
Privacy & Data Use — Public Beta
Last updated August 28, 2026. This page documents the current ClassOrbit public-beta data practices and will be reviewed with final legal terms before broad public launch.
What ClassOrbit is for
ClassOrbit is a school-managed Chromebook classroom-control service. It is designed for authorized school staff to manage classroom sessions, apply browsing controls, view current classroom activity, and administer managed devices.
Data ClassOrbit processes
- Account identity such as name, email address, Google account identifier, organization membership, role, and sign-in/session security information.
- School configuration such as organizations, classes, rosters, student records supplied by the school, device assignments, and managed-deployment settings.
- Chromebook technical information such as ClassOrbit device ID, extension version, Chrome version, management mode, policy version, enrollment/heartbeat timestamps, current connection state, and—on administrator-authorized managed deployments—enterprise serial/Directory device identifiers and the primary signed-in school profile used to resolve the correct student/device assignment.
- During an active classroom session, current or recent browser tab metadata needed for teacher visibility and Focus/attention features. When an authorized teacher explicitly turns on Live Student Screens, the Student Agent can also relay temporary JPEG frames of the Chromebook's currently visible Chrome tab. Those live frames are not stored as screenshot history or recordings. ClassOrbit continues to use current/latest state rather than continuous screen recording or permanent browsing-history collection by default.
- Classroom communications such as teacher/student chat, class or group announcements, acknowledgement/delivery status, saved announcements, and student Raise Hand requests. These records may be retained for authorized school review and classroom accountability.
- Classroom command results, Focus/attention events, security/audit events, and operational error information needed to run and secure the service.
How data is used
ClassOrbit uses these data only to provide classroom-management, device-management, account, security, support, and service-operation functions requested by the school or authorized user. ClassOrbit does not use classroom data for advertising and does not sell personal data to advertisers.
Google authentication
ClassOrbit uses Google Identity for supported staff sign-in. ClassOrbit does not ask for or store the user's Google password. Authentication tokens and ClassOrbit sessions are used to verify access and protect school accounts.
Student Agent permissions
The ClassOrbit Student Agent requests browser/tab, navigation, network-rule, window, storage, alarm, identity-email, offscreen WebRTC, and managed ChromeOS device-attribute capabilities because those permissions are necessary for classroom visibility, teacher-initiated active-tab live screen view, Focus Mode, Pause/Lockdown, Teacher Control, classroom communication, realtime status, managed configuration, and administrator-authorized student/device matching. The offscreen permission hosts an invisible extension-owned WebRTC engine; it does not open a camera, microphone, or full-desktop capture source. Enterprise device attributes are used only on policy-installed managed ChromeOS devices; unmanaged installs may not provide them. School administrators control deployment through Google Admin for managed Chromebooks.
ClassOrbit LocalStream
ClassOrbit LocalStream is available only to staff authorized for the active class. The managed Student Agent has site access so it can capture the currently visible Chrome tab after a teacher starts LocalStream; it does not capture the full ChromeOS desktop, login screen, camera, or microphone. After ClassOrbit verifies the organization, class, active session, teacher, and device, it issues a short-lived live-view ticket. A bundled offscreen extension document negotiates a direct WebRTC DataChannel while the existing ephemeral Cloudflare frame path remains available. Cloudflare STUN can assist network discovery; when the operator separately configures Cloudflare TURN, ClassOrbit generates short-lived session credentials server-side and never packages the long-lived TURN key in the Student Agent. WebRTC connectivity candidates are used temporarily for negotiation; student local IP addresses are not shown in the normal teacher UI or written to permanent ClassOrbit logs. ClassOrbit does not create a screen recording or permanent screenshot history. Starting and stopping LocalStream is auditable.
Retention and school control
ClassOrbit keeps operational data needed to provide the service and maintain security/auditability. A formal public-launch retention schedule, deletion process, and school data-processing terms will be finalized before general availability. Schools remain responsible for deciding who is authorized to use ClassOrbit and which users/devices are placed under managed deployment.
Security
ClassOrbit uses tenant-scoped access controls, revocable staff sessions, hashed enrollment/session credentials, HTTPS, and managed-device credentials. No security system is perfect; suspected security issues should be reported to the ClassOrbit operator before broad public launch contact information is finalized.