PackArcade Full Lockdown Privacy Policy
PackArcade Full Lockdown is the official School-GIT browser-assurance and optional focus-lockdown extension. This policy explains what the extension and School-GIT use, why those permissions exist, what is stored, and what the extension does not collect.
1. What the extension is for
The extension provides School-GIT device assurance, cryptographic installation verification, optional Google-linked trusted-device recovery, and user-initiated focus/lockdown controls. When a School-GIT Realm requires browser assurance, the extension can prove that the genuine installed extension is active instead of relying on a simple “I installed it” button.
If the extension cannot be installed, such as on a school-managed Chrome profile, School-GIT can use its Managed Access Realm instead. The privacy policy remains readable whether or not the extension is installed.
2. Information used for extension verification
- Installation identity: a random installation ID and an ECDSA P-256 cryptographic key pair generated by the extension. The private key remains in Chrome extension storage; School-GIT receives the public key when verification is performed.
- Verification challenge data: one-time challenge IDs, signatures, extension ID, and verification timestamps used to prove that the extension is active.
- Focus state: whether the optional focus lockdown is active and its start/end time, stored locally so the extension can maintain the session.
The current extension does not fetch a public IP address for installation verification and does not use IP-address fingerprinting as proof that the extension is installed.
3. Google account linking and trusted-device recovery
Google account linking is optional and is used only to associate a verified Google identity with the correct School-GIT account and support trusted-device recovery. The extension requests the OpenID Connect identity scopes openid, email, and profile.
During extension-based verification, a Google OAuth access token is transmitted to School-GIT over HTTPS so the School-GIT server can verify the token with Google and confirm its OAuth audience and verified account identity. The token is used for that verification flow; the persistent School-GIT Google-link record stores hashed Google subject/email identifiers, a masked email hint, link time, and last successful bootstrap time—not the Google password.
School-GIT does not use this permission to read Gmail messages, Google Drive files, Contacts, Google passwords, or unrelated Google account content.
4. Browsing and lockdown permissions
The extension requests tab, navigation, window, and declarative network-request permissions because an active focus-lockdown session can limit browsing to approved School-GIT/PackArcade destinations, redirect blocked navigation, and maintain a fullscreen focus window.
The extension evaluates navigation URLs locally while lockdown is active so it can decide whether a destination is allowed. The current extension implementation does not upload a general browsing-history log to School-GIT and does not use browsing activity for advertising.
5. What is stored
In Chrome extension storage
Installation ID, the installation key pair, and current focus/lockdown state. This storage belongs to the extension installation on that Chrome profile.
On School-GIT servers
Verification/public-key records needed for device assurance and, when Google linking is enabled, hashed Google identifiers plus a masked email hint and link/bootstrap timestamps.
6. Information the extension does not need
- Google passwords.
- Gmail message contents.
- Google Drive document contents.
- Google Contacts contents.
- A public-IP lookup for extension attestation.
- Advertising identifiers or sale of extension identity data to advertisers.
7. Data sharing, security, and retention
Extension identity data is used for School-GIT account assurance, policy enforcement, focus operation, and trusted-device recovery. It is not intended for targeted advertising or sale to advertisers. Google tokens used during verification are sent to Google verification endpoints and School-GIT as necessary to validate the identity flow.
School-GIT uses one-time challenges and cryptographic signatures to reduce the risk of a webpage falsely claiming that the extension is installed. Server-side Google verification also checks that the token belongs to the configured School-GIT extension OAuth client.
Local extension data remains with the Chrome extension profile until it is removed or cleared. School-GIT-linked records are retained as needed to maintain the account/device link and can be removed through the applicable School-GIT account or support process.
8. User choices
Installing the extension is not the only way to access School-GIT. When installation is unavailable, School-GIT can apply Managed Access with reduced capabilities instead of requiring a false installation confirmation. Google account linking is also optional; normal School-GIT account authentication remains available independently of Google-linked recovery.
A user can remove the extension through Chrome, clear the extension’s local storage by removing it, and use School-GIT account controls/support processes to manage account-linked information.
9. Changes and contact
This page is the canonical privacy policy for PackArcade Full Lockdown. Material changes to the extension’s data use should be reflected here when a new extension release changes those practices.
For privacy or account-data questions, use the support/contact channel published by School-GIT. The main platform is available at school-git.packarcade.win.