Privacy

In short: we store an encrypted token, you hold the key, and Claude can only read.

Encryption and access

Your LMS token is encrypted at every step. It is decrypted only in memory, and only while a request is being served.

1 · Connect

The bookmark encrypts the token before it leaves your browser

On your LMS, the Connect bookmark asks for an app token and encrypts it with our server's public key. The token never appears in plain text in a URL, your browser history or the console.

RSA-OAEP · server public key

2 · Stored

Only your personal key can unlock it

The server encrypts the token with a key derived from your personal key and stores only that ciphertext, plus a check value for the key. We don't keep your key, so nobody, including us, can decrypt the stored token without it.

AES-256-GCM · key derived from your personal key

3 · In use

Decrypted in memory, one request at a time

When you connect an app such as Claude, you enter your key once. The token is decrypted and placed in that app's connection record, encrypted again with the app's own access token. On each request it is decrypted in memory, used for one read-only LMS call and discarded.

Encrypted per app · decrypted per request

Who can read your token?

You, with your personal keyYes

The key is shown once and never stored.

Mcp4Lms, at restNo

The database holds only ciphertext and a check value for your key.

Mcp4Lms, during a requestIn memory only

Decrypted while serving the request, then discarded.

ClaudeNo

Claude receives course data, never the token itself.

Your LMSIssued it

You can revoke it there by logging out of all devices.

What we store

We don't store your name, email, password, course content or grades. Course data passes through our server to Claude only when Claude requests it, and is never saved or logged.

What we never see

Your LMS or Microsoft password. You log in to your LMS on its own site, in your own browser. The Connect bookmark only asks the LMS for an app token, the same kind the official Moodle app uses, and encrypts it before sending it to us.

What Claude can do

Read your courses, course contents, deadlines, assignments and submission status, grades, announcements, and the text of course files (PDF, Word, PowerPoint, plain text). Mcp4Lms allows only a fixed set of read-only LMS functions. Claude cannot submit assignments, post, send messages or change anything.

What you should know

Security contact and disclosure

Found a vulnerability? Email security@mcp4lms.com. Include the steps to reproduce it, and don't access other people's data while testing. We aim to acknowledge reports within 3 days and will tell you when the issue is fixed.

For anything else, such as questions, data requests or requests from a university, write to maintainers@mcp4lms.com. The code is public on GitHub; please report security issues by email rather than in a public issue.

Opting out

  1. Open Account, enter your key, and disconnect individual apps or delete everything. Deletion removes your account, the encrypted token and all app connections immediately.
  2. Lost your key? Connect again from your LMS. This issues a new key and invalidates the old one, and you can then delete your account from the Account page.
  3. To also end the app token on your LMS, log out of all devices there.
  4. If you do nothing, your data is deleted automatically when the access period you chose expires.
  5. If you administer an LMS and want it excluded from Mcp4Lms, email maintainers@mcp4lms.com.

Disclaimer

Mcp4Lms is provided free of charge, as is, without warranty of any kind. It is an independent open-source project released under the AGPL-3.0 license. It is not affiliated with, endorsed by or operated by any university, Moodle HQ, Anthropic, OpenAI, Google, Anysphere (Cursor) or any other AI tool vendor.

You use the service at your own risk. You are responsible for keeping your personal key private, for how you use your course data in AI tools, and for complying with your university's rules on account use and academic integrity.

AI tools can misread, omit or summarize information incorrectly. Always verify deadlines, grades and assignment requirements on your LMS before acting on them.

To the extent permitted by law, the people running this service are not liable for any damages, missed deadlines, lost data, grading outcomes or account problems arising from its use. The service may change or stop at any time without notice.