Privacy Policy
Last updated: 2026-08-20
This Privacy Policy describes how Schoolar ("we", "us", "our") collects, uses, and protects information when schools, staff members, parents, and students ("you") use the Schoolar platform at schoolar.in and the related mobile applications (the "Service").
1. Information we collect
We collect information in the following ways:
- Information you provide. When a school signs up, we collect the school's name, address, contact details, the principal's name and email, and billing information. When staff, students, or parents are added to the platform — typically by the school — we store the information the school enters: names, contact details, class, section, attendance, marks, fees, and similar academic and administrative records.
- Information generated through use. Logs of feature usage, pages visited, IP addresses, device information, and approximate location derived from your IP address are collected to operate the Service, troubleshoot issues, and detect abuse. This is separate from the precise GPS location described in Section 3, which is collected only during an attendance punch.
- Payments. When a school subscribes or a parent pays fees, payments are processed by Razorpay. We receive payment-status information (success, failure, refund) but never receive or store full card numbers.
2. Biometric data (staff face attendance)
Schools may enable face-verified attendance punching for their staff. This section applies only to staff members at schools that have turned that feature on. We never collect face data from students or parents. No student or parent is ever asked to enroll a face, and no student or parent record can hold a face template.
What is stored. During enrollment you are guided through several captures from different angles. Each capture is converted on your own device into a face template — a list of numbers (a mathematical descriptor) computed from the image. Only those numbers are transmitted to our servers and stored against your staff record. The photographs themselves are never transmitted and never stored. A stored template cannot be turned back into a picture of you.
Templates may be added automatically after you enroll. When a punch succeeds, the template computed during that punch may be added to your stored set, so that recognition keeps working as your appearance, eyewear, facial hair, or lighting conditions change. This means your enrollment record grows over time from your own successful punches, without any further action or prompt from you. No photograph is stored when this happens — only the numeric template.
Where the comparison happens. The match between the face at the camera and your stored templates is computed on your device. Your device's camera is active only while an enrollment or a punch is actually in progress.
Purpose limitation. Face templates are used for exactly one purpose: verifying that the person recording an attendance punch is the staff member the record belongs to. They are not used to identify you anywhere else in the Service, are not used to infer age, emotion, health, or any other characteristic, are not used for advertising or profiling, are never sold, and are never shared with any third party.
Retention and deletion. Your templates are kept for as long as face punching is enabled for you at your school. They are deleted when your school's principal resets your enrollment (which they can do at any time, and which forces a fresh enrollment), when your staff record is removed, or when you delete your account as described in Section 10. Removal from the live database is immediate; residual copies inside routine encrypted database backups age out on the normal backup rotation.
3. Location data (staff attendance punches)
This section likewise applies only to staff at schools that have enabled attendance punching.
We read precise GPS location, not approximate location. When you punch in or punch out, the app asks your device for its location with high accuracy enabled, so that the distance between you and your school can be measured meaningfully.
What is stored, and for how long. Every punch attempt permanently records, as part of the attendance event log: the latitude and longitude your device reported, the accuracy radius your device reported for that reading, and the distance we compute between that point and your school's registered location. These values are retained for as long as the attendance record they belong to.
Refused attempts are recorded too. If a punch is rejected — because you were outside the school's permitted radius, because the GPS reading was too imprecise to trust, or because the face check did not pass — the attempt is still written to the log together with its coordinates. Starting a punch and not completing it successfully therefore still leaves a stored location record.
Who can see it. Your school's principal can see the coordinates, the reported accuracy, the computed distance from the school, and the reason a punch was flagged or refused, for every punch including refused ones. Other staff members cannot: each staff member can see only their own punch history.
We never collect your location in the background. Location is read only in the moment you are actively making a punch, only while that screen is open, and the reading stops as soon as you leave it. The app requests no background-location permission and runs no background location service — you can verify this yourself in the permissions list on the app's Play Store listing.
4. How we use information
We use the information described above to:
- Provide, operate, and improve the Service
- Verify staff attendance where a school has enabled face and location punching
- Send transactional notifications related to the school's operations (fees due, attendance alerts, exam schedules, report cards) via the channels the school has enabled (email, SMS, WhatsApp, in-app)
- Detect, investigate, and prevent fraud and abuse
- Comply with applicable law, including tax, accounting, and education regulations in India
- With the school's permission, send occasional product updates and educational content
5. The school is the data controller
For information about staff, students, and parents added by a school, the school is the data controller and Schoolar is the data processor. The school is responsible for obtaining the consents required to upload and use this information on the platform — including, where a school enables face attendance, the consents required from its staff. Parents and students seeking to access, correct, or delete their information should first contact their school.
6. How we share information
We do not sell personal information. We share information only with:
- Service providers who help us operate the Service — cloud hosting (Supabase / AWS regions), payment processing (Razorpay), messaging providers (WhatsApp Business, SMS gateways, email providers), and analytics. These providers are contractually obligated to use the information only to perform services for us. Face templates are not shared with any of them.
- Authorities when required by law, valid legal process, or to protect rights, property, or safety.
- Successors in connection with a merger, acquisition, or sale of assets, with notice to affected schools.
7. Data security
Schoolar uses industry-standard security measures: encryption in transit (TLS), encryption at rest, row-level security in the database to isolate each school's data, role-based access controls, audit logs for sensitive actions, and regular backups. No system can be guaranteed perfectly secure, but we work continuously to reduce risk.
8. Data retention
We retain school data for the duration of the school's subscription and for 60 days after cancellation to allow data export. After that, personal information is deleted or anonymized, except where retention is required by law (for example, financial records may be retained for the period required under Indian tax law).
9. Your rights
Depending on the laws applicable to you, you may have rights to access, correct, delete, or restrict the use of your personal information, and to object to its processing. To exercise these rights, contact your school first; if the school does not respond, contact us at contact@schoolar.app.
10. Deleting your account
You can delete your Schoolar account yourself:
- Signed in, in the mobile app or on the web: open My Profile and choose Delete my account.
- Without signing in: the instructions are published at schoolar.in/delete-account.
What deletion removes: your login credentials, your profile (name, phone number, avatar), your role assignments, your school memberships, your push-notification device registrations, and — if you are a staff member enrolled in face attendance — every stored face template.
What deletion does not remove: records that belong to your school rather than to you, such as attendance history, marks, and fee and payment records. Your school is the data controller for those (see Section 5) and may be legally required to keep them; financial records are retained for the period required under Indian tax law. To have school-held records about you corrected or erased, contact your school.
If you are the sole owner of a school that still has other members, we cannot delete your account on the spot, because removing the only owner would lock every remaining teacher, accountant, and parent out of their school's records. In that case we record your deletion request and tell you so immediately; we will contact you within 7 days to transfer ownership, and your account is deleted within 30 days of your request.
11. Children's privacy
Schoolar is used in schools and contains information about students, including children. Information about children is collected and used by the school for legitimate educational purposes. Schools using Schoolar are responsible for obtaining the parental consents required by law. The face and location features described in Sections 2 and 3 are available to staff members only and are never applied to students.
12. International transfers
The Service is operated from infrastructure located in India and other regions our hosting providers operate in. By using the Service, you consent to the transfer of information to these regions.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to the school's primary contact and posted on this page with an updated "Last updated" date.
14. Contact
Questions about this Privacy Policy? Email us at contact@schoolar.app.