Acceptable Use Policy
What you may not do with CourseLite.
Effective date: 4 September 2026 Last revised: 4 September 2026
This policy is part of the Terms of Service. Breaking it is a breach of those Terms and can cost you your account.
It is written in plain language on purpose. If a rule below is unclear, ask us at support@courselite.org before doing the thing.
The one-line version
Use CourseLite on your own courses, from your own account, at human speed, and follow your school's rules. Almost everything below follows from that.
1. No malicious uploads
Do not use CourseLite to introduce anything harmful.
You must not add, upload, or point CourseLite at:
- malware, viruses, worms, ransomware, spyware, or anything designed to damage or gain unauthorised access to a system;
- files crafted to break a parser — a decompression bomb, a file that lies about its type, a document engineered to exhaust memory or CPU; or
- content designed to make CourseLite generate something it would otherwise refuse, or to manipulate the AI into acting against another user's interests.
Why this matters here. CourseLite does not have a file-upload endpoint. Your files are opened in your own browser and only extracted text crosses the network. That removes a lot of risk and none of this rule: a crafted file can still attack your own browser, and a document that carries instructions aimed at the model is still an attack on the product.
If you find a way to break something, that is a security report, not a licence. Send it to security@courselite.org — see SECURITY.md.
2. No unauthorised access
Do not try to reach anything you were not given.
You must not:
- access, or try to access, any account, course, document, draft or record that is not yours;
- probe, scan or test the security of the Service, or of the systems it runs on, without our written permission;
- get around, disable or interfere with any authentication, authorisation, rate limit, or quota check;
- modify, tamper with, or replay a request in order to make the Service act as another user; or
- access the Service by any means other than the interfaces we provide — the web app, the official extension, and the documented API.
Every record in CourseLite belongs to exactly one account, and a request for somebody else's record is answered as though the record does not exist. Trying to find out otherwise is a breach of this policy whether or not it works.
3. No credential theft, and no borrowed accounts
You must not:
- collect, guess, buy, or otherwise obtain another person's sign-in details for CourseLite, for Canvas, for Google, or for anything else;
- use another person's account, or let another person use yours;
- sell, rent, or share access to a CourseLite account; or
- phish anybody, or build anything with CourseLite that helps you phish anybody.
CourseLite never asks for your Canvas password and never receives it. The extension reads Canvas using the session already in your browser; your Canvas credentials never leave your machine. If anything ever asks you for your Canvas password on our behalf, it is not us — report it to support@courselite.org.
The same is true of Google. CourseLite never sees your Google password, and its Google permission covers only files it creates or that you pick.
4. Do not misuse the browser extension
The extension runs inside your browser, with your access. Keep it honest.
You must not:
- install or run the extension on a device or browser profile that is not yours, or on an account you are not authorised to use;
- modify, repackage, decompile, or redistribute the extension, or ship a modified build to anyone;
- use the extension against a Canvas instance you do not have a legitimate account on;
- use it to crawl, scrape, mirror, or bulk-download a Canvas instance, or to extract material for anyone other than yourself;
- use it to gather material for redistribution, resale, or a dataset; or
- run it in a way that puts load on your university's systems beyond what a student using their own courses would produce.
Read-only, and only your courses. The extension makes read requests to Canvas and nothing else. There is no write path. Using it to do something Canvas would not let you do by hand is out of bounds even if a bug makes it possible.
5. Do not access another student's information
CourseLite is for your own coursework.
You must not use it to view, collect, index, store, or generate material from:
- another student's submissions, drafts, grades, feedback, or personal information;
- a discussion, group space, or shared drive containing other students' personal information, where processing it would breach your school's rules or a privacy law that applies to you; or
- anything that identifies another person and that you were given access to for a different purpose.
If your course material happens to contain other people's names — an instructor's, a classmate's in a discussion thread — do not go out of your way to extract, aggregate or generate content about them.
FERPA and equivalents. Student records are protected in many countries. Your own record is yours; somebody else's is not, and having access to it through a shared course space is not permission to feed it into a tool.
6. No illegal or infringing content
You must not use CourseLite to store, process, or generate:
- anything illegal where you are, or where we operate;
- material that infringes a copyright, trademark, patent, trade secret, or moral right;
- material you have obtained by breaking an access control, a paywall, or a licence — including textbooks or course packs you did not lawfully obtain;
- child sexual abuse material, which we report to the authorities without notice and which ends your account permanently;
- content that harasses, threatens, defames, or incites violence against a person or group; or
- content that violates somebody's privacy rights.
Only bring in material you have lawful access to. CourseLite reads your course through your own account. That your account can open a file does not always mean you may copy or redistribute it — check your institution's rules and the material's own licence.
7. No automated abuse
CourseLite is priced and built for one person studying.
