Moodle Pro for Notts
Effective date / Last updated: 6 October 2026
Extension version covered: 4.0.1
Developer: Haoming Xia
Privacy and support contact: [email protected]
This policy explains how Moodle Pro for Notts handles information when you use the browser extension. The current extension package is named Nottingham Moodle Assistant. Both names refer to the extension covered by this policy.
The extension provides optional university sign-in assistance, course change tracking through Monitor, file download shortcuts, and appearance and accessibility controls for Nottingham Moodle. Its page scripts operate on https://moodle.nottingham.ac.uk/* and https://login.microsoftonline.com/*.
The extension has no developer-operated data server, cloud backup, analytics service, advertising service, or automatic diagnostic upload. Its saved extension records remain in your local browser profile. Sign-in and downloads still communicate with the relevant university and Microsoft services through your browser, as described below.
The extension reads the numeric user ID of the authenticated Moodle user from the current user's menu and page configuration. The Moodle site address and this ID identify a local partition. School email settings, sign-in and feature preferences, course baselines, Monitor changes, read and unread state, highlights, personal flags, and per-course controls are saved separately for each user. Switching to another user selects that user's records; returning restores the earlier user's records. The extension does not use a saved email as proof of the current Moodle identity.
The overall extension switch, popup language and privacy-consent version apply to the whole browser profile. If the current identity cannot be confirmed, course records are not read or written. Page bindings are revoked on an account switch or logout, preventing an earlier page or popup request from writing to another user's partition.
If you enable sign-in assistance, you can save your school email prefix and select @nottingham.edu.cn, @nottingham.ac.uk or @nottingham.edu.my for the current user. The extension uses the resulting email address to start the normal Moodle sign-in process, choose the matching account displayed by Microsoft, or fill the Microsoft email field and advance to the next step. To support assistance after logout, it also keeps the most recently configured email and sign-in switch as the next sign-in target in the encrypted vault. This target does not authorize access to that user's course history. When no Moodle user is identified, you may configure this next target without changing a previously bound user's settings.
The extension examines relevant page elements, including displayed account identifiers and sign-in or error states, to decide whether this action is appropriate. These page observations are processed locally. It does not retain a list of other accounts displayed on the Microsoft page.
The extension does not read password or verification-code values, save passwords, or extract authentication cookies or Microsoft SSO tokens. Password entry, multifactor authentication, authorization prompts, and other authentication decisions remain with you and the services involved. The saved email is submitted through Microsoft's normal sign-in form; the developer does not receive it.
To coordinate a sign-in across tabs and page transitions, the extension temporarily holds the target email, tab association, an internal operation identifier, expiry information, and workflow status in browser session storage. Internal identifiers are generated by the extension and are not university or Microsoft authentication tokens. The extension keeps a one-attempt limit and a pause after an explicit logout for the relevant tab, but does not create a persistent sign-in activity history.