Skip to content
Lectern
Set-up guide Connect

Privacy

Lectern connects your Brightspace to the chat app you choose. Its tools read course information; they do not submit work, post messages or edit grades. It does not ask for or collect your Brightspace password.

What Lectern collects and processes

To answer a request, Lectern receives an instruction from the chat app you connected, reads the information from Brightspace with your session, and returns it to that app. That information can include courses, deadlines, submissions, grades, announcements, content, files, syllabuses, discussions, calendars and class rosters, and so can include information about instructors and other students; a class roster names other students but does not return their email address, account identifier or last sign-in time. It passes through Lectern's server and is not kept there. What is kept:

  • Cookies matching the Brightspace address you approve, including the authentication cookies and any other cookies returned for that address, and the Brightspace API token and its expiry that are minted from that session.
  • If you allow renewal, the cookies matching your school's sign-in address (for example login.microsoftonline.com). Lectern uses them to test and renew access to the same Brightspace account, and keeps them while the connection exists.
  • Your Brightspace name and user id, your course names (up to twelve) and the total count, your school's Brightspace and sign-in addresses, your browser family and time zone, the extension version, the connection identifier, creation and activity times, renewal state, credential and link versions, and the version and time of the terms you agreed to.
  • Operational records: connection attempts, browser syncs, link changes, OAuth approvals, MCP requests and the operator's own actions. Depending on the event they hold the connection identifier, time, school, tool or protocol method, duration, response size, status and error information, browser or client, request origin, IP address and approximate country, region and city. An MCP request's address usually belongs to the chat provider rather than to you. Tool arguments and answer content are not kept.
  • Cloudflare, which runs the server, also keeps request and diagnostic logs of its own for a few days. Those are separate from the records above and are not removed by deleting a connection. The private link is masked before it reaches Lectern's own error logs.

Stored cookies and tokens are encrypted with a key derived for your connection from Lectern's server key. The server can decrypt them, because that is how it operates the connection; this is not end-to-end encryption, and the other records are not encrypted in that way. No security measure removes every risk. Lectern keeps security measures appropriate to its size and to the sensitivity of what it holds: credentials are encrypted at rest, access to the server and to the records is limited to the Operator and protected by a hardware security key, and what is stored is kept to what the connection needs. If credentials or records are exposed, the Operator notifies the people affected and the authorities the law requires, without unreasonable delay, and says what was exposed and what to do about it. Report a suspected exposure to hello@lectern.chat, without including credentials.

Who can see it

The chat app you connect receives the Brightspace information it asks for: Anthropic when you use Claude, OpenAI when you use ChatGPT, Google when you use Gemini, and whoever runs any other client you choose. Each of them handles that information under its own terms, privacy policy and account settings, including retention, human review and model training; check those before you connect. Deleting Lectern does not delete what a provider already received. Cloudflare processes information to host and run Lectern. The Operator can open a connection's record, including the name, school, courses, state and the operational records above, for support, abuse handling, security incidents and legal obligations. Lectern does not sell personal information and does not use it for advertising.

How long

Connection records and stored credentials remain until the connection is deleted, or until the connection has gone 180 days without a question or a renewal, after which it is deleted as abandoned. Operational records tied to a connection go with it, or are removed by a scheduled clean-up after 90 days, whichever comes first. A record of each acceptance of the terms (the version, the time, the wording shown, the extension version, the connecting IP address and its location, the browser, the connection identifier, the Brightspace display name and user id, and the school) is kept for six years from the acceptance and is not deleted with the connection, so that the agreement can be shown to have been made. Website visit records are removed after 180 days. Daily usage counters expire after 40 days. Markers that stop a used token from being replayed remain for up to 400 days and hold no personal information. The clean-up runs on a schedule, so removal can lag the period by a short time.

Deleting

Choose Forget from the Lectern icon, or remove the extension. Once the deletion is processed, the connection record, the stored credentials and the operational records tied to the connection are deleted and the link stops working. A deletion or uninstall record keeps the connection identifier, school, time, country and browser for 90 days; it does not hold your IP address or city. The record of your acceptance of the terms remains for the period stated under How long. A first connection that fails leaves a similar record with the failure reason. Cloudflare's database recovery copies can hold deleted rows for up to 30 days. Removing the extension relies on Chrome opening a Lectern page at that moment; if it cannot, add the extension again and choose Forget, or email hello@lectern.chat.

