Syla
Updated 15 August 2026

Privacy Policy

Syla connects your course material to the AI assistant you already use. This policy describes exactly what that involves, in the order it actually happens.

The short version

  • Syla never receives your Canvas password, and never asks for it.
  • Your course material is read in your own browser, using the Canvas session you already have, and only for courses you explicitly select.
  • Syla does not sell your data, and does not use it for advertising.
  • An AI assistant receives only the specific course context it requests, on the request it requests it. Connecting Syla does not hand your whole term to anyone.
  • You can delete any course, or your whole account, at any time.

What Syla collects

Account information. Your email address, and your name if you sign in with Google. Used to identify your account and to contact you about the service.

Course material from Canvas. For courses you select: course names, instructors, terms, assignment titles and due dates, submission status and grades, announcements, course pages, and course files such as lecture slides and readings. Text is extracted from those files so it can be searched.

Usage records. When a sync ran, what changed, and which assistant connections exist. Used to show you sync status and to operate the service.

Syla does not collect your browsing history, keystrokes, passwords, authentication cookies, location, or any page outside Canvas. The extension reads only Canvas. It starts from a tab where you click Syla, and it can later read the Canvas site in the background only if you explicitly enable automatic sync for that site.

How Canvas access works

Syla does not log in to Canvas as you and does not store Canvas credentials. The browser extension runs in a tab where you are already signed in and reads Canvas's own API using the session your browser already holds. That session never leaves your device.

Only courses you check in the extension are read. Reading is read-only: Syla never submits work, posts, changes, or deletes anything in Canvas.

If you enable automatic sync, Chrome grants Syla access to that one Canvas origin so selected courses can stay current in the background. The permission is optional, is removed when you turn automatic sync off, and never grants background access to other sites.

How your data is used

Course material is organised into a per-course index so an authorised AI assistant can answer questions about your classes with references back to the original file and page. That is the single purpose of the product, and the data is used for nothing else.

Small amounts of text are sent to model providers to create search indexes and to answer your questions. Providers are used under agreements that prohibit training on the data sent to them.

Syla does not sell or rent your data, does not share it with data brokers or advertising platforms, and does not use it for personalised advertising or credit decisions.

What assistants can see

When you connect ChatGPT, it can call Syla and receive course context relevant to what you ask. It does not receive your entire academic history, and it receives nothing unless a request is made.

The same applies to any tool or script you connect with an agent token you created: it reads through the same tools, under the scopes you chose, and nothing more.

Assistant and agent connections are individually revocable from your Syla settings, and revoking one takes effect immediately.

What Syla remembers about your studying

On paid plans, Syla keeps a record of the questions you ask it: the wording, the class, the time, and whether your own materials turned out to contain an answer. It uses this to notice which topics you come back to on different days, so an assistant can tell a first question from a fourth instead of repeating the same explanation.

Syla cannot see your answers, your work, or your grades, so it does not record or infer anything about how well you understand a subject. It stores what you asked, never a judgement about you, and nothing here is ever shown to your school or your instructor.

You can read the whole of it under Settings, on the Privacy & data page, in the same words an assistant receives, and erase all of it there with one button. It is kept for 90 days. On the free plan it is not recorded at all.

Separately, Syla keeps a copy of search queries and which documents came back, so that when the search is changed it can be checked against real questions rather than only the ones its author invented. These records hold the question, the files and page numbers returned, and how confident the match was. They never hold the text of your materials, and they are covered by the same erase button and deleted after 60 days.

Cookies

Syla sets first-party cookies only. A session cookie keeps you signed in. Two small cookies support understanding how people find Syla: a random visitor identifier, and, if you arrived through a creator's link, which link that was. They identify a browser to Syla only, are never shared with anyone, and are not used to track you across other sites. There are no third-party analytics or advertising cookies.

Like almost every web service, Syla's servers briefly process IP addresses to rate-limit abuse and keep the service available. They are not used to build profiles.

Human access

Syla staff do not read your course material. Access is limited to cases where you explicitly ask for help with a specific problem, where it is necessary to investigate abuse or a security incident, or where the law requires it. Aggregate and anonymised counts are used to operate and improve the service.

Storage and security

Data is stored on managed infrastructure in the United States. Traffic is encrypted in transit with HTTPS, and data is encrypted at rest. Access is isolated per account at the database level, so one student's material is not reachable from another's session.

Credentials Syla issues, including browser and assistant connection tokens, are stored only as cryptographic hashes.

Your controls

  • Change which courses are connected at any time, from the extension.
  • Delete a course, which removes its material, index, and stored files.
  • Disconnect a browser, which stops all syncing from that device.
  • Revoke an assistant connection, which takes effect on its next request.
  • Erase what Syla has noticed about your studying, without affecting anything else.
  • Delete your account, which removes everything associated with it.

Deleted material is removed from live systems promptly and from backups within 30 days.

Retention

Course material is kept while the course is connected and your account is active. If you delete a course or your account, it is deleted. Inactive accounts are removed after 24 months of no activity.

Children

Syla is intended for university and college students and is not directed at children under 13. Accounts are not knowingly created for them.

Changes and contact

Material changes to this policy will be announced in the product before they take effect. Questions, requests for a copy of your data, or deletion requests: founder@usesyla.app.

Syla is not affiliated with, endorsed by, or sponsored by Instructure, Canvas, or OpenAI.