For IT Administrators & School Boards

Security & Data Overview

This page explains what ClassWatcher is, what data it accesses, and how it protects student and teacher information, written for IT teams and board administrators.

1. What is ClassWatcher?

ClassWatcher is a Chrome browser extension used by teachers to track missing assignment submissions in D2L Brightspace. It helps teachers quickly identify which students have not submitted work, and optionally send SMS or email reminders, to the right audience for their school level:

ClassWatcher is a productivity tool for teachers. It does not modify Brightspace, does not interact with grades, and does not have access to assignment content or course materials.

In plain terms: ClassWatcher reads the list of student names on an assignment or quiz submission page and compares it against the teacher's class list to find who's missing. That is the full extent of its data access from Brightspace.

2. What Data Does ClassWatcher Access?

ClassWatcher accesses only what is visible to the teacher on screen:

ClassWatcher does NOT access or transmit:

Evaluating ClassWatcher without an account: a teacher can install the extension and use the on-page missing list without creating an account at all. This is the mode an IT team will most likely be asked to approve first, because it involves no sign-up, no credentials and no data leaving the device.

In that mode the on-page list sends nothing to us: opening a page, checking who has not submitted, importing a class and sorting the list make no requests to our servers, and we receive no information about the teacher, their school, their courses or their students.

Three ordinary website visits are the only exceptions. When the extension is first installed it opens our getting-started page in a new tab; if the teacher opens the ClassWatcher side panel it loads our web app and asks our server whether they are signed in; and if they remove the extension, Chrome opens a short goodbye page on our site. That sign-in check carries a random installation identifier and nothing else, and when there is no account we store nothing from it. All three are ordinary web requests to classwatcher.com and are covered by the standard server logs described in our Privacy Policy.

Signing in does not change what ClassWatcher reads from Brightspace — only which features are available and which records are kept on our servers.

3. Google Sheets Integration

ClassWatcher offers an optional Google Sheets export feature. When a teacher uses this feature, ClassWatcher requests permission to create a spreadsheet in the teacher's own Google Drive.

OAuth ScopeWhat It AllowsWhat ClassWatcher Uses It For
https://www.googleapis.com/auth/drive.file Create and edit only the files ClassWatcher itself creates in the user's Drive — no access to any other Drive file or existing spreadsheet Creates one spreadsheet called "ClassWatcher.com" with the teacher's class list, missing items grid, and contact history

ClassWatcher does not read, access, or transmit any other files in the teacher's Google Drive. The authorization token is stored locally in the teacher's browser and is never sent to ClassWatcher servers. Teachers can revoke this access at any time via their Google Account permissions page.

ClassWatcher's use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

If your board restricts Google API access: Some boards configure their Google Workspace environment to block third-party OAuth applications by default. If teachers encounter an error when attempting to export to Google Sheets, a board administrator can allowlist ClassWatcher using the details below.

FieldValue
App name ClassWatcher
OAuth Client ID 1088965326290-s3gl7cgge4nh0q48282vt60748a6ohg1.apps.googleusercontent.com
Google Cloud Project Number 1088965326290
Scope requested https://www.googleapis.com/auth/drive.file

In Google Workspace Admin Console, go to Security → API Controls → App Access Control and add the OAuth Client ID above to your allowlist. For questions, contact [email protected].

4. Where Is Data Stored?

Where data sits when the teacher has no account. Of the four locations above, only the first is in use. Nothing reaches ClassWatcher servers, no Google Drive access is requested, and no delivery provider is involved, because messaging is not available without an account.

Two things are kept on the teacher's own computer. First, if they choose to import a class, the student list Brightspace already holds — names, Brightspace usernames and the internal ID numbers Brightspace uses to identify students — is saved in the browser's local extension storage so the extension can tell who is missing work. Nothing is imported unless they confirm it, and this list is never sent to us while they have no account.

Second, the extension counts how many distinct assignment or quiz pages they have opened, up to fifty, so it knows when to offer a first-run tip and when to ask for a Chrome Web Store review. That count identifies pages by the school's Brightspace web address and the course and assignment numbers Brightspace itself uses — never student names or page content. The page count is kept in Chrome's synced storage, so Chrome may copy it between that teacher's own Chrome profiles through their Google account; class lists are not — they stay in local storage on that computer only.

If the teacher later creates an account, one number is sent with the sign-up: how many pages they had checked, capped at fifty. Neither the page list nor the class list is sent.

ProviderPurposeData ReceivedRetention
Twilio SMS delivery Recipient phone number, message text, student first name Governed by Twilio's Privacy Policy. ClassWatcher message logs are purged after 365 days.
AgentMail Email delivery Recipient email address, message subject and body, student first name Governed by AgentMail's Privacy Policy. ClassWatcher email logs are purged after 365 days.

ClassWatcher does not use third-party analytics, advertising networks, or data brokers. Student data is never sold, shared, or used for any purpose other than delivering the features the teacher explicitly uses.

5. Security Measures

ClassWatcher follows the Principle of Least Privilege — the extension requests only the permissions needed for each specific feature, and does not hold broad access by default.

PermissionWhy It's Needed
storage Saves class lists, watch lists, and settings locally in the teacher's browser — these are never sent to ClassWatcher servers
tabs Opens assignment and quiz pages in background tabs to scan submission status without disrupting the teacher's active session
scripting Injects the ClassWatcher interface (side panel, student badges) into Brightspace pages the teacher is already viewing
sidePanel Displays the ClassWatcher panel alongside Brightspace using Chrome's native side panel API
alarms Runs a background watchdog timer to clean up stalled scans — no data is accessed or transmitted by this timer
Brightspace domain access
(host_permissions, all frames)
Allows the content script to read submission pages on known Brightspace domains. Scoped to specific domains: brightspace.com, desire2learn.com, and a small set of other known Brightspace hostnames. The extension runs across all frames on these pages because D2L Brightspace uses nested iframes as part of its own page structure — this is required for accurate scanning, not a request for broader access
Any-site access
(optional — not held by default)
Some school boards host Brightspace on a custom domain (e.g. learn.schoolboard.ca) that doesn't match the standard Brightspace patterns. If a teacher enters a custom Brightspace URL in ClassWatcher Settings, the extension requests access to that specific domain only at that moment. This permission is never requested or held unless a custom domain is configured by the teacher

In plain terms: ClassWatcher reads your browser, not your Brightspace. No administrator needs to approve an API integration, no OAuth token is issued to the LMS, and nothing changes on the Brightspace side when a teacher installs ClassWatcher. The extension is entirely teacher-controlled and session-bound.

6. School Plan — Multi-Teacher Accounts

The School plan includes 1 admin seat plus 10 teacher seats under a single billing account (the per-school seat limit can be raised on request). The account holder (admin seat) has access to a usage dashboard showing activity across all seats. This section explains the data boundary between the admin seat and individual teacher seats.

What the admin seat can see for each teacher:

What the admin seat cannot see:

The admin seat is a billing and oversight role — it can see that a teacher sent 12 messages this month, but not who was contacted or what was said. Each teacher's student data remains private to their own account.

7. Privacy Compliance

ClassWatcher is operated by David W Cooper and is designed with the following privacy frameworks in mind. Teachers and administrators are responsible for ensuring use of ClassWatcher aligns with their institution's acceptable use policies.

PIPEDA (Canada): Canada's federal private-sector privacy law. ClassWatcher limits data collection to what is necessary for the features the teacher explicitly uses and does not share data with third parties. As a data-minimization measure, message logs are retained for 365 days and then deleted. ClassWatcher maintains a public Privacy Policy and IT overview. See our PIPEDA compliance guide for full details.

FERPA (United States): The Family Educational Rights and Privacy Act applies to US schools receiving federal funding. Key points for evaluating ClassWatcher under FERPA:

See our FERPA compliance guide for a full analysis. For DPA requests or security questionnaires, contact [email protected].

Provincial laws (Canada): Ontario (MFIPPA), Alberta (FOIPPA), and BC (PIPA) govern school boards rather than tool vendors. ClassWatcher's data minimization design is intended to support compliance. Note: ClassWatcher's servers are hosted in the United States (DreamHost). Boards with data residency requirements should consult their privacy officer before adopting any US-hosted tool.

Full details are in our Privacy Policy and Terms of Service.

8. Contact for IT Inquiries

Questions from your IT or security team?

We're happy to provide additional documentation, answer security questionnaires, or discuss board-specific requirements. Reach out directly:

Email [email protected]

You can also review our Privacy Policy and Terms of Service for full legal detail.