What Gradeshuttle handles
Gradeshuttle reads a page only when a teacher presses Grab or Fill. Its page script is injected at that moment. Nothing runs in the background, and there are no content scripts on every page.
| Data | Why | Where it’s kept | How long | Sent anywhere? |
|---|---|---|---|---|
| Student names on the clicked rows | To match students between the two systems | Browser memory (storage.session, extension-only) | Until Chrome closes, the teacher presses Clear, or 60 min (you can set less) | No |
| The one grade per student in the clicked column | To type it into the gradebook | Same as above | Same as above | No |
| Page host name and column title | So the teacher sees where data came from | Same as above | Same as above | No |
| Remembered matches (opt-in, Pro) | To skip re-fixing the same name next time | The device, as keyed HMAC codes, not names | Until July 31 (end of the school year). Off by default on School and District licenses. | No |
| Settings and license key | Preferences and plan | The device | Until removed | No |
| Transfer receipt (optional CSV) | The teacher’s record of a fill | Wherever the teacher saves it | Your records policy applies | No (a local download) |
Gradeshuttle never reads other columns, other pages, cookies, passwords, browsing history or the clipboard. It never presses the gradebook’s Save button.
How data flows
How the “nothing is sent” claim is enforced:
- Extension pages: Content Security Policy
connect-src 'none', so the side panel and service worker cannot open a network connection. - Page-reading script: contains no network APIs (
fetch, XHR, WebSocket, beacons, form submission, remote images). A release gate scans every build and fails it if any appear. - Behaviour test: an automated test loads the extension in Google Chrome, performs a grab and a fill, and confirms no network requests were made.
- No remote code: Manifest V3 and no
eval. Every rule ships inside the reviewed package.
Controls for IT
Set these through Chrome’s managed policy for the extension. Teachers see a “managed by your school” note where a setting is locked.
| Policy key | What it does | Default |
|---|---|---|
licenseKey | Turns on School or District features for every teacher who gets the policy | none |
allowedSites | Host names Gradeshuttle may read or fill, e.g. *.powerschool.com. Everything else is refused. | any site the teacher allows |
lockSettings | Teachers can’t change the defaults you set | false |
autoClearMinutes | Erase grabbed data after this many minutes; also the maximum teachers can pick | 60 |
allowNameMemory | Allow remembered matches | off for School/District |
allowReceipts | Allow CSV receipt downloads | true |
allowOverwrite | Allow replacing grades already in the gradebook | true (but off until a teacher ticks it) |
matchStrictness | strict, balanced or loose | balanced |
missingAs, excusedAs | What to type for Missing and Excused work (empty = skip and flag) | skip |
roundingDecimals | Round values to 0–2 decimals | no rounding |
supportContact | Your help desk, shown in Gradeshuttle’s help | none |
Deploy with Google Admin
- In the Google Admin console, go to Devices › Chrome › Apps & extensions › Users & browsers and select the organizational unit for teachers.
- Add Gradeshuttle from the Chrome Web Store by ID (
[extension ID, published at launch]) and set it to Force install. Pinning it to the toolbar helps. - Under Policy for extensions, paste your configuration (template below) with the license key we send you.
- Optional: under the extension’s Permissions and URL access, limit site access to your LMS and SIS hosts. This works alongside
allowedSites. - Ask two or three teachers to run a transfer on a test section. Rollout usually takes an afternoon.
{
"licenseKey": { "Value": "GSK1.your-district-key" },
"allowedSites": { "Value": ["classroom.google.com", "*.instructure.com", "*.powerschool.com", "sis.yourdivision.ab.ca"] },
"lockSettings": { "Value": true },
"allowNameMemory": { "Value": false },
"allowReceipts": { "Value": true },
"allowOverwrite": { "Value": false },
"autoClearMinutes": { "Value": 30 },
"matchStrictness": { "Value": "balanced" },
"missingAs": { "Value": "" },
"supportContact": { "Value": "Division IT Service Desk, ext. 4400" }
}
Microsoft Edge works too: use the same JSON in Edge’s extension policy.
Alberta: POPA & PIPA
Which law applies
- Public, separate and Francophone school boards and charter schools come under the Protection of Privacy Act (POPA), in force since June 11, 2025. It replaced the privacy parts of FOIP, and access requests moved to the Access to Information Act (OIPC, alberta.ca).
- Independent schools (called private schools before September 1, 2025) come under the Personal Information Protection Act (PIPA).
- Board student-record policies must comply with POPA under the Student Record Regulation.
What that likely means for adopting Gradeshuttle
- The Protection of Privacy (Ministerial) Regulation treats information about minors as high sensitivity. A school authority adding Gradeshuttle as a new practice will probably need a privacy impact assessment (PIA), submitted to the OIPC, and an entry in its privacy management program. Confirm with your privacy office.
- Gradeshuttle keeps everything on the teacher’s device, in Canada for Alberta users, and nothing goes to a vendor. That makes the PIA shorter: there’s no service provider holding student data, no cross-border storage, no sale, no secondary use and no profiling.
- After the OIPC’s 2025 PowerSchool investigation and its April 2026 guidance on contracting service providers, expect your contracts office to want written privacy and security terms anyway. We provide them.
What we give Alberta school authorities
- A PIA support pack organized to follow the OIPC’s POPA PIA template: data inventory, data flow, authority notes, safeguards, retention, and a risk register with mitigations.
- A privacy schedule for POPA (with a PIPA version for independent schools) committing us to no collection, no sale, no secondary use, breach notice and audit cooperation.
- Security questionnaire answers and our incident response plan.
- Policy controls to enforce your decisions: allowed sites, a shorter auto-clear, memory off, receipts off and locked settings.
French-language support is on our roadmap for Francophone authorities.
United States
- FERPA: Gradeshuttle never receives education records. Data moves inside the teacher’s browser between systems the school already uses. Where your district treats Gradeshuttle as a school official, our terms cover direct control, no re-disclosure and use only for the stated purpose.
- State laws such as California’s SOPIPA, New York Education Law 2-d and Illinois SOPPA: no targeted advertising, no profiling, no sale and no student data stored by us. We’re glad to review your state’s standard data privacy agreement.
- COPPA: Gradeshuttle is used by teachers and collects nothing from children.
Security practices
| Practice | Status |
|---|---|
Manifest V3, no remote code, no eval | In place |
Strict CSP with connect-src 'none' | In place |
| Release gate: no network APIs, minimal permissions, no secrets in the package | In place |
| Real-browser test asserting zero network requests during grab and fill | In place |
| Optional site access requested at runtime; no install-time host permissions | In place |
| Offline license checks; teacher keys contain no personal data | In place |
| Publisher account: group with 2+ owners and hardware security keys, verified uploads | Set up at launch |
| Reproducible builds with published SHA-256 hashes | In place |
Vulnerability disclosure policy and security.txt | Published |
| Independent code review or penetration test | Planned before the first district contract |
| SOC 2 | Not applicable: we run no hosted service that holds customer data |
The most realistic risk for any browser extension is a hijacked update. Our security page explains how we guard against that and what we would do if it happened.
Documents & pilot
- PIA support pack (POPA and PIPA, with a FERPA crosswalk)
- Privacy schedule / DPA template
- Security questionnaire answers (HECVAT-lite / SDPC style)
- Incident response plan summary
- Google Admin policy template (above)
We send the pack the same week you ask. A pilot is free for 30 days, for up to 25 teachers, and includes a 45-minute training session.