Privacy Policy - Endpoint Proctoring

Effective Date: 2026-09-03
Last Updated: 2026-09-03

This policy covers the proctoring product only: the Endpoint Proctoring Chrome extension, the candidate check-in flow, and the exam monitoring that goes with them. For our device-monitoring and BYOD product, which is a separate service with its own desktop agent, see https://endpoint.solutions/privacy.

1. Introduction

This Privacy Policy describes how Endpoint Solutions ("we", "us", "our") collects, uses, stores and shares information when you take a proctored examination that uses the Endpoint Proctoring Chrome extension ("the Extension") and the Endpoint check-in flow.

We provide this service to the institution, employer or certification provider that administers your exam. That organisation decides that your exam will be proctored, chooses several of the settings described below, and reviews the results. In this policy we refer to it as "the institution".

The Extension is distributed through the Chrome Web Store at
https://chromewebstore.google.com/detail/endpoint-proctoring/idhddiimegopogcbepnbbipjkojdnnbm.

2. What we collect

2.1 Camera video and microphone audio

During a proctored exam the Extension records a continuous video stream from your camera, at approximately 1280x720 and 15 frames per second.

Your microphone is recorded as part of that stream. The camera recording is encoded with both a video track and an audio track, and both are uploaded to our servers in short segments, roughly every five seconds, for the duration of the exam. The audio is retained with the video and is available to reviewers. It is not automatically analysed, transcribed or matched against anything.

2.2 Screen recording

The Extension also records your screen or browser window continuously, at up to 1920x1080 and up to 10 frames per second, and uploads it in the same way. The screen recording captures video only - no system audio and no tab audio is included.

Whether the screen recording is kept after the exam is an institution setting. Where the institution has not enabled screen-recording retention, the screen recording is deleted from our servers when the exam session is finalised.

2.3 Periodic still frames sent for automated analysis

Separately from the recordings above, the Extension captures a still image from your camera - 640x480, JPEG - starting 60 seconds after monitoring begins and then approximately every 30 seconds for the rest of the exam.

Each of these frames is sent to our servers and then on to OpenAI for automated analysis (see section 4.1). The frames themselves are not stored; only the result of the analysis is kept - an event record and any violation it raises.

2.4 Check-in media: photo ID, selfies, and room scan

Before the exam starts, the check-in flow captures and stores:

  • One photograph of your government or institutional identity document.
  • Five selfie frames taken as a liveness check, in a fixed sequence: facing centre, looking left, facing centre, looking right, facing centre.
  • Six room-scan photographs at fixed checkpoints: your desk, under your desk, behind your monitor, the wall to your left, the wall to your right, and the doorway.
  • One continuous video recording of the room scan.

Accepted formats are JPEG, PNG and WebP for images and WebM for video. Stills are limited to 10 MB each and the room-scan video to 50 MB.

You may be permitted up to three check-in attempts. The media from every attempt is stored, not only the attempt that succeeded.

The identity document, the five selfie frames and all six room-scan photographs are transmitted to OpenAI for automated verification, as described in section 4.1. The room-scan video is not sent to OpenAI.

2.5 Browser and exam-page activity

While the exam is in progress, the Extension monitors and reports:

  • Tab and window activity: switching away from the exam tab, and the exam window losing focus. The record of a tab switch contains internal tab identifiers, not the addresses of your other tabs.
  • New tabs and pop-ups: the Extension closes tabs and pop-up windows opened during the exam.
  • Navigation attempts: attempts to leave the exam page, to submit a form to another address, or to load a frame from another address. These records contain the full web address involved, including any query string. Exam links issued by some platforms carry an access token in the address, so that token can appear in a record.
  • Clipboard activity: copy, cut and paste actions. For clipboard actions that are not performed with a keyboard shortcut, the first 100 characters of the copied, cut or pasted text are recorded and transmitted.
  • Keyboard shortcuts: we detect a fixed list of shortcuts - copy, cut and paste; the developer-tools shortcuts; print; the print-screen key; and the application-switch shortcut. We record which shortcut was pressed. We do not log your keystrokes and we do not record anything you type into the exam.
  • Right-click, drag-start, and unusually large text selections.
  • Print attempts.
  • Developer-tools detection, both by inspecting the console and by watching for changes in the size of the browser frame. Those frame measurements are included in the record.
  • Screen-sharing attempts started from the exam page.
  • A second display being connected. This is recorded as a true or false indicator only. We do not collect the number of monitors or their resolutions.
  • Elements or frames injected into the exam page.
  • Free text that you enter into the "report an issue" prompt, if you use it.