You must not:
- use bots, scripts, headless browsers, or automated agents to drive the Service;
- generate requests at a rate no person could produce;
- run load tests, stress tests, or benchmarks against our systems;
- build a wrapper, proxy, or reseller that puts other people's traffic through your account; or
- use the Service to make bulk requests to an AI provider on our account.
Fair use. Where a plan says a feature is unlimited, that means we do not meter it against a published number — not that we will serve a script. There is an internal ceiling, set far above what a person studying can reach, and exceeding it can pause the feature on your account. We do not publish the number. If it ever trips for you and that seems wrong, contact us and we will fix it.
8. No quota evasion, and no throwaway accounts
The Free plan exists so a student can see whether CourseLite works on a real course. It is not a supply of free capacity.
You must not:
- create more than one account in order to get more free allowance;
- create accounts to reset an allowance you have used;
- delete an account and sign up again to reset a free allowance;
- use disposable or throwaway email addresses to obtain repeated free allowances;
- share one paid account among several people; or
- otherwise circumvent, or try to circumvent, any plan limit, quota, rate limit, or fair-use ceiling.
What we check, and what we deliberately do not. To enforce this, CourseLite records irreversible one-way hashes of relationships you chose — your CourseLite account, your verified email, your Canvas login, and a random installation identifier. A fifth, your Google account, is provided for in the code and is never actually used, because CourseLite is not told which Google account you connected (see the Privacy Policy, section 3.5). It does not fingerprint your device: no canvas rendering, no fonts, no audio, no WebGL, no battery, no screen geometry, no browsing history, no extension list, no cross-site tracking, and no behavioural biometrics. These are absent by design. A shared IP address contributes only to rate limiting and can never on its own deny you anything. See docs/ABUSE.md.
If we get it wrong, tell us. A refusal always names a stable code, a reset date, and whether paying fixes it. If you think a limit has been applied to you incorrectly, contact support@courselite.org and an operator can release it.
9. No impersonation
You must not:
- pretend to be another person, another student, an instructor, an administrator, or a member of CourseLite staff;
- misrepresent your age in order to create an account — CourseLite is for people aged 13 and over, and confirming that you are 13 or older when you are not is a breach of this policy and of the Terms;
- misrepresent your affiliation with a school, an organisation, or with us;
- use CourseLite to produce work that you present as somebody else's, or that somebody else presents as their own where that is not allowed;
- sit an assessment, complete coursework, or communicate on behalf of another student; or
- build, name, or brand anything so as to suggest it is CourseLite, or that CourseLite endorses it.
CourseLite is not affiliated with Canvas, Instructure, Blackboard, Moodle, or any university. Do not suggest otherwise, and do not use our name or marks to imply a partnership, an endorsement, or an official integration.
10. Do not use CourseLite to submit work automatically
CourseLite has no submission path, and this rule exists so nobody builds one around it.
You must not:
- build, use, or distribute any tool, script, extension, macro or automation that takes CourseLite output and submits it to Canvas, or to any other learning management system, assessment platform, or instructor;
- automate the step between "CourseLite produced a draft" and "the work was handed in"; or
- use CourseLite in any workflow where work is submitted without a person reading it first.
The student presses submit, every time, having read what they are submitting. That is not a feature we forgot; it is the boundary the product is built around. See the Academic Integrity Policy.
11. Do not represent AI output as guaranteed correct
You must not:
- present CourseLite output as verified, fact-checked, reviewed, or approved by us;
- state or imply that CourseLite guarantees accuracy, correctness, originality, or any grade;
- republish generated material as authoritative — as a study guide sold to other students, a course resource, a reference work, or professional advice; or
- remove or contradict a disclaimer we show alongside generated content.
Generated text can be wrong, incomplete, out of date, or fabricated. It is a draft for you to check, and that is how it must be described wherever it goes.
12. What happens if you break this policy
Depending on what happened and how serious it is, we may:
- contact you and ask you to stop;
- rate-limit, pause, or restrict a feature on your account;
- remove material that breaches this policy;
- suspend your account; or
- terminate your account permanently.
For serious abuse — attacking the Service, trying to reach data that is not yours, automated abuse at scale, or illegal content — we may act immediately and without notice, and we may report it to law enforcement or to your institution where the law requires it or where somebody is at risk.
If we end your account for a breach, we do not owe you a refund for the rest of a paid period, except where a consumer-protection law says otherwise.
13. Reporting a problem
| What | Where |
|---|---|
| Somebody misusing CourseLite | support@courselite.org |
| A security vulnerability | security@courselite.org — see SECURITY.md |
| A copyright complaint | support@courselite.org |
| A limit you think was applied wrongly | support@courselite.org |
We may update this policy. The current version, with its effective date, is always the one that applies.