Privacy¶
The SUFS Expense Tracker is an independent, unofficial tool; it is not made by or affiliated with Step Up For Students. Its makers don't run any service that receives your data: there are no accounts with us, no analytics, no tracking and no advertising. What you enter stays where you choose to keep it, as described below for each way of using the tracker.
This policy applies from 6 October 2026. Questions: open an issue at gitlab.com/uda/sufs-tracker.
The tracker page (standalone)¶
The tracker you open as a web page, for example at sufs-tracker.myjigs.de, keeps everything in your own browser: your decisions, expenses, students and attached files stay in that browser's storage on your device. Nothing you enter is sent anywhere.
- A data file or folder you choose (Chrome and Edge) receives a copy of your data on your own computer. If that folder is synced by a service such as Google Drive, Dropbox, OneDrive or iCloud, that service handles it under its own terms; people you share the folder with see the data in it.
- Reading receipts (text recognition, PDF text) happens in your browser; the file isn't uploaded.
- Exports are files saved to your device.
- What the page loads from elsewhere: its fonts come from Google Fonts, and, the first time they're needed, the libraries for reading files and for .sqlite exports come from the public code hosts cdnjs and jsDelivr. Like any website, these receive the usual details of a download request (your IP address and browser), not your data. The page itself is served by GitLab Pages, which keeps ordinary web server logs under GitLab's privacy statement.
The browser extension¶
The SUFS Tracker companion for Chrome and Edge works in your browser and keeps what it reads in the extension's own storage on your device.
- On the SUFS portal (
apply.stepupforstudents.org, and no other site), it reads the list of your reimbursement requests that the portal page loads for you: their status, items, amounts, dates, reviewers' reasons and comments. It doesn't change what the page does. Once a day at most it asks the portal for that same list again, exactly as the portal's own page does, with your existing sign-in, which it never stores or sends anywhere. - On the new-reimbursement form, it fills fields from an expense only when you click to do so. It never submits anything; you review and submit.
- Where it sends data: only to the tracker you choose in its options: the tracker built into the extension (it stays in the extension), a tracker page at an address you enter (the extension then has access to that one address, and passes data to that page in your browser), or a tracker server you enter with your own access token (see below).
- The bundled version includes the tracker itself and everything it needs; it loads nothing from the internet. Its data stays in the extension's storage on your device, and removing the extension deletes it.
- The debug version can also record the structure of portal screens, for mapping the portal. Recordings have personal details removed, stay in the extension, and leave it only if you export them yourself.
A tracker server¶
The shared, server version of the tracker is software that anyone can run. Whoever hosts a tracker server controls it and is responsible for the data on it; this project doesn't receive or have access to it.
A tracker server stores what its users enter (decisions, expenses, students, attached files), their usernames, and their passwords and access tokens in a form that can't be read back. It sets a cookie to keep you signed in. Like most web servers, it may log requests (addresses and pages asked for) as its host has configured. Ask the person or organization hosting the server you use about their own practices.
Children's information¶
The tracker is meant for parents and guardians managing their family's SUFS scholarships. Information about students that you enter (names, birth years, programs, purchases) stays wherever you keep it, as described above.
Changes¶
If this policy changes, the new version is published on this page with the date it applies from.