Privacy Policy
Last updated: September 24, 2026
1. Overview
Banished is a content-filtering and policy-enforcement extension for
school-managed Chromebooks (and similar managed Chrome environments).
It helps school or district IT enforce acceptable-use rules by detecting and blocking
unauthorized proxies/circumvention tools, title spoofing, and other configured distractions.
The extension is intended to be installed and configured by the educational organization,
not by individual students.
2. What we do not do
- We do not record general browsing history on permitted sites.
- We do not sell, lease, or share data with advertisers or data brokers.
- We do not use extension data for advertising or marketing profiles.
- We do not require students to create a Banished account.
3. Information processed
Processing depends on how the school configures the extension.
3.1 On-device enforcement (always)
- Page URL/content signals needed to decide whether a page violates policy (proxies, patterns, titles, etc.).
- Policy settings from Chrome managed storage (Google Admin JSON), such as allow/block lists and feature toggles.
- Optional local features when enabled by policy (e.g. clipboard/anti-AI copy rules, bookmark cleanup, easter egg).
3.2 Block event reporting (when a block occurs)
When a policy block is enforced, limited event metadata may be sent for enforcement and domain-safety curation:
- Sanitized URL (typically origin + path; query string, fragment, and credentials stripped where applicable)
- Hostname
- Violation category / detection reason
- Optional short detail string related to the match
Schools may route these events to a district-controlled endpoint (for example a Google Form
and/or a district Apps Script backend). This is for blocked events only, not continuous monitoring of allowed sites.
3.3 Optional remote policy & fleet telemetry (off by default)
If the organization enables remote policy (managed setting such as
enableRemotePolicy), the extension may communicate with a
district-operated backend to:
- Fetch policy configuration
- Send periodic heartbeats (online status, extension version, platform, policy version)
- Associate block events with a device for an admin “fleet” view
- Register for push messages so policy can refresh more quickly (e.g. FCM), when configured
In that mode, the following may be processed by the district backend:
- Device identifier: a Banished-generated id stored in extension local storage (e.g.
DEV-…), used to recognize the same browser install over time—not a government ID.
- Google account email (when available): read via Chrome Identity from the signed-in profile (typical on managed Workspace Chromebooks). If unavailable (e.g. some personal/dev profiles), the fleet view falls back to the device id only. Email is used to help IT identify which user/device is online or generating blocks—not for advertising.
- Push token (when push is configured), for policy refresh messages.
- Block telemetry tied to that device (time, type/reason, sanitized URL, optional details).
Turning remote policy off stops heartbeats, remote policy fetch, push registration use, and API block telemetry.
Managed-policy enforcement and any school-configured form reporting remain subject to the school’s setup.
4. Permissions (why they are requested)
- declarativeNetRequest – Apply network rules (e.g. search cleanup / selected resource blocking).
- storage – Read managed policy and store local state (device id, last policy cache, etc.).
- tabs – Apply config to open tabs and enforce blocking UX.
- bookmarks – Only if the administrator enables bookmark management/cleanup features.
- alarms – Schedule periodic policy sync / heartbeat when remote features are enabled.
- gcm – Optional push-based policy refresh when the district configures FCM.
- identity / identity.email – Optional: read signed-in profile email for fleet identification when remote admin features are enabled; falls back to device id if email is not available.
- Host access (<all_urls> or equivalent) – Required to evaluate pages for proxy/policy signals and enforce blocks.
5. Data sharing & third parties
- Block and fleet data are intended for the deploying school/district and tools they operate (e.g. Google Forms, Google Sheets, Apps Script, Firebase Cloud Messaging if they enable push).
- Data is not sold or used for advertising.
- Infrastructure providers used by the district (Google services, etc.) process data under the district’s configuration and those providers’ terms.
6. Children’s privacy (K–12)
Banished is aimed at educational institutions on managed devices. Schools should deploy it under their
COPPA/FERPA/CIPA (or local equivalent) obligations. The extension is designed to avoid general surveillance
of permitted activity and to limit reporting to policy-relevant block events and optional admin telemetry
controlled by the institution.
7. Data retention
Retention is controlled by the school/district (forms, spreadsheets, admin backends they operate).
The extension keeps limited local state (such as device id and last-known policy cache) on the device
to function offline and avoid losing configuration.
8. Contact
For questions about deployment, data handling, or this policy, contact your
school or district IT administrator (the organization that installed and configured Banished).
This privacy policy applies to the Banished Chrome extension.