These monitors become active only on the armed exam page and on the check-in pages. They are not active on other sites you visit.

2.6 Technical information

We collect:

  • Your browser user-agent string.
  • The version of the Extension.
  • Timestamps for every recorded event.
  • The size of your browser frame, only where developer-tools detection is triggered.
  • Whether a second display is connected, as a true or false indicator.
  • Your IP address. Our servers record the IP address of the first request the Extension makes for your session, and note in our logs when that address changes during the session. We also record the IP address from which you accepted the exam rules.

When you accept the exam rules and the recording notice, we record that you accepted, the time you accepted, the IP address you accepted from, and the point in the flow at which you accepted.

2.8 Identity information supplied by the institution

Your name and email address are supplied to us by the institution or the exam platform when your session is created, so that the session can be matched to you. We store them with the session record.

3. What we do not collect

To be clear about the limits of the monitoring:

  • We do not log keystrokes and we do not record what you type.
  • We do not track mouse or cursor movement.
  • We do not collect your screen resolution, your monitor count, your operating-system platform string, your time zone, your language, your hardware details, your device serial number, or a list of your installed applications.
  • We do not perform any geolocation lookup on your IP address for proctoring sessions.
  • The Extension does not read file contents and does not monitor file activity on your device.
  • The Extension does not monitor your browsing outside the exam and check-in pages.
  • The Extension performs no face detection, eye tracking or gaze analysis on your device. All image analysis happens on our servers and at OpenAI.
  • The Extension contains no analytics, advertising, error-reporting or other third-party code, and it makes no network request to any third party. Our servers use no analytics or error-reporting service that would receive your data.
  • We do not use tracking cookies. The Extension holds session data in Chrome's local extension storage on your own device. It does not use Chrome's synchronised storage, so nothing is copied to your Google account.
  • We do not sell personal information.

4. Who we share your information with

4.1 OpenAI - automated image analysis

Your exam and check-in imagery is sent to OpenAI. This is the most significant third-party disclosure in this policy, and it applies to every proctored session.

We send the following to OpenAI's API (api.openai.com), using the gpt-4o-mini model:

  • Your identity document photograph. We ask the model to read and return the name, date of birth, expiry date, document number and issuing authority shown on the document.
  • Your five liveness selfie frames, to assess whether a live person is present.
  • Your identity document together with one selfie frame, to compare the two faces.
  • All six room-scan photographs, together with one stored image of your face from the liveness step, to assess the room. The name the institution holds on file for you is included in the text of this request.
  • Each periodic still frame captured during the exam (section 2.3), to look for indicators such as another person present, a phone or other device visible, prohibited materials, poor lighting, or the candidate appearing to look away from the screen.

The camera recording, the microphone audio, the screen recording and the room-scan video are not sent to OpenAI.

This analysis cannot be switched off by the institution and there is no candidate opt-out. If the analysis service is unavailable, check-in fails rather than continuing without it.

4.2 The institution administering your exam

The institution has a console of its own. In that console it can see a list of its exam sessions, and for each session your name, your email address, the exam name, the session status, the date and your compliance score. The console does not show your check-in media, your recordings, or the detail of individual violations.

The institution receives the fuller record through the channels below, not through that console.

Where the institution has configured a notification endpoint, we send that endpoint a summary at the end of your session. It contains your name and your email address, the exam and course names, your compliance score, every violation with its description, and a reference to each recording. Those messages are cryptographically signed. If the institution configures an endpoint that does not use HTTPS, that information travels without encryption.

Where the institution has not configured its own storage bucket, that summary can include a time-limited download link to a recording. The link is valid for seven days and requires no login, so anyone who holds it can download the recording during that period.

4.3 Storage controlled by the institution

The institution can configure its own Amazon S3 bucket, or an S3-compatible bucket, in which case we copy your recordings into its bucket. The stored object carries metadata that includes your email address. Once a recording has been copied successfully, our own copy is deleted.

Where the institution configures a bucket that is not Amazon S3 but an S3-compatible service at an address of its own choosing, we do not verify the certificate of that address when we upload.

We do not operate an object-storage bucket of our own for proctoring recordings.

4.4 The exam platform

Where your exam is delivered by an integrated exam platform - for example TrueAbility - we send that platform your session identifier, your compliance score, the list of violations with their descriptions, severities and timestamps, and the type, duration and storage reference of each recording. We also use that platform's interface to start, pause, extend or stop your exam at the institution's direction.

