Privacy & child safety
SchoolSetu handles children's personal and educational data. This summary explains the commitments built into the product. It is a demo document, not legal advice, and must be reviewed by qualified Indian legal counsel before production launch.
What we never do
- • No behavioural advertising or profiling of children
- • No sale of student data to anyone
- • No hidden tracking or third-party ad pixels
- • No facial recognition or emotion detection
- • No public student leaderboards by default
- • No use of student conversations to train models
Consent and control
- • Purpose-specific consent, recorded with a full consent history
- • Verifiable parent or lawful guardian consent where required
- • Consent withdrawal workflow at any time
- • Parent access and correction requests
- • Data export and deletion, subject to legal retention rules
Data handling
- • Data minimisation and purpose limitation
- • Role-based visibility — staff only see what their role requires
- • Complete tenant isolation between schools
- • Encryption in transit and at rest
- • Append-only audit events for sensitive changes
- • Student personal data is never written to application logs
Grievances
- • Privacy contact: privacy@demo.schoolsetu.app (demo address)
- • Breach-response workflow with school notification
- • A privacy impact assessment is a release gate before production