Skip to content

docs(legal): every claim about the extension matches its code, for 0.8.2 and 0.8.4 - #66

Merged
bryanfawcett merged 2 commits into
stagingfrom
claude/blissful-bell-4liuye
Oct 5, 2026
Merged

bryanfawcett merged 2 commits into
stagingfrom
claude/blissful-bell-4liuye

Conversation

@bryanfawcett

Copy link
Copy Markdown
Member

The legal pages now match what the Toddle Enhancement Extension's code does, checked against the extension's source and its data-fields document (docs/toddle-data-fields.md). They describe both 0.8.2, which teachers have now (0.8.3 carries the same code), and 0.8.4, the next patch. Where the two differ, the pages say "from version 0.8.4". The version numbers live once, in extensionVersions in src/data/legal.ts.

What changed

  • Flags. From 0.8.4, flags show as Toddle shows them. The free switch hides them everywhere. Versions before 0.8.4 hid them by default. Unless flags are hidden, the sidebar asks Toddle for a student's flags each time it opens, and keeps them only while it is open.

  • Memory. "Held for a few minutes" is replaced by what the code does. Answers stay in the tab's memory until the tab is closed or reloaded. They are never written to storage, and are reused for at most 5 minutes (2 for a student's day).

  • Storage. The pages now list every stored value:

    • the extension's own: settings, licence key, last revocation check, and the signed-in Toddle email (on the device only);
    • four values on Toddle's own site storage, each described.

    No student data is stored. The pages no longer mention a "message button style" value, which doesn't exist.

  • Switches. All seven are listed, including gradebook tools and student details on the Attendance dashboard.

  • Licence binding. A key may name who it is for. Where it does, the check runs in the browser and nothing is sent. A key naming no one works for any account until it expires (security page).

  • Reads. The pages now cover the gradebook, home page, profile page and Attendance dashboard reads, not just the sidebar. They also say the extension adds read-only fields to two of Toddle's own requests.

  • Sign-in. "Never sees your password" becomes "never asks for or stores your password". The sign-in headers stay in tab memory and go only to Toddle.

  • What leaves the device:

    • Toddle's API, with the teacher's own session;
    • student photos, from wherever Toddle serves them;
    • Formspree feedback, only on Send;
    • the revocation GET to licences.nyuchi.dev, which carries nothing.

    Teacher actions: CSV saved locally, mailto and tel links, and Toddle's chat.

  • Revocation check. "At most once a day" (a new key within 5 minutes). If the check fails, the last result stands.

  • Security page. It says which versions it covers. It adds the 6 October 2026 review (findings 13–16, fixed in 0.8.4 before publication) and what code inside Toddle's page cannot promise.

  • Terms and product page. The licence covers the Attendance dashboard's details.

  • Dates. legal.updated is 2026-10-06, and llms.txt matches.

Files: src/data/legal.ts, src/pages/legal/{privacy,data,cookies,security,student-privacy,terms,vulnerability-disclosure}.astro, src/pages/toddle-enhancement-extension.astro, public/llms.txt, SECURITY.md, CHANGELOG.md.

Checks

  • npm run check and npm run ci:check: 0 errors, 0 warnings.
  • npm run format:check: clean.
  • npm test: build clean, 87/87 tests, CSP check passes.
  • npm run lint: 1 error and 5 warnings, the same as on staging. They are all in files this PR doesn't touch (astro.config.mjs, CookieBanner.astro, scripts/qa.mjs, scripts/probe-intercom-csp.mjs).

Known issue, not fixed here

The built HTML drops the space where a line break sits between text and an inline tag, giving Applies to<strong>…. This PR fixes the cases in its own new text. The rest predates it and needs a separate fix, probably in the HTML compression.

Open questions

  • "Nyuchi does not log it" (the IP address at licences.nyuchi.dev) is kept from before. It can't be checked from code here.
  • The reviews are described as adversarial; "independent" was dropped where review text was rewritten. Put it back if it is true.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq


Generated by Claude Code

…8.2 and 0.8.4

Checked against the extension at 75876d4 (docs/toddle-data-fields.md, the
security reviews, SECURITY.md, licence.js, background.js and the code).

- Flags: from 0.8.4 they are shown as Toddle shows them and the free switch
  hides them everywhere; before 0.8.4 they were hidden by default. Unless
  flags are hidden, the sidebar asks Toddle for them each time it opens.
- Memory: answers stay in the tab until it is closed or reloaded, reused
  for at most 5 minutes (2 for a student's day); never written to storage.
- Storage: licenceCheck and licenceViewer in the extension's storage, and
  the four values on Toddle's site, each described. Drops a "message button
  style" value the code does not have.
- Switches: adds gradebook tools and the Attendance dashboard's details.
- Licence keys may, not must, name who they are for.
- Reads: gradebook, home page, profile page and Attendance dashboard, plus
  the sign-in headers and academic year noted from Toddle's own requests.
- What leaves the device, listed exactly, student photos included.
- Security page: the review of 6 October 2026 (findings 13 to 16) and what
  code inside Toddle's page cannot promise; says which versions it covers.
- Version facts in one place (extensionVersions); dated 6 October 2026.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq
@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
learning Ready Ready Preview Oct 5, 2026 11:40pm UTC

Request Review

…g spaces

- The privacy policy names the two laws Nyuchi holds itself to: Zimbabwe's
  Cyber and Data Protection Act [Chapter 12:07], and the EU and UK GDPR,
  applied to everyone. "The law we follow" names POTRAZ, says where data goes
  and how transfers out of the EU and UK are covered. The rights section
  lists each right, the one-month answer and where to complain (POTRAZ, the
  ICO, or an EU authority). Each legal basis carries its GDPR article.
- Breaches go to POTRAZ within 24 hours (Zimbabwe's Act), and to an EU or
  UK regulator within 72 where the GDPR requires it (privacy and data pages).
- Student privacy names both laws. Singapore's PDPA is no longer named, in
  the pages or the consent notes. The facts live once, in `dataProtection`.
- compressHTML off: Astro's compression dropped the space where a line break
  sat next to an inline tag ("Applies to<strong>…"), about 90 times across
  the legal and product pages. Now none; CSP hashes unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CoDNYz27iJ7o8PPztCzTpq
@bryanfawcett
bryanfawcett marked this pull request as ready for review October 5, 2026 23:45
@bryanfawcett
bryanfawcett merged commit 5883db5 into staging Oct 5, 2026
13 checks passed
@bryanfawcett
bryanfawcett deleted the claude/blissful-bell-4liuye branch October 5, 2026 23:46

This branch was successfully deployed

1 active deployment
Preview — 9936fee9 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants