Updated September 9, 2026
Privacy for the Lens pilot
XQ Lens helps teachers identify competency learning opportunities in curriculum. This notice describes the extension and its pilot backend. Contact dfernandes@xqinstitute.org with privacy questions.
What Lens reads and sends
Lens reads content from a tab you open after you start the extension and allow access to that site. It can also extract text locally from a PDF you choose or accept text you paste. It does not crawl other pages or collect your browsing history.
Before analysis, you can review and edit the extracted text. Choosing Start scan or Scan again sends the selected text, competency targets, and framework version over HTTPS to the Lens backend and then to Google’s Gemini API. Starting a scan authorizes that request to continue while you browse other tabs with Lens open. The normal scan payload does not include the page URL or browser history.
What is kept
The extension stores an anonymous installation identifier, connection settings, and site permissions in Chrome’s local extension storage on your device. Source text and scan cards are held in memory while the panel is open; Lens does not save them as student assessments.
The application backend processes source text and AI results transiently. It does not persist them in a database or write them to application logs. A dedicated Lens schema in Supabase holds time-bounded usage counters and concurrency leases keyed by anonymous installation identifiers, not source text, quotes, student names, or page URLs.
Hosting and API providers may process request metadata, such as timestamps, network addresses, request paths, and diagnostic information, under their own terms. Google’s handling and retention of content depend on the Gemini account’s service terms and settings. See Gemini API terms, Vercel privacy policy, and Supabase privacy policy.
Evidence highlighting
On accessible webpages, evidence highlighting happens locally and does not edit the source or make another AI request. For PDFs, Lens may add the quote to a URL fragment and reload the same PDF tab. The fragment is not sent in the PDF’s HTTP request, but it can remain in browser history or appear in a copied link. Inaccessible sources use the local scanned-text preview.
Your choices
Use public curriculum during the pilot and remove private details before scanning. You can close the panel, remove site access in Chrome, forget enabled sites in Settings, or uninstall Lens. These actions do not retract a scan that has already been sent. Contact support with privacy requests. Usage windows expire automatically, and expired counter records are cleaned up during subsequent scan requests. Operational backups may retain prior counter records under the database provider’s retention settings.
Limited use
Lens uses collected information to provide curriculum scanning, display source-grounded results, apply usage limits, and prevent abuse. We do not sell it or use it for advertising. XQ Lens’s use of information complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Lens is a teacher-facing tool and does not create student mastery scores or profiles.