Audit & privacy
Understand the plugin-owned personal data, audit surfaces, and Moodle privacy workflow.
Audit surfaces
Preferences audit
Search plugin actions, filter by action name, and open recorded details. Requires the audit_logs feature.
Report audit
Review a report’s visits, time, access dates, IP, operating system, browser, and calendar drilldowns.
Stored data
Plugin-owned personal data can include:
- report enabled/favorite preferences and user parameters;
- direct user audience assignments;
- schedule ownership and delivery configuration;
- Lenarys Analytics action logs and client metadata;
- AI prompts, context summaries, responses, generated definitions, and status;
- page visits, tracked seconds, and daily/hourly aggregates;
- the first-run guide completion preference.
Moodle privacy API
The plugin declares its data through Moodle’s privacy subsystem in the system context. It supports context discovery, user listing, export, deletion for one user, deletion for approved user lists, and deletion for all users in the system context.
External data boundary
The licensing service should receive only the minimum site, license, catalogue, update, and Moodle Marketplace entitlement metadata required for the product. Moodle users, courses, grades, report rows, and learning-time records should not be sent to the licensing API. Payment-card data is processed by Moodle Marketplace and its connected Stripe flow, never by the plugin.
Governance checklist
- Document purpose and lawful basis before enabling tracking.
- Publish a clear privacy notice for users.
- Limit analytics capabilities and audience access.
- Define retention for plugin logs, AI history, and tracking data.
- Review schedule recipients and exported files.
- Exercise Moodle privacy exports and deletions in a test environment.
Was this page helpful?
Your feedback is stored in this browser.