For IT & privacy officers

Approve it once. Roll it out in an afternoon.

Gradeshuttle has no servers, no accounts and no analytics, so there’s no vendor database of your students. This page gives you what a privacy review needs: what the extension touches, the controls you get, and the documents we provide.

What Gradeshuttle handles

Gradeshuttle reads a page only when a teacher presses Grab or Fill. Its page script is injected at that moment. Nothing runs in the background, and there are no content scripts on every page.

DataWhyWhere it’s keptHow longSent anywhere?
Student names on the clicked rowsTo match students between the two systemsBrowser memory (storage.session, extension-only)Until Chrome closes, the teacher presses Clear, or 60 min (you can set less)No
The one grade per student in the clicked columnTo type it into the gradebookSame as aboveSame as aboveNo
Page host name and column titleSo the teacher sees where data came fromSame as aboveSame as aboveNo
Remembered matches (opt-in, Pro)To skip re-fixing the same name next timeThe device, as keyed HMAC codes, not namesUntil July 31 (end of the school year). Off by default on School and District licenses.No
Settings and license keyPreferences and planThe deviceUntil removedNo
Transfer receipt (optional CSV)The teacher’s record of a fillWherever the teacher saves itYour records policy appliesNo (a local download)

Gradeshuttle never reads other columns, other pages, cookies, passwords, browsing history or the clipboard. It never presses the gradebook’s Save button.

How data flows

How the “nothing is sent” claim is enforced:

  • Extension pages: Content Security Policy connect-src 'none', so the side panel and service worker cannot open a network connection.
  • Page-reading script: contains no network APIs (fetch, XHR, WebSocket, beacons, form submission, remote images). A release gate scans every build and fails it if any appear.
  • Behaviour test: an automated test loads the extension in Google Chrome, performs a grab and a fill, and confirms no network requests were made.
  • No remote code: Manifest V3 and no eval. Every rule ships inside the reviewed package.

Controls for IT

Set these through Chrome’s managed policy for the extension. Teachers see a “managed by your school” note where a setting is locked.

Policy keyWhat it doesDefault
licenseKeyTurns on School or District features for every teacher who gets the policynone
allowedSitesHost names Gradeshuttle may read or fill, e.g. *.powerschool.com. Everything else is refused.any site the teacher allows
lockSettingsTeachers can’t change the defaults you setfalse
autoClearMinutesErase grabbed data after this many minutes; also the maximum teachers can pick60
allowNameMemoryAllow remembered matchesoff for School/District
allowReceiptsAllow CSV receipt downloadstrue
allowOverwriteAllow replacing grades already in the gradebooktrue (but off until a teacher ticks it)
matchStrictnessstrict, balanced or loosebalanced
missingAs, excusedAsWhat to type for Missing and Excused work (empty = skip and flag)skip
roundingDecimalsRound values to 0–2 decimalsno rounding
supportContactYour help desk, shown in Gradeshuttle’s helpnone

Deploy with Google Admin

  1. In the Google Admin console, go to Devices › Chrome › Apps & extensions › Users & browsers and select the organizational unit for teachers.
  2. Add Gradeshuttle from the Chrome Web Store by ID ([extension ID, published at launch]) and set it to Force install. Pinning it to the toolbar helps.
  3. Under Policy for extensions, paste your configuration (template below) with the license key we send you.
  4. Optional: under the extension’s Permissions and URL access, limit site access to your LMS and SIS hosts. This works alongside allowedSites.
  5. Ask two or three teachers to run a transfer on a test section. Rollout usually takes an afternoon.
{
  "licenseKey":       { "Value": "GSK1.your-district-key" },
  "allowedSites":     { "Value": ["classroom.google.com", "*.instructure.com", "*.powerschool.com", "sis.yourdivision.ab.ca"] },
  "lockSettings":     { "Value": true },
  "allowNameMemory":  { "Value": false },
  "allowReceipts":    { "Value": true },
  "allowOverwrite":   { "Value": false },
  "autoClearMinutes": { "Value": 30 },
  "matchStrictness":  { "Value": "balanced" },
  "missingAs":        { "Value": "" },
  "supportContact":   { "Value": "Division IT Service Desk, ext. 4400" }
}

Microsoft Edge works too: use the same JSON in Edge’s extension policy.