4.5 Your learning management system

Where your exam is launched from a learning management system over LTI, we report violation flags to that system, including a severity and a reason description, and we report identity-verification failures with a reason code. Where recordings have been copied to an institution-controlled bucket, we register the bucket name and the object key with that system. We do not send the recording data itself and we do not send a download link.

We may disclose information where the law requires it - in response to a court order or other legal process, or to a government authority acting with proper authority - and where it is necessary to protect our legal rights or to prevent fraud or a security threat.

5. How we use your information

We use the information described above to:

  1. Confirm that the person taking the exam is the registered candidate.
  2. Detect and record conduct that can breach the exam rules.
  3. Produce a compliance report for the institution to review.
  4. Give a reviewer the evidence needed to reach a decision about a flagged session.
  5. Answer your support requests and diagnose technical faults.
  6. Meet our legal obligations.

The Extension does not end your exam. It records and reports. A human reviewer and the institution decide what follows, and any termination is carried out by the exam platform.

6. Where your information is stored

  • Check-in media - your identity document photograph, your five liveness frames, your six room-scan photographs and your room-scan video - is stored as binary data inside our application database. It is not stored as files on a public web server and it is not reachable at any public web address. Requests to the /storage/ path on our servers are refused outright.
  • Camera and screen recordings are assembled and held on the private disk of the application server that received them, outside any publicly served directory, until they are either copied to an institution-controlled bucket or deleted.
  • Session records, violations, events and verification outcomes are stored in our application database.
  • Recordings copied to an institution-controlled bucket are then held by that institution, in storage that it controls, under its own terms.

Our application enforces HTTPS for all connections in production, so your information is encrypted while it travels between your browser and our servers, and while it travels to OpenAI.

7. Retention and deletion

We prefer to be accurate here rather than reassuring.

Our system does not currently perform any automated deletion of proctoring data based on age. There is no scheduled job, task or timer that removes exam sessions, check-in media, recordings, violations or event logs after a set period. Your check-in media, your recordings, your violation records and your event logs are retained until the institution or we delete them, and a deletion request is carried out by hand.

The deletions our system does perform are operational, not time-based:

  • Where a recording has been copied successfully to an institution-controlled bucket, our own copy of it is deleted.
  • Where the institution has not enabled screen-recording retention, the screen recording is deleted when the session is finalised.
  • Deleting an exam session record from our database also deletes the check-in media, the recording records, the violations and the event records attached to it.

Deleting a session record from our database does not remove any copy that an institution already holds in its own bucket. That copy is subject to the institution's own retention practices.

If you want your proctoring data deleted, contact the institution that administered your exam, or write to us at the address in section 12. We will act on a verified request.

8. Who can access your information

  • Our administrators. Your check-in media, your recordings and the detail of your violations can be retrieved only through administrator endpoints that require an active, signed-in Endpoint Solutions administrator session. Check-in media is served as a file download that browsers and caches are told not to keep, and only within the exam session it belongs to. These administrator accounts belong to Endpoint Solutions staff, not to the institution. They use a single factor: an email address and a password. We do not currently require multi-factor authentication for administrator access.
  • The institution, as described in section 4.2 - a session list in its own console, its notification endpoint, and its own storage bucket.
  • The exam platform and the learning management system, as described in sections 4.4 and 4.5.
  • OpenAI, for the imagery described in section 4.1.
  • You. The candidate flow has no login and no facility for you to view or download your own recordings, check-in media or violation records. A request for a copy of your data must be made to the institution or to us, and it is handled by hand.

9. Your rights and choices

Before the exam

  • Choosing not to continue. You can decline to install the Extension or to complete check-in. Doing so will usually mean that you cannot sit the exam. The institution, not us, sets that requirement.
  • Being informed. You can ask, before you start, what will be collected. This policy is the answer. You can also ask us or the institution.
  • Technical check. The check-in flow lets you confirm that your camera, your microphone and screen sharing work before the exam begins.

After the exam

  • Access. You can request a copy of the data we hold about your session. Requests are handled by hand and, where the institution controls the exam record, we will usually direct the request to the institution.
  • Correction. You can dispute a violation record or a verification outcome. Decisions about the consequences of a flagged session rest with the institution.
  • Deletion. You can request deletion of your data, as described in section 7.
  • Complaint. You can raise a concern with the institution, with us, or with your data-protection authority.

