Brightspace Dashboard — Privacy Policy
Brightspace Dashboard is a browser extension built for University of Ottawa students that reads your Brightspace (D2L) course data and organizes it into a calendar and dashboard. This page explains what data the extension accesses, what we store, and what we never touch.
What the extension reads
The extension only runs on uottawa.brightspace.com. Using your existing, already
logged-in Brightspace session, it reads:
- Your enrolled course list and course names/codes
- Course content listings (module and file titles, not full file contents — except syllabus-type PDFs, see below)
- Announcements posted by your instructors
- Assignment/dropbox folder names and due dates
- Text extracted from syllabus-style PDF files, used only to detect exam and assignment dates. If a syllabus page has no extractable text (a scanned or photocopied page), an image of that page is used instead, read directly by the AI the same way a person would
Where that data lives
Nearly everything above — your course list, calendar events, deadline checkmarks, theme preference, and Pomodoro timer state — is stored only in your browser's local extension storage, on your own device. The one deliberate exception is the optional mobile calendar feed described below, which you have to explicitly turn on.
AI-based date scanning
To catch exam/assignment dates that aren't in a structured due-date field, subscribers' syllabus PDF text (or, for scanned/image-based syllabus pages, images of those pages — see above) and new announcement text are sent to our backend server, which forwards that content to Anthropic's Claude API to extract dates, then returns the result to your device. This processing is transient — our backend does not keep a copy of that text or those images after the request completes. Only your device retains the resulting dates. Requests to this feature are rate-limited per account to prevent abuse and control cost; hitting the limit only ever delays a scan, it never affects what's already saved on your device.
Account & subscription (Discord + Whop)
Signing in uses Discord OAuth. We receive and store, only for the life of your session, your Discord user ID and username — used solely to check whether you hold the "Subscriber" role in the Brightspace Dashboard Discord server. We do not access your Discord messages, DMs, friends list, or any other server you belong to.
Payment is handled entirely by Whop. We never receive or store your payment card details — Whop automatically grants or revokes your Discord "Subscriber" role based on your payment status, and our backend simply checks that role live on each request. See Whop's own privacy policy for how they handle payment data.
Only one device can be signed in per subscription at a time, so a subscription can't be shared across multiple people simultaneously — signing in with Discord on another device ends the session on this one. Whenever a session ends this way, or you sign out yourself, or your Subscriber role lapses, any AI-detected dates already saved on this device are automatically deleted from local storage. Signing back in simply re-scans and restores them.
Mobile calendar feed (optional, Subscribers only)
Subscribers can turn on a private link (Settings → Mobile calendar) to add to Apple/Google Calendar on their phone, so their deadlines stay updated there without opening the extension. This is the only feature where we keep anything server-side: a small snapshot — just each event's title, date, and course name, nothing else — tied to a random link only you have, refreshed automatically every time you sync. It's off by default and only exists if you turn it on.
Treat that link like a password: anyone who has it can see those event titles and dates, the same limitation every "subscribe by URL" calendar feed has (Apple/Google Calendar's own share links work the same way). You can generate a new one at any time from Settings, which immediately invalidates the old link, or turn the feature off entirely, which deletes it. It's also deleted automatically the moment your Subscriber role lapses or another device signs in (see above) — though not by simply uninstalling the extension, since there's no way for an extension to reliably signal that on removal. If you want it gone before uninstalling, turn it off first from Settings.
What we don't do
- No advertising, no ad trackers, no analytics SDKs
- We never sell or share your data with third parties for marketing purposes
- No tracking of your browsing outside of
uottawa.brightspace.com
Your control over your data
Uninstalling the extension deletes all locally stored data. Signing out discards your session token immediately. You can also clear the extension's local storage at any time from Chrome's extension management page.
Security
All communication with our backend happens over HTTPS. Sessions use short-lived signed tokens that are re-validated against your live Discord role membership, so a lapsed subscription is reflected quickly without needing to store a separate record of your payment status.
Who this is for
Brightspace Dashboard is intended for current university students and is not directed at children.
Changes to this policy
If our data practices change, we'll update this page and the "Last updated" date above.
Contact
Questions about this policy or your data? Email uoextensions@gmail.com.