This is the one to forward when someone at your school asks whether it is safe to install. Every statement below is about how the software is built, and can be checked against it.
The short version
It reads Toddle inside the teacher's own browser, for the teacher at the screen, and only what that teacher's Toddle account can already see.
It never writes to Toddle.
It stores no student data. What it keeps on the computer is the teacher's settings, a licence key if one is entered, and the email of the Toddle account in use.
Nothing it reads from Toddle is sent anywhere. Its only connections outside Toddle are feedback a person chooses to send, and a daily check for cancelled licence keys that carries no data.
Where it runs
Only on web.toddleapp.com. It is declared against that one site and has no access to any other. Its only other permission is storage, for its own settings. On every other website it does nothing at all.
What it reads from Toddle
What Toddle already lets the signed-in teacher see, and only when the teacher does something that needs it:
Gradebook columns and CSV export: one assessment's tools (rubric criteria, descriptors and levels, checklist items, scores, standards, learning goals) and each assigned student's name, email, student ID, submission status and responses.
My classes and primary teacher names: the class list Toddle's home page already loads, with each class's staff.
The student sidebar: when a teacher opens a student or a class, the student's profile, contacts, classes and their teachers, homeroom advisor, and today's timetable and attendance marks.
The Attendance dashboard details: what the dashboard already loads, plus the primary teacher of the class each student is in now.
It reads through Toddle's own interface, reusing the session the teacher is already signed in with, and only through a fixed list of read-only requests. Anything else is refused. Student flags are read only for the student sidebar, for the student it has open, and are forgotten when it closes.
It never sees or stores a password. The authentication token stays inside Toddle's own page; the part of the extension that draws the interface cannot read it.
What it writes
Nothing. Write operations are blocked outright rather than merely avoided, so it cannot change a gradebook even by accident. Its message buttons open Toddle's own chat; the teacher writes and sends any message in Toddle, under the school's messaging rules.
What it keeps on the teacher's computer
In Chrome's own storage for the extension, on that computer only:
the teacher's switch settings;
the licence key, if one has been entered;
the email of the Toddle account last seen, to check who a licence is for;
the result of the last cancelled-key check: whether the key is cancelled, and when it was checked. Never the list itself.
On Toddle's own site, in the browser: a copy of the switch settings, the flags choice, whether the My classes filter is chosen, and the academic year Toddle is showing.
No student data is stored anywhere. What it reads from Toddle is held in the open tab's memory, reused for a few minutes at most, and gone when the tab is closed or reloaded.
Uninstalling the extension removes what it stored in Chrome. The few small settings it keeps on Toddle's site stay until the browser's data for Toddle's site is cleared.
What it sends
Nothing it reads from Toddle. There is no account, no analytics, no telemetry, no advertising and no remote code. It has two connections outside Toddle, and neither carries anything from Toddle:
Feedback, only when someone sends it. The toolbar menu's Send feedback form sends what the person typed (a topic, a message, and an email address if they give one) and the extension's version number, and only when they press Send. It goes to Nyuchi's feedback form, processed by Formspree.
A daily check for cancelled licence keys. Once a day, and only while a licence key is entered, the extension downloads Nyuchi's signed list of cancelled keys from
licences.nyuchi.dev. The request carries no key, no email, no identifier and no cookies. Like any web request, it reaches the server from the computer's IP address. If the check fails, the extension keeps working.
The licence key itself is never sent: it is checked by verifying its signature on the computer it is on.
A teacher can still take data out themselves, as they could from Toddle: a gradebook CSV they choose to download, an email address they copy, or an email they start.
Who is responsible: the school, Toddle and Nyuchi
Your school is the controller of its student data, and Toddle remains its processor, exactly as before the extension was installed. The extension's processing happens on the school's own devices, in the teacher's browser.
We are not your data processor. A processor receives personal data and acts on it for the controller. We receive none: the extension reads what the browser has already loaded from Toddle, shows it differently on the same screen, and transmits none of it.
For the data Nyuchi does hold (the email address and order of whoever bought a licence, feedback people send us, and support conversations) Nyuchi is the controller. We follow two laws: Zimbabwe's Cyber and Data Protection Act [Chapter 12:07], because Nyuchi is a Zimbabwean company, and the EU and UK GDPR. The detail is in our privacy policy.
For your data protection officer
Data handling: what Nyuchi holds, the services that process it for us, and how long it is kept.
Student privacy: FERPA, COPPA and data processing agreements.
The data schema: a field-by-field list of every piece of Toddle data the extension reads, keeps and sends, request by request. Ask for it at [email protected].
A data processing agreement is available on request from [email protected].
Can we verify this ourselves?
Yes, and you are welcome to. A Chrome extension is a folder of readable JavaScript: your IT team can unpack the installed package and read it. We will also answer specific questions: write to [email protected].
One limitation worth knowing
Toddle does not publish the interface the extension reads, so a Toddle release can change it and break a feature. When that happens the extension tells you when something could not be read rather than quietly showing less. It is not a reason to distrust it, but it is a reason to confirm anything you are about to act on in Toddle itself.
