Skip to main content
  • _csp_line_me_R_ti_p__40uhl4994a
Languages

Privacy Policy - Satit Chula Classroom Tools

Effective date: 1 September 2026

This policy describes what the Satit Chula Classroom Tools Chrome extension does, what data it touches, and who controls it. It is written to match the software exactly.

Who is who

Developer

Loxley Orbit, who built and maintains the extension and backend software.

Operator / Data Controller

โรงเรียนสาธิตจุฬาลงกรณ์มหาวิทยาลัย ฝ่ายมัธยม (Chulalongkorn University Demonstration School, Secondary Division). The school runs its own copy of the backend and database, inside its own Google Cloud project, administered by its own Google Workspace staff. Loxley Orbit does not operate the school's deployment and does not have standing access to the data it holds.

Contact

support@loxleyorbit.com

Who uses this extension

Only used at the school account profile. It is installed on every user’s School account Chrome profiles, and every use of it requires signing in with a @satitm.chula.ac.th Google account. Any student data it touches is data the school already holds in Google Classroom, processed here on the school's own authority as the institution that runs the class — the same basis on which the school already keeps attendance and coursework records without asking each student to separately consent to Google Classroom itself.

What the extension does

Three things, all on classroom.google.com:

  1. Re-colours Classroom's interface with the school's own branding.

  2. Lets a teacher mark students Present/Absent on the People tab, and shows a past-attendance report.

  3. Shows a traffic-light indicator next to an assignment's due-date field, summarising how many other assignments students already have due that day.

What data is collected, and where it goes

1. Sign-in

When a teacher clicks Sign in, the extension asks Google for an identity token (via chrome.identity), requesting only the openid, email, and profile scopes — the same non-sensitive information used to prove who is signing in. This token is:stored in the browser's session storage, cleared when the browser session ends;sent only to the school's own backend, over HTTPS, as proof of identity on each request;verified there against Google directly, checked for a @satitm.chula.ac.th address, and never stored in the database. There is no server-side log of "who marked this attendance" — the school's records identify a day and a course, not the staff member who entered it.

The extension never receives, stores, or transmits a Google password.

2. Attendance records

When a teacher marks students and saves, the extension sends: each student's Classroom-assigned ID, their display name as shown in Classroom, the mark (Present / Absent / Late / Excused), and an optional note. This is stored in the school's own Firestore database (Google Cloud, Bangkok region), keyed by course and date. It is read back only when a teacher with a valid school sign-in requests attendance for that course.

Retention: attendance records are kept indefinitely by default — there is currently no automatic deletion. The school's administrator has direct control of the Firestore database and can delete records at any time; this is a known limitation the school should be aware of when deciding how long to keep records.

3. Reading Google Classroom

To show the workload indicator, the backend reads course rosters and coursework due-dates from the Google Classroom API. This is done as the signed-in teacher, through domain-wide delegation configured by the school's own Workspace administrator — not through one shared account that can see everyone's classes. The teacher only ever sees data for courses they already have access to in Classroom. Access is strictly read-only: this software cannot create, edit, or delete anything in Google Classroom. The scopes used are:

  • classroom.courses.readonly

  • classroom.rosters.readonly

  • classroom.coursework.students.readonly

A short-lived cache (5 minutes) of "how many assignments are due on this date" is kept in Firestore to avoid repeated Classroom API calls; it holds no more than the due-date summary already described.

What is never collected

The extension does not use analytics, advertising, or tracking of any kind. It does not read email, files, calendars, or anything outside classroom.google.com. It does not execute code fetched from anywhere at runtime — everything it can run ships inside the extension package reviewed by the Chrome Web Store.

Sharing

Data is shared only with:Google, as the operator of Classroom, Firestore, and the identity service that verifies sign-in — this is inherent to how the tool functions, not an additional disclosure.The school itself, since the school runs and owns the backend and database this data lives in.

Data is never sold, and never shared with any other third party.

Security

All traffic between the extension, the backend, and Google's APIs is encrypted in transit (HTTPS/TLS). Firestore encrypts data at rest by default. The backend refuses every data request that does not carry a valid, verified Google sign-in token for the school's domain — including from the extension itself if a token is missing or invalid.

Children's privacy

The school is a secondary school; some students whose names appear in attendance records are minors. Data about students is processed by the school, for the school's own educational administration, under the school's own legal basis for keeping such records — the same basis it already relies on to operate Google Classroom itself. Families with questions about how the school handles their child's records should contact the school directly at the address above.

Changes to this policy

If what the extension collects or how it is used changes materially, this document will be updated and the effective date above will change. Continued use of the extension after an update constitutes acceptance of the revised policy.

Contact

Questions, requests to review or delete data, or concerns about this policy: saran.o@satitm.chula.ac.th

Satit Chula Classroom Tools — developed by Loxley Orbit, operated by Chulalongkorn Univeristy Demonstration School (Secondary)