SherpaBeta

What Sherpa stores

Sherpa keeps as little as it can get away with. Student trust is the whole product.

Stored

  • Your name and the email you signed up with
  • Your classification and major, if you gave them
  • Your calendar link, kept private and never shown in full
  • Task titles, due dates, instructions and attachment names from D2L — quizzes included, with their time limits and attempts
  • Rubrics attached to assignments, and events your professors put on the D2L calendar
  • The words inside files your professor attached, and on announcements, course pages and discussion prompts
  • The names of pages, files and folders in Content, and of the category each assignment is filed under, so Sherpa can tell which one is an assignment's instructions
  • The grades D2L publishes — for each course, and for each graded item in it — exactly as it publishes them
  • Whether and when D2L shows you handed each assignment in — not what you handed in
  • The written feedback your professor publishes on your graded work — just the words
  • Text from handouts, emails or class notes you add yourself
  • Notes you write yourself
  • Which tasks you've ticked off or removed
  • If you turn notifications on: the address your browser gives Sherpa to reach that device, and which kinds you want
  • If you record a class: the audio for 30 days, and its transcript, any notes you type during it, and the notes Sherpa writes from it until you delete them

Never stored

  • Your D2L password — Sherpa never sees it
  • Photos and PDFs you add — read for their words, then deleted (a big file waits in private storage only for the seconds it takes to read)
  • Files from D2L — read for their words, then discarded
  • What you submit — your files, your text, your comments
  • Files your professor attaches to feedback, and graders' private notes
  • Discussion replies — yours or anyone else's
  • Anything from courses you've hidden

Where your data lives. In a Postgres database hosted by Supabase, in the United States, with row-level security so your rows are only ever readable by your own signed-in session. Your profile photo is the exception: it stays in your browser and is never uploaded.

What the browser extension does. It reads your own D2L courses and sends what it finds to your own Sherpa account: assignment titles, due dates and instructions; your quizzes, with their time limits, attempts and when they open and close; the rubrics attached to assignments; the files your professor attached; announcements and Content pages, which is where more than half of all instructions actually live, including a file posted in Content when its name matches an assignment or the category it’s filed under; events your professors put on the D2L calendar, like an exam in class; the prompt your professor writes for each discussion, though never anyone’s replies to it; the grades D2L publishes for each course and each graded item in it; the written feedback your professor publishes on your graded work — the words only, never files attached to it or a grader’s private notes; and whether D2L shows each assignment as handed in, and when — never the work itself. It runs only on d2l.oru.edu, only ever reads, and has no way to submit work, post anywhere, or change anything in D2L. Attached files are sent once so their text can be pulled out, and the file itself is never kept — the same rule as a photo you add yourself. Grades are stored exactly as D2L reports them and are never estimated, averaged or predicted.

How Sherpa breaks an assignment down. When you open an assignment for the first time, its instructions are sent to OpenAI, which is the service that turns them into steps. The instructions for work due in the next few weeks are also sent, in the background, so Sherpa can estimate how long each will take — only the title and instructions (your professor’s, and any handout you added), never your notes or anything about you. The same happens to a photo or PDF you add — it is sent to be read, Sherpa keeps the words it found, and the file itself is never stored. Your photo stays where it already was, in your camera roll. OpenAI’s terms for this kind of access say data sent through it is not used to train their models.

Recording a class. Only when you press Record, and only until you press Done or cancel. Every thirty seconds the audio is sent to Sherpa as the recording itself, kept in your account, private to you, so you can play it back for 30 days — after that the audio is deleted and the transcript and notes stay — and sent to Groq (or OpenAI) to be turned into words. When you finish, the whole transcript — and any notes you typed while recording — is sent to OpenAI once more, so Sherpa can write it up as notes and look for anything said about your homework, which it only ever suggests; nothing is added unless you say so. Cancelling a recording, or deleting it later, deletes its audio, transcript and notes. Many schools and professors require permission to record a class; Sherpa asks you to confirm you have it before the first recording.

Live translation. Only while you record a class with translation turned on and the transcript open. A few seconds of audio at a time are sent to Groq (or OpenAI) to be turned into words, and those words to OpenAI to be translated. The translation is shown to you and not kept; the saved transcript stays in the class’s own language.

Dictating. Only while the mic beside a box is on. What you say is sent to Groq (or OpenAI) to be turned into words, with the names of your courses so they’re spelled right; the words go into the box, and the audio isn’t kept.

Notifications. Only if you turn them on, and only on the devices you turn them on for. They go through your browser’s own push service — Apple’s, Google’s or Mozilla’s — encrypted so that service can deliver them but can’t read them. They name an assignment or an announcement and its course; a grade notification says a grade was posted, never what it was. Turning them off in Settings, or in your browser, stops them.

When you ask Sherpa a question. Asking about an assignment sends what Sherpa has for that assignment to OpenAI to answer from. Asking about a whole course sends what it has for that course — the instructions, announcements, pages and dates, your posted grade, and your own notes and anything you added, each labelled as yours — but only when you ask, and only the course you asked about. Apart from a question you ask, your notes only go to OpenAI if you add them to an assignment’s Homework Context yourself, so its steps can be built from them. Questions and answers aren’t saved.

Who else sees it. Nobody beyond that. Your coursework is not sold or shared, there is no advertising and no third-party analytics. Email delivery (Resend), hosting (Vercel, Supabase), OpenAI, and Groq for transcribing recorded classes, dictation and live translation are the only ones involved, and each only ever handles what it needs to do its job.

Deleting it. Settings → Delete my account removes everything Sherpa holds for you, immediately and for real. Your work in D2L is untouched.

Questions, or something here that looks wrong? Settings → Help center has a way to reach the person who builds Sherpa.