DCS Quick Login Privacy Policy
Release candidate 1.0.0. Updated 5 October 2026. This policy describes the Chrome/Chromium and desktop Firefox extensions. The userscript is a separate development/testing version.
Data and purpose
DCS Quick Login accesses either the Google Sheet URL supplied by the teacher or a locally selected Excel (.xlsx) / UTF-8 CSV (.csv) file. Both sources provide Nama (pupil name), Kelas (class), Username (DCS username), and Password (DCS password). It processes this data locally to list pupils, filter by class, search by name, autofill DCS credentials, and initiate the selected pupil's DCS login. It does process credentials; it is not a service that processes no data. Local import also records the original filename, selected worksheet, import time and pupil/class counts. Original file bytes are not intentionally retained after processing.
Before the first Sheet fetch, including for older saved configurations, the connection screen explains this handling. Connect & Allow records acceptance for the configured Sheet. Closing the screen without connecting makes no Sheet request. Change Google Sheet clears the usable roster and requires acceptance again. Normal opening and refresh for an accepted configuration do not repeatedly request acceptance.
For local files, the connection screen explains persistent local credential storage before Import & Allow. Selecting a file does not import it until that action. Successful import permits reuse without repeated consent or uploading the file again. The file is read locally and is not uploaded to Google, the developer or another server. Only one explicitly saved source type is active. Failed replacement leaves the previous valid source available.
Storage and retention
Browser extension local storage persists the configured Sheet URL, spreadsheet ID, gid, selected class, floating icon position, acceptance state for that configuration, and explicit dataSourceType. In Google Sheet mode, the fetched full roster and DCS username/password dataset are not intentionally persisted long-term; they remain in DCS page memory until replaced, cleared on refresh/change, or the page closes/reloads.
In local-file mode, the normalized full pupil roster, including DCS usernames and passwords, is deliberately persisted in extension-local storage with filename, worksheet name, importedAt and counts. It remains across page reloads and browser restarts until replaced, Remove Local Data is confirmed, a successful Google connection replaces the active local source, or extension storage is cleared. No storage.sync is used. Chrome storage.local (and Firefox's equivalent) is chosen for extension isolation and restart persistence with the existing storage permission; session storage cannot meet restart persistence. This is not a claim that local credential storage is encrypted or protected from someone with device/profile access. A working active page holds its own memory copy; after removal/replacement, close or reload other open DCS tabs to discard older copies.
Selected credentials from either source are placed in the DCS page's input fields, where that page can access them.
Settings and local-file credentials are not sent to browser storage sync and are not encrypted by a separate extension encryption layer. Protect the device and browser profile, avoid shared untrusted profiles, and remove local data when no longer needed. Browser/OS backup or device management behavior is outside this extension's control.
Transmission and external providers
The background context requests the configured Sheet directly over HTTPS from https://docs.google.com/, without Google OAuth, API keys, or login cookies. Google receives the request for the configured document/tab and ordinary network information needed to serve it. The extension does not send the roster back to Google or to a developer server.
When the user selects a pupil, their username and password are filled into http://dcs.moe.edu.my/ and the DCS Login control is clicked. The DCS website performs its authentication request. Production extensions operate only on http://dcs.moe.edu.my and https://dcs.moe.edu.my. DCS Quick Login operates on the DCS origin provided by the DCS service. The live DCS service is currently reachable through HTTP, as reported by teachers; HTTPS currently returns a connection refusal. HTTP DCS traffic, including the website authentication request, is not encrypted by HTTPS. The extension does not control the transport/security configuration, subsequent processing, retention or navigation of the DCS website. Pupil credentials are used only to populate the selected pupil's DCS login form and initiate its existing Login action. No developer backend receives these credentials.
Google Sheets and DCS are external services operated by their respective providers and are subject to those providers' policies. The extension cannot guarantee their security or availability.
Developer collection and use
There is no developer backend, Firebase, analytics, telemetry, advertising, sale of user data, or remote developer logging. The developer does not receive or store users' pupil credentials. No credentials are deliberately printed to the console. Local diagnostic messages concern form detection or failures, not a roster upload.
Data use is limited to the extension's stated pupil-selection and DCS login purpose. It is not used for advertising, profiling, unrelated services, or developer access to pupil records. Transfers are limited to the configured Google Sheet request and the selected DCS login. This describes the implementation's limited use, rather than a claim of store approval or legal certification.
User control
- Replace a Sheet using Settings, Change Google Sheet, then Connect & Allow.
- Replace locally stored data using Replace File, then Import & Allow; there is no automatic disk refresh. Successful replacement overwrites the old persisted roster. Original Excel/CSV files on disk are not modified or deleted.
- Switch sources explicitly. Google activation requires a successful validated connection; local activation requires a successful validated import. Previous Google configuration is kept when switching to local mode, and remains inactive. Successful switching to Google removes the stored local roster and metadata.
- Remove Local Data requires confirmation, deletes the persisted local roster/metadata and clears this page's roster, leaving an explicit no-source setup state. It retains any previous Google configuration without fetching it automatically. Reload or close other DCS tabs to clear their independent memory copies.
- Change Google Sheet stops use of the current in-memory roster and revokes acceptance. Close without reconnecting to leave it inactive. The previous URL remains locally saved; this action is not a full deletion or a dedicated Disconnect feature.
- To erase all extension settings, disable it, then remove it through Chrome's extension manager or Firefox's add-on manager. Removal normally clears local extension storage; Firefox temporary add-on testing can retain storage.
- For explicit clearing in a developer/testing installation, inspect the extension context and clear its local extension storage: Chrome storage.local.clear() or Firefox browser.storage.local.clear(), then reload the DCS page. Use the extension context, not the DCS webpage console. Close DCS tabs to discard their in-memory roster.
- Removing or clearing the extension does not change or delete the source Sheet or DCS accounts. Do not treat clearing this extension as revoking access to a public Sheet.
Security and administrator responsibility
The school/teacher must authorize use of pupil credentials, control access to the Sheet and its link, and protect the workstation. Required sharing is Anyone with the link, Viewer. Anyone who obtains that link may be able to read all Sheet contents, including credentials. The extension does not make a link-shared Sheet private. Change sharing permissions or rotate credentials with the responsible administrator when needed.
Private/incognito operation is disabled in production manifests. Persistent data remains local to the normal browser profile. Firefox declares authentication-information transmission because the helper initiates a DCS login even though the developer receives no credentials.
Before public submission, the publisher must supply a public URL for this policy and a real support/privacy contact. Neither is fabricated in this repository.
Tutorial site and voluntary support
The static tutorial site contains locally served assets and a user-triggered header-copy button. It has no analytics, tracking code, cookies, forms for collecting pupil data, or developer payment verification. Its external hosting provider may process ordinary web request information under its own policies. Tutorial and Support links in the extension open the configured site only after a deliberate user click; they do not attach Sheet settings or pupil data to the URL.
Optional support via the supplied payment QR does not unlock features. DCS Quick Login is free and remains free. Payments are handled separately by the user's bank/eWallet and the recipient's payment provider under their own policies. The extension and site do not request receipts, verify payments, maintain supporter accounts, or track donations. The recipient may receive ordinary payment details through the payment provider, independently of this extension. No pupil credentials are sent as part of support navigation.