Privacy Policy
Last updated: June 2026 · Applies to school.appcafe.in and all school instances powered by AppCafe School Management.
AppCafe School Management ("the Platform", "we", "us") is built to help schools manage their
day-to-day operations. This policy explains what personal data we collect, why we collect it,
how it is protected, and what rights you have over it. Please read it carefully.
1. Who This Policy Covers
This policy applies to all users of the Platform, including:
- Students — enrolled learners with a student portal account.
- Parents / Guardians — linked to one or more students, with a parent portal account.
- Teachers & Class Teachers — academic staff with a teacher portal account.
- Support Staff — non-teaching staff with a staff portal account.
- Bus Drivers — transport staff with a driver portal account.
- Administrators / Principal / HeadMaster — school management with elevated access.
- Visitors — anyone who browses the public landing, contact, or admission pages.
2. Data We Collect
2.1 Account & Identity
- Full name, email address, and system-generated username.
- Role assignment (student, parent, teacher, staff, driver, admin).
- Hashed password — plaintext passwords are never stored.
- Phone number (where provided during enrolment or profile setup).
2.2 Student Academic Records
- Admission number, class, section, academic year, and board/medium.
- Daily attendance (morning and afternoon sessions).
- Exam schedules, marks entered by teachers, and published results.
- Library borrowing history — books issued, returned, and any overdue fines.
- Fee structure, payment records, receipts, and outstanding balances.
- Leave applications and approval status.
- Transport assignment — bus route, stop, and daily boarding/alighting records.
- Doubts submitted and replies received from teachers.
- Class documents and videos accessed.
- AI Tutor conversation history (stored locally on the school's server; not transmitted externally).
2.3 Teacher & Staff Records
- Subject assignments, class/section allocation, and timetable.
- HR actions — appointment letters, salary records, leave history, and employment documents.
- Attendance entries made by the teacher.
- Exam results entered and published.
- Messages and replies within the platform inbox.
2.4 Parent Records
- Linked student(s) and relationship.
- Notifications received (attendance alerts, fee reminders, results).
- Bus tracking sessions — the platform does not record the parent's device location.
- Messages sent and received via the platform inbox.
2.5 Contact & Admission Inquiries
- Name, email, phone, and message text submitted via the Contact or Admission pages.
- These are stored and visible only to school administrators.
2.6 Technical / Usage Data
- Standard web server logs (IP address, browser type, pages visited) — used for security monitoring and debugging only.
- No third-party analytics (e.g. Google Analytics) are embedded in the authenticated portal.
3. How We Use Your Data
- To operate the school management functions described above.
- To send WhatsApp or email notifications — attendance alerts, fee reminders, result announcements — when enabled by the school administrator.
- To allow teachers and administrators to carry out their institutional duties.
- To generate reports, certificates, and analytics used by school management.
- To authenticate users and enforce role-based access controls.
- To respond to contact or admission inquiries submitted through the public pages.
We do not use personal data for advertising, profiling, or any commercial purpose unrelated to school management.
4. Data Sharing
We do not sell, rent, or trade personal information. Data may be shared only in the following limited circumstances:
- Email delivery — outgoing notification emails are relayed via a configured SMTP provider (e.g. Gmail SMTP or SendGrid). Only the minimum required data (recipient address and message body) is transmitted.
- WhatsApp / SMS notifications — sent via MSG91 (Indian provider). Only the recipient phone number and message text are transmitted.
- Legal obligation — if required by applicable Indian law or a lawful order from a competent authority.
- School-hosted instances — when a school runs its own self-hosted instance, data resides entirely on their server and is under their control.
5. Data Security
- All passwords are hashed using ASP.NET Core Identity's default PBKDF2 algorithm. Plaintext passwords are never stored or logged.
- Access to all data is gated by role-based authorisation — a parent cannot see another student's records; a teacher cannot access fee payment data; and so on.
- Anti-forgery tokens are enforced on all POST actions to prevent cross-site request forgery (CSRF).
- The AI Tutor (Ollama) runs entirely on-premise. No student conversations are sent to external AI services.
- HTTPS is enforced on the demo instance and recommended for all school deployments.
6. Data Retention
- Student academic records (attendance, results, fees) are retained for the duration required by applicable Indian educational regulations and the school's own policy.
- Deactivated or graduated student accounts are archived — they remain in the database for historical reporting but are not actively accessible for login.
- Teacher and staff employment records are retained for the period required by labour law.
- Contact and admission inquiry records are retained until reviewed by an administrator and may be deleted thereafter.
- Server access logs are retained for up to 90 days for security purposes.
7. Children's Privacy
The Platform is used in a school context and may hold data about minors. Student accounts
are created by school administrators — students do not self-register. Parent accounts are
linked to students by the school, providing an additional layer of oversight. We do not
knowingly collect data from children outside the school management context.
8. Your Rights
Depending on applicable law, you may have the right to:
- Access — request a copy of the personal data held about you.
- Correction — request that inaccurate data be updated (e.g. name spelling, contact number).
- Deletion — request removal of data where there is no legal or operational requirement to retain it.
- Portability — request your data in a structured, machine-readable format.
To exercise any of these rights, contact your school administrator directly, or reach us via
the Contact Us page.
9. Cookies
The Platform uses a single session cookie to maintain your login state (ASP.NET Core Identity
authentication cookie). No third-party tracking or advertising cookies are used.
10. Changes to This Policy
We may update this policy from time to time to reflect changes in the platform or in
applicable regulations. Significant changes will be communicated through the platform or
via the registered contact email. Continued use after the updated policy is posted
constitutes acceptance of the revised terms.
11. Contact
For any privacy-related queries, data access requests, or concerns, please use the
Contact Us page. We will respond
within a reasonable time.