1. Scope and operating roles
This notice applies to the School LMS application and its learning, assessment, communication, attendance, support, HR, live-class, and AI-assisted features. Where a school or institution manages accounts and determines why records are processed, that institution may have its own legal responsibilities and privacy notice in addition to this one.
Effective date: 16 July 2026.
2. Data we process
- Identity and account information such as name, email, role, grade, parent-child relationship, and authentication identifiers.
- Learning records including enrollments, content progress, practice activity, assessment attempts, answers, timing, grades, feedback, and improvement plans.
- Attendance, leave, staff, HR, shift, and assigned-asset records where those modules are used.
- Chats, support tickets, AI doubt conversations, moderation records, and associated media.
- Uploaded images, documents, audio, video, profile media, answer images, and IELTS test assets.
- Operational security data such as request identifiers, failure categories, rate-limit events, and deployment diagnostics. Private message or answer bodies are not intended to be written to operational logs.
3. Why we use it
- Deliver role-appropriate learning, teaching, parent, staff, and administration workflows.
- Run assessments, preserve attempt integrity, provide results, and support teacher review.
- Operate live classes, communication, support, safety moderation, attendance, and institution workflows.
- Generate requested AI assistance, feedback, evaluation, content, audio, and academic suggestions.
- Protect accounts, prevent abuse, troubleshoot failures, and maintain reliable service.
- Meet applicable academic, contractual, safety, audit, and legal obligations.
School LMS does not currently contain an advertising system and does not use student records for targeted advertising.
4. Children and parent or guardian involvement
The platform is designed to process information about students, including people under eighteen. Institution-managed accounts should be created under the institution's authority and applicable parent or guardian process. Direct-learning accounts involving a child require an appropriate parent or guardian basis before personal data is used.
School LMS should not be used to profile, track, or target children in a way that is unrelated to education, safety, support, or institution operations. Parent-child access is restricted to verified account links.
5. AI-assisted processing
Some answers, essays, prompts, images, scripts, course material, and progress signals may be sent to configured AI providers when a user invokes an AI feature. AI output may be incomplete or incorrect. Teachers and administrators remain responsible for consequential academic or administrative decisions.
Read the detailed AI transparency notice.
6. Service providers
Current technical providers may include Supabase for authentication and PostgreSQL data, Vercel for hosting, Cloudinary for media, LiveKit for live classes, and configured AI services such as GitHub Models, Groq, OpenAI, Gemini, or Wit.ai. The exact provider used depends on the enabled feature and deployment configuration.
Providers may process data in other countries. Provider contracts, account settings, retention, and model-training controls must be reviewed by the service operator before commercial launch.
7. Retention and deletion
- Chat messages are configured for a fifteen-day application retention cycle.
- Chat media retention is controlled by administrator settings and provider deletion is attempted before database metadata is removed.
- Academic, grade, attendance, audit, safeguarding, support, and employment records may need to be retained after account access ends.
- Provider-hosted files and database records have separate deletion processes.
- Backups may retain deleted records temporarily until the applicable backup cycle expires.
A request for erasure is therefore assessed record by record rather than treated as an unsafe blanket database deletion.
8. Access and sharing
Access is limited by role and relationship: students access their own learning records, parents access linked children, teachers access assigned courses or classes, and administrators access institution operations. Authorized support, moderation, security, and legal access may occur where necessary.
School LMS does not claim that every administrator action is invisible to administrators; privileged access is instead restricted, logged where implemented, and subject to policy.
9. Your choices and rights
Depending on applicable law and the institution relationship, you may request access, correction, eligible erasure, account deactivation, consent withdrawal, grievance handling, or parent or guardian review. Identity and authority may need to be verified before action is taken.
10. Security and changes
School LMS uses authenticated role checks, bounded uploads, rate limits, restricted provider credentials, privacy-scrubbed diagnostics, and automated regression checks. No system can promise absolute security. Material changes to this notice should receive a new version and effective date.