Privacy Policy

Profet by TAUR — Connect Brightspace

Last updated: July 2026Extension: Profet by TAUR — Connect Brightspace (Chrome/Edge)Provider: Mondoro Holdings ("TAUR")Contact: privacy@taur.ai

This policy explains exactly what the Profet by TAUR — Connect Brightspace browser extension collects, why, where it goes, and how to remove it. We designed the extension to touch the minimum data needed to answer your Brightspace questions in your chat, and nothing else.

1. What the extension does

This extension is the access point that lets your TAUR assistant work with Brightspace on your behalf. Brightspace has no self-service way to grant an app access, so you unlock it yourself: you log in normally in your own browser (including any multi-factor step), and the extension hands TAUR the session key Brightspace already issued to you. With that key, TAUR can look up your courses, grades, due dates, announcements and content when you ask in your chat — nothing more.

You are always in control. You grant access by installing and consenting; you revoke it at any time by removing the extension or messaging "disconnect" (Section 7). The extension reads only your Brightspace session cookies, sends them to TAUR encrypted at rest, and never touches your password or any other site.

2. What we collect

Read by the extension and sent to TAUR:

  • Brightspace session cookies only — the D2L cookies d2lSessionVal, d2lSecureSessionVal, d2lSameSiteCanaryA, and d2lSameSiteCanaryB from your institution's Brightspace domain (e.g. brightspace.carleton.ca). These act as a temporary key that lets TAUR make read-only requests to Brightspace as you.

Stored only on your device (in the extension's local storage, never uploaded):

  • A one-time pairing code, a poll token, and a connection token used to link this browser to your chat account, plus the timestamp of the last session refresh.

Provided by you through your chat (not read by the extension):

  • Your chat account ID on the messaging channel you connect (for example your Telegram user ID or phone number), which becomes the account the captured session is linked to. You supply it by sending the link code to Profet.

3. What we do NOT collect

  • We do not read, receive, or store your Brightspace password.
  • We do not read cookies, data, or activity from any site other than your configured Brightspace domain.
  • We do not collect browsing history, keystrokes, form contents, files, or advertising identifiers.
  • We do not sell your data or use it for advertising, and we do not share it with third parties except the limited processors described in Section 5.

4. How your data is used

  • The session cookies are used solely to make read-only Brightspace API requests to retrieve the information you ask for (courses, due dates, grades, announcements, content, assignments, quizzes).
  • When you ask a question in your chat, the relevant retrieved information (e.g. a list of your courses or upcoming due dates) is used to generate a natural-language answer.
  • The extension re-sends fresh cookies when you visit Brightspace so your assistant stays connected without you logging in again.

5. Where your data goes (sub-processors)

To operate the service, limited data is processed by:

  • TAUR backend / hosting (TAUR's own servers) — stores your encrypted session and the link to your chat account.
  • Your messaging channel (whichever one you connect — for example Telegram) — delivers messages between you and the assistant, under that service's own privacy policy.
  • AI model provider (via OpenRouter: Google Gemini, with OpenAI as a fallback) — receives the specific Brightspace information relevant to your question in order to phrase the answer. Only the data needed to answer is sent; your raw session cookies are never sent to the AI provider.

We use these providers only to deliver the service and do not authorize them to use your data for their own purposes.

6. Storage, security & retention

  • Session cookies are encrypted at rest on our server (authenticated symmetric encryption) and transmitted only over HTTPS/TLS.
  • Device-side tokens live in the extension's local storage and are removed when you uninstall the extension.
  • We retain your linked session only as long as needed to provide the service. When your Brightspace session expires it is marked unusable (kept only so Profet can tell you to refresh it) and overwritten on your next refresh. You can trigger deletion at any time (Section 7).

7. Your choices & how to disconnect

  • Stop refreshing / disconnect: remove the extension from chrome://extensions. This deletes all device-side tokens and stops any further cookie capture.
  • Delete your server-side session and chat link: send "disconnect" to Profet in your chat, or email privacy@taur.ai and we will purge your stored session and account link.
  • Because access is read-only and cookie-based, revoking is also as simple as logging out of Brightspace, which invalidates the captured session.

8. Children's privacy

The service is intended for post-secondary students and is not directed to children under 13 (or the applicable age in your jurisdiction).

9. Limited Use disclosure

TAUR's use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically: data accessed by this extension is used only to provide and improve the single user-facing feature described above (answering your Brightspace questions in TAUR); it is not sold, not used for advertising, and not transferred to others except as needed to provide the service, to comply with applicable law, or as part of a merger with equivalent protections and your consent.

10. Changes to this policy

We may update this policy; material changes will be reflected by the "Last updated" date and, where appropriate, an in-product notice.

11. Contact

Questions or data requests: privacy@taur.ai

TAUR is operated by Mondoro Holdings. For data requests or questions, email privacy@taur.ai.

← Back to Marketplace