Privacy & Security Policy

KST Learning VU Assistant • Version 1.0 • Effective 2 October 2026

Overview

KST Learning VU Assistant is an independent Chrome extension that provides an encrypted local VU LMS account manager, course information, results and local grade forecasting, a local Grade Book view, a personalized degree Road Map, Quick Links, lesson-progress controls, local quiz copying and PDF export, and an Academic Calendar view.

Unofficial product: This extension is developed by KST Learning. It is not affiliated with, sponsored by, maintained by or endorsed by Virtual University of Pakistan.

Information handled

For account management, the extension handles information that the user voluntarily enters into its account form:

For the course assessment display, the extension reads the following limited information from authenticated VU LMS pages after updated consent:

On the VU LMS Student Grade Book page, the extension reads the student summary, degree program, credit totals, semesters, course codes and titles, grades, Grade Points, equivalent percentages and percentiles already displayed on that page. It uses those values only to render the modern Grade Book view, calculate clearly labelled semester summaries, generate a PDF when the user requests one and build the personalized Road Map when the user opens it.

Quick Links reads student name, father name, VU ID, VU and personal email addresses, birth date, CNIC, study program and current semester from the signed-in VU LMS profile and displays them only in the current page. These profile details are not saved by Quick Links.

The extension does not retain fetched page HTML, session cookies, personal marks, grades, assignment submissions or lesson activity. The quiz PDF feature temporarily retains the limited quiz information described below.

On a supported lesson page, Lesson Auto-Watch reads the lesson identifiers already present in that VU LMS page and asks VU LMS to record completion. When a lesson contains a non-graded formative quiz, a user-initiated Complete & Next or Auto-Watch run selects an available response and submits the quiz to VU LMS so the lesson can continue. Quiz responses are not retained by the extension. A short-lived local automation flag is stored only while moving through lessons and expires after two hours.

On a supported quiz page, Quiz Copy reads the visible question, choices, mathematical notation and image descriptions only after the user clicks Copy Quiz. The formatted text is written to the device clipboard. Separately, when the user saves a selected quiz answer in VU LMS, the quiz PDF feature stores the question, choices, selected answer, course and quiz details, timestamp and a rendered question image locally. It keeps up to 25 questions from the current quiz to generate a PDF when the quiz finishes.

Purpose of use

This information is used solely to improve the user's VU LMS workflow: locally managing selected accounts, performing a user-initiated fill and sign-in action, showing official course and profile information, displaying results, rendering the local Grade Book theme and PDF, generating a degree-specific Road Map from official credit progress, calculating user-controlled grade forecasts in the current page, recording user-requested lesson progress, completing non-graded lesson quizzes during that requested progression, copying visible quiz content locally and creating the local quiz PDF.

Local storage and encryption

Saved account details are encrypted before being written to chrome.storage.local. The vault uses AES-GCM with a 256-bit key. That key is derived from the user's master password using PBKDF2 with SHA-256 and a random salt.

The master password and derived encryption key are not saved to Chrome storage. The derived key exists only in the extension-origin account-manager frame's memory while the vault is unlocked. The extension automatically locks the in-memory vault after 15 minutes of inactivity, when the extension is disabled, or when the user chooses the lock action.

The sensitive vault interface runs from the extension's own origin in an isolated iframe. It communicates with the VU LMS page through a restricted private channel. Only the selected Student ID and password are passed to the page when the user directly requests sign-in.

Assessment Scheme results are stored separately from the encrypted credential vault. Each cache record contains only a format version, course code, semester key, validated percentage values, attendance status and update time. It does not contain credentials or full page content. The cache is keyed by course code and semester and is refreshed from VU LMS.

Encryption reduces exposure of credentials at rest, but no software can guarantee absolute security on a compromised or unlocked device. Users should protect their Chrome profile and operating-system account.

Data transmission

The extension does not transmit saved credentials, master passwords or account lists to KST Learning servers, analytics services, advertisers or unrelated third parties. It contains no analytics SDK, advertising SDK or remote executable code.

When the user chooses a saved account, the extension places that account's Student ID and password into the VU LMS login form and initiates sign-in. The resulting communication is between the user's browser and the VU LMS website and is subject to Virtual University of Pakistan's own terms and privacy practices.

When course percentages are enabled, the browser makes same-origin HTTPS requests only to https://vulms.vu.edu.pk/ using the user's current signed-in session. Fetched scripts are treated as inert text and are never executed. Extracted assessment data is not sent to KST Learning or any other party.

When the user clicks a course card's Results or Forecast option, the extension reads that course's official Assignment, Quiz, GDB and GradeBook MidTerm pages in the current VU LMS session. Results displays Title, Total Marks, Obtained Marks and weighted aggregate. Smart Grade Forecaster combines those reported marks with the official Assessment Scheme and the user's temporary what-if slider values to calculate current, expected, best-case and worst-case estimates in the open page. Result page HTML, marks and forecast inputs are not cached or sent to KST Learning.

The modern Student Grade Book view, its downloadable PDF and the personalized Road Map are created entirely inside the current browser tab from Grade Book values supplied by VU LMS. The Road Map requests the official Grade Book page only after the user opens Road Map. Grade Book data, Road Map inputs and generated PDFs are not transmitted to KST Learning or any third party.

When the user opens Academic Calendar from the LMS sidebar, the extension fetches VU's public calendar page at https://vu.edu.pk/StudentServices/AcademicCalendar, parses event rows and renders them inside VU LMS. Calendar page HTML is not cached.

When Lesson Auto-Watch or Complete & Next is used, completion requests and any selected non-graded formative quiz response are sent only to VU LMS through the current lesson page. KST Learning does not receive lesson information or quiz responses.

Quiz Copy and the quiz PDF feature make no AI or third-party API request. Copied quiz text goes to the user's local clipboard; the current quiz's saved questions, choices, selected answers and rendered images are kept only in local extension storage until PDF generation clears them.

Sharing, sale and advertising

KST Learning does not receive, sell, rent, disclose or use the extension's saved account data for advertising, profiling, marketing or credit-related purposes. Human access by KST Learning personnel is not possible because the extension does not send the saved data to KST Learning.

Limited Use disclosure: Data handled by this extension is used only to provide or improve the clearly disclosed encrypted account-management, user-initiated VU LMS login, course and profile information, user-requested results, local Grade Book and PDF, personalized degree Road Map, local grade forecasts, lesson-progress, local quiz-copy and quiz PDF, and public Academic Calendar functionality. It is not used for personalized advertising, transferred for unrelated purposes or made available for human review by KST Learning. The extension also displays links to KST Learning services; academic or account data is not sent to those services by the extension.

Retention and deletion

Encrypted account records remain in the current Chrome profile until the user deletes an individual account, resets the entire vault, uninstalls the extension, clears extension data or resets the Chrome profile. Assessment cache entries are used for no more than 45 days and remain in chrome.storage.local until replaced by refreshed values, the extension is uninstalled or its data is cleared. Lesson automation state is deleted when stopped, completed, disabled or expired after two hours. The current quiz archive is removed after successful PDF generation; if a quiz is interrupted or PDF generation fails, that local archive may remain until replaced by another quiz, the extension is uninstalled or its data is cleared. Grade Book page data, Road Map data, generated PDF content, result marks, grade forecasts and what-if slider values are not stored. Disabling the extension removes injected page controls and stops new requests but does not itself erase local storage.

User controls

Master-password recovery

KST Learning cannot recover a forgotten master password because it is never stored or transmitted. A user who forgets the master password must reset the vault, which permanently deletes the encrypted account records.

Permissions

The extension requests the minimum permissions needed for its purpose:

Changes to this policy

If the handling of user data changes materially, KST Learning will update this policy and require renewed in-product consent where appropriate.

Contact

For support or privacy questions, contact KST Learning through kstlearning.com.