PRIVACY & PERMISSIONS
Know what stays.
Know what goes.
Updated October 11, 2026
No AI or developer data server
The extension runs deterministic workflows in Chrome. It has no AI model, advertising, analytics or academic-data collection server. Its installation website has no school-account sign-in or student-data forms. The hosting provider may process ordinary request information when serving the website.
How sensitive data is protected
Connections from the extension to Google APIs and supported Genesis pages use HTTPS, which encrypts data in transit. Google handles sign-in through Chrome OAuth; the extension does not ask for or collect your Google or Genesis password. Access tokens are handled in the extension background context and Chrome’s token cache, not placed in student reports, page URLs or public website requests.
Connected operations verify the Google account and the applicable school configuration or current Classroom teacher membership. Before a save or send, source, recipient and permission checks run again. Missing, stale or conflicting evidence stops the affected action. Only approved extension pages can request background operations; ordinary web pages cannot use that message interface. Extension storage access is restricted to trusted extension contexts, excluding injected content scripts.
Academic reports and message previews use temporary Chrome session storage and expiry checks; they are not stored in Chrome Sync or a developer database. Persistent duplicate-prevention receipts contain opaque fingerprints instead of student names, addresses, assignment text or message bodies. The extension has no AI processing, advertising, analytics or developer endpoint collecting academic records.
Local Chrome storage is not encrypted by the extension itself. Its protection depends on Chrome, the operating system and the security of the signed-in device. Disconnect clears temporary reports and cached authorization, while the retention rules below govern remaining local metadata. Google stores outputs you choose to create under its own account and school settings.
Local reports are temporary, not storage-free
Classroom reports and email previews expire after 15 minutes. They are removed on the next state or action check, Disconnect, or browser session end; an idle open dashboard also checks expiry periodically. Calendar reads use bounded session checkpoints. Preferences, connection metadata and opaque duplicate-send/draft receipts can remain locally; completed receipts are normally retained for 35 days and unresolved receipts are retained until resolved. Verified Google ID/email remain locally until Disconnect. Account-hashed receipt namespaces remain with duplicate-prevention records; uncertain legacy history blocks repeat sending. Closing a page is not the same as revoking Google access.
What each tool uses
- Calendar: approved Genesis staff identity, year, terms, teaching dates, classes and rooms; existing primary-calendar events for comparison. No student records enter Calendar.
- Missing work: your verified teaching courses, student names/emails, assignments, submission identifiers and rendered Missing labels. Grades/state may suppress inappropriate reminders; blank grades do not mean Missing. No student answers or attachments are requested.
- Quiz to Forms: files and text you choose are parsed locally. Reviewed question text, choices, supplied answer keys and points are sent to Google only when you import. Source files and image crops are not uploaded by the extension; add images manually in Google Forms.
- Role & task guide: public content and selections in page memory. A role choice never grants data access. Signature details stay in the page until you copy them; pasted signatures are then handled by your email provider.
Your chosen outputs
Calendar saves change Google Calendar. The separate Delete by event name option can delete eligible future events you organize, including events created outside this extension, only after preview and explicit confirmation. Forms import creates an unpublished Google Form and verifies the saved content; it does not publish or share it. Copying a message uses the clipboard. Open in Gmail passes its recipient and message through a Google compose URL, which may be handled by browser history and Gmail. Direct sending, where enabled, happens only after confirmation and source checks. No unattended or scheduled email is sent.
Permissions are separate
Google account identity binds connected operations. Classroom permissions apply to teaching courses; Calendar uses owned events; Forms uses the drive.file permission, which can manage files created by or explicitly opened with the app. This importer only creates and verifies a new unpublished Form; it does not browse Drive, read responses or delete files. Optional Gmail sending does not read your inbox. Google permissions and school policy still apply. Disconnect stops connected work and clears temporary reports/tokens; saved Google outputs stay. Quiz text, edits and image crops remain in page memory until you choose Clear this quiz or close the quiz page. Revoke OAuth grants through Google Account security settings.
Public links and school resources
External links open the named provider and follow its terms. Recommendations describe non-AI workflows; some products offer separate optional AI. Licensing and approval vary. This is not a blanket FERPA-compliance certification. Existing school Drive permissions remain enforced.
Contact
eguduk@cjcollegeprep.org. Describe problems without student records, passwords or access tokens. Google user data is used only for the visible requested features, consistent with the Google API Services User Data Policy, including Limited Use requirements.