The extension

The extension notices visits to Brightspace pages so it can offer the school to connect, and keeps up to five recently seen Brightspace addresses with their times in Chrome's local extension storage. After connecting, it also stores there the connection credentials, the private link, the school, your name, a course summary, the renewal choice and the connection state. lectern.chat can ask the installed extension for the connection state, the seen addresses and the private link, to run the set-up and authorization pages. The extension reads cookies only for the sites you approve, and sends them only to lectern.chat. Chrome words every site permission as "read and change"; Lectern's tools only read. Lectern's handling of user data, including information obtained through Chrome APIs and Brightspace, complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

The website

lectern.chat sends the page path, the referring address, the query string and what the set-up page found to Lectern's server without a cookie. The visit record keeps the page path, the referring site, campaign parameters, the event, the time, the approximate country, region and city, and the browser family, operating system and device class. Each visit carries an identifier derived from the IP address, the browser and the day; it changes daily, but the records are not guaranteed to be anonymous. Cloudflare's Web Analytics script loads on every page, and the pages request fonts from Google Fonts, which receives the request and the visitor's IP address.

Tracking

Lectern does not track visitors across other websites, and no advertising or analytics partner is allowed to build a cross-site profile from its pages. Some browsers send a Do Not Track signal; Lectern does not change what it collects when it receives one, because it collects the same minimal record either way, described above. Cloudflare's analytics script and Google Fonts receive the requests described above and handle them under their own policies.

Who operates Lectern

The individual who operates Lectern, the Operator, is responsible for the data practices described here and is reached at hello@lectern.chat. Lectern is not affiliated with, endorsed by or approved by D2L Corporation, any school, Anthropic, OpenAI or Google. Lectern runs on Cloudflare's hosting, database and storage services; information may be processed outside your state or country.

Your school and D2L

No school has approved Lectern and D2L has not either. D2L's end user licence agreement and many schools' acceptable-use policies restrict automated access, extraction by a program and third-party use of an account, and many treat handing over a session as sharing a credential. Read the ones that apply to your account before you connect. Connecting sends your Brightspace session, and with renewal your sign-in session, to Lectern's server, which then reads Brightspace with them. Do not connect unless the agreements that apply to your account, or written permission you have obtained, allow this access, as the terms explain. Your school and its sign-in provider may log and detect Lectern's activity through your account, including server addresses, access patterns and session renewals; Lectern does not make that activity invisible to them.

Who may use it

Lectern is for students who are at least 18 and have reached the age of majority where they live, connecting only their own student account. Do not connect or use Lectern if you live in, or are in, the European Union, the European Economic Area, the United Kingdom or Quebec. Lectern refuses school addresses associated with those regions and refuses connections that appear to come from them, but neither check is exact, and passing one does not make you eligible. A connection found to be ineligible is deleted.

Your rights

The extension and the set-up page show a summary of your connection, and the extension lets you delete it at any time. They do not export every record. For access, a copy, a correction or a deletion beyond that, email hello@lectern.chat; do not include your private link, cookies or tokens. Lectern arranges a proportionate way to verify the request and answers within the period the applicable law requires. If you email Lectern, it receives your address, message and attachments, and uses them to answer; the correspondence is kept only as long as needed to resolve the matter.

Terms

Connecting requires affirmative acceptance of the terms, which include warranty disclaimers, liability limits and your responsibilities concerning permitted access; those provisions apply only to the extent the law permits. On a first connection Lectern records the accepted terms version and the server time of acceptance in the connection record. When the terms or this policy change materially, the new version is posted here with a new date and the extension asks you to accept it; the version recorded on your connection is the one you accepted.

Disputes

To the fullest extent permitted by law, every dispute, claim or controversy between you and the Operator about this policy, the handling of your information or anything else connected to Lectern belongs to the state or federal courts sitting in New York County, New York, and you and the Operator each consent to their jurisdiction. You and the Operator each waive a trial by jury and the right to bring or take part in a class, collective, consolidated or representative action; claims are brought and resolved one person at a time. An eligible claim may instead be brought individually in a small claims court, a complaint may always be made to a regulator, and a right that the applicable law does not allow to be waived is not waived. The terms state the one-year period for starting a claim and the New York law that governs.

Legal requests

If a court, a regulator or a law enforcement agency makes a lawful demand for information about a connection, the Operator provides only what the demand requires, and tells the person affected unless the law or the demand forbids it. A demand can also be made to Cloudflare or to another provider, which may answer it without telling the Operator. Lectern does not volunteer information about a connection to a school, to D2L or to anyone else.

Contact

hello@lectern.chat, for questions, privacy requests and security reports. Do not send passwords, cookies, tokens or private links.

Last updated 2026-09-15.

Lectern

Lectern is independent of D2L, Anthropic, OpenAI, Google and your school.

hello@lectern.chat

Set-up guideConnectPrivacyTerms

Lectern, 2026A Chrome extension for Brightspace