Privacy Policy & FERPA Compliance Statement
CueBoard — Canvas Quiz Note Dock & Proctor Review
Last Revised: September 30, 2026 • Applies to v1.2.0 and higher
Summary
Everything CueBoard keeps on a device is encrypted, and everything it sends to the cloud is encrypted on the device first. To share a teacher's settings with students and deliver student notes to the teacher, CueBoard stores encrypted records in a Google Firebase project (Cloud Firestore) run by the developer. Google hosts the data but cannot read it. There are no analytics, ads, or third-party scripts. The full, always-available version is in the extension (privacy.html), linked from the notes panel, the teacher settings card, and the popup.
1. What is stored
On the device (AES-GCM encrypted, chrome.storage.local): notes (drafts and locked copies), name or nickname and identity choice, consent date, integrity flags, display preferences (paper, font, size, panel width and side), quiz settings, and the teacher's private key (teachers only).
In the cloud (encrypted on the device first):
| Record | Readable by | Contents |
|---|---|---|
| Quiz settings (one per quiz) | CueBoard users on that quiz | Encrypted dates, limits, keywords, options, message; teacher's public key; hashed student names in the unlock list |
| Student note (one per student per quiz) | That student's device and the quiz owner's device only | Encrypted note text, name or nickname, time, integrity flags |
| Anonymous account | Firebase | Random account ID, no email or name |
Not encrypted: a hashed quiz ID, anonymous account IDs, timestamps, record sizes.
2. What we never collect
Email addresses, student IDs, Canvas user IDs, school names, quiz questions or answers, scores, browsing history, cookies, passwords, location, advertising or device identifiers, keystroke logs, or recordings.
Google Firebase, like any web service, sees ordinary network metadata (such as an IP address) when syncing; we do not receive or store it. Teacher/student role detection uses the page address and teacher-only links on the page and is held in memory only.
3. How data is used and shared
Used only to show the note dock, enforce teacher limits, scan notes on-device with simple rules (no AI or remote checker), share settings and notes through encrypted cloud records, and let teachers review, export, and clear records.
Requests go only to firestore.googleapis.com, identitytoolkit.googleapis.com, and securetoken.googleapis.com. Data is never sold, rented, used for advertising, profiling, or model training.
4. Roles and scenarios
- Role choice: on first use you choose Student or Teacher (switchable later). Teacher tools appear only on pages where Canvas shows teacher-only controls (Edit Quiz, Moderate, Statistics, SpeedGrader), and the popup console stays locked until that has been seen once. This is a convenience check of what Canvas displays, not an identity check; Canvas decides who can edit a quiz, and only the first account to save a quiz's settings can change them.
- Students: choose real name or nickname, can reset it, and can delete their notes (device and cloud) from the Privacy window.
- Teachers: see a settings card on the quiz edit page, a “View Student Notes” viewer on the quiz page, and the popup console. They can read submitted notes from any device once synced.
- Parents/guardians and eligible students: may ask the school to inspect or delete records.
- Shared/lab Chromebooks: data and the anonymous account belong to the signed-in profile; sign out or delete your data before handing off.
- Managed devices: school administrators may be able to read or clear extension data under school policy.
- Offline or blocked network: everything works on the device; syncing resumes on the next save. Schools that block Google Firebase will see “Saved on this device” and notes will not reach the teacher.
- Teacher not set up yet: student notes stay on the device until the teacher saves settings for the quiz.
- Teacher in Student View or New Quizzes: a teacher already verified on this browser sees the student notes dock as a preview, with a header button for the student notes viewer. Nothing extra is collected.
-
Active attempt (
/take): notes are a read-only reference. After the quiz: hidden unless the teacher allows review. - Under 13 (COPPA): no contact information or advertising identifiers; nicknames available to all; use is school-directed.
- Declining: a student can decline and take the quiz normally.
- Lockdown browsers: CueBoard does not interfere with or bypass proctoring.
- Lost or stolen device: local data is encrypted but tied to that profile. A student's submitted note remains in the cloud. A teacher who loses the device loses the key needed to read uploaded notes.
- Data breach: a breach of the cloud database would expose ciphertext and the metadata above, not note text.
5. Legal framework
FERPA (34 CFR Part 99): names are stored only after a student provides one; a nickname is always available; records are encrypted and accessible only to the student and the teacher.
COPPA (15 U.S.C. 6501-6506): no personal information collected by us; schools may authorize use.
Student Privacy Pledge principles and the Chrome Web Store User Data Policy are followed. Google Firebase acts as our service provider. Schools retain their own compliance duties; this is not legal advice.
6. Permissions
| Permission | Need |
|---|---|
| storage | Keep encrypted data on the device |
| https://*.instructure.com/* | Script checks the address first and exits immediately unless it is a Classic Quiz page or a New Quizzes player frame (a quiz-lti address, or an embedded frame whose Return button appears within 30 seconds) |
| activeTab | Let the popup read the current tab's address, only when opened, to fill in the quiz ID |
|
firestore.googleapis.com identitytoolkit.googleapis.com securetoken.googleapis.com |
Encrypted sync and anonymous sign-in; no other hosts |
No tabs, cookies, webRequest, identity, history, or <all_urls>.
7. Retention, export and deletion
Students: “Delete My Notes & Identity” removes notes, history and identity on the device and deletes the encrypted cloud note.
Teachers: “Purge All Exam Records” clears notes on the device (export first if needed).
Cloud records remain until the owning or authoring account deletes them; on request through the Chrome Web Store listing the developer will delete the records for a quiz. Uninstalling removes local data but not cloud records, so delete your note first.
8. Security and limits
- Device storage uses AES-GCM with a non-extractable key held by the extension.
- Each cloud note uses a fresh AES-256 key wrapped with the teacher's RSA-2048 public key; only the teacher's device holds the private key.
- Cloud quiz settings are encrypted with a key derived from the Canvas site, course and quiz identifiers. Students using CueBoard on that quiz must be able to read them, so they are not secret from those students.
- The teacher's private key lives only in that browser profile. If it is cleared, uploaded student notes and ownership of the quiz settings cannot be recovered.
- The notes panel runs in an isolated Shadow DOM and sanitizes user-entered text before display.
9. Changes and contact
Updates change the date above and are reflected in the extension before shipping. Schools, privacy officers, parents, and guardians may contact the developer through the Chrome Web Store listing.