Alberta: POPA & PIPA

This section summarizes our reading of current law to help your review. It isn’t legal advice; your privacy office makes the call.

Which law applies

  • Public, separate and Francophone school boards and charter schools come under the Protection of Privacy Act (POPA), in force since June 11, 2025. It replaced the privacy parts of FOIP, and access requests moved to the Access to Information Act (OIPC, alberta.ca).
  • Independent schools (called private schools before September 1, 2025) come under the Personal Information Protection Act (PIPA).
  • Board student-record policies must comply with POPA under the Student Record Regulation.

What that likely means for adopting Gradeshuttle

  • The Protection of Privacy (Ministerial) Regulation treats information about minors as high sensitivity. A school authority adding Gradeshuttle as a new practice will probably need a privacy impact assessment (PIA), submitted to the OIPC, and an entry in its privacy management program. Confirm with your privacy office.
  • Gradeshuttle keeps everything on the teacher’s device, in Canada for Alberta users, and nothing goes to a vendor. That makes the PIA shorter: there’s no service provider holding student data, no cross-border storage, no sale, no secondary use and no profiling.
  • After the OIPC’s 2025 PowerSchool investigation and its April 2026 guidance on contracting service providers, expect your contracts office to want written privacy and security terms anyway. We provide them.

What we give Alberta school authorities

  • A PIA support pack organized to follow the OIPC’s POPA PIA template: data inventory, data flow, authority notes, safeguards, retention, and a risk register with mitigations.
  • A privacy schedule for POPA (with a PIPA version for independent schools) committing us to no collection, no sale, no secondary use, breach notice and audit cooperation.
  • Security questionnaire answers and our incident response plan.
  • Policy controls to enforce your decisions: allowed sites, a shorter auto-clear, memory off, receipts off and locked settings.

French-language support is on our roadmap for Francophone authorities.

United States

  • FERPA: Gradeshuttle never receives education records. Data moves inside the teacher’s browser between systems the school already uses. Where your district treats Gradeshuttle as a school official, our terms cover direct control, no re-disclosure and use only for the stated purpose.
  • State laws such as California’s SOPIPA, New York Education Law 2-d and Illinois SOPPA: no targeted advertising, no profiling, no sale and no student data stored by us. We’re glad to review your state’s standard data privacy agreement.
  • COPPA: Gradeshuttle is used by teachers and collects nothing from children.

Security practices

PracticeStatus
Manifest V3, no remote code, no evalIn place
Strict CSP with connect-src 'none'In place
Release gate: no network APIs, minimal permissions, no secrets in the packageIn place
Real-browser test asserting zero network requests during grab and fillIn place
Optional site access requested at runtime; no install-time host permissionsIn place
Offline license checks; teacher keys contain no personal dataIn place
Publisher account: group with 2+ owners and hardware security keys, verified uploadsSet up at launch
Reproducible builds with published SHA-256 hashesIn place
Vulnerability disclosure policy and security.txtPublished
Independent code review or penetration testPlanned before the first district contract
SOC 2Not applicable: we run no hosted service that holds customer data

The most realistic risk for any browser extension is a hijacked update. Our security page explains how we guard against that and what we would do if it happened.

Documents & pilot

  • PIA support pack (POPA and PIPA, with a FERPA crosswalk)
  • Privacy schedule / DPA template
  • Security questionnaire answers (HECVAT-lite / SDPC style)
  • Incident response plan summary
  • Google Admin policy template (above)

We send the pack the same week you ask. A pilot is free for 30 days, for up to 25 teachers, and includes a 45-minute training session.