Security and privacy

Your course material is yours. Here is how we keep it that way.

A plain-language overview for students, parents and school IT teams. The legal detail is in the privacy policy; this page is what actually happens.

AreaWhat Clevaly does
Sign-inEmail and password (8+ characters), Google, magic link, or Sign in with Apple on iOS. Optional two-factor with an authenticator app and backup codes. Password resets sign out every device.
Course-site connectionsMoodle and Brightspace connect through the school's own login (SSO and MFA included) and return a read-only app token. Canvas uses a personal access token limited to your account. Tokens are encrypted at rest with AES-256-GCM.
What sync readsCourse files, modules or sections, syllabus files and assignment or quiz due dates. Never grades, submissions, messages or other students' work. Nothing is ever written back.
Your filesStored in a private class library, indexed so Cleva can search them for you, and never used to train models. Delete a file, a class or your account and it is gone from the library and the index.
AI processingGeneration and Cleva conversations run on third-party model providers under agreements that do not permit training on your content. Cleva only sees material in your own workspace.
AI agents (MCP)Every agent goes through OAuth consent. Read access is always granted; write access is your choice. Access tokens expire after an hour, consent is re-checked on every call, and Disconnect revokes immediately.
PaymentsCard details never touch Clevaly. Web billing is handled by Stripe; app purchases by Apple and Google through RevenueCat.
DeletionSettings → Danger zone deletes your account and everything in it immediately, with no grace period. Backups are purged on a rolling schedule. See the data deletion policy.
Where data livesClevaly is operated from Alberta, Canada. Data is stored with cloud providers that may be located outside your country; the privacy policy has the details.

For school IT teams

Clevaly does not require anything to be installed on your learning platform. Moodle and Brightspace connections use the same mobile-app web services as the official apps; Canvas uses a student-created personal access token. Connections appear in the student's own account like any other app token and can be revoked from either side.

Sync is read-only and scoped to the student's enrolled courses. Clevaly never posts, submits, grades or reads other students' work, and the browser extension only reads course pages the student has open.

Questions about a rollout, data processing agreements, or an accessibility or security review can go to support@clevaly.com.

Report a vulnerability

If you find a security issue, email security@clevaly.com with steps to reproduce. Please give us a reasonable time to fix it before disclosing, and do not access other people's data while testing. We reply to every report and credit researchers who want it.

The policies

Questions before you connect?

Read the integrations guides or write to us. We would rather answer than have you guess.