← Syllo

Privacy

Syllo stores the coursework metadata needed for your dashboard: active courses, assignment titles and deadlines, submission states, grades, recent announcements, and your schedule. Your tasks, study progress and preferences are saved to your account so they work across devices.

Your Canvas connection

You enter a Canvas access token once over an encrypted connection. The server validates it and encrypts it with AES-256-GCM before saving it. The encryption key stays on the server. Your token is never returned to the browser after connection, placed in a URL, or included in application logs.

Your data

Supabase provides account authentication and a database with row-level ownership rules. The app reads Canvas on your behalf; it does not submit work, change grades or modify enrollment. Canvas files, lecture videos and attachments are not copied into storage. Assignment instructions are read on demand. Public CS2000 resources and public Northeastern meeting times are shared cache data.

Retention and control

You can disconnect Canvas in Settings to remove its encrypted token and cached academic data. Delete Account removes your account and all user-owned data. Routine cleanup removes announcements older than 90 days, changes older than 45 days, and disposable academic caches for accounts inactive for 180 days. Personal tasks remain until you remove them or delete the account. Database backups may retain deleted records until the hosting provider’s backup retention expires.

Services and cookies

The application uses Supabase for authentication and storage and can run on Vercel. Essential HttpOnly cookies keep you signed in. No third-party product analytics or advertising trackers are included. Aggregate operational counters record request and sync counts without grades, coursework or access tokens.

Updated September 17, 2026

Account settings →