Privacy Policy
FPS Device Chrome extension and the Fairfield Public Schools Device Portal
Effective: September 14, 2026
Fairfield Public Schools ("FPS", "the District", "we") provides the FPS Device Chrome extension to manage the Chromebooks it issues to students and staff. This policy explains what the extension collects, why, who can see it, and how long it is kept.
1. Who this applies to
The extension is distributed privately through the Chrome Web Store and installed automatically
(force-installed) by Google Admin policy on Chromebooks enrolled in the District's Google
Workspace for Education domain. It is not offered to the general public. This policy also covers
the Device Portal website (device.fairfieldschools.org) that the extension reports to
and that staff use to manage devices and repairs.
2. What the extension collects
The extension reads the following from the Chromebook and sends it to District servers:
| Data | Why we collect it |
|---|---|
| Signed-in District account email (and Google account ID) | To record which student or staff member is using which device, confirm device
assignments, and address check-in prompts to the right person. Only accounts on
District domains (fairfieldschools.org / fairfieldschools.net)
are accepted. |
| Device identifiers: serial number, Google directory device ID, asset tag and location annotation from the Google Admin console | To match the device to the District's inventory record. On enrolled Chromebooks the serial may be cryptographically attested through Chrome Verified Access so that only a genuine District device can be linked to an inventory record. |
| Network information: local IP address, the public IP address the device connects from, Wi-Fi network name (SSID/BSSID), and the device's MAC address | To determine whether the device is on a District campus (and which one) or off-site. This supports location-based check-ins and recovery of lost or stolen devices. |
| Software versions: ChromeOS version, Chrome version, extension version | To support the device, troubleshoot problems, and roll out extension updates safely. |
| Sign-in and sign-out events with timestamps | To maintain an accurate history of device use for inventory, repair intake, and investigation of missing devices. |
| Active-use periods and connectivity: the start and end times of periods in which the device was in active use, recorded per signed-in District account and derived only from the operating system's idle state (whether there has been keyboard, mouse or touch input in the last minute); and periods when the device was offline or asleep | To identify unused or non-reporting devices, to distinguish a device that is in daily use from one that may be lost, and to show staff how much a device is being used and by which account. This is an activity level only — the extension records that the device was in use, never what was being done: no page content, web addresses (URLs), page titles, or application names. |
| Check-in responses ("this is my device", "wrong device", "not mine") and a device lookup code shown in the extension | To confirm or correct device assignments and to let a student or staff member start a repair request for the right device. |
What the extension does not collect
- Web browsing history, page contents, search terms, or form entries
- Keystrokes, screenshots, camera, microphone, or precise GPS location
- Files, downloads, email, Drive documents, or the contents of any account
- Anything from personal (non-District) Google accounts or from devices the District does not manage
The extension does not inject scripts into web pages and does not read the pages you visit. Presence detection uses only the operating system's idle/active signal.
3. How we use the information
Information collected by the extension is used solely to operate the District's device program:
- Keeping the device inventory and student/staff device assignments accurate
- Prompting periodic or triggered device check-ins and recording the answers
- Detecting device swaps, shared devices, or devices that have stopped reporting
- Locating lost, stolen, or unreturned District devices
- Processing repair, loss, and damage claims and related communications with guardians
- Supporting and troubleshooting devices and rolling out extension updates
We do not use this information for advertising, profiling, or any commercial purpose, and we do not sell it. Use of Chrome data obtained through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
4. Who can see it
Data is stored on District-controlled systems. Access is limited, by role, to District technology staff, library/media staff, and building administrators who need it to manage devices, repairs, and assignments. Guardians can see repair and billing information for their own student through the guardian portal. Access by staff is logged.
We share data only with:
- Service providers that host or protect District systems on our behalf and are bound to use the data only for that purpose — for example our web hosting provider and Cloudflare, which fronts the extension's connection to District servers. Google receives device attestation requests (Chrome Verified Access) for enrolled devices and already administers the District's Workspace domain.
- Payment processing (Stripe) for guardians who choose to pay repair or insurance charges online; the extension itself sends nothing to Stripe.
- Law enforcement or as required by law, for example to recover a stolen device or to comply with a subpoena or court order.
Student information collected through the extension is an education record maintained by the District and is handled in accordance with the Family Educational Rights and Privacy Act (FERPA) and Connecticut student data privacy law (Conn. Gen. Stat. § 10-234aa et seq.). It is not used for targeted advertising and is not disclosed except as permitted by those laws and District policy.
5. How long we keep it
- Active-use periods (the individual start/end records) are automatically deleted after 21 days. Before they expire they are summed into a daily total per device and account (minutes of active use on a given day, with no start/end detail), which is kept for 400 days for year-over-year device-use reporting.
- Connectivity telemetry (offline periods and heartbeat details) is automatically deleted after 90 days.
- Answered check-in records are deleted after 400 days (roughly one school year plus a term, so year-over-year assignments can be reconciled).
- Device inventory, assignment history, and repair records are retained for the life of the device in the District's fleet and as required by the District's records retention schedule.
- Extension credentials issued to a device are revoked when the device is re-registered, retired, or idle for 180 days.
On the Chromebook itself the extension stores only what it needs to work offline: its device credential, its configuration, a short queue of events waiting to be sent, and the active-use periods not yet reported (at most a few hundred, oldest discarded first). Removing the extension (or the device from District management) deletes that local data.
6. Security
All communication between the extension and District servers uses HTTPS. Each device receives its own credential, which is stored only as a hash on the server. The extension's connection secret is delivered by enterprise policy rather than bundled in the extension, and requests are rate limited. Only District-managed Chromebooks can link to an inventory record.
7. Your choices and rights
Because the extension is required on District-issued devices, it cannot be disabled by the user. Students, staff, and parents/guardians may review the information the District holds about their device and use, request corrections, and ask questions by contacting the District Technology Department (below). Parents and eligible students have the rights afforded under FERPA to inspect and request amendment of education records. Guardians who prefer not to use the online repair or payment portal may handle repairs in person at their school's library/media center.
8. Children's privacy
The extension is used by students, including students under 13, on devices the District issues for educational purposes. The District collects this information under its authority as a school acting in the educational interest of its students, and does not permit its use for any commercial purpose. No account is created and no information is requested from a child beyond the device check-in responses described above.
Consistent with the Children's Online Privacy Protection Act (COPPA), the District provides consent on behalf of parents for this limited, school-authorised use of district-issued devices. The information described in this policy is collected solely to manage District equipment and support students — it is never used for behavioural advertising, for building marketing or commercial profiles, or for any purpose beyond the District's device program. Parents who wish to discuss their child's device record should contact the Technology Department using the details below.
9. Changes to this policy
We will post any changes on this page and update the effective date above. Material changes will also be communicated through the District's normal channels.
10. Contact
Fairfield Public Schools — Technology Department
501 Kings Highway East, Fairfield, CT 06825
[email protected]
See also our Terms of Use.