Security and data
What the extension can access, what our server stores, and who can see it.
What's on our server
- The text of your files, pages and assignments, with course, folder and title
- The link to each item on itslearning
- A sha256 hash of each file, so the same file in the same course isn't processed twice
- Your email, your plan and your sync reports (counts and error codes only)
- Your school on itslearning (e.g. "sdu") as plain text, and an HMAC fingerprint of your itslearning person id, so the account belongs to one itslearning user. The extension sends the person id; the server stores only the fingerprint
What is never sent to us
- Your original files: PDFs, slides, documents, images
- Your itslearning password. The extension never sees it.
- The extension's itslearning sign-in key. It's kept in the extension's storage in the browser and is sent only to itslearning.
- Video and audio, which the extension doesn't download
The extension only reads
It fetches what you can already see on itslearning and doesn't hand in, post or change anything. It only has access to pages on itslearning.com, itslearning.net and docta.dk.
Your own itslearning sign-in
The extension syncs with your own itslearning sign-in in the browser and goes through itslearning's normal sign-in links. So a sync signs the browser in to itslearning or keeps it signed in. If you don't want that, turn on Keep itslearning signed out after a sync in the extension's settings. Cookies from itslearning stay in your browser and are never sent to us. Read more.
No passwords
You sign in to us with a link in your email. The extension signs in to us through a window from docta.dk and never sees a password. There are no passwords for us to store.
Only you can search your library
Your AI gets access when you sign in and approve it, or with a personal token. Under My account you can see when each token and each connected app was last used, and remove them. Your AI only sees your library and can't change it.
We don't read it
The text is stored unencrypted on our server so it can be searched. Our admin tool shows counts, sizes and error codes for libraries, not content.
Server in the EU
The library lives on one server at Netcup GmbH, Germany. No files are processed on the server; it only stores and searches text.
Logs without content
For each request the server logs the time, account, method, address (without course and file ids) and status code, for 30 days. Not text from your library, tokens, itslearning ids or IP addresses.
Encrypted weekly backups
Accounts and libraries are backed up weekly. The backup is encrypted with age, and the key that opens it isn't on the server; we keep it offline. A backup is deleted after 28 days. A deleted account is never restored: every restore deletes the deleted accounts again. So copies of your account disappear automatically within 4 weeks after you delete it.
Payment at Stripe
You pay on Stripe's own page. We don't see your card number.
Download and delete your data
Under My account, signed in on the website, you can download everything we hold about you as a zip file, and delete your account. The extension's sign-in isn't enough for that. When you delete your account, it is deleted right away and confirmed by email. Copies in our encrypted backups disappear automatically within 4 weeks and are never restored.
Found a security issue?
Email support@docta.dk with the subject "Security". We reply within 2 working days.