Nexora

Nexora and Nexora Sync

Privacy

Last updated 31 August 2026

The short version

Nexora reads your university's learning management system so that your coursework appears in one place — Brightspace through the session you are already signed into, Canvas through an access token you issue yourself. It never asks for, sees, or stores your university password. Your coursework is stored against your Nexora account and is not sold, shared with other students, or used for advertising.

What the browser extension does

Nexora Sync runs only when you ask it to. When you press Import my courses, it reads the Brightspace pages you already have access to and sends the following to your Nexora account:

  • Course codes, names, terms, and course images
  • Assignment, quiz, and deadline titles and their due dates
  • Announcement titles and text
  • Links back to the original items in your LMS
  • The text of a lecture or course outline — only for the specific file you ask Nexora to summarise, analyse, or turn into study tools

It does not read anything outside your LMS. It has no access to your other tabs, your browsing history, or any site you have not explicitly granted it.

If you use Canvas instead

Canvas publishes an API, so there is no extension and nothing is scraped. You create an access token in your own Canvas settings and give it to Nexora, which then reads your courses, assignments, due dates, announcements, module listings and your own marks directly.

That token is a key to your Canvas account, so it is stored encrypted rather than in the clear: reading the database is not enough to use it. It is only ever sent back to your own university's Canvas, never anywhere else, and Nexora only ever reads — it never submits work or changes anything.

You can revoke it at any time from Canvas under Account → Settings → Approved Integrations, which cuts Nexora off immediately, or press Disconnect in Nexora, which deletes the token from the database.

Permissions, and why each one exists

  • Your university's domain — requested one origin at a time, when you press "Allow this Brightspace" on your own LMS. Nothing is granted at install.
  • storage — remembers your Nexora address, your sync preference, and the key that links the extension to your account.
  • tabs — finds the Brightspace tab you already have open.
  • scripting — runs the reader on that page when you ask it to.
  • alarms — schedules the optional background refresh, if you turn it on.

Artificial intelligence

When you ask Nexora to analyse a course outline or build a summary, flashcards, a quiz, or a study guide, the text of that document is sent to Google's Gemini API to produce the result. Google processes it to return the response. Nothing is sent to any AI service unless you press a button that asks for it.

What is stored, and where

Your account, courses, deadlines, grades, and generated study material are stored in a private database belonging to this application, hosted on Render. Passwords are stored only as salted hashes and are never recoverable. Password-reset tokens are stored hashed, expire after an hour, and can be used once.

Error reporting

If error reporting is enabled, crash reports are sent to Sentry with personal information deliberately switched off. Your grades and the text of your course documents are your private record and are never attached to a crash report.

Deleting your data

Removing a course from Nexora deletes its imported content, grades, outline analysis, and tasks. Uninstalling the extension stops all reading immediately. To delete your account and everything in it, ask through the nexora.notify@gmail.com and it will be removed.

What Nexora never does

  • Ask for or store your university password
  • Sell your data, or share it with advertisers or data brokers
  • Show your coursework to any other student
  • Read pages outside the LMS domain you granted
  • Submit work, post, or change anything in your LMS — it only reads

Contact

Questions about any of the above: nexora.notify@gmail.com.