Privacy Policy for User Auth Guard

Effective Date: January 07, 2025

1. Introduction

Welcome to User Auth Guard. We are dedicated to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines how we collect, use, store, and share your data when you use our services.

2. Information We Collect

We collect the following types of information:

Personal Information:

This includes your name, email address, and other identifiers necessary for account creation and management.

Google User Data:

With your explicit consent, we access specific Google account information to provide our services. The data accessed depends on the permissions (scopes) you grant during the OAuth authorization process. The scopes we request include:

  • https://www.googleapis.com/auth/admin.directory.device.chromeos: Allows viewing and managing metadata of Chrome OS devices in your domain.
  • https://www.googleapis.com/auth/admin.directory.user: Permits viewing and managing the provisioning of users on your domain.
  • https://www.googleapis.com/auth/admin.directory.group: Enables viewing and managing the provisioning of groups on your domain.
  • https://www.googleapis.com/auth/admin.directory.orgunit: Grants access to view and manage organizational units on your domain.
  • https://www.googleapis.com/auth/admin.directory.resource.calendar: Allows viewing and managing the provisioning of calendar resources on your domain.
  • https://www.googleapis.com/auth/admin.reports.audit.readonly: Permits viewing of audit reports for your Google Workspace domain.
  • https://www.googleapis.com/auth/admin.reports.usage.readonly: Enables viewing of usage reports for your Google Workspace domain.

3. How We Use Your Information

We use the collected information to:

  • Provide and Improve Services: Utilize your data to operate and enhance the features of User Auth Guard.
  • Communicate with You: Send updates, notifications, and respond to your inquiries.
  • Ensure Security: Monitor and protect against unauthorized access or misuse of our services.

4. Sharing Your Information

We do not sell or rent your personal information to third parties. We may share your data with:

  • Service Providers: Trusted partners who assist in operating our services, subject to strict confidentiality agreements.
  • Legal Obligations: Authorities when required by law or to protect our rights and safety.

5. Data Security

We implement robust security measures to protect your information from unauthorized access, alteration, or disclosure. However, no method of transmission over the internet is entirely secure, and we cannot guarantee absolute security.

6. Your Choices

You have the right to:

  • Access and Update: Review and modify your personal information.
  • Withdraw Consent: Revoke permissions granted to access your Google data at any time.
  • Delete Account: Request the deletion of your account and associated data.

7. AuthGuard Classroom Monitor Chrome Extension

Our Chrome extension provides real-time classroom monitoring and screen time tracking capabilities for educational institutions. Here's how it works and what data it collects:

Extension Features:

  • Screen Monitoring: Captures screenshots of student screens at configurable intervals (default: 5 seconds) during active monitoring sessions
  • Screen Time Tracking: Tracks time spent on websites and applications, categorized by educational value (similar to iPhone Screen Time)
  • Activity Monitoring: Records user interactions including clicks, keystrokes (excluding passwords), and scrolling to measure engagement
  • Keyword Alerts: Monitors for concerning keywords related to self-harm, violence, or inappropriate content
  • Search Logging: Records search queries for safety monitoring
  • Time Limits: Enforces daily/weekly time limits for different website categories

Data Collection:

The extension collects the following data when monitoring is active:

  • Screenshots: Captured images of the active browser tab (not the entire screen)
  • Website URLs and Titles: To track which sites are being visited
  • Time Spent: Duration on each website/application
  • Activity Metrics: Click counts, keystroke counts (excluding sensitive fields), scroll distance
  • Search Queries: What students search for online
  • Tab Information: Open tabs and their status
  • Idle Time: Periods of inactivity

Privacy Protections:

  • Passwords and email fields are explicitly excluded from keystroke monitoring
  • Monitoring only occurs when explicitly initiated by authorized school personnel
  • Students are notified when monitoring is active via browser badge
  • Data is transmitted securely via WebSocket connections to your school's AuthGuard server
  • Screenshots and activity data are retained according to your organization's data retention policy
  • The extension requires explicit user authentication through AuthGuard before activation

Permissions Required:

The extension requires the following Chrome permissions:

  • tabs: To track which websites are being visited
  • desktopCapture: To capture screenshots of browser tabs
  • storage: To store monitoring settings and temporary data
  • webNavigation: To track page navigation
  • idle: To detect when the user is away from the computer
  • notifications: To alert users about time limits and monitoring status
  • host permissions: To inject monitoring scripts on all websites

Data Usage:

Data collected by the extension is used exclusively for:

  • Providing real-time visibility to teachers during classroom sessions
  • Generating screen time reports and usage analytics
  • Ensuring student safety through keyword and content monitoring
  • Enforcing organizational policies and time limits
  • Creating activity summaries for parents and administrators

Data Retention:

  • Screenshots are retained for 30 days by default (configurable by your organization)
  • Screen time data is aggregated daily and retained for reporting purposes
  • Alert logs for safety incidents are retained according to your school's policy
  • Raw activity data older than 90 days is automatically purged

User Control:

  • The extension only activates when a user is logged into AuthGuard
  • Monitoring sessions must be explicitly started by authorized personnel
  • Users can see when monitoring is active via the extension badge
  • School administrators can configure which features are enabled
  • Parents can request access to their child's screen time data

8. Compliance with Google API Services User Data Policy

Our use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements.

9. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of any significant changes by posting the new policy on our website and updating the effective date.

Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us at:

User Auth Guard

Email: support@userauthguard.com

Address: 13, Station Ave, Schwenksville PA 19473