Privacy Policy
Last updated 24 September 2026
Klassmate ("we", "us", "the Platform") provides a school-management application used by schools, teachers, office staff, and the guardians of students at those schools. This policy explains what personal data we collect, why, and what rights you have over it — including specific protections for the data of students, who are minors.
1. Who this applies to
This policy covers three kinds of people who use Klassmate:
- School staff (administrators, teachers) — accounts created by the school.
- Guardians (parents/guardians of enrolled students) — accounts created by the school on the guardian's behalf, activated by the guardian.
- Students — do not hold accounts themselves. Their data is entered and managed by the school and viewed by their guardian(s) and their teachers.
2. What we collect
| Category | Examples | Collected from |
|---|---|---|
| Student profile | Name, date of birth, gender, blood group, address, admission number, roll number, photo | School (entered by staff, or via CSV import) |
| Academic & attendance | Attendance records, class diary entries, homework, worksheets | Teachers |
| Fees & payments | Invoices, payment status, payment method, transaction references | School office; payments processed via Razorpay |
| Communication | Announcements, class broadcasts, private replies between a guardian and a teacher | Teachers and guardians using the app |
| Staff/guardian account data | Name, email, phone, password (stored hashed, never in plain text), role | School (staff), guardian (own account) |
| Device & usage | Push-notification device tokens, basic error/crash reports | Automatically, from the mobile app |
3. Children's data — specific protections
Much of the data above concerns students, who are minors. We treat this with additional care, in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act):
- A student's data is processed on the basis of consent given by their guardian, not the student directly. A guardian is asked to consent when activating their Klassmate account.
- We do not use student data for behavioural tracking, profiling, or targeted advertising, and we do not run advertising on Klassmate at all.
- Student data is visible only to that student's own guardian(s) and the teachers/staff at their school — never to other guardians, other schools, or the public.
- A guardian may request correction or erasure of their child's data at any time by contacting the school or writing to us at theadmin@klassmate.space.
4. Why we process this data
- To operate the core features of the app: attendance, the class diary, fee collection, and school-to-guardian communication.
- To send absence alerts and fee-due reminders to guardians.
- To process payments and issue receipts.
- To maintain the security and integrity of the platform, and to investigate misuse.
- To comply with legal obligations (e.g. financial record-keeping requirements).
5. Who we share data with
We do not sell personal data. We share it only with the following, each solely to provide the service:
- Razorpay — payment processing. Razorpay receives what's needed to process a payment; Klassmate does not receive or store full card numbers.
- Cloudflare R2 — storage for uploaded photos and message attachments.
- Supabase — our database host.
- MSG91 — SMS delivery for absence/fee alerts, once enabled for a school.
- The school itself — a school's own staff can see the data of its own students, as needed to run the school.
Each of these is bound to use the data only to provide their specific service to us, not for their own purposes.
6. Where data is stored
Klassmate's database is currently hosted on Supabase infrastructure in Singapore (ap-southeast-1). Uploaded media is stored via Cloudflare's global network. We review data-residency requirements as Indian data-protection regulation develops.
7. How long we keep data
We retain a student's data for as long as they are enrolled at the school, plus a reasonable period after they leave to handle any outstanding administrative matters. Financial records (invoices, payments, receipts) are retained for 8 years from the date of the transaction, in line with applicable financial record-keeping requirements under Indian law.
8. Your rights
Under the DPDP Act, you (or, for a student, their guardian) have the right to:
- Access the personal data we hold.
- Request correction of inaccurate data.
- Request erasure of data, subject to our legal retention obligations (see §7).
- Withdraw consent at any time (this may limit or end your ability to use the app).
- Lodge a complaint with our Grievance Officer, and with India's Data Protection Board if unresolved.
9. Security
Access to the platform requires authentication; each school's data is isolated from every other school's at the database level. Passwords are stored hashed, never in plain text. We use HTTPS everywhere and monitor for errors and security issues in production.
10. Grievance Officer
For privacy questions, correction/erasure requests, or complaints, contact our Grievance Officer at theadmin@klassmate.space.
11. Changes to this policy
We may update this policy as the product or the law changes. Material changes will be reflected by updating the date at the top of this page.