Privacy Policy - Satit Chula Classroom Tools
Effective date: 1 September 2026
This policy describes what the Satit Chula Classroom Tools Chrome extension does, what data it touches, and who controls it. It is written to match the software exactly.
Who is who
Developer | Loxley Orbit, who built and maintains the extension and backend software. |
Operator / Data Controller | โรงเรียนสาธิตจุฬาลงกรณ์มหาวิทยาลัย ฝ่ายมัธยม (Chulalongkorn University Demonstration School, Secondary Division). The school runs its own copy of the backend and database, inside its own Google Cloud project, administered by its own Google Workspace staff. Loxley Orbit does not operate the school's deployment and does not have standing access to the data it holds. |
Contact | support@loxleyorbit.com |
Who uses this extension
Only used at the school account profile. It is installed on every user’s School account Chrome profiles, and every use of it requires signing in with a @satitm.chula.ac.th Google account. Any student data it touches is data the school already holds in Google Classroom, processed here on the school's own authority as the institution that runs the class — the same basis on which the school already keeps attendance and coursework records without asking each student to separately consent to Google Classroom itself.
What the extension does
Three things, all on classroom.google.com:
Re-colours Classroom's interface with the school's own branding.
Lets a teacher mark students Present/Absent on the People tab, and shows a past-attendance report.
Shows a traffic-light indicator next to an assignment's due-date field, summarising how many other assignments students already have due that day.
What data is collected, and where it goes
1. Sign-in
When a teacher clicks Sign in, the extension asks Google for an identity token (via chrome.identity), requesting only the openid, email, and profile scopes — the same non-sensitive information used to prove who is signing in. This token is:stored in the browser's session storage, cleared when the browser session ends;sent only to the school's own backend, over HTTPS, as proof of identity on each request;verified there against Google directly, checked for a @satitm.chula.ac.th address, and never stored in the database. There is no server-side log of "who marked this attendance" — the school's records identify a day and a course, not the staff member who entered it.
The extension never receives, stores, or transmits a Google password.
2. Attendance records
When a teacher marks students and saves, the extension sends: each student's Classroom-assigned ID, their display name as shown in Classroom, the mark (Present / Absent / Late / Excused), and an optional note. This is stored in the school's own Firestore database (Google Cloud, Bangkok region), keyed by course and date. It is read back only when a teacher with a valid school sign-in requests attendance for that course.
Retention: attendance records are kept indefinitely by default — there is currently no automatic deletion. The school's administrator has direct control of the Firestore database and can delete records at any time; this is a known limitation the school should be aware of when deciding how long to keep records.
3. Reading Google Classroom
To show the workload indicator, the backend reads course rosters and coursework due-dates from the Google Classroom API. This is done as the signed-in teacher, through domain-wide delegation configured by the school's own Workspace administrator — not through one shared account that can see everyone's classes. The teacher only ever sees data for courses they already have access to in Classroom. Access is strictly read-only: this software cannot create, edit, or delete anything in Google Classroom. The scopes used are:
classroom.courses.readonly
classroom.rosters.readonly
classroom.coursework.students.readonly
A short-lived cache (5 minutes) of "how many assignments are due on this date" is kept in Firestore to avoid repeated Classroom API calls; it holds no more than the due-date summary already described.
What is never collected
The extension does not use analytics, advertising, or tracking of any kind. It does not read email, files, calendars, or anything outside classroom.google.com. It does not execute code fetched from anywhere at runtime — everything it can run ships inside the extension package reviewed by the Chrome Web Store.
Sharing
Data is shared only with:Google, as the operator of Classroom, Firestore, and the identity service that verifies sign-in — this is inherent to how the tool functions, not an additional disclosure.The school itself, since the school runs and owns the backend and database this data lives in.
Data is never sold, and never shared with any other third party.
Security
All traffic between the extension, the backend, and Google's APIs is encrypted in transit (HTTPS/TLS). Firestore encrypts data at rest by default. The backend refuses every data request that does not carry a valid, verified Google sign-in token for the school's domain — including from the extension itself if a token is missing or invalid.
Children's privacy
The school is a secondary school; some students whose names appear in attendance records are minors. Data about students is processed by the school, for the school's own educational administration, under the school's own legal basis for keeping such records — the same basis it already relies on to operate Google Classroom itself. Families with questions about how the school handles their child's records should contact the school directly at the address above.
Changes to this policy
If what the extension collects or how it is used changes materially, this document will be updated and the effective date above will change. Continued use of the extension after an update constitutes acceptance of the revised policy.
Contact
Questions, requests to review or delete data, or concerns about this policy: saran.o@satitm.chula.ac.th
Satit Chula Classroom Tools — developed by Loxley Orbit, operated by Chulalongkorn Univeristy Demonstration School (Secondary)
