VULMS Tools Privacy Policy
VULMS Tools sends data to one place, and only when you ask it to: the AI provider you chose, using an API key you supplied, at the moment you press Solve with AI or Test key.
Nothing else leaves your device. There is no analytics, no tracking, no error reporting, no advertising and no account. We run no server, so your data has nowhere to go. The AI feature is off by default; if you never turn it on, the extension makes no network requests at all.
VULMS Tools is an independent browser extension. It is not made by, endorsed by or affiliated with the Virtual University of Pakistan, DigiSkills or Cisco.
What leaves your device
| Destination | What is sent | When |
|---|---|---|
api.anthropic.com |
The question, as described below | Only when you press Solve with AI or Test key with Anthropic selected |
api.openai.com |
The same | The same, with OpenAI selected |
generativelanguage.googleapis.com |
The same | The same, with Google selected |
Only the provider you have selected is contacted. These requests go directly from your browser to that provider; they do not pass through any server of ours. Your key authenticates your own account with the provider, and any usage is billed to you.
What is sent to an AI provider
When you press Solve with AI on a quiz question, the request contains:
- a fixed instruction, the same text every time;
- the question and its answer options, exactly as shown on the page;
- the model you chose;
- and, in the request headers, your API key.
That is the whole request. It does not include your name, your student ID, your LMS login, the page address, cookies, your other tabs, your course list, your marks, or anything else from the page. Test key sends even less: a minimal request with no question in it, only to check that the key works.
What the provider does with it
Once a question reaches Anthropic, OpenAI or Google, it is governed by that provider's privacy policy and your agreement with them, not by this policy. Some providers keep API requests for a period. We cannot see, control or delete what you send them.
You stay in control
- The AI feature is off until you turn it on, and nothing is sent until you press the button.
- It cannot work without an API key you obtained and entered yourself.
- Turning the feature off stops it immediately, in tabs that are already open.
- Nothing is sent in the background, on a timer or when a page loads.
What is stored on your device
| What | Where | Leaves your device? |
|---|---|---|
| Which features are on, which LMS theme you chose, and the theme to restore with the shortcut | Extension storage on this computer | No |
| Where you left the extension's panels, and whether they are folded | Extension storage on this computer | No |
| Whether a one-time tip has been shown | Extension storage on this computer | No |
| Your AI API keys | Extension storage on this computer | No, never synced |
| Language, appearance, animation and diagnostic-log preferences, and your AI provider and model choice | Chrome's synced extension storage | Only through your own Chrome sync, to your own devices |
| A lecture-completion run in progress | Session storage, in memory only | No; gone when the browser closes |
Synced preferences travel between your devices through Google's Chrome sync, the same way your bookmarks do; we never see them. To stop that, turn off extension sync in Chrome. Your API keys are never synced.
Nothing else is stored: no quiz content, no assignment text, no page contents, no browsing history, no student ID and no password. A question sent to an AI provider is not kept by the extension once the answer is shown.
Backup in Settings writes your preferences to a file on your computer. Your API keys are included only if you tick that option; if you do, keep the file private.
About your API key
Your key is stored in the extension's local storage without encryption. Plainly, that means:
- Other extensions cannot read it; extension storage is private to each extension.
- Websites, including the LMS, cannot read it; it is only ever used inside the extension's background process.
- Someone with access to your computer and your signed-in browser profile could read it, as they could your saved passwords.
If you share this computer with someone you would not trust with your key, use a key with a spending limit, or do not save one.
What the extension reads on a page
VULMS Tools runs only on vu.edu.pk, digiskills.pk and
netacad.com. On those pages it reads the content already displayed to you,
in order to:
- recolour the page in the theme you chose, checking that text stays readable;
- copy, screenshot or solve a question when you ask;
- allow pasting in the assignment editor;
- build a PDF of a quiz result you are viewing;
- list the page's own links, courses and tabs when you open Quick jump.
What it reads stays on your device unless you press Solve with AI, in which case only the question and its options go to the provider you chose. Screenshots and PDFs are made in your browser and saved to your downloads folder; they are not uploaded anywhere. The extension does not run on, or read, any other website.
Lecture completion
One feature changes something outside your browser: marking lectures complete updates the progress record your university keeps for you. It works through the LMS page you are already signed in to, the same way watching the lecture would, and sends nothing to us or to anyone else. Because it cannot be undone from the extension, it always asks first: one press for the lecture on screen, and for a whole course a list of what will change and a confirmation before anything happens.
Permissions
| Permission | Why it is needed |
|---|---|
| Storage | Remember your settings, your switches and your API key. |
| Tabs | Let the toolbar popup see which page you are on, so it can show the tools that work there. |
| Context menus | Add the extension's actions to the right-click menu on supported pages. |
| Downloads | Save a screenshot or PDF you asked for to your downloads folder. |
| Clipboard write | Copy a question to your clipboard when you press Copy. |
| Scripting | Apply your theme before a page appears, load the screenshot tool when you press Screenshot, and run the LMS's own functions when you ask, such as marking a lecture complete. |
| Offscreen | Lay out a PDF in a hidden page inside the extension. |
Access to vu.edu.pk, digiskills.pk, netacad.com |
Work on those sites, and nowhere else. |
| Access to the three AI provider addresses | Send your question to the provider you chose, when you ask. |
The extension has no access to any other website, your email, or your other tabs.
Deleting your data
- Removing the extension deletes everything it stored on this computer, including your API key.
- To delete only the key, clear it in Settings and press Save.
- Synced preferences are removed when you remove the extension while signed in to the Chrome profile that holds them.
- Anything already sent to an AI provider can only be deleted through that provider.
Our commitments
- No analytics or tracking will be added without your explicit opt-in, off by default.
- Your data will not be uploaded to any server of ours, sold, or shared with anyone.
- Nothing is sent to an AI provider unless you press a button to send it.
- Nothing is recorded on your university progress unless you press a button to record it.
- Any new place the extension sends data will be listed in this policy before it ships.
Changes and contact
When this policy changes, the new version ships with the extension update and the date at the top changes. For questions, or to report behaviour that contradicts this policy, use the support contact on the extension's Chrome Web Store page.