unicorn runs on your own Cloudflare account and holds your course data there. Nobody else operates it, and there is no unicorn service in the middle. This page says what it keeps, what it can and cannot do, and how to shut access off.

What is stored, and where

unicorn keeps no copy outside your Cloudflare account. It makes no calls to any AI service. Your agent’s provider sees whatever your agent reads from unicorn during a chat, under that provider’s terms, the same as anything else you share with it.

It cannot write to your sources

unicorn reads from Ed, Moodle, Canvas and Gmail. It has no code path that posts a thread, submits work, changes a grade, replies to a message or sends mail. The consent text shown when you connect an app says so: it can read your unicorn memory and update unicorn’s own state, never your sources. What unicorn does write is its own state: briefs, plans, labels on items, and corrections you ask your agent to save. One caveat applies to feeds. A manifest that reads from a remote MCP server calls whichever tool the manifest names. The built-in sources only read. Install a manifest you did not write only after you have read what it calls.

Who can read your memory

Both tokens are random and long when the installer makes them. Neither is printed again after install, except the Connect your agent card, which shows the MCP token to you when you are signed in to the settings page. The admin token is shown nowhere. Approving a new app needs the admin token, so a stranger who finds your Worker address cannot add an app. A stranger can register a name for an app, up to 20 of them, but cannot get access from it.

Tokens

Treat both tokens like passwords. Keep them in a password manager. Do not paste them into a shared chat or commit them. To replace the MCP token:
Apps that used the old one must be given the new one. Replace the admin token the same way with ADMIN_TOKEN. Credentials you saved in the settings page are encrypted with a key from the admin token, so after you replace it they show as needing re-entry and you must paste them again. See Troubleshooting.

Revoke access

  • One app: open the settings page and remove it under Connected apps. The app has to ask for approval again.
  • A source: click Disconnect on its card, and revoke the credential at the source: delete the Ed token, sign out of Moodle, delete the Canvas token, or remove unicorn’s access at myaccount.google.com/permissions.
  • Everything: replace both tokens, then delete the Worker and the database in the Cloudflare dashboard.

What unicorn needs from you

  • Use a long, unique admin token and keep it private.
  • Give Ed, Canvas and Moodle credentials the least access they allow. unicorn only reads, but the credential itself may do more.
  • Share the deployment with no one. It is built for one student, and anyone who has the admin token can approve an app that reads everything in it.