Back to Home

Privacy Policy — TecerTools PBD Extension

A Chrome browser extension that helps teachers automate PBD data entry on the official MOE/IDME portal. This policy explains what data the extension accesses, how it is used, and what is (and isn’t) sent anywhere.

Last updated: 3 Julai 2026 / 3 July 2026

View the main TecerTools Privacy Policy

Introduction

TecerTools PBD ("the extension") is a Chrome browser extension built by TecerTools to help teachers in Malaysia automate PBD (Pentaksiran Bilik Darjah) data entry on the official MOE/IDME portal (*.moe.gov.my, sppb.moe.gov.my). The responsible data controller is TecerTools, operated by its developer.

This extension is part of the TecerTools service and is subject to the same PDPA framework as our main Privacy Policy (linked below).

Summary

  • The extension only reads and fills in data on IDME pages that you, the signed-in teacher, are already viewing in your own browser.
  • It never sends data to MOE servers on its own — it only interacts with IDME’s own on-page form fields, the same way you would by typing into them yourself.
  • The only data that ever leaves your browser is: (a) your login email, handled by Firebase Authentication, if you choose to sign in; and (b) an optional data pull from your own TecerTools account, only if you use that specific feature.
  • We do not sell data, run ads, or use analytics/tracking scripts in the extension.

What data the extension accesses

While active on an IDME page, the extension reads what’s already rendered on that page in order to automate data entry, including:

  • Student names and IC (identification card) numbers, as shown in the class roster table
  • TP (Tahap Penguasaan) levels and markah (marks) values entered on the page
  • Class/subject labels needed to locate the right rows and fields

This data is read directly from the webpage in your browser session (via a content script) and used only to fill in TP levels, kemahiran (skills) assessments, and comments on the same page. It is processed locally and is not transmitted anywhere by this step.

What data is stored

Chrome local storage (chrome.storage.local), on your own device only:

  • Your cached login session (email, display name, Firebase ID token) if you sign in
  • Your cached subscription/plan status, refreshed periodically

Chrome session storage (chrome.storage.session), cleared when the browser closes:

  • In-progress form selections in the extension popup (e.g. which TP level you were about to apply), so you don’t lose your place if the popup loses focus

None of this is readable by MOE, IDME, or any other website — it is scoped to the extension itself.

Permissions requested

As declared in the extension’s manifest, the following permissions are requested, each for a specific function:

  • storage — to keep the cached login session and plan status on your device
  • activeTab — to run automation on the active IDME tab when you use the extension
  • alarms — to refresh sign-in and plan status periodically so account-gated features stay accurate
  • Host permissions include *.moe.gov.my and sppb.moe.gov.my for IDME pages, plus Firebase/Google domains such as securetoken.googleapis.com, identitytoolkit.googleapis.com, firestore.googleapis.com, and asia-southeast1-tecertools-dcdd9.cloudfunctions.net for sign-in, Firestore, and TecerTools Cloud Functions

Account sign-in

Signing in is optional and only required for certain advanced features (see below). Manual PBD entry works without an account.

  • Sign-in is handled by Firebase Authentication (Google’s identity platform), currently via email and password.
  • We store your email address and a Firebase-issued session token to keep you signed in.
  • We do not receive or store your password — Firebase Authentication handles that directly.

Firebase Authentication is a Google service. Your sign-in email and token may be processed by Google outside Malaysia, subject to comparable protections as described in our main Privacy Policy.

Optional feature: pulling your own TecerTools records

If you have a TecerTools account at tecertools.my and use the extension’s "pull from source" feature, the extension will:

  • Send a request, authenticated with your Firebase login, to a TecerTools backend endpoint to fetch your own previously saved student records
  • Use the returned records (names, IC numbers, TP/markah values) to fill in the IDME page, matching rows by IC number or student name

This request only happens when you actively choose to use this feature. No IDME page data is sent to TecerTools as part of this — it only pulls your existing records down to fill the page.

Limited Use

The use of information received by this extension adheres to the Chrome Web Store Limited Use requirements. Specifically:

  • We only use data to provide and improve the features described in this policy.
  • We do not transfer or sell data to third parties for advertising, marketing, or unrelated purposes.
  • We do not use data for any purpose other than those disclosed, and do not allow humans to read your data except with your consent or as required by law.

What we don’t do

  • We do not sell, rent, or share your data with third parties for advertising or marketing.
  • We do not run analytics, ad, or third-party tracking scripts inside the extension.
  • We do not transmit IDME/MOE student data to any TecerTools server as part of manual entry — that data only ever moves between the IDME page and the extension, locally in your browser.
  • We do not access any webpage other than the MOE/IDME domains this extension is built for.

Data retention & deletion

  • Local extension data (cached login, cached plan status) stays on your device until you sign out or remove the extension, at which point it is cleared.
  • Records stored in your TecerTools account (used only for the optional pull feature) are retained per your TecerTools account settings. You can request deletion of your TecerTools account and associated data by contacting us.

Children’s data

This extension is a professional tool for teachers. While it processes student names and IC numbers as part of assessment data entry, this happens entirely within the teacher’s own authorized MOE/IDME session and is not collected, stored, or transmitted by TecerTools except as described above (i.e., only when the teacher’s own saved records are pulled back into IDME at their request).

Changes to this policy

If this policy changes, the "Last updated" date above will be revised. Material changes will be reflected here before they take effect.

Contact

Questions about this policy or your data can be sent to: tecertools@gmail.com

© 2026 tecertools. All rights reserved.

Necessary storage (including the record of this setting) is always on because the site does not work without it. Analytics is optional.