where the data is stored

WhatWhereHow long
Assignments, calendar events, settings, quick links chrome.storage.local — on your computer only Until you remove them, clear extension data, or uninstall AURA
To-do items and widget preferences chrome.storage.sync — on your computer, and synced by Chrome to your own Google account so they follow you between your devices Until you delete them or uninstall AURA

The developer has no access to any of this. There is no AURA server that receives, mirrors or backs up your data.

4. The only times data leaves your device

There are exactly two, and both only happen because you chose to start them.

a. Reading a grid-layout calendar PDF — optional feature

Some teachers post six-week calendars as PDFs laid out as a month grid. AURA reads most calendar PDFs entirely on your own device. For grid layouts it cannot read alone, and only if you have granted the optional permission for it, AURA sends the plain text it extracted from that PDF to a small endpoint operated by the developer at aura-proxy-update.vercel.app, which forwards it to Google's Gemini API purely to work out which homework belongs to which date. The extracted dates come back and the text is discarded. The PDF file itself is never uploaded, no identifier of you is attached, and the endpoint keeps no database of what was sent. Google's handling of that text is governed by the Gemini API terms. If you never grant the optional permission, this never happens.

b. Sending feedback — only when you press the button

If you use the Feedback form inside AURA, the message you typed (and an email address, if you supply one) is delivered to the developer through FormSubmit. Nothing else is attached.

5. What AURA does not do

6. Optional permissions

AURA installs with the smallest permission set it can work with: local storage, a periodic refresh alarm, and access to Canvas. This extra is requested later, and only if you turn the matching feature on. Declining it leaves the rest of the extension fully working.

You can withdraw any of them at any time from chrome://extensions → AURA Calendar → Details.

7. Children and students

AURA is aimed at students, including students under 18. It deliberately collects nothing that could identify a child: no name, no school, no age, no location, no contact details, no account. Everything stays on the student's own device. If a parent, guardian or school has a concern, write to aura.calendar.app@gmail.com and it will be addressed.

8. Deleting your data

Because no data is held on any server, there is nothing else to request the deletion of.

9. Security

All network requests use HTTPS. Canvas is read through your own already-authenticated browser session, so AURA never asks for, sees or stores your Canvas password, and it never handles a password of any kind.

10. Changes to this policy

If this policy changes, the "last updated" date at the top changes with it, and the new version is published at this same address. Any change that would meaningfully expand what AURA collects will also be described in the extension's Chrome Web Store update notes.


AURA Calendar · Contact: aura.calendar.app@gmail.com