Brightspace Dashboard — Privacy Policy

Last updated: August 13, 2026

Brightspace Dashboard is a browser extension built for University of Ottawa students that reads your Brightspace (D2L) course data and organizes it into a calendar and dashboard. This page explains what data the extension accesses, what we store, and what we never touch.

What the extension reads

The extension only runs on uottawa.brightspace.com. Using your existing, already logged-in Brightspace session, it reads:

The extension never sees or stores your Brightspace username or password. It reuses the browser session your university login already created, exactly like the normal Brightspace website does.

Where that data lives

Nearly everything above — your course list, calendar events, deadline checkmarks, theme preference, and Pomodoro timer state — is stored only in your browser's local extension storage, on your own device. The one deliberate exception is the optional mobile calendar feed described below, which you have to explicitly turn on.

AI-based date scanning

To catch exam/assignment dates that aren't in a structured due-date field, subscribers' syllabus PDF text (or, for scanned/image-based syllabus pages, images of those pages — see above) and new announcement text are sent to our backend server, which forwards that content to Anthropic's Claude API to extract dates, then returns the result to your device. This processing is transient — our backend does not keep a copy of that text or those images after the request completes. Only your device retains the resulting dates. Requests to this feature are rate-limited per account to prevent abuse and control cost; hitting the limit only ever delays a scan, it never affects what's already saved on your device.

Account & subscription (Discord + Whop)

Signing in uses Discord OAuth. We receive and store, only for the life of your session, your Discord user ID and username — used solely to check whether you hold the "Subscriber" role in the Brightspace Dashboard Discord server. We do not access your Discord messages, DMs, friends list, or any other server you belong to.

Payment is handled entirely by Whop. We never receive or store your payment card details — Whop automatically grants or revokes your Discord "Subscriber" role based on your payment status, and our backend simply checks that role live on each request. See Whop's own privacy policy for how they handle payment data.

Only one device can be signed in per subscription at a time, so a subscription can't be shared across multiple people simultaneously — signing in with Discord on another device ends the session on this one. Whenever a session ends this way, or you sign out yourself, or your Subscriber role lapses, any AI-detected dates already saved on this device are automatically deleted from local storage. Signing back in simply re-scans and restores them.

Mobile calendar feed (optional, Subscribers only)

Subscribers can turn on a private link (Settings → Mobile calendar) to add to Apple/Google Calendar on their phone, so their deadlines stay updated there without opening the extension. This is the only feature where we keep anything server-side: a small snapshot — just each event's title, date, and course name, nothing else — tied to a random link only you have, refreshed automatically every time you sync. It's off by default and only exists if you turn it on.

Treat that link like a password: anyone who has it can see those event titles and dates, the same limitation every "subscribe by URL" calendar feed has (Apple/Google Calendar's own share links work the same way). You can generate a new one at any time from Settings, which immediately invalidates the old link, or turn the feature off entirely, which deletes it. It's also deleted automatically the moment your Subscriber role lapses or another device signs in (see above) — though not by simply uninstalling the extension, since there's no way for an extension to reliably signal that on removal. If you want it gone before uninstalling, turn it off first from Settings.

What we don't do

Your control over your data

Uninstalling the extension deletes all locally stored data. Signing out discards your session token immediately. You can also clear the extension's local storage at any time from Chrome's extension management page.

Security

All communication with our backend happens over HTTPS. Sessions use short-lived signed tokens that are re-validated against your live Discord role membership, so a lapsed subscription is reflected quickly without needing to store a separate record of your payment status.

Who this is for

Brightspace Dashboard is intended for current university students and is not directed at children.

Changes to this policy

If our data practices change, we'll update this page and the "Last updated" date above.

Contact

Questions about this policy or your data? Email uoextensions@gmail.com.