ClassOrbit

Privacy & Data Use — Public Beta

Last updated August 28, 2026. This page documents the current ClassOrbit public-beta data practices and will be reviewed with final legal terms before broad public launch.

What ClassOrbit is for

ClassOrbit is a school-managed Chromebook classroom-control service. It is designed for authorized school staff to manage classroom sessions, apply browsing controls, view current classroom activity, and administer managed devices.

Data ClassOrbit processes

How data is used

ClassOrbit uses these data only to provide classroom-management, device-management, account, security, support, and service-operation functions requested by the school or authorized user. ClassOrbit does not use classroom data for advertising and does not sell personal data to advertisers.

Google authentication

ClassOrbit uses Google Identity for supported staff sign-in. ClassOrbit does not ask for or store the user's Google password. Authentication tokens and ClassOrbit sessions are used to verify access and protect school accounts.

Student Agent permissions

The ClassOrbit Student Agent requests browser/tab, navigation, network-rule, window, storage, alarm, identity-email, offscreen WebRTC, and managed ChromeOS device-attribute capabilities because those permissions are necessary for classroom visibility, teacher-initiated active-tab live screen view, Focus Mode, Pause/Lockdown, Teacher Control, classroom communication, realtime status, managed configuration, and administrator-authorized student/device matching. The offscreen permission hosts an invisible extension-owned WebRTC engine; it does not open a camera, microphone, or full-desktop capture source. Enterprise device attributes are used only on policy-installed managed ChromeOS devices; unmanaged installs may not provide them. School administrators control deployment through Google Admin for managed Chromebooks.

ClassOrbit LocalStream

ClassOrbit LocalStream is available only to staff authorized for the active class. The managed Student Agent has site access so it can capture the currently visible Chrome tab after a teacher starts LocalStream; it does not capture the full ChromeOS desktop, login screen, camera, or microphone. After ClassOrbit verifies the organization, class, active session, teacher, and device, it issues a short-lived live-view ticket. A bundled offscreen extension document negotiates a direct WebRTC DataChannel while the existing ephemeral Cloudflare frame path remains available. Cloudflare STUN can assist network discovery; when the operator separately configures Cloudflare TURN, ClassOrbit generates short-lived session credentials server-side and never packages the long-lived TURN key in the Student Agent. WebRTC connectivity candidates are used temporarily for negotiation; student local IP addresses are not shown in the normal teacher UI or written to permanent ClassOrbit logs. ClassOrbit does not create a screen recording or permanent screenshot history. Starting and stopping LocalStream is auditable.

Retention and school control

ClassOrbit keeps operational data needed to provide the service and maintain security/auditability. A formal public-launch retention schedule, deletion process, and school data-processing terms will be finalized before general availability. Schools remain responsible for deciding who is authorized to use ClassOrbit and which users/devices are placed under managed deployment.

Security

ClassOrbit uses tenant-scoped access controls, revocable staff sessions, hashed enrollment/session credentials, HTTPS, and managed-device credentials. No security system is perfect; suspected security issues should be reported to the ClassOrbit operator before broad public launch contact information is finalized.

Return to ClassOrbit