Lyceum

Privacy

Updated 25 September 2026

The short version

This app brings your coursework, schedule, and work together. It stores that coursework, the files your courses publish, and what you tell it about your own time. It does not sell your data or serve advertisements, and does not use third-party advertising trackers.

Operational records, such as account creation, saved document changes, and completed study actions, are also counted in aggregate to understand use and improve the app. These aggregate measurements do not include names, email addresses, chat text, or document contents.

Your Canvas token

The token you paste on the connect screen is encrypted before it reaches the database and is never written to a log, an error message, or any page. Your browser holds it only for the moment it takes to submit the form — every Canvas request after that is made by the server.

You can wipe it at any time from Settings, which sets the connection to revoked and clears the stored value. That stops this app from using it; it does not revoke the token itself, which you do in Canvas under Account → Settings → Approved Integrations. Doing both is the complete answer.

What is stored

  • Your courses, assignments, due dates, submission states and scores, as Canvas reports them.
  • The text of course materials your courses publish — slides, readings, pages — so questions can be answered from what was actually taught, with a citation. Handwritten and image-only pages are read by a vision model to get text out of them.
  • Your own entries: effort estimates, to-dos, commitments, and the study guides, games, and drafts you generate.
  • A daily record of each course standing. This is the one thing that cannot be re-fetched — Canvas’s API returns only the current grade, never the history.

Your documents and Ari

Write stores your drafts, notes, presentation slides, and saved revisions. For a problem set, it also stores the PDF you upload or import from Canvas, along with your drawings and typed answers. Importing a file creates a private copy in your workspace.

When you ask Ari for help in a document, Lyceum sends the document content, your request, and recent conversation context to the model. For PDFs, this includes an image of the current page with your annotations. Linked course passages may also be included when you leave “Use linked course material” selected. Proposed edits are saved only after you apply them.

This browser can keep a local recovery copy of unsaved work. Keep your device account private on a shared computer. Export work you want to keep independently of Lyceum. Submitting an eligible text assignment to Canvas is a separate action that you review and confirm.

Where it goes

Anthropic answers chat and writes study material, OpenAI turns text into the vectors that make search work and transcribes audio, and Neon hosts the database. Anthropic also reads image-based course material and PDF pages sent for document help. Render runs the backend and background jobs; Vercel serves the web app.

Neither model provider trains on what is sent through their APIs. Both keep short-lived abuse-monitoring logs, which is the only copy that exists outside this app’s own database.

Optional Outlook connections

Outlook is separate from Canvas and Google. Lyceum requests your Microsoft account identity and read access to basic calendar and email details. You choose which calendars to include and whether to import email suggestions. Your school or employer may require approval.

Selected calendars reserve occupied time from the previous seven days through the next 90 days. Refreshes reconcile changes and cancellations. Email suggestions use your chosen search in your Outlook Inbox and import up to 30 subjects and senders per refresh. Email bodies and attachments are not read. Lyceum does not send mail or edit your Outlook events.

Connection credentials are encrypted. Imported details belong to your Lyceum account and are not automatically sent to a model. A task you create from a message, or event information needed for a scheduling request, can be included when you ask the agent for help. Microsoft data is not used to train general-purpose AI models, sold, or used for advertising.

Message details no longer seen during refresh expire after 30 days. Disconnecting removes stored tokens, imported events and message details; tasks you added remain. You can also revoke access through your Microsoft account’s app permissions.

Optional Google connections

Connecting Google is separate from Canvas. Lyceum requests read access to your calendar list, calendar events and Gmail, plus your Google email address to identify the connection. You choose which calendars to include and whether to enable Gmail suggestions.

For selected calendars, Lyceum imports occupied time from the previous seven days through the next 90 days. Refreshes reconcile changed and cancelled events. Gmail suggestions use your chosen search and read up to 30 message senders, subjects and short previews per refresh. Full email bodies and attachments are not imported. Lyceum does not send email or edit Google events.

Google credentials are encrypted in the database. Imported previews are private to your Lyceum account. They are not automatically sent to a model. When you make a task from a message, or ask the agent to work with your schedule, the task or event information needed for that request can be included in the model call. Google data is not used to train general-purpose AI models, sold, or used for advertising. Lyceum’s use and transfer of Google API data follows the Google API Services User Data Policy, including its Limited Use requirements.

Message previews no longer seen during refresh are removed after 30 days. Disconnecting removes the stored Google tokens, imported events and message previews from Lyceum. Tasks you explicitly added remain yours. You can also revoke Lyceum’s access in your Google Account’s third-party connections.

Deleting it

Settings has a delete button. It removes the account and everything attached to it in one operation — coursework, materials, chats, artifacts and the grade history — and there is no undo and no backup copy kept for you. The grade history in particular cannot be reconstructed afterwards, because Canvas cannot be asked about the past.

What this does not promise

This is a personal project, not a company. There is no security team, no compliance certification, and no guarantee of uptime or of the data surviving. Keep Canvas as the record of your grades; treat this as a tool for deciding what to do next.

Course materials are indexed for the account that has access to them through Canvas. If a reading is copyrighted, this app holds a copy of its text for as long as your account does.