Privacy policy

Classroom Desk is operated by Classroom Desk. Contact: jarvis404.dev@gmail.com.

Data accessed and used

With your permission, this service reads your Google Classroom courses, announcements, coursework, course materials metadata, topics, and your own submissions and grades to answer requests from your connected MCP client. It requests six Classroom read-only permissions and no Google Drive, Gmail, or Google write permission.

Classroom attachment titles and links may be shown when Google Classroom provides them. Public V1 does not request Google Drive access and cannot read arbitrary attachment file contents.

Authentication and token handling

Google handles sign-in. This service never receives your Google password. In production, authorization records include an internal connection identifier, encrypted Google refresh grant, OAuth client and token records, and timestamps needed to maintain your connection.

Storage, sharing, and infrastructure

Authorization records are stored in encrypted PostgreSQL-backed production storage. We do not persist course content or attachment bodies as an application cache. Requested Classroom information is returned to your connected MCP client, which may process it under that client's own terms and privacy policy. Google processes sign-in and Classroom API requests. Cloudflare and the database provider process hosting and storage operations needed to run the service.

We do not sell Classroom data or use it for advertising.

Google API Services Limited Use

Classroom Desk uses information received from Google APIs only to provide the user-requested Classroom features described here and will follow the Google API Services User Data Policy, including its Limited Use requirements. When you ask ChatGPT to answer from your Classroom, the requested result is sent to your connected ChatGPT/MCP client so it can answer your request. Classroom Desk does not use Classroom data for advertising or to train generalized models.

Retention, disconnect, and deletion

Authorization records remain while the connection is active and are deleted when you disconnect. Short-lived OAuth attempts expire, MCP access tokens expire after one hour, and MCP refresh tokens after 30 days. Disconnect attempts Google revocation and removes this service's local grant and MCP tokens. You can also revoke access in your Google Account.

To request help or deletion, contact jarvis404.dev@gmail.com. Minimal operational logs contain route category, status, and duration, without tokens, request bodies, or Classroom content.

Last updated: 3 October 2026.