Your course material is yours. Here is how we keep it that way.
A plain-language overview for students, parents and school IT teams. The legal detail is in the privacy policy; this page is what actually happens.
| Area | What Clevaly does |
|---|---|
| Sign-in | Email and password (8+ characters), Google, magic link, or Sign in with Apple on iOS. Optional two-factor with an authenticator app and backup codes. Password resets sign out every device. |
| Course-site connections | Moodle and Brightspace connect through the school's own login (SSO and MFA included) and return a read-only app token. Canvas uses a personal access token limited to your account. Tokens are encrypted at rest with AES-256-GCM. |
| What sync reads | Course files, modules or sections, syllabus files and assignment or quiz due dates. Never grades, submissions, messages or other students' work. Nothing is ever written back. |
| Your files | Stored in a private class library, indexed so Cleva can search them for you, and never used to train models. Delete a file, a class or your account and it is gone from the library and the index. |
| AI processing | Generation and Cleva conversations run on third-party model providers under agreements that do not permit training on your content. Cleva only sees material in your own workspace. |
| AI agents (MCP) | Every agent goes through OAuth consent. Read access is always granted; write access is your choice. Access tokens expire after an hour, consent is re-checked on every call, and Disconnect revokes immediately. |
| Payments | Card details never touch Clevaly. Web billing is handled by Stripe; app purchases by Apple and Google through RevenueCat. |
| Deletion | Settings → Danger zone deletes your account and everything in it immediately, with no grace period. Backups are purged on a rolling schedule. See the data deletion policy. |
| Where data lives | Clevaly is operated from Alberta, Canada. Data is stored with cloud providers that may be located outside your country; the privacy policy has the details. |
For school IT teams
Clevaly does not require anything to be installed on your learning platform. Moodle and Brightspace connections use the same mobile-app web services as the official apps; Canvas uses a student-created personal access token. Connections appear in the student's own account like any other app token and can be revoked from either side.
Sync is read-only and scoped to the student's enrolled courses. Clevaly never posts, submits, grades or reads other students' work, and the browser extension only reads course pages the student has open.
Questions about a rollout, data processing agreements, or an accessibility or security review can go to support@clevaly.com.
Report a vulnerability
If you find a security issue, email security@clevaly.com with steps to reproduce. Please give us a reasonable time to fix it before disclosing, and do not access other people's data while testing. We reply to every report and credit researchers who want it.
The policies
Privacy policy
What is collected, why, and your rights.
Data deletion
How to delete and what happens after.
AI content policy
Accuracy, responsibility and academic integrity.
Terms of service
The agreement between you and Clevaly.
Acceptable use
What you can and cannot do on the platform.
Copyright
How to file a notice and how we respond.
Questions before you connect?
Read the integrations guides or write to us. We would rather answer than have you guess.