Privacy Policy
Effective September 2, 2026
Professor is a product of Ledgerwood LLC, a California limited liability company. You can reach us any time at support@professors.world or by mail at Ledgerwood LLC, 415 Laurel St STE 3062, San Diego, CA 92101.
Professor is a study tool that shows your Canvas assignments in one place and offers AI help that drafts and explains work you review and submit yourself. This policy explains, in plain terms, what we collect and how we use it. We keep it to what the app actually does.
What we collect
- Your email address, so you can sign in with an emailed code (there is no password). Signing in sets a session cookie so you stay signed in.
- Your Canvas connection, which is either a Canvas access token or a read-only calendar-feed URL that you choose to add. A token is stored encrypted and used only to read your own Canvas assignments, grades, and course materials on your behalf.
- Assignment and course data pulled from Canvas using your connection, cached so the app loads quickly.
- Things you add in the app: manual to-dos, notes, your drafts, reminder preferences, and (if you use it) a short writing sample you paste or upload to shape drafts in your own voice.
- A Google connection (only if you use “Open in Google Docs”). We store a Google refresh token encrypted, with the narrow
drive.filepermission, so the app can create only the documents it makes for you in your Drive. It never reads your other files. You can disconnect it at any time. - Billing details, if you buy a paid plan. Payments are handled by Stripe; your card number is entered on Stripe and never reaches our servers. We store a Stripe customer and subscription reference so we know which plan you are on.
- A referral code, if you arrive through someone's referral link or share your own. To prevent abuse we store the code and a normalized (dots and plus-aliases collapsed) form of the referred account's email.
- Usage counts tied to your account: how many AI drafts you have generated and similar per-feature counts, so we can apply your plan's monthly limits and understand overall activity.
- Your IP address, used only in the moment to rate-limit requests and prevent abuse (through our provider Upstash) and kept briefly in server logs for security. It is not attached to your profile.
How we use it
- To show your assignments sorted by class and due time.
- To power the study helper: when you ask for help, the relevant assignment text, the related course materials, your current draft or the text you are working on, and your writing-style profile are sent to our AI provider (Anthropic) to generate a draft or explanation you review. Drafts are a starting point you revise and submit yourself.
- To email you due-soon reminders (your email and the assignment title, course, and due date go to our email provider Resend). These are on once you connect Canvas, since due-date tracking is what you connected it for. Every reminder has a one-click link to turn them off, and you can also turn them off in settings. Turning them off does not affect sign-in codes.
- To learn your writing style, only from samples you give us. A writing sample you paste or upload is sent to Anthropic to build a short style profile. You can turn this off.
- To let you register interest in a paid plan: when you tap “Request access,” your email is sent to a Ledgerwood LLC inbox so we can follow up.
- To keep the Service secure, comply with the law, and enforce our Terms.
We do not sell your data, show ads, or use your Canvas data for anything other than running Professor for you.
Submission Check
Submission Check helps you review your own work before you turn it in. Here is exactly what it does with your data:
- The requirement checklist, the hidden-character and formatting scan, and your writing-process summary run on our own servers. On paid plans, the document text is also sent to Anthropic to produce the AI-writing estimate. Nothing is sent to an outside originality service unless you turn one on.
- External scanning is off until you turn it on. If you choose to run an originality, AI-writing or citation scan, the text of that document is sent to Copyleaks, our scanning provider, and to no one else. We ask for your agreement first, every provider is named, and you can revoke it in Settings.
- A Copyleaks scan compares your text against public web sources and Copyleaks's own database of previously scanned documents. It reads that database; it does not add your text to it. Your work is never added to any plagiarism database or shared repository, and it is not used to train AI models.
- To run a check, we store a copy of the document you check, plus the specific passages that were AI-generated or pasted, on our servers so the results are reproducible. While you write in Professor, the editor also records writing-process signals: active writing time, how much was typed, deleted, or pasted, and when AI help was inserted. We do not record raw keystrokes or timing patterns.
- Stored check content and scans are kept for up to 30 days, then deleted automatically. You can delete any check yourself sooner, which also asks the scanning provider to delete its copy.
- Results are evidence to help you review your work. They are never proof of authorship or misconduct, and we word them that way.
Who we share it with
We share data only with the service providers that run Professor, and only so they can provide their piece. Each one is under contract to use your data only to provide its service to us. We do not sell your data. Our providers are:
- Supabase: database and passwordless sign-in (stores your account and everything tied to it).
- Vercel: hosting and anonymous usage analytics.
- Anthropic: the AI that generates study help, style profiles, and the AI-writing estimate. Receives assignment text, course materials, your drafts, and writing samples when you use those features. Anthropic does not use content sent through its API to train its models and may keep it briefly for safety monitoring under its own terms.
- Resend: sends your reminder and account emails.
- Upstash: rate-limiting and abuse prevention (sees your IP address transiently).
- Stripe: payment processing for paid plans (handles your card details directly).
- Google: only if you connect Google Docs, to create documents in your Drive.
- Copyleaks: external originality and AI-writing scans, only if you turn one on and consent.
- Canvas / Instructure: your school's learning system, which we read on your behalf using the connection you provide.
Beyond those providers, we would share data only if the law requires it (for example, a subpoena or court order), to protect the rights and safety of you, us, or others, or if Professor is ever sold, merged, or moved to a successor company, in which case the same commitments follow your data.
Our usage analytics are anonymous and operational: they record events like a page view or an assignment being opened so we can see where the product is confusing. They never include your email, your Canvas tokens, or the text of your assignments.
Cookies and analytics
Professor sets one cookie of its own: the sign-in session that keeps you logged in. Our analytics (Vercel Web Analytics) are cookieless and receive only a short, fixed list of coarse events, never your email, tokens, or assignment text. Stripe sets its own cookies on the pages it hosts for checkout and billing. We do not use advertising or cross-site tracking cookies, which is why there is no cookie banner. Because we do not track you across other sites, we do not change our behavior in response to browser Do Not Track signals.
Who can use Professor
Professor is designed for college and university students and is intended for people who are at least 13 years old. If you are under 18, please use it with a parent or guardian's permission. We do not knowingly collect information from children under 13; if you believe a child under 13 has an account, email us and we will remove it.
Your school and FERPA
You supply your own education records by connecting your own Canvas account. We are not a school official, we have no agreement with your school, and we receive nothing from your school directly. Everything in Professor comes from you, on your instructions, and you can remove it at any time.
How it's protected
Your data is scoped to your account with row-level security on every user table, so you only ever access your own. Canvas access tokens and Google refresh tokens are encrypted at rest with AES-256-GCM. Traffic is encrypted in transit, with HSTS and a Content Security Policy enforced on the site. Sensitive endpoints check the request origin and are rate-limited, and every Canvas fetch validates the destination on the server. Card numbers never touch our servers. You can disconnect Canvas at any time, which removes the stored token. No system is perfectly secure, and we do not promise otherwise.
Security incidents
If a security breach affects your personal information, we will notify you by email without unreasonable delay and as required by law, and tell you what happened and what we are doing about it.
Your choices
- Disconnect your Canvas token or feed at any time.
- Turn reminders and the writing-style feature on or off.
- Delete your account yourself from Settings → Delete account. You can also email us and we'll do it for you.
Your California privacy rights
Wherever you live, you can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it (Settings handles deletion on its own, or email us). We do not sell your personal information or share it for cross-context behavioral advertising, and we will never treat you differently for exercising these rights. We answer requests within 45 days and may ask you to confirm your identity by signing in or replying from your account email. California residents may also ask, under Civil Code section 1798.83, whether we disclose personal information to third parties for their own direct marketing; we do not. Professor is operated from the United States and your data is processed there.
How long we keep it
Disconnecting Canvas removes the stored access token right away. Your cached assignments and course materials are refreshed each time you load Professor, so old data is overwritten rather than accumulated. Submission Check content is kept for up to 30 days as described above.
When you delete your account, everything tied to it is removed at the same time: your profile, Canvas connection, cached assignments and materials, saved edits, writing style, study-help history, and any Submission Check results. If an external scan exists at a provider, we queue its deletion there too and follow up until it is confirmed. This is immediate and can't be undone. Routine infrastructure backups roll off on their normal schedule.
Changes to this policy
If this policy changes, we will update the date at the top. If a change is material, we will tell you by email or by a notice in the app before it takes effect.
Contact
Questions or a deletion request? Email support@professors.world or write to Ledgerwood LLC, 415 Laurel St STE 3062, San Diego, CA 92101.
Professor is an independent tool and is not affiliated with, or endorsed by, Instructure (Canvas) or your school.