Traffic Lite Security
Last updated: September 8, 2026
Overview
Traffic Lite is designed to help K–12 schools communicate and manage AI-usage expectations within Google Classroom.
Traffic Lite was intentionally designed using a data-minimization approach. The platform does not collect student submissions or student private communications from Google Classroom and does not store teacher-authored assignment body or instruction content. When an educator intentionally uses Traffic Lite GPS, limited teacher-authored assignment content may be processed transiently solely to provide the requested AI-usage policy recommendation.
Traffic Lite processes limited account, classroom, and AI-policy metadata only as necessary to provide the service.
Privacy Commitments
Traffic Lite:
Does not sell student, teacher, or school data
Does not display advertising
Does not build behavioral advertising profiles
Does not use student or school data to train general-purpose AI models
Does not access student submissions or private communications
Collects only the minimum information necessary to operate the service
Traffic Lite is intended for school-authorized educational use.
Data Collected
Depending on configuration and user role, Traffic Lite may process:
Teacher and administrator name/email
Google account identifier
Google Classroom course identifiers
Google Classroom coursework/material identifiers
AI-policy selection metadata (including selected color, Google Classroom course name, and post title)
Basic usage telemetry and timestamps
Application diagnostics and security logs
User-submitted support requests and optional attachments
Google Workspace staff-directory information, when Workspace Sync is enabled by an authorized administrator, which may include staff name, primary email, Google user identifier, selected organizational unit/Google Group relationship metadata used for sync, account/sync status, and synchronization timestamps
Last-active / usage timestamps used for account-status and inactive-user management
Teacher-authored assignment title and instruction content processed transiently when an educator intentionally uses Traffic Lite GPS; this content is not retained by Traffic Lite after the requested recommendation is returned
IP address and approximate location derived from IP address (such as city, region, or country), where used for security or account-install notifications
School or organization email-domain and account-volume information, and publicly available institution/administrator contact information obtained through Google Gemini API / Google Search-grounded research, when domain-cluster alerts are enabled
Traffic Lite does NOT collect:
Student assignment submissions
Student essay/writing content
Student private communications
Financial/payment information
Precise geolocation information
Health or biometric information
Student browsing history unrelated to Traffic Lite functionality
Data Storage Regions
Traffic Lite data is currently hosted using cloud infrastructure providers operating primarily within the United States.
Certain subprocessors may process limited operational metadata within other approved jurisdictions consistent with applicable agreements and law.
Google API Access
Google API Access
Traffic Lite integrates with Google using limited OAuth scopes in two separate contexts.
1) Ordinary Traffic Lite authentication and Google Classroom integration
Traffic Lite currently uses scopes including:
userinfo.profile
classroom.courses.readonly
classroom.courseworkmaterials
classroom.topics
Traffic Lite does not request Google Classroom roster/member-email scopes in its current production configuration.
2) Optional Google Workspace Directory Sync for authorized school and district administrators
When enabled, Traffic Lite uses limited read-only Google Admin SDK Directory permissions to retrieve administrator-selected staff organizational units, Google Groups/group memberships, and user directory information needed for staff provisioning and synchronization. Workspace Directory permissions are not required for ordinary teacher use.
Directory scopes used for this feature:
admin.directory.user.readonly
admin.directory.group.readonly
admin.directory.group.member.readonly
admin.directory.orgunit.readonly
Google Workspace Directory authorization credentials are stored server-side and encrypted at rest and are not exposed to the client application. Disconnecting Workspace Sync revokes or removes the associated directory authorization credentials.
Traffic Lite’s use of Google user data adheres to the Google API Services User Data Policy, including Limited Use requirements.
Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy
Security Practices
Traffic Lite uses administrative, technical, and physical safeguards designed to protect school-related information, and follows a least-privilege access philosophy designed to limit internal access to production systems and data.
Security measures include:
Encryption in transit using HTTPS/TLS
Industry-standard cloud infrastructure providers
Restricted administrative access
Role-based access controls where applicable
Authentication through Google OAuth
Environment separation between staging and production systems
Monitoring and logging for reliability and security purposes
Limited internal access to production systems
Vendor/subprocessor review and management
Traffic Lite aligns its security practices with industry-standard cybersecurity principles, including concepts reflected in the NIST Cybersecurity Framework.
Traffic Lite maintains operational backup and recovery practices designed to support service continuity and incident recovery.
Data Retention & Deletion
Traffic Lite retains data only as long as necessary to provide the service, maintain security, comply with contractual obligations, or satisfy legal requirements.
Schools and authorized educators may request deletion of associated data.
Deletion requests may be submitted to Derek Tranchina at Derek@TrafficLiteEdu.com
Traffic Lite will work with schools to securely delete or transfer applicable data within commercially reasonable timeframes and in accordance with applicable agreements.
Incident Response
Traffic Lite maintains procedures designed to identify, investigate, and respond to potential security incidents.
In the event of a confirmed data breach involving protected school-related information, Traffic Lite will provide notice consistent with applicable law and contractual obligations.
Subprocessors
Traffic Lite uses carefully selected third-party service providers (“subprocessors”) to help operate the platform.
Current subprocessors may include:
Google (California, USA): Authentication, Google Classroom API services, optional Google Workspace Directory API services, Google Gemini API services used to provide educator-initiated Traffic Lite GPS recommendations, and, when domain-cluster alerts are enabled, limited Google Gemini API / Google Search-grounded research of publicly available institution information | https://cloud.google.com/terms/data-processing-addendum | https://ai.google.dev/gemini-api/terms
Railway (California, USA): Application hosting/infrastructure | https://railway.com/legal/dpa
MongoDB Atlas (New York, USA): Database hosting/storage | https://www.mongodb.com/legal/data-processing-agreement | https://www.mongodb.com/legal/customer-service-agreement/technical-and-organizational-security-measures
Resend (California, USA): Transactional email delivery | https://resend.com/legal/dpa
Netlify (California, USA): Frontend hosting/deployment | https://www.netlify.com/gdpr-ccpa/
Kloudend, Inc. d/b/a ipapi (Nevada, USA): IP-based approximate location lookup used for security and account-install notifications | https://ipapi.co/privacy/ | https://ipapi.co/dpa
These providers process data only as necessary to provide their services.
Traffic Lite works to ensure subprocessors maintain reasonable security and privacy protections.
Accessibility
Traffic Lite is committed to improving accessibility and usability for all users.
Traffic Lite strives to align with applicable accessibility standards, including WCAG guidance, where feasible for a Chrome extension and related web applications.
Accessibility questions or requests may be sent to: Derek@TrafficLiteEdu.com
Security Contact
Questions regarding security or privacy may be directed to:
Derek Tranchina | Leading Edge Learning, LLC | Derek@TrafficLiteEdu.com