Where you are in a jurisdiction that gives you statutory rights over your personal information - for example under the GDPR or the California Consumer Privacy Act - those rights apply, and we will act on a verified request. Note that the institution has its own obligations as the organisation that decided to proctor your exam, so a request that concerns the exam record itself is often best directed there.

10. Security

These are the measures our system applies:

  • HTTPS is enforced for all connections in production.
  • Check-in media is held inside the application database rather than as web-served files, and the public file path that once served it is now blocked at the server level.
  • Check-in media is served only to a signed-in administrator, only as an attachment, with caching disabled, and only within the exam session that it belongs to.
  • Uploaded media must match a strict list of permitted formats. Anything else is rejected before it is stored.
  • Requests from the Extension are authenticated with a per-session token, and a request that submits a camera frame for analysis must also carry a valid cryptographic signature.
  • Summaries sent to an institution's notification endpoint are cryptographically signed.
  • Connections to the analysis provider verify the provider's certificate.
  • Credentials that an institution gives us for its own storage bucket are stored encrypted.

To avoid a misleading impression: we do not currently apply application-level encryption to stored check-in media, to recordings, or to the session fields that hold your name and email address. Those rely on the protections of our hosting platform and our database. Administrator access is single-factor, as section 8 states.

If we become aware of a breach that affects your information, we will notify the institution and, where we are required to, you and the relevant authorities.

11. Children, international transfers, and California

Children. This service is not directed at children under 13 years of age. Where an exam involves a minor, the institution is responsible for obtaining any consent that the law requires, including under COPPA and FERPA.

International transfers. Your information can be transferred to and processed in countries other than the one in which you sit the exam, including the United States. In particular, the automated image analysis described in section 4.1 is performed by OpenAI in the United States.

California. If you are a California resident, you have the right to know what personal information we collect and how it is disclosed, to request deletion, and not to be treated differently because you exercised those rights. We do not sell personal information.

12. Contact

Endpoint Solutions - Proctoring

Email: support@endpoint.solutions
Suggested subject line: "Proctoring Privacy Request"

For the device-monitoring and BYOD product, see https://endpoint.solutions/privacy.

13. Chrome extension permissions

The Extension requests these Chrome permissions, and it uses all of them:

  • tabs - detect switching away from the exam tab, and close tabs opened during the exam.
  • windows - detect the exam window losing focus, and keep it in front.
  • webNavigation - detect pop-ups and new-window links opened from the exam page.
  • storage - hold session state on your own device while the exam runs.
  • scripting - load the monitoring scripts into the exam page.
  • notifications - show you Chrome notifications about the state of monitoring.
  • activeTab - interact with the tab in the foreground.

The Extension also declares an optional permission to access any HTTPS site. Because it is optional, Chrome does not grant it when you install the Extension. It is requested only if you press the button that allows it, only for the single web address that hosts your exam, and only where the launching institution's own configuration vouches for that address. The Extension gives the permission back when the exam session ends.

The Extension contains no remotely loaded code.

When you install the Extension and complete check-in, you acknowledge that you have read this policy, that you understand what is collected and who receives it, and that you agree to the collection and the use described here for the purpose of sitting a proctored exam.

15. Changes to this policy

We can update this policy. When we do, we will change the "Last Updated" date at the top and record the change in the table below. The current version of this policy is the one that applies to your exam, and it is the version linked from the Extension's Chrome Web Store listing. Where a change is material, we will tell the institutions that use the service.

Our consent record keeps the fact that you accepted the exam rules, the time and the IP address. It does not keep a copy of the text you accepted or a version number for it, so we cannot show which revision of this policy was in force for a past session.

Date Change
2026-09-03 First published version. Rewritten against the current system. Corrected the description of how check-in media is stored and protected; disclosed the OpenAI image-analysis processor and exactly what is sent to it; disclosed the capture of clipboard text, full web addresses and IP addresses; replaced the stated 30-day and 90-day retention periods with an accurate statement that no automated age-based deletion is implemented; and removed claims of multi-factor authentication, at-rest encryption, end-to-end encryption, security certification and audit programmes that the system does not implement.

If you have a question about this policy, or about the data we hold, write to support@endpoint.solutions.

(c) 2026 Endpoint Solutions.


This policy covers the Endpoint Proctoring browser extension and exam sessions. The policy for the Endpoint device-monitoring platform is at /